How Many Documents Each Compliance Framework Actually Requires
A complete ISO/IEC 27001:2022 documentation set runs to about 24 policies and procedures plus the 93-control Statement of Applicability; a SOC 2 set is around 22 policies mapped to the Trust Services Criteria; a small-practice HIPAA set is about 18 policies plus a Security Risk Assessment; and NIST CSF 2.0 spans 6 Functions, 22 Categories and 106 Subcategories. The exact list depends on scope, but these are the document counts auditors typically expect.
Updated
Document counts by framework
The table below shows the core policy/procedure count, the key register or workbook, and the structural facts for each framework. These counts are concrete and verifiable, and rarely published in one place. The exact number always depends on your scope — treat the figures as the typical full documentation set, not a fixed legal minimum.
| Framework (current version) | Core policies / procedures | Key register / workbook | Structural facts |
|---|---|---|---|
| ISO/IEC 27001:2022 | 24 (complete) / 16 (core) | Risk register + 93-control Statement of Applicability | Clauses 4–10; 93 Annex A controls in 4 themes |
| SOC 2 (AICPA TSC) | 22 (complete) / 15 (core) | Control–TSC mapping | No fixed control list; you define controls to the Trust Services Criteria |
| HIPAA Security & Privacy Rules | 18 | Security Risk Assessment workbook | Self-attested; OCR-enforced; no official certification |
| GDPR (Reg. 2016/679) | 14 | Records of Processing Activities (Art. 30) | Accountability principle, Art. 5(2) |
| NIST CSF 2.0 | 15 | Profile & Assessment workbook | 6 Functions · 22 Categories · 106 Subcategories |
| ISO/IEC 42001:2023 | 14 | Annex A Statement of Applicability + AI risk register | Clauses 4–10; 38 Annex A reference controls |
| AI Governance (EU AI Act + NIST AI RMF) | 10 | AI risk register | EU AI Act = Reg. 2024/1689; 4 risk tiers |
| WISP (FTC Safeguards, 16 CFR 314) | 9 | Risk assessment workbook | Implements GLBA; IRS Pub 4557/5708 |
Counts are the typical full documentation set ComplianceDocs ships for each framework; your required set varies with scope. No document set, by itself, makes an organization certified or compliant.
How much documentation ISO 27001 and SOC 2 actually share
A question the published counts never answer: if you already hold ISO 27001, how much of a SOC 2 set do you already own? In ComplianceDocs' own template library, 9 of the documents in its 24-document ISO 27001 Complete toolkit cover the same underlying control as a document in its 22-document SOC 2 Complete toolkit — 4 of them under identical titles and 5 under framework-specific title variants — leaving 37 distinct documents across the pair.
That is a floor, not a ceiling. It counts documents, not controls, and it deliberately keeps apart pairs that serve different audiences — an ISO "Cryptographic Controls Policy" and a SOC 2 "Encryption and Key Management Policy" address a shared control domain but are written for different readers. It is also why the dual toolkit ships all 46 documents plus a crosswalk guide rather than deduplicating them: an auditor reading your SOC 2 evidence should not have to accept a document titled for a different standard.
The edition structure is equally concrete. The 16-document ISO 27001 Core pack is a strict subset of the 24-document Complete toolkit, and the 15-document SOC 2 Core pack is a strict subset of the 22-document SOC 2 Complete toolkit. Each of the four ISO 27001 industry editions is the same 16-document core plus exactly one industry-specific policy.
ISO 27001 Complete and SOC 2 Complete — documentation overlap in the ComplianceDocs library
| Measure | Documents |
|---|---|
| ISO 27001 Complete toolkit | 24 |
| SOC 2 Complete toolkit | 22 |
| Same control, identical title | 4 |
| Same control, framework-specific title variant | 5 |
| Same control, total | 9 |
| Distinct documents across the pair | 37 |
How we counted: figures describe the ComplianceDocs template library only, and no other vendor. Overlap is measured at the document level using our published title-canonicalization map — the same "these describe one control" judgement that drives the canonical tags on our policy pages — so it is a floor for control-level overlap. Derived by script from the product catalog; regenerated whenever the catalog changes.
How to read these counts
A higher document count is not “more compliant” — it reflects how a framework is structured. ISO 27001 and ISO 42001 are management-system standards, so they include a fixed clause structure plus a Statement of Applicability. SOC 2 has no fixed control list at all: you define controls that meet the Trust Services Criteria, then a CPA firm examines them. HIPAA, GDPR, NIST CSF and the WISP are operated and self-attested rather than certified. Match the toolkit to your framework below; each ships the register or workbook named in the table.
Frequently asked questions
- How many policies does ISO 27001 require?
- A complete ISO/IEC 27001:2022 set is about 24 policies and procedures, plus a risk register and the 93-control Statement of Applicability. A lean core starter set is around 16 policies. The exact number depends on your ISMS scope and which Annex A controls you apply.
- What documents are in a SOC 2 audit?
- SOC 2 has no fixed control list. A working set is around 22 policies mapped to the AICPA Trust Services Criteria, plus a control-to-criteria mapping. You define the controls that satisfy the criteria in your audit scope, and a licensed CPA firm examines them.
- Can I reuse my ISO 27001 policies for SOC 2?
- Partly. In ComplianceDocs' own template library, 9 of the 24 documents in the ISO 27001 Complete toolkit cover the same underlying control as a document in the 22-document SOC 2 Complete toolkit — 4 under identical titles and 5 under framework-specific variants — so 37 distinct documents cover both. The overlap is real but it is not a shortcut: SOC 2 evidence is examined by a CPA firm against the Trust Services Criteria, so the wording and the control mapping still have to speak to that framework.
- How many subcategories are in NIST CSF 2.0?
- NIST CSF 2.0 has 106 Subcategories, organized under 22 Categories and 6 Functions — Govern, Identify, Protect, Detect, Respond and Recover. It is a voluntary framework you self-assess against, not a certification.
Related guides: ISO/IEC 27001 · SOC 2 · HIPAA · GDPR · NIST CSF 2.0
Toolkits that help
ISO 27001 Complete Toolkit
All 24 policies and procedures plus the risk register, 93-control Statement of Applicability and audit evidence checklist.
SOC 2 Complete Toolkit
22 policies plus the risk register, full Trust Services Criteria mapping and audit evidence checklist — built for startups facing their first SOC 2.
HIPAA Compliance Toolkit — Medical Practices
18 editable HIPAA policies plus the Security Risk Assessment workbook and audit evidence checklist, written for small medical practices and clinics.
GDPR Compliance Pack for Small Business
14 editable GDPR documents — privacy notices, DSAR procedure, DPIA, breach response, processor DPA checklist — plus a pre-filled Records of Processing Activities (Art. 30) workbook and evidence checklist.
NIST CSF 2.0 Complete Toolkit
15 editable policies and plans covering all six CSF 2.0 functions, plus a Profile & Assessment workbook with every one of the 106 subcategories, a risk register, and an audit evidence checklist.
ISO 42001 AI Management System Toolkit
14 editable ISO/IEC 42001:2023 policies and procedures — impact assessments, AI lifecycle, data governance, third-party AI — plus the Annex A Statement of Applicability, an AI risk register, and an audit evidence checklist.
AI Governance Policy Pack
10 editable AI policies — including an employee AI use policy and an AI risk register — aligned to the EU AI Act and NIST AI RMF. Govern workplace AI before regulators and clients ask.
WISP Toolkit for Tax Professionals
Complete Written Information Security Plan package for tax preparers, CPAs and accounting firms — FTC Safeguards Rule (16 CFR 314) crosswalk, IRS Pub 4557-aligned policies, risk assessment workbook, training logs and incident response — everything Pub 5708 doesn't operationalize.
Related articles
- How Long Compliance Documentation Actually Takes
- Compliance Documentation Benchmarks: What a Policy Library Actually Contains
- 2026 Compliance Template Pricing Index
- Compliance Questions, Answered
- What a Data Breach Costs: The Verified 2026 Numbers
Get new templates and guides by email
An occasional email when we publish a new free template, guide, or dataset. Unsubscribe any time.
