What are the 7 documents your SOC 2 auditor actually needs?

March 6, 20262 min readSOC 2 Policies and Documentation

The Seven Core Documents

Auditors don't want a hundred documents. They want a focused set that covers the Trust Services Criteria in your scope. Here are the seven that every SOC 2 audit requires:

#DocumentMaps ToWhat It Covers
1Information Security PolicyCC1.1-CC1.5Overall security program, roles, responsibilities
2Access Control PolicyCC6.1-CC6.8Who gets access, how, and approval process
3Change Management PolicyCC8.1How code changes are approved and deployed
4Incident Response PlanCC7.3-CC7.5How you detect, respond to, and recover from incidents
5Risk AssessmentCC3.1-CC3.4Identified risks and how you mitigate them
6Vendor Management PolicyCC9.1-CC9.2How you evaluate and monitor third-party vendors
7System DescriptionSection 3Your infrastructure, data flows, and boundaries

What Each Document Needs

Every document should include: the purpose of the policy, who it applies to, the specific controls you follow, how you monitor and enforce the controls, and when the policy was last reviewed.

The most critical thing: each document must describe your actual systems and processes. If your change management policy says "all deployments require two reviewer approvals" but your GitHub repo allows one, the auditor will flag that mismatch.

Common Mistakes

  • Too many documents: Some consultants create 20-30 policies. Auditors don't need that. Seven well-written documents cover the criteria.
  • Too generic: Policies that say "the company uses industry-standard encryption" without specifying which encryption. Name your systems.
  • Outdated: Policies written six months ago that don't reflect current infrastructure. Review before audit.

Where Screenata Helps

Screenata generates these seven documents by reading your codebase and cloud infrastructure. Each policy references your actual tools and configurations, so they match what the auditor will observe during testing.

Ready to Automate Your Compliance?

Join 50+ companies automating their compliance evidence with Screenata.

© 2025 Screenata. All rights reserved.