SOC 2 readiness hub
SOC 2 templates & guides
Score gaps, read startup-focused guides, download Word-ready templates, or grab a phase toolkit — everything for audit readiness in one place.
Start here
Free · ~5 min assessmentSOC 2 Readiness Gap Assessment
Eight questions on scope, controls, policies, and evidence — get a readiness score with SOC template and phase kit picks.
Start assessment →Guides & resources
Long-form articles for scoping, policies, evidence, and timelines — view all guides.
SOC 2 Readiness for Bootstrapped Startups
Templates vs. automation platforms — cost, effort, and timelines for lean teams.
Read guide → GuideSOC 2 System Description for SaaS Startups
What to include, what to skip, and how to draft an auditor-approved narrative.
Read guide → GuideSOC 2 Readiness Checklist for Startups
A practical 12-week audit plan for bootstrapped SaaS teams.
Read guide → GuideWrite a SOC 2 Security Policy Without a Consultant
Step-by-step guide for bootstrapped SaaS founders.
Read guide → GuideSOC 2 Scoping Guide: System Boundary
Define your authorization boundary and TSC scope without over-scoping.
Read guide → GuideSOC 2 Evidence Collection Checklist
Screenshots, exports, and folder structures auditors actually request.
Read guide →Toolkits
Bundled ZIP downloads with every template and guide for that stage of your audit journey — for teams that want the full program, not one-off files.
Starter Kit
Scoping, system description, core policies, and project plan — foundation before implementation.
11 templates
View toolkit → Phase 2 · ToolkitImplementation Kit
HR, engineering, SDLC, access reviews, incidents, and vendor controls — includes Phase 1.
34 templates
View toolkit → Phase 3 · ToolkitAudit & Evidence Bundle
Governance minutes, evidence mapping, PBC tracker, and auditor handoff — full Phases 1–2 included.
Complete bundle
View toolkit →Templates
À la carte downloads when you only need one file — or get every SOC document synced in a phase kit above.
Readiness Guide & Roadmap
Step-by-step preparation with scoping prompts, ownership tables, and evidence examples.
View template → SOC-002 · .docxScoping Questionnaire
Structured questions for systems, vendors, environments, and TSC selection.
View template → SOC-003 · .xlsxControl Scoping Worksheet
Map TSCs to systems, assign owners, and track implementation status.
View template → SOC-004 · .docxSystem Description Workbook
Document architecture, boundaries, and data flows for auditors.
View template → COR-001 · .docxInformation Security Policy
Foundational policy for assets, acceptable use, and security responsibilities.
View template → COR-002 · .docxAccess Control Policy
Provisioning, access reviews, privilege management, and authentication.
View template →