Includes Phases 1–2 • Auditor handoff & evidence

SOC 2 Phase 3 Audit & Evidence Bundle

Close the loop from control operation to auditor delivery. Governance minutes, risk registers, evidence mapping, PBC trackers, and format-only samples — plus the full Phase 1 and Phase 2 kits in one ZIP.

Includes Phase 1 Starter Kit + Phase 2 Implementation Kit

61 Templates (all phases)
PBC-ready Evidence index & tracker
Samples Format-only examples (3D_Samples)
Includes Phase 1 + Phase 2 kits Evidence mapping & PBC tracker Risk register & governance minutes Auditor kickoff & Q&A prep

Audit week, organized

SOC-021 evidence index and SOC-028 PBC tracker reduce scrambles when the auditor asks for proof.

Criteria traceability

SOC-022 and SOC-023 map Trust Services Criteria to artifacts and control owners.

Complete program in one ZIP

Phases 1–2 included — 1_Foundation through 2C plus 3A–3D governance and evidence folders.

Reduce rework penalties

Structured handoff beats paying consultants to rebuild evidence indexes from scratch mid-audit.

What’s inside the ZIP

61 templates — foundation, implementation, governance, evidence, auditor handoff, and format samples

1 Foundation

COR-001Word

Information Security Policy

Editable template with section-by-section guide at lintgrc.com/templates/information-security-policy-template/.

SOC 2Foundation
COR-002Word

Access Control Policy

Editable template with section-by-section guide at lintgrc.com/templates/access-control-policy-template/.

SOC 2Foundation
COR-003Word

Risk Management Policy

Editable template with section-by-section guide at lintgrc.com/templates/risk-management-policy-template/.

SOC 2Foundation
COR-004Word

Data Retention and Deletion Policy

Editable template with section-by-section guide at lintgrc.com/templates/data-retention-deletion-policy-template/.

SOC 2Foundation
COR-005Word

Organizational Chart Template

Editable template with section-by-section guide at lintgrc.com/templates/organizational-chart-template/.

SOC 2Foundation
SOC-001Word

SOC 2 Readiness Guide and Roadmap

Editable template with section-by-section guide at lintgrc.com/templates/soc-001-readiness-guide-and-roadmap/.

SOC 2Foundation
SOC-002Word

SOC 2 Scoping Questionnaire

Editable template with section-by-section guide at lintgrc.com/templates/soc-2-scoping-questionnaire/.

SOC 2Foundation
SOC-003Excel

SOC 2 Control Scoping Worksheet

Editable template with section-by-section guide at lintgrc.com/templates/soc-2-control-scoping-worksheet/.

SOC 2Foundation
SOC-003AExcel

SOC 2 Readiness Scanner and Gap Analysis

Editable template with section-by-section guide at lintgrc.com/templates/soc-2-readiness-scanner-gap-analysis/.

SOC 2Foundation
SOC-004Word

SOC 2 System Description Workbook

Editable template with section-by-section guide at lintgrc.com/templates/soc-2-system-description-workbook/.

SOC 2Foundation
SOC-005Excel

SOC 2 Project Plan Template

Editable template with section-by-section guide at lintgrc.com/templates/soc-2-project-plan-template/.

SOC 2Foundation

2A People and HR

COR-006Word

Security Awareness Policy

Editable template with section-by-section guide at lintgrc.com/templates/security-awareness-policy-template/.

SOC 2Implementation
HR-001Word

Employee Onboarding Checklist

Editable template with section-by-section guide at lintgrc.com/templates/employee-onboarding-checklist-template/.

SOC 2Implementation
HR-002Excel

Employee Offboarding Checklist and Log

Editable template with section-by-section guide at lintgrc.com/templates/employee-offboarding-checklist-template/.

SOC 2Implementation
HR-003Word

Contractor and Vendor Onboarding Checklist

Editable template with section-by-section guide at lintgrc.com/templates/contractor-vendor-onboarding-checklist-template/.

SOC 2Implementation
SOC-006Excel

Security Training Completion Log

Editable template with section-by-section guide at lintgrc.com/templates/security-training-completion-log-template/.

SOC 2Implementation

2B Policies and Admin

COR-007Word

Incident Response Policy

Editable template with section-by-section guide at lintgrc.com/templates/incident-response-policy-template/.

SOC 2Implementation
COR-008Word

Vendor Management Policy

Editable template with section-by-section guide at lintgrc.com/templates/vendor-management-policy-template/.

SOC 2Implementation
COR-009Word

Data Classification Policy

Editable template with section-by-section guide at lintgrc.com/templates/data-classification-policy-template/.

SOC 2Implementation
COR-010Word

Asset Management Policy

Editable template with section-by-section guide at lintgrc.com/templates/asset-management-policy-template/.

SOC 2Implementation
COR-011Word

Acceptable Use and Remote Work Policy

Editable template with section-by-section guide at lintgrc.com/templates/acceptable-use-remote-work-policy-template/.

SOC 2Implementation
COR-012Word

Physical Security Policy (Remote-First)

Editable template with section-by-section guide at lintgrc.com/templates/physical-security-policy-template/.

SOC 2Implementation
COR-013Excel

Document Control and Version Log

Editable template with section-by-section guide at lintgrc.com/templates/document-control-version-log-template/.

SOC 2Implementation
COR-014Word

Risk Acceptance Form

Editable template with section-by-section guide at lintgrc.com/templates/risk-acceptance-form-template/.

SOC 2Implementation

2C Engineering and Ops

SOC-007Word

SDLC Standard

Editable template with section-by-section guide at lintgrc.com/templates/sdlc-standard-template/.

SOC 2Implementation
SOC-008Word

Logging and Monitoring Standard

Editable template with section-by-section guide at lintgrc.com/templates/logging-monitoring-standard-template/.

SOC 2Implementation
SOC-009Word

Authentication and MFA Standard

Editable template with section-by-section guide at lintgrc.com/templates/authentication-mfa-standard-template/.

SOC 2Implementation
SOC-010Excel

User Access Review Procedure

Editable template with section-by-section guide at lintgrc.com/templates/user-access-review-procedure-template/.

SOC 2Implementation
SOC-011Word

Change Approval Workflow Guide

Editable template with section-by-section guide at lintgrc.com/templates/change-approval-workflow-guide-template/.

SOC 2Implementation
SOC-012Word

Code Review Checklist Template

Editable template with section-by-section guide at lintgrc.com/templates/code-review-checklist-template/.

SOC 2Implementation
SOC-013Excel

Incident Log and Triaging Tracker

Editable template with section-by-section guide at lintgrc.com/templates/incident-log-triaging-tracker-template/.

SOC 2Implementation
SOC-014Excel

Asset Inventory and Subprocessor Register

Editable template with section-by-section guide at lintgrc.com/templates/asset-inventory-subprocessor-register-template/.

SOC 2Implementation
SOC-015Word

Backup and Restore Testing Procedure

Editable template with section-by-section guide at lintgrc.com/templates/backup-restore-testing-procedure-template/.

SOC 2Implementation
SOC-016Word

Vulnerability Management Procedure

Editable template with section-by-section guide at lintgrc.com/templates/vulnerability-management-procedure-template/.

SOC 2Implementation

3A Governance

COR-015Excel

Policy Exception Log

Editable template with section-by-section guide at lintgrc.com/templates/policy-exception-log-template/.

SOC 2Audit
SOC-017Word

Security Steering Committee Minutes

Editable template with section-by-section guide at lintgrc.com/templates/security-steering-committee-minutes-template/.

SOC 2Audit
SOC-018Word

Quarterly Access Review Sign-Off

Editable template with section-by-section guide at lintgrc.com/templates/quarterly-access-review-sign-off-template/.

SOC 2Audit
SOC-019Word

Risk Review Meeting Minutes

Editable template with section-by-section guide at lintgrc.com/templates/risk-review-meeting-minutes-template/.

SOC 2Audit
SOC-020Word

Vendor Review Meeting Template

Editable template with section-by-section guide at lintgrc.com/templates/vendor-review-meeting-template/.

SOC 2Audit

3B Evidence and Mapping

SOC-021Excel

Evidence Index

Editable template with section-by-section guide at lintgrc.com/templates/evidence-index-template/.

SOC 2Audit
SOC-022Excel

Traceability Matrix

Editable template with section-by-section guide at lintgrc.com/templates/traceability-matrix-template/.

SOC 2Audit
SOC-023Excel

TSC Crosswalk

Editable template with section-by-section guide at lintgrc.com/templates/tsc-crosswalk-template/.

SOC 2Audit
SOC-024Excel

Control Ownership Matrix

Editable template with section-by-section guide at lintgrc.com/templates/control-ownership-matrix-template/.

SOC 2Audit
SOC-030Excel

Risk Register and Treatment Plan

Editable template with section-by-section guide at lintgrc.com/templates/risk-register-template/.

SOC 2Audit

3C Auditor Handoff

SOC-025Word

Auditor Kickoff Package

Editable template with section-by-section guide at lintgrc.com/templates/auditor-kickoff-package-template/.

SOC 2Audit
SOC-026Word

Bridge Letter Template

Editable template with section-by-section guide at lintgrc.com/templates/bridge-letter-template/.

SOC 2Audit
SOC-027Word

Management Representation Letter

Editable template with section-by-section guide at lintgrc.com/templates/management-representation-letter-template/.

SOC 2Audit
SOC-028Excel

PBC Tracker (Evidence Request List)

Editable template with section-by-section guide at lintgrc.com/templates/pbc-tracker-template/.

SOC 2Audit
SOC-029Word

Sample Audit RFP Response

Editable template with section-by-section guide at lintgrc.com/templates/auditor-rfp-response-template/.

SOC 2Audit
SOC-031Word

Auditor Q&A Prep Sheet

Editable template with section-by-section guide at lintgrc.com/templates/auditor-qa-prep-sheet-template/.

SOC 2Audit

3D Samples

SOC-SAMP-01Excel

Sample Completed Risk Register

Editable template with section-by-section guide at lintgrc.com/templates/sample-completed-risk-register/.

Sample only
SOC-SAMP-01Excel

Sample Completed Risk Register

Editable template with section-by-section guide at lintgrc.com/templates/sample-completed-risk-register/.

Sample only
SOC-SAMP-02Excel

Sample Completed Access Review

Editable template with section-by-section guide at lintgrc.com/templates/sample-completed-access-review/.

Sample only
SOC-SAMP-02Excel

Sample Completed Access Review

Editable template with section-by-section guide at lintgrc.com/templates/sample-completed-access-review/.

Sample only
SOC-SAMP-03Word

Sample Completed Incident Report

Editable template with section-by-section guide at lintgrc.com/templates/sample-completed-incident-report/.

Sample only
SOC-SAMP-03Word

Sample Completed Incident Report

Editable template with section-by-section guide at lintgrc.com/templates/sample-completed-incident-report/.

Sample only
SOC-SAMP-04Word

Sample Vendor Review Minutes

Editable template with section-by-section guide at lintgrc.com/templates/sample-vendor-review-minutes/.

Sample only
SOC-SAMP-04Word

Sample Vendor Review Minutes

Editable template with section-by-section guide at lintgrc.com/templates/sample-vendor-review-minutes/.

Sample only
SOC-SAMP-05ZIP

Sample Evidence Package

Editable template with section-by-section guide at lintgrc.com/templates/sample-evidence-package/.

Sample only
SOC-SAMP-05ZIP

Sample Evidence Package

Editable template with section-by-section guide at lintgrc.com/templates/sample-evidence-package/.

Sample only

5 Examples

AI-SAMP-01Excel

Example Completed AI Risk Register

Editable template with section-by-section guide at lintgrc.com/templates/example-completed-ai-risk-register/.

SOC 2Audit

Audits fail in the evidence room, not the policy room

Phase 3 is the auditor-facing layer — indexes, traceability, and handoff artifacts built on your Phase 1–2 control IDs.

Control → evidence mapping

SOC-022/023 tie each criterion to files your team already maintains from Phase 2.

PBC tracker built in

SOC-028 tracks prepared-by-client items with status — no last-minute spreadsheet invention.

Governance evidence

SOC-017–020 minutes and COR-015 support CC1/CC2 board and management oversight.

Samples are format-only

3D_Samples/ files show correct layout — clearly marked fictional; never submit to auditors.

Spreadsheet chaos vs. LintGRC Phase 3

Auditor handoff as a system, not a folder dump

System Feature
Generic Templates
LintGRC Phase 3
Evidence index
Ad hoc Google Drive links
SOC-021 structured index
Criteria mapping
Manual matrix
SOC-022/023 traceability workbooks
PBC management
Email threads
SOC-028 PBC tracker
Prior phases
Repurchase or mismatch
Phase 1 + 2 folders included
Sample quality
Risk of fake data submission
Labeled format-only samples in 3D_Samples
Price
Free (incomplete)
$899 one-time

One control ID language end-to-end

From SOC-003 scoping through SOC-024 owners to SOC-028 PBC rows.

SOC-003 → SOC-024 owner register
SOC-009 access reviews → evidence index rows
COR-013 policy log → governance minutes
SOC-031 → auditor kickoff agenda

SOC 2 Phase 3 Audit & Evidence Bundle

$997 $899 one-time
  • Complete Phase 1 + Phase 2 kits in one ZIP
  • 27 Phase 3 governance, evidence, and handoff templates
  • SOC-SAMP-* format-only examples (do not submit)
  • Risk register, evidence index, and PBC tracker
  • Website guide for every template
  • Instant download after purchase
Get the Audit & Evidence Bundle — $899

Already own Phase 2? Add this phase for $400 →

Never submit 3D_Samples/ files to your auditor — format reference only. Expansion ZIP adds 3A–3D folders only — merge into your Phase 2 kit.

Frequently asked questions

What’s in 3D_Samples?

Fictional examples (SOC-SAMP-01 through 05) that demonstrate correct evidence format. They are clearly labeled and must not be submitted as real audit evidence.

Do I need Phases 1 and 2 separately?

No. Phase 3 includes the full Phase 1 and Phase 2 folder trees inside the same ZIP.

When should I buy Phase 3?

Best when controls are operating and you are 4–12 weeks from audit fieldwork — evidence indexing and PBC tracking pay off in audit week.

Disclaimer: Templates support SOC 2 readiness; they do not guarantee audit passage. Never submit sample files in 3D_Samples to your auditor. Licensed for your organization only — do not redistribute.