Verigo Global
//SOC 2 Toolkit
Implementation ToolkitSOC 2 · Type I & II

The SOC 2 toolkit, ready to deploy.

A complete, practitioner-maintained document set — 20 policies, 16 procedures, and all 61 Trust Services Criteria control templates — tailored to your organization so you build an examination-ready control environment without starting from a blank page.

Inside the toolkit
20
Approval-ready policies
16
Operational procedures
61
Trust Services Criteria templates
95+
Documents, checklists & samples
Overview

Everything the examination tests — pre-built and tailored.

The Verigo SOC 2 toolkit is the document backbone of an examination-ready control environment. It pairs the security policies and procedures with implementation templates for every point of focus across the five Trust Services Criteria.

Each artefact is maintained by senior practitioners and tailored to your organization, systems, and selected criteria — then embedded into how you operate, the Compliance by Design way, so the evidence a Type II window needs is produced by the process itself.

Tailored, not generic

Every policy and procedure is shaped to your scope, systems, and existing tooling — not a one-size-fits-all template dump.

Cross-framework ready

Controls are mapped so the same evidence supports ISO 27001, HIPAA, and NIST without duplication.

Built for Type I and Type II

Stand up control design for a Type I, then run the evidence engine the Type II observation window will sample.

Coverage

Wall-to-wall across the criteria

The toolkit covers both halves of a SOC 2 examination — the mandatory Common Criteria and every optional Trust Services category you choose to add.

Security · Common Criteria · CC1–CC9
CC1
Control Environment
CC2
Communication
CC3
Risk Assessment
CC4
Monitoring
CC5
Control Activities
CC6
Access Controls
CC7
System Operations
CC8
Change Mgmt
CC9
Risk Mitigation
Trust Services Criteria · five categories, 61 points of focus
33

Security · Common Criteria

3

Availability

2

Confidentiality

5

Processing Integrity

18

Privacy

Toolkit contents

Browse the full set — and take it with you

Explore every policy, procedure, and criterion in the toolkit. Download any list as a branded PDF; we'll ask for a few details so a practitioner can tailor it to you.

Policy Library
The complete, criteria-aligned security policy set — 20 approval-ready policies covering the Common Criteria and every optional Trust Services category.
01
Information Security Policy
Top-level security mandate, objectives, and management commitment.
02
Access Control Policy
Rules for granting, reviewing, and revoking logical and physical access.
03
Acceptable Use Policy
Expected behaviour for users of systems, data, and assets.
04
Risk Assessment & Management Policy
How security and availability risk is identified, scored, and treated.
05
Vendor & Third-Party Management Policy
Security requirements for subservice organizations and vendors.
06
Change Management Policy
Controlled, authorized, and tested changes to systems and software.
07
Data Classification & Handling Policy
Labelling and handling rules by sensitivity and confidentiality level.
08
Encryption & Key Management Policy
Use of cryptography in transit and at rest, plus key lifecycle.
09
Incident Response Policy
Detecting, escalating, and responding to security incidents.
10
Business Continuity & Disaster Recovery Policy
Maintaining and recovering operations during disruption.
11
Backup Policy
Backup scope, frequency, encryption, and restoration testing.
12
Logging & Monitoring Policy
Event logging, alerting, retention, and review obligations.
13
Vulnerability Management Policy
Identifying, prioritising, and remediating technical weaknesses.
14
Secure Software Development Policy
Security requirements across the development lifecycle.
15
Human Resources Security Policy
Security across the employment lifecycle, from screening to exit.
16
Security Awareness & Training Policy
Role-based awareness and training expectations for all staff.
17
Physical & Environmental Security Policy
Protection of facilities, equipment, and secure areas.
18
Network Security Policy
Segmentation, boundary protection, and monitoring of networks.
19
Data Retention & Disposal Policy
Retaining and securely disposing of information and media.
20
Privacy Policy
Lawful collection, use, retention, and disclosure of personal data.
Samples

See exactly what you'll receive

Representative pages from the toolkit — a policy, a procedure, a Trust Services Criteria control template, and an examination-readiness checklist.

Want the full sample?

Preview the complete package index as a branded PDF — we'll ask for a few details first.

Samples are illustrative. Delivered documents are tailored to your organization and branding.

POL-02 · Access Control Policy

Access Control Policy

Classification
Internal
Version
2.1
Owner
CISO
Framework
AICPA SOC 2
1.0Purpose
This policy establishes the requirements for controlling logical and physical access to systems and data on a least-privilege, need-to-know basis, in support of Common Criteria CC6.1–CC6.3.
2.0Scope
Applies to all employees, contractors, and third parties who access organizational systems, applications, and data in scope for the SOC 2 examination.
3.0Policy statements
  • Access is provisioned through a formal request and approval workflow tied to documented roles.
  • Privileged access is restricted, logged, and reviewed at least quarterly.
  • Multi-factor authentication is enforced for remote and administrative access.
  • Access rights are recertified every 90 days and revoked within 24 hours of a leaver event.
4.0Roles & responsibilities
System owners approve access; IT operations provisions it; the CISO owns this policy and its annual review.
5.0Review
Reviewed annually or upon significant change. Next review: 12 months from approval.
Packages

Build without the evaluation

Start from the document toolkit at $1,495 and add exactly what you need — see your custom total update live, then download a quote.

Starter

The complete document toolkit, ready to deploy.

All 20 policies, 16 procedures & 61 Trust Services Criteria templates
Editable source files (Word & Excel)
Control matrix & evidence request (PBC) tracker
Audit-readiness checklists
Most popular
Professional

The toolkit tailored to you, with practitioner guidance.

Everything in Starter
Documents tailored to your scope & selected criteria
Half-day kickoff & gap-review workshop
Online readiness self-assessment
Enterprise

End-to-end support, all the way to a clean opinion.

Everything in Professional
Hands-on implementation support
Type II observation-window readiness
Pre-examination mock audit & findings log
Starts from $1,495 · add only what you need · live pricing
Online evaluation · ~10 minutes

Know where you stand before you start.

Our online SOC 2 readiness evaluation measures your current state against the Trust Services Criteria and maps every gap straight to the toolkit documents that close it. Get your score in about ten minutes.

01

Answer ~30 questions

Mapped to specific SOC 2 criteria across CC1–CC9 and every optional category — about 12 minutes.

02

Get your readiness score

An instant maturity score with a gap heat-map across all five categories.

03

See your next steps

A prioritized action plan showing exactly which toolkit documents close each gap.