Templates
Auditors do not just want controls in place — they want the documented policy that says the control is supposed to exist, dated and version-controlled. These templates are starting drafts for that documentation layer: access control policies, incident response plans, and the other written artifacts that show up on evidence request lists across SOC 2 and ISO 27001 engagements.
Every template is a starting point, not a finished policy. Auditors check that a policy matches what you actually do, not that it uses particular boilerplate — a template copied verbatim without editing the placeholders to reflect your real process is a common audit finding, not a shortcut past one. Read the corresponding control page for what the policy needs to cover before you adapt the template.
Each template is published as readable HTML on its own page, which is the canonical version for reference and search. Download the .docx copy when you need to edit placeholders and get a document ready for internal sign-off.
- Access control policy template
SaaS logical access control policy template covering joiner-mover-leaver, MFA, reviews, and privileged access — maps to SOC 2 CC6 and ISO A.5.15 themes.
- Business continuity and disaster recovery policy template
SaaS continuity and disaster recovery policy with impact analysis, RTO/RPO, backups, exercises, and communications.
- Change management policy template
SaaS change management policy template for production changes, emergencies, and segregation of duties — maps to SOC 2 CC8.1 and ISO A.8.32 themes.
- Data classification policy template
Data classification and handling template covering inventory, labels, access, transmission, retention, and disposal.
- Employee security awareness policy template
Workforce security awareness policy covering onboarding, recurring training, phishing, reporting, and role-based education.
- GDPR DPA and HIPAA BAA addendum template
Modular data-processing addendum template with GDPR Article 28 and HIPAA business-associate clauses for counsel review.
- Incident response policy template
SaaS incident response policy template covering severity, roles, evidence, and communications — maps to SOC 2 CC7 and ISO A.5.24–A.5.26 themes.
- Information security policy template
SaaS-oriented information security policy template with placeholders for company name, owner, and review cadence — maps to ISO A.5.1 themes.
- SOC 2 management assertion letter template
Management assertion starting point for a SOC 2 examination, with scope, criteria, period, and responsibility placeholders.
- Vendor risk management policy template
SaaS vendor / supplier security policy template for tiering, diligence, and reviews — maps to ISO A.5.19–A.5.22 themes.