Case File · SOC 2 Readiness / Security Sales draft — v1.0

Readiness kit · Common Criteria CC1–CC9

Walk into your SOC 2 audit without paying for the paperwork.

12 policies, a gap analysis, and an evidence tracker — the documentation a consultant would bill you thousands for, already written. You adapt it to how your company actually operates.

Audit prep with a consulting firm: $10,000–$200,000 · This kit: $349

The evidence

This isn't a made-up problem.

In a Hacker News thread asking how to reach SOC 2 Type II as a solo founder — 173 points, 138 replies — the conversation keeps landing on the same numbers, from founders who don't know each other:

"Their fee was around $15k, and there's ongoing verification after that."
Ask HN — How to be SOC2 Type II compliant as a solo-entrepreneur?
"It can easily cost more than $10,000 — and if you need a Big Four firm, you're talking hundreds of thousands."
Ask HN — same thread

Nobody's disputing what the auditor itself charges — the market sets that, and there's no shortcut around it. What is avoidable is paying that same order of magnitude just to have someone write your access control policy or your gap analysis from a blank page.

What's in the case file

Three pieces, fully editable.

  • 0112 security policies.md — with placeholders
  • 02Gap analysis checklist29 controls, CC1–CC9
  • 03Evidence trackerwhat to keep, how often

Covers Information Security, Access Control, Acceptable Use, Data Classification, Incident Response, Change Management, Vendor Risk, Business Continuity, Risk Assessment, Passwords, Encryption, and Onboarding/Offboarding.

This isn't a certification — only an accredited auditor can issue that. It's the drafting work that comes before the audit, done once and adaptable to any software company.

See it before you buy

One full policy, no cuts.

This is policy 02 of 12, exactly as it ships in the kit — only the placeholders are unfilled. The other eleven follow the same structure: purpose, scope, numbered policy statements, ownership, and a revision table an auditor recognizes on sight.

policies/02-access-control-policy.md1 of 12

Access Control Policy

Company: {{COMPANY_NAME}}  ·  Version: 1.0  ·  Effective date: {{DATE}}
Control owner: {{OWNER_ROLE}}  ·  Related controls: CC6

1. Purpose

Ensure access to {{COMPANY_NAME}}'s systems, data, and infrastructure is granted only to those who need it for their role (least privilege) and revoked promptly.

2. Scope

All production systems, code repositories, cloud infrastructure, and internal tools holding sensitive data.

3. Policy statements

  1. Access is granted under the principle of least privilege: each person receives only the permissions necessary for their role.
  2. All access to critical systems (production, database, cloud admin console) requires multi-factor authentication (MFA).
  3. New or elevated access requests must be approved by {{OWNER_ROLE}} or the system's direct owner, and logged.
  4. Access is reviewed at least quarterly; access unused for 90 days is flagged for review.
  5. When an employee's employment or contract ends, all their access is revoked the same business day.
  6. Shared system credentials (if any) are managed through a secrets manager, never in plain text or chat messages.
  7. Service accounts (non-human) are documented with their purpose and owner, and their credentials are rotated periodically.

4. Roles and responsibilities

{{OWNER_ROLE}}: approves and reviews access, runs the quarterly review. Team managers: notify hires and departures in advance so access can be managed.

5. Associated evidence

Identity provider exports (Google Workspace/Okta/Azure AD) showing MFA enabled, and quarterly access review logs.

VersionDateChangesApproved by
1.0{{DATE}}Initial version{{OWNER_ROLE}}

Free tool

Control Matrix — where you stand today

The interactive version of the kit's gap analysis. Mark each control (tap to cycle: not in place → partial → evidenced) and see which Common Criteria you're most exposed on. State is saved in this browser.

0%
Overall readiness

Pricing

$349one-time
  • 12 policies in Markdown, ready to adapt
  • Gap analysis checklist (same as the tool above)
  • Evidence tracker per control
  • Unlimited use — one company, no revision limit
Buy the kit — instant download

Secure checkout via Gumroad. The .zip unlocks immediately after payment.

Terms & refunds

FAQ

Does this replace the auditor?
No. It replaces the drafting and organizing work that many consulting firms bill separately from the auditor's own fee.
Does it work for SOC 2 Type I and Type II?
Yes — these policies are the documentation baseline for both. Type II additionally requires maintaining evidence over 3-6 months, which is what the tracker is for.
Do I need to be technical to use it?
You need to understand your infrastructure well enough to fill in the placeholders. No prior compliance knowledge required — that's what the checklist is for.