{"id":589,"date":"2026-08-09T19:47:59","date_gmt":"2026-08-09T19:47:59","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=589"},"modified":"2026-08-09T19:47:59","modified_gmt":"2026-08-09T19:47:59","slug":"soc-2-policies-documentation","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/blog\/soc-2-policies-documentation\/","title":{"rendered":"SOC 2 Policies and Documentation: The Complete List for Startups"},"content":{"rendered":"\n<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n<meta charset=\"UTF-8\">\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n<title>SOC 2 Policies and Documentation: The Complete List for Startups | Osto<\/title>\n<meta name=\"description\" content=\"The SOC 2 policies every auditor expects, what each one covers, the three audit-specific artifacts, and the rule that decides whether your documentation helps or hurts you.\">\n<style>\n  :root{\n    --ink:#0e1330;\n    --brand:#1c267a;\n    --brand-2:#3a46c0;\n    --accent:#00c2a8;\n    --accent-soft:#e6f7f4;\n    --paper:#ffffff;\n    --mist:#f4f6fb;\n    --line:#e3e7f2;\n    --muted:#5a6284;\n    --danger:#e2564d;\n    --radius:16px;\n    --shadow:0 1px 2px rgba(16,19,48,.04),0 12px 40px rgba(16,19,48,.06);\n    --maxw:860px;\n  }\n  *{box-sizing:border-box}\n  html{scroll-behavior:smooth}\n  body{\n    margin:0;\n    font-family:-apple-system,BlinkMacSystemFont,\"Segoe UI\",Inter,Roboto,Helvetica,Arial,sans-serif;\n    color:var(--ink);background:var(--paper);line-height:1.65;-webkit-font-smoothing:antialiased;\n  }\n  a{color:var(--brand-2);text-decoration:none}\n  a:hover{text-decoration:underline}\n\n  .topbar{border-bottom:1px solid var(--line);background:rgba(255,255,255,.9);backdrop-filter:saturate(160%) blur(8px);position:sticky;top:0;z-index:20}\n  .topbar-inner{max-width:1120px;margin:0 auto;padding:14px 24px;display:flex;align-items:center;justify-content:space-between;gap:16px}\n  .logo{display:flex;align-items:center;gap:9px;font-weight:800;letter-spacing:-.02em;color:var(--brand);font-size:20px}\n  .logo-mark{width:26px;height:26px;border-radius:8px;background:linear-gradient(135deg,var(--brand),var(--brand-2));display:grid;place-items:center;color:#fff;font-size:14px;font-weight:800}\n  .nav-cta{background:var(--brand);color:#fff;padding:9px 18px;border-radius:10px;font-weight:600;font-size:14px;white-space:nowrap}\n  .nav-cta:hover{background:var(--brand-2);text-decoration:none}\n\n  .wrap{max-width:var(--maxw);margin:0 auto;padding:0 24px}\n  .breadcrumb{font-size:13px;color:var(--muted);padding:26px 0 6px}\n  .breadcrumb a{color:var(--muted)}\n  .eyebrow{display:inline-block;margin:22px 0 14px;font-size:12px;font-weight:700;letter-spacing:.14em;text-transform:uppercase;color:var(--brand-2);background:var(--mist);padding:6px 12px;border-radius:999px;border:1px solid var(--line)}\n  h1{font-size:clamp(30px,5vw,46px);line-height:1.1;letter-spacing:-.03em;margin:0 0 18px;font-weight:800}\n  .dek{font-size:19px;color:var(--muted);margin:0 0 8px;max-width:50ch}\n\n  .meta{display:flex;flex-wrap:wrap;gap:8px 20px;align-items:center;font-size:13px;color:var(--muted);margin:22px 0 4px;padding-bottom:26px;border-bottom:1px solid var(--line)}\n  .meta .dot{width:4px;height:4px;border-radius:50%;background:var(--line)}\n\n  .tldr{margin:30px 0;border:1px solid var(--line);background:linear-gradient(180deg,var(--accent-soft),#fff 70%);border-radius:var(--radius);padding:22px 24px}\n  .tldr h2{margin:0 0 8px;font-size:13px;letter-spacing:.14em;text-transform:uppercase;color:var(--brand)}\n  .tldr p{margin:0 0 10px;font-size:16.5px}\n  .tldr p:last-child{margin:0}\n\n  h2.sec{font-size:27px;letter-spacing:-.02em;margin:52px 0 14px;font-weight:800;scroll-margin-top:80px}\n  h3{font-size:20px;margin:34px 0 10px;letter-spacing:-.01em;font-weight:700}\n  p{margin:0 0 16px;font-size:16.5px}\n  .lead-in{color:var(--muted)}\n  em{font-style:italic}\n\n  .jump{background:var(--mist);border:1px solid var(--line);border-radius:var(--radius);padding:20px 24px;margin:30px 0}\n  .jump h4{margin:0 0 12px;font-size:13px;letter-spacing:.1em;text-transform:uppercase;color:var(--muted)}\n  .jump ol{margin:0;padding-left:20px;columns:2;column-gap:32px}\n  .jump li{margin:6px 0;font-size:15px}\n  @media(max-width:560px){.jump ol{columns:1}}\n\n  .analogy{background:var(--mist);border-radius:var(--radius);padding:20px 22px;margin:22px 0;border:1px solid var(--line);font-size:16.5px}\n  .analogy strong{color:var(--brand)}\n\n  ul.clean{padding-left:0;list-style:none;margin:16px 0}\n  ul.clean li{position:relative;padding:6px 0 6px 30px;font-size:16px;border-bottom:1px solid var(--mist)}\n  ul.clean li:last-child{border-bottom:none}\n  ul.clean li::before{content:\"\";position:absolute;left:4px;top:14px;width:9px;height:9px;border-radius:3px;background:var(--accent)}\n  ul.warn li::before{background:var(--danger)}\n\n  \/* TSC cards *\/\n  .tsc{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:22px 0}\n  .tsc-card{border:1px solid var(--line);border-radius:14px;padding:18px;background:#fff}\n  .tsc-card.req{border-color:var(--brand);background:#f6f8ff}\n  .tsc-card .tag{font-size:11px;font-weight:700;letter-spacing:.08em;text-transform:uppercase;color:var(--muted)}\n  .tsc-card.req .tag{color:var(--brand)}\n  .tsc-card h4{margin:6px 0 6px;font-size:16px;color:var(--ink)}\n  .tsc-card p{font-size:14px;color:var(--muted);margin:0}\n  @media(max-width:720px){.tsc{grid-template-columns:1fr 1fr}}\n  @media(max-width:480px){.tsc{grid-template-columns:1fr}}\n\n  \/* stat band *\/\n  .fig{margin:30px 0;border:1px solid var(--line);border-radius:var(--radius);overflow:hidden;box-shadow:var(--shadow)}\n  .fig-head{padding:16px 22px;background:var(--brand);color:#fff;display:flex;align-items:baseline;justify-content:space-between;gap:12px;flex-wrap:wrap}\n  .fig-head .ttl{font-weight:700;font-size:15px;letter-spacing:.02em}\n  .fig-head .src{font-size:11.5px;color:#b9c0f0}\n  .fig-foot{padding:14px 22px;border-top:1px solid var(--line);font-size:12.5px;color:var(--muted);background:#fbfcfe}\n  .stat-band{display:grid;grid-template-columns:repeat(3,1fr)}\n  .stat-cell{padding:24px 16px;text-align:center;border-right:1px solid var(--line)}\n  .stat-cell:last-child{border-right:none}\n  .stat-cell .num{font-size:30px;font-weight:800;color:var(--brand);letter-spacing:-.02em;line-height:1.05}\n  .stat-cell .num.accent{color:var(--accent)}\n  .stat-cell .lab{font-size:12.5px;color:var(--muted);margin-top:8px;line-height:1.4}\n  @media(max-width:560px){.stat-band{grid-template-columns:1fr}.stat-cell{border-right:none;border-bottom:1px solid var(--line)}.stat-cell:last-child{border-bottom:none}}\n\n  \/* timeline *\/\n  .timeline{padding:8px 24px 4px}\n  .tl-item{display:grid;grid-template-columns:130px 1fr;gap:16px;padding:14px 0;border-bottom:1px solid var(--mist)}\n  .tl-item:last-child{border-bottom:none}\n  .tl-date{font-weight:800;color:var(--brand);font-size:14px}\n  .tl-what{font-size:14.5px}\n  .tl-what b{display:block;margin-bottom:2px}\n  @media(max-width:520px){.tl-item{grid-template-columns:1fr;gap:2px}}\n\n  .tablewrap{overflow-x:auto;margin:22px 0;border:1px solid var(--line);border-radius:var(--radius);box-shadow:var(--shadow)}\n  table{border-collapse:collapse;width:100%;min-width:600px;font-size:14.5px}\n  thead th{background:var(--mist);text-align:left;padding:14px 16px;font-size:12.5px;text-transform:uppercase;letter-spacing:.05em;color:var(--muted);border-bottom:1px solid var(--line);font-weight:700}\n  thead th.osto{background:var(--brand);color:#fff}\n  tbody td{padding:14px 16px;border-bottom:1px solid var(--line);vertical-align:top}\n  tbody tr:last-child td{border-bottom:none}\n  tbody td:first-child{font-weight:600;color:var(--ink)}\n  td.osto{background:#f6f8ff;font-weight:600}\n  .yes{color:var(--accent);font-weight:700}\n  .no{color:var(--danger);font-weight:700}\n\n  .callout{border:1px solid var(--line);border-radius:var(--radius);padding:24px;margin:44px 0;background:linear-gradient(135deg,#141b52,#2a34a0);color:#fff;box-shadow:var(--shadow)}\n  .callout h3{margin:0 0 8px;color:#fff}\n  .callout p{color:#cfd4f5;margin:0 0 18px}\n  .callout a.btn{display:inline-block;background:#fff;color:var(--brand);font-weight:700;padding:11px 22px;border-radius:10px;font-size:15px}\n  .callout a.btn:hover{text-decoration:none;background:#eef0ff}\n\n  .disclaimer{font-size:13.5px;color:var(--muted);background:var(--mist);border:1px solid var(--line);border-radius:12px;padding:16px 18px;margin:34px 0}\n\n  .faq{border-top:1px solid var(--line);margin-top:48px;padding-top:8px}\n  details{border-bottom:1px solid var(--line);padding:6px 0}\n  summary{cursor:pointer;list-style:none;padding:16px 4px;font-weight:600;font-size:17px;display:flex;justify-content:space-between;align-items:center;gap:16px}\n  summary::-webkit-details-marker{display:none}\n  summary::after{content:\"+\";color:var(--brand-2);font-size:22px;font-weight:400}\n  details[open] summary::after{content:\"\u2013\"}\n  details p{padding:0 4px 18px;color:var(--muted);margin:0}\n\n  footer{border-top:1px solid var(--line);margin-top:60px;background:var(--mist)}\n  .foot-inner{max-width:1120px;margin:0 auto;padding:36px 24px;display:flex;flex-wrap:wrap;gap:16px;justify-content:space-between;align-items:center;font-size:14px;color:var(--muted)}\n  .foot-inner .logo{font-size:17px}\n\n  .related{margin:42px 0 0}\n  .related h3{margin-bottom:14px}\n  .related-grid{display:grid;grid-template-columns:1fr 1fr;gap:14px}\n  .rc{border:1px solid var(--line);border-radius:12px;padding:16px 18px;background:#fff}\n  .rc .k{font-size:11px;letter-spacing:.1em;color:var(--brand-2);font-weight:700;text-transform:uppercase}\n  .rc a{font-weight:600;color:var(--ink);display:block;margin-top:6px;font-size:15.5px}\n  @media(max-width:640px){.related-grid{grid-template-columns:1fr}}\n\n  \/* --- bright, clean additions --- *\/\n  .bright-strip{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:30px 0}\n  .bright-strip .bcard{border-radius:16px;padding:22px 20px;color:#fff}\n  .bright-strip .bcard .n{font-size:26px;font-weight:800;line-height:1.1}\n  .bright-strip .bcard .l{font-size:13px;margin-top:6px;opacity:.95;font-weight:500}\n  .bc-navy{background:linear-gradient(135deg,#1c267a,#3a46c0)}\n  .bc-teal{background:linear-gradient(135deg,#00c2a8,#12b3d6)}\n  .bc-indigo{background:linear-gradient(135deg,#3a46c0,#5a63d6)}\n  @media(max-width:640px){.bright-strip{grid-template-columns:1fr}}\n\n  .pillrow{display:flex;gap:10px;flex-wrap:wrap;margin:22px 0}\n  .pill{border-radius:999px;padding:9px 16px;font-size:14px;font-weight:600;background:var(--accent-soft);color:#0a7a68;border:1px solid #bfece4}\n  .pill.i{background:#eef0ff;color:#3a46c0;border-color:#d6dbff}\n\n  .bigcards{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:26px 0}\n  .bigcard{border-radius:16px;padding:22px;background:#fff;border:1px solid var(--line);box-shadow:0 8px 30px rgba(16,19,48,.05)}\n  .bigcard .ic{width:44px;height:44px;border-radius:12px;display:grid;place-items:center;font-size:20px;font-weight:800;color:#fff;margin-bottom:12px}\n  .bigcard h4{margin:0 0 6px;font-size:16px;color:var(--ink)}\n  .bigcard p{margin:0;font-size:13.5px;color:var(--muted)}\n  @media(max-width:720px){.bigcards{grid-template-columns:1fr}}\n\n  .keyrow{display:grid;grid-template-columns:1fr 1fr;gap:0;border-radius:16px;overflow:hidden;border:1px solid var(--line);margin:26px 0}\n  .keyrow>div{padding:20px 22px}\n  .keyrow .k1{background:#eef0ff}\n  .keyrow .k2{background:var(--accent-soft)}\n  .keyrow .lab{font-size:11px;font-weight:800;letter-spacing:.08em;text-transform:uppercase;margin-bottom:6px}\n  .keyrow .k1 .lab{color:#3a46c0}.keyrow .k2 .lab{color:#0a7a68}\n  .keyrow .big{font-size:19px;font-weight:800;color:var(--brand);margin-bottom:4px}\n  .keyrow .sm{font-size:13.5px;color:var(--muted)}\n  @media(max-width:560px){.keyrow{grid-template-columns:1fr}}\n\n  .flow{display:flex;gap:8px;flex-wrap:wrap;align-items:stretch;margin:26px 0}\n  .flow .step{flex:1;min-width:130px;border-radius:14px;padding:16px 14px;text-align:center}\n  .flow .step .t{font-weight:800;font-size:14px}\n  .flow .step .d{font-size:12px;margin-top:4px;opacity:.9}\n  .flow .arrow{align-self:center;color:#c3c9e6;font-size:20px;font-weight:700}\n\n\n  .bbox{border-radius:14px;background:#fff;padding:16px 20px;margin:22px 0;font-size:14.5px;line-height:1.6}\n  .bbox strong{color:var(--brand)}\n  .bbox.navy{border:2px solid #1c267a}.bbox.indigo{border:2px solid #3a46c0}.bbox.teal{border:2px solid #00c2a8}\n  .bbox .bt{font-size:11px;font-weight:800;letter-spacing:.06em;text-transform:uppercase;margin-bottom:5px}\n  .bbox.navy .bt{color:#1c267a}.bbox.indigo .bt{color:#3a46c0}.bbox.teal .bt{color:#0a7a68}\n  .docpills{display:flex;gap:8px;flex-wrap:wrap;margin:14px 0 6px}\n  .docpills .dp{font-size:13px;padding:8px 14px;border-radius:10px;background:#eef0ff;color:#3a46c0;border:1px solid #d6dbff;font-weight:600}\n  .docpills.mist .dp{background:var(--mist);color:var(--brand);border-color:var(--line);font-weight:500}\n  .grouplab{font-size:11px;font-weight:800;letter-spacing:.07em;text-transform:uppercase;color:var(--muted);margin:18px 0 4px}\n  .bigcards{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:24px 0}\n  .bigcard{border-radius:16px;padding:20px;background:#fff;border:1px solid var(--line);box-shadow:0 8px 30px rgba(16,19,48,.05)}\n  .bigcard .ic{width:40px;height:40px;border-radius:11px;display:grid;place-items:center;font-size:15px;font-weight:800;color:#fff;margin-bottom:11px}\n  .bigcard h4{margin:0 0 5px;font-size:15px;color:var(--ink)}\n  .bigcard p{margin:0;font-size:13px;color:var(--muted)}\n  @media(max-width:720px){.bigcards{grid-template-columns:1fr}}\n\n  .callout a[href*=\"book-demo\"]{color:#ffffff !important;font-weight:700;text-decoration:underline}\n  .callout a[href*=\"book-demo\"] span{color:#ffffff !important}\n<\/style>\n<\/head>\n<body>\n\n<div class=\"wrap\">\n  <p class=\"dek\">The SOC 2 policies every auditor expects, what each one covers, and the single rule that decides whether your documentation helps you or works against you.<\/p>\n\n  <div class=\"meta\">\n    <span>Osto Security Team<\/span>\n    <span class=\"dot\"><\/span>\n    <span>8 min read<\/span>\n    <span class=\"dot\"><\/span>\n    <span>Compliance &amp; Trust<\/span>\n  <\/div>\n\n  <div class=\"tldr\">\n    <h2>TL;DR<\/h2>\n    <p>SOC 2 has no legally fixed list of documents. Auditors expect a coherent library of security policies that describe your controls, plus evidence that those controls operate, plus three audit-specific artifacts.<\/p>\n    <p>The rule that matters most: a policy states an intention, evidence proves it became a habit. A policy your logs contradict is worse than no policy, because it shows a gap between what you claim and what you do.<\/p>\n  <\/div>\n\n  <div class=\"jump\">\n    <h4>On this page<\/h4>\n    <ol>\n      <li><a href=\"#nolist\">Why there is no official list<\/a><\/li>\n      <li><a href=\"#core\">The core policy suite<\/a><\/li>\n      <li><a href=\"#fuller\">The fuller library<\/a><\/li>\n      <li><a href=\"#artifacts\">The three audit artifacts<\/a><\/li>\n      <li><a href=\"#vs\">Policies vs evidence<\/a><\/li>\n      <li><a href=\"#templates\">Using templates well<\/a><\/li>\n      <li><a href=\"#osto\">Where policies meet controls<\/a><\/li>\n    <\/ol>\n  <\/div>\n\n  <h2 class=\"sec\" id=\"nolist\">Why there is no official list of SOC 2 policies<\/h2>\n  <p>Unlike ISO 27001, SOC 2 does not prescribe a mandatory set of SOC 2 policies or documents. It is built on the Trust Services Criteria, and your auditor examines the controls that satisfy them, however you have chosen to document them.<\/p>\n\n  <div class=\"bbox teal\"><div class=\"bt\">The practical shape<\/div>Most startups land on a core of roughly a dozen policies, with fuller suites running to 24 or more as the company grows. Start with the core, and add the rest as your scope widens.<\/div>\n\n  <h2 class=\"sec\" id=\"core\">The core policy suite<\/h2>\n  <p>If you do nothing else, these are the SOC 2 policies almost every auditor will look for. Start here.<\/p>\n\n  <div class=\"docpills\">\n    <span class=\"dp\">Information Security<\/span>\n    <span class=\"dp\">Access Control<\/span>\n    <span class=\"dp\">Risk Assessment<\/span>\n    <span class=\"dp\">Incident Response<\/span>\n    <span class=\"dp\">Change Management<\/span>\n    <span class=\"dp\">Vendor Management<\/span>\n    <span class=\"dp\">Business Continuity<\/span>\n    <span class=\"dp\">Data Classification<\/span>\n  <\/div>\n\n  <h2 class=\"sec\" id=\"fuller\">The fuller library, as you scale<\/h2>\n  <p>As your scope grows or a buyer asks for more Trust Services Criteria, auditors may expect additional policies. You do not need all of these on day one; add them as they become relevant.<\/p>\n\n  <div class=\"docpills mist\">\n    <span class=\"dp\">Anti-Malware<\/span>\n    <span class=\"dp\">Asset Management<\/span>\n    <span class=\"dp\">Network Security<\/span>\n    <span class=\"dp\">Configuration Management<\/span>\n    <span class=\"dp\">Remote Access<\/span>\n    <span class=\"dp\">Mobile Device<\/span>\n    <span class=\"dp\">Physical Security<\/span>\n    <span class=\"dp\">Backup<\/span>\n    <span class=\"dp\">Data Retention &amp; Disposal<\/span>\n    <span class=\"dp\">Confidentiality<\/span>\n    <span class=\"dp\">Privacy<\/span>\n    <span class=\"dp\">Software Development Lifecycle<\/span>\n  <\/div>\n\n  <div class=\"bbox indigo\"><div class=\"bt\">Add these when the trigger appears<\/div>Anti-malware and asset management for endpoint and inventory control. Network and configuration management for infrastructure hardening. Remote access and mobile device for distributed teams and BYOD. Backup and data retention for the data lifecycle. Confidentiality and privacy if you scope in those criteria. SDLC for how you build and test software securely.<\/div>\n\n  <h2 class=\"sec\" id=\"artifacts\">The three documents your auditor specifically needs<\/h2>\n  <p>Beyond the policy library, every SOC 2 engagement produces three artifacts that are distinct from your internal policies. Knowing them ahead of time saves a scramble.<\/p>\n\n  <div class=\"bigcards\">\n    <div class=\"bigcard\"><div class=\"ic bc-navy\">1<\/div><h4>Management assertion<\/h4><p>Your leadership&#8217;s formal written statement about your system and the controls in place. You assert; the auditor tests.<\/p><\/div>\n    <div class=\"bigcard\"><div class=\"ic bc-indigo\">2<\/div><h4>System description<\/h4><p>A written description of the system in scope: what it does, its boundaries, and the controls that protect it. It anchors the whole report.<\/p><\/div>\n    <div class=\"bigcard\"><div class=\"ic bc-teal\">3<\/div><h4>Control matrix<\/h4><p>The map linking each control to the criterion it satisfies, its owner, and the evidence that proves it. The backbone of the audit.<\/p><\/div>\n  <\/div>\n\n  <h2 class=\"sec\" id=\"vs\">The rule that matters most: policies vs evidence<\/h2>\n  <p>Here is what separates a smooth audit from a painful one. A policy states an intention. Evidence proves the intention became a habit. For a Type II report, policies alone are never enough.<\/p>\n\n  <div class=\"keyrow\">\n    <div class=\"k1\"><div class=\"lab\">A policy<\/div><div class=\"big\">States the intention<\/div><div class=\"sm\">It describes the control you mean to run. On its own, it proves nothing to an auditor.<\/div><\/div>\n    <div class=\"k2\"><div class=\"lab\">Evidence<\/div><div class=\"big\">Proves the habit<\/div><div class=\"sm\">Dated records showing the control actually ran. This is what the auditor inspects.<\/div><\/div>\n  <\/div>\n\n  <div class=\"bbox navy\"><div class=\"bt\">Why this matters<\/div>Auditors verify by inspecting records, not by reading policy statements. A policy your evidence contradicts, say a quarterly access review you never actually ran, is worse than no policy, because it documents the gap for the auditor.<\/div>\n\n  <h2 class=\"sec\" id=\"templates\">How to use policy templates the right way<\/h2>\n  <p>SOC 2 policies from a template are a smart starting point, not a finish line. The failure mode is downloading a pack and adopting it word for word, then getting caught claiming controls you do not run.<\/p>\n\n  <ul class=\"clean\">\n    <li><strong>Read every section and ask &#8220;does this fit us?&#8221;<\/strong> If yes, keep it. If it needs adjusting to match reality, adjust it.<\/li>\n    <li><strong>Cut what does not apply.<\/strong> If a section is not relevant and you can explain why, remove it. Auditors accept a tailored, honest policy over a bloated generic one.<\/li>\n    <li><strong>Assign an owner and get approval.<\/strong> Every policy needs a named owner and a dated leadership sign-off.<\/li>\n    <li><strong>Make sure the control behind it is real.<\/strong> The policy describes a control. If the control is not actually running, the policy is a liability, not an asset.<\/li>\n  <\/ul>\n\n  <h2 class=\"sec\" id=\"osto\">Where policies meet real controls<\/h2>\n  <p>Notice the theme running through this entire page: a SOC 2 policy is only as good as the control it describes and the evidence that control produces. Documentation that points at controls which do not run is what turns an audit painful.<\/p>\n\n  <div class=\"bbox teal\"><div class=\"bt\">Osto closes the seam<\/div>The controls your policies describe are built into the platform, and the evidence those controls produce is collected automatically from the same modules. Your documentation points at controls that genuinely run, with the proof already attached.<\/div>\n\n  <div class=\"callout\">\n    <h3>Policies that point to controls that actually run.<\/h3>\n    <p>Osto is a one-stop cybersecurity and compliance platform for growing companies. Not a folder of templates gathering dust, but documentation backed by controls running on one platform, with the evidence collected in the same place. Get SOC 2 ready in about 115 days.<\/p>\n    <p style=\"margin-top:16px;\"><a href=\"https:\/\/osto.one\/book-demo\/\" style=\"color:#ffffff;font-weight:700;text-decoration:underline;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a Demo &rarr;<\/span><\/a><\/p>\n  <\/div>\n\n  <h2 class=\"sec\" id=\"faq\">Frequently asked questions<\/h2>\n\n  <details>\n    <summary>What SOC 2 policies are required?<\/summary>\n    <p>SOC 2 has no legally fixed list, but auditors expect a core suite: information security, access control, change management, incident response, risk assessment, vendor management, business continuity, and data classification, with a fuller library added as you scale.<\/p>\n  <\/details>\n  <details>\n    <summary>Are policy templates enough?<\/summary>\n    <p>They are a useful starting point but not sufficient on their own. Auditors do not grade the writing; they check whether each policy is owned, approved, matched by a real control, and backed by evidence that the control ran.<\/p>\n  <\/details>\n  <details>\n    <summary>What is the difference between a policy and evidence?<\/summary>\n    <p>A policy states what you intend to do; evidence proves you actually did it. For a Type II report, policies alone are not enough because the auditor tests whether the control operated, using dated records.<\/p>\n  <\/details>\n  <details>\n    <summary>What audit-specific documents will I need?<\/summary>\n    <p>Beyond your internal policies, every SOC 2 engagement includes a management assertion (leadership&#8217;s formal statement about the system and controls), a system description, and a control matrix mapping each control to its criterion, owner, and evidence.<\/p>\n  <\/details>\n  <details>\n    <summary>How many policies do startups usually have?<\/summary>\n    <p>Most begin with a core of roughly a dozen policies covering governance, access, change, operations, and people. Fuller suites run to 24 or more as scope grows or additional Trust Services Criteria are added.<\/p>\n  <\/details>\n\n<\/div>\n<\/body>\n<\/html>\n","protected":false},"excerpt":{"rendered":"<p>SOC 2 Policies and Documentation: The Complete List for Startups | Osto The SOC 2 policies every auditor expects, what\u2026<\/p>\n","protected":false},"author":8,"featured_media":590,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[],"class_list":["post-589","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/589","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=589"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/589\/revisions"}],"predecessor-version":[{"id":591,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/589\/revisions\/591"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/590"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=589"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=589"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=589"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}