SOC 2 policies. 72 hours. $997.

Your SOC 2 policies, written and branded for your company, in 72 hours.

Eleven questions. Three days. A 15-policy kit tailored to your company, mapped to every Common Criteria code your auditor will check.

72-hour delivery · Mapped to AICPA 2017 TSC · Full refund if your auditor rejects the kit
Built by an operator who has shipped SOC 2s firsthand.

How it works

Built for founders and operators whose auditor, investor, or biggest prospect just asked for their SOC 2 documentation — and who don't have weeks to figure out what "SOC 2 documentation" even means.

01

Buy

$997. Stripe checkout. Under a minute.

02

Tell us about you

Eleven questions. Upload a logo. About ten minutes.

03

We write your kit

15 policies, controls matrix, evidence checklist. Tailored. Branded. Auditor-ready.

04

Delivered in 72 hours

A single zipped package. Word and PDF. Forward it to your auditor or your customer.

What's in the kit

Everything a first-time SOC 2 audit actually needs. Mapped to AICPA 2017 Trust Services Criteria with 2022 Revised Points of Focus.

Information Security Policy
Access Control Policy
Acceptable Use Policy
Data Classification & Handling
Encryption Policy
Incident Response Policy
Business Continuity / DR
Vendor & Third-Party Risk
Change Management
Risk Assessment
Asset Management
HR Security
Secure SDLC
Logging & Monitoring
Physical & Environmental Security
+ Controls matrix (xlsx)
+ Evidence checklist
+ Auditor-readiness brief

The difference

What you get when you stop shopping at the obvious places.

Template shopsPolicyDone
Site experienceBloated, multi-step, datedOne page, one decision
ProductGeneric templates you editTailored documents delivered ready
Price$2,000–$5,000$997
TurnaroundUndefined, often weeks72 hours
DeliveryEmail attachment, on your ownBranded zipped package, ready to ship
LanguageLegacy consulting-speakOperator-to-operator, auditor-defensible

One price. One outcome. Done.

If you need something bigger — a multi-entity rollout, HIPAA layered on top, or an enterprise-scale engagement — reach out and we'll price it. For everyone else:

PolicyDone SOC 2 Kit
$997one time
Delivered in 72 hours. Full refund if your auditor rejects the kit (written confirmation required).
  • 15 policy documents, tailored & branded
  • Controls matrix (64 Common Criteria controls)
  • Evidence checklist — what auditors actually ask for
  • Auditor-readiness brief
  • Word and PDF, delivered as a single zip
Get your kit — $997
Secure checkout via Stripe · Invoiced to your company
Email us first if you'd rather.

Common questions

Email rob@policydone.io. Same-day reply.

Will this actually pass my auditor?

Yes. Every policy is mapped to AICPA 2017 Trust Services Criteria with 2022 Revised Points of Focus, and each control narrative is cross-referenced to the specific Common Criteria code auditors walk through. If the kit doesn't clear your auditor's initial review, we refund.

How is this different from free templates on GitHub?

Free templates are generic, unmapped to Common Criteria, and assume you already know what's supposed to be in them. Our kit is tailored to your company, mapped to the criteria your auditor will cite, and written so you can defend every line.

Do I need to already be in a SOC 2 audit?

No. Most buyers we've talked to are pre-audit — they just lost a deal because a prospect asked for their SOC 2 documents. This kit is what you hand over while you line up the audit itself.

What if my auditor follows up with questions?

Forward the question to rob@policydone.io. You'll get a reply within 24 hours with the relevant Common Criteria citation and, if the wording needs sharpening, a suggested edit you can paste in.

What if I also need HIPAA or ISO 27001?

Email us. We're rolling out HIPAA and ISO 27001 kits. In the meantime we can add a HIPAA layer on top of the SOC 2 kit for a custom quote.

Who writes these?

I'm Rob Shaner, founder of PolicyDone. I've lived through multiple SOC 2 audits — as the founder getting asked for them, and as the person cleaning up after consultants who billed for the sales call. The kit is produced with AI-assisted drafting against a compliance knowledge base grounded in the AICPA standard. Then I read every line before it ships. LinkedIn.

What happens after I buy?

You'll get an email with a link to our 11-question intake form. Fill it out (about 10 minutes). Within 72 hours, you'll get a second email with a download link to your kit.

Refund policy?

Full refund if your auditor rejects the kit. We ask for written confirmation of the rejection — a note from your auditor pointing to what was wrong. That's how we both keep each other honest and how we keep improving the product. Full refund policy here.