SOC 2 · HIPAA · ISO 27001 — policies without the drag

Auditor-ready SOC 2 policies, tailored to your company, in days.

Answer 12 questions. We deliver a 15-document policy kit, branded with your company, mapped to every Common Criteria code your auditor will ask about. No templates. No back and forth. No "compliance journey."

Delivered in 3–5 business days · Refund if it doesn't pass your auditor's initial review

How it works

Built for founders and operators whose auditor, investor, or biggest prospect just asked for their SOC 2 documentation — and who don't have weeks to figure out what "SOC 2 documentation" even means.

01

Buy

One tier. $997. Stripe checkout. Takes under a minute.

02

Tell us about your company

Twelve questions. Upload your logo. Name your systems. Ten minutes, tops.

03

We build your kit

15 policies, controls matrix, evidence checklist — tailored, branded, auditor-ready.

04

Download and ship

A single zipped package. Word and PDF. Ready to send to your auditor or your customer.

What's in the kit

Everything a first-time SOC 2 audit actually needs. Mapped to AICPA 2017 Trust Services Criteria with 2022 Revised Points of Focus.

Information Security Policy
Access Control Policy
Acceptable Use Policy
Data Classification & Handling
Encryption Policy
Incident Response Policy
Business Continuity / DR
Vendor & Third-Party Risk
Change Management
Risk Assessment
Asset Management
HR Security
Secure SDLC
Logging & Monitoring
Physical & Environmental Security
+ Controls matrix (xlsx)
+ Evidence checklist
+ Auditor-readiness brief

The difference

What you get when you stop shopping at the obvious places.

The usual template shopPolicyDone
Site experienceBloated, multi-step, datedOne page, one decision
ProductGeneric templates you editTailored documents delivered ready
Price$2,000–$5,000$997
TurnaroundUndefined, often weeks3–5 business days
DeliveryEmail attachment, on your ownBranded zipped package, ready to ship
LanguageLegacy consulting-speakOperator-to-operator, auditor-defensible

One price. One outcome. Done.

If you need something bigger — a multi-entity rollout, HIPAA layered on top, or an enterprise-scale engagement — reach out and we'll price it. For everyone else:

PolicyDone SOC 2 Kit
$997one time
Delivered in 3–5 business days. Refund if the kit doesn't pass your auditor's initial review.
  • 15 policy documents, tailored & branded
  • Controls matrix (64 Common Criteria controls)
  • Evidence checklist (what auditors actually ask for)
  • Auditor-readiness brief
  • Word and PDF formats, in one zipped delivery
Get your kit — $997
Secure checkout via Stripe · Invoiced to your company
Talk to us first if you'd rather.

Questions auditors-in-training ask

If yours isn't here, email rob@policydone.io. We reply same day.

Will this actually pass my auditor?

Yes. Every policy is mapped to AICPA 2017 Trust Services Criteria with 2022 Revised Points of Focus, and each control narrative is cross-referenced to the specific Common Criteria code auditors walk through. If the kit doesn't clear your auditor's initial review, we refund.

How is this different from free templates on GitHub?

Free templates are generic, unmapped to Common Criteria, and assume you already know what's supposed to be in them. Our kit is tailored to your company, mapped to the criteria your auditor will cite, and written so you can defend every line.

Do I need to already be in a SOC 2 audit?

No. Most of our customers are pre-audit — they just lost a deal because a prospect asked for their SOC 2 documents. This kit is what you hand over while you line up the audit itself.

What if I also need HIPAA or ISO 27001?

Email us. We're rolling out HIPAA and ISO 27001 kits. In the meantime we can add a HIPAA layer on top of the SOC 2 kit for a custom quote.

Who writes these?

PolicyDone is built by an operator who has lived through multiple SOC 2 audits firsthand. The kit is produced with AI-assisted drafting, human review, and a compliance knowledge base grounded in the AICPA standard — and nothing ships without a human approving every line.

What happens after I buy?

You'll get an email with a link to our 12-question intake form. Fill it out (10 minutes). Within 3–5 business days, you'll get a second email with a download link to your kit.

Refund policy?

Full refund within 14 days if the kit doesn't pass your auditor's initial review. Refund requests after you've delivered the kit to your auditor or a prospect are assessed case by case.