About 60% of the policies required by ISO 27001, ISO 9001, ISO 14001, SOC 2, HIPAA, CMMC, NIS2 and the EU Cyber Resilience Act are the same documents wearing different clause numbers. ITSECOPS writes that shared 60% from an audited baseline, then customises the remaining 40% to your organisation with AI-assisted GRC tooling and a senior consultant’s review. You receive the complete, audit-ready policy set in one week, at a fixed price that is typically 60-80% below what compliance consultancies quote for the same 4-8 week engagement.
Updated September 2026. This page explains which policies every framework shares, which ones must be written for you specifically, how the one-week process works, and why it costs a fraction of the usual price. If you already know what you need, request a quote and we reply with a fixed price and the full document list within one business day.
Get my policy quote See what is included
Quick answer: what you get, how fast, and what it costs
| Question | Answer |
|---|---|
| What is delivered? | The full policy and procedure set for your chosen frameworks (typically 18-32 documents), a control-to-policy mapping table, an approval and review register, and a distribution record that auditors accept as evidence. |
| How long does it take? | One week from intake to final approved set. Compliance consultancies and “audit-ready” firms usually take 4-8 weeks for the same scope because they draft every document from a blank page and bill by the hour. |
| What does it cost? | Fixed price, quoted within one business day. Because the shared 60% comes from a maintained baseline and the custom 40% is drafted with AI-assisted GRC tooling before a consultant finishes it, the price is typically 60-80% below a consultancy engagement. Already have a quote? Send it with your request and we tell you plainly whether we can beat it. |
| Which frameworks? | ISO 27001:2022, ISO 9001, ISO 14001, ISO 42001, ISO 45001, SOC 2, HIPAA, CMMC and NIST SP 800-171, NIS2 (all EU transpositions), EU Cyber Resilience Act, DORA, GDPR, PCI DSS, NIST CSF 2.0, Cyber Essentials, TISAX. Select several at once: overlapping policies are written once and mapped to every framework. |
| Will an auditor accept AI-assisted policies? | Yes, when they are specific to your organisation, approved by management, version-controlled and communicated. Auditors reject generic template packs, not well-written documents. Every document leaves us reviewed and signed off by a CISA-certified consultant. |
Why 60% of compliance policies are the same document
Every management-system standard and every security regulation asks the same underlying questions: who is responsible, what is in scope, how do you control access, how do you manage change, how do you respond to incidents, how do you handle suppliers, how do you train people, and how do you prove all of it. The clause numbers differ. The policies do not. The table below shows the core set that appears, under one name or another, in each framework.
| Policy or procedure | ISO 27001 | SOC 2 | HIPAA | CMMC / 800-171 | NIS2 | ISO 9001 | ISO 14001 | EU CRA |
|---|---|---|---|---|---|---|---|---|
| Information security policy (top-level) | 5.1, A.5.1 | CC1, CC5 | 164.316 | 3.12, SSP | Art. 21(2)(a) | 5.2 (quality policy) | 5.2 (env. policy) | Annex I |
| Roles, responsibilities and governance | 5.3, A.5.2 | CC1.3 | 164.308(a)(2) | SSP roles | Art. 20 | 5.3 | 5.3 | Art. 13 |
| Risk assessment and treatment | 6.1, 8.2 | CC3 | 164.308(a)(1)(ii)(A) | 3.11 | Art. 21(2)(a) | 6.1 | 6.1 | Art. 13(2) |
| Access control and identity | A.5.15-5.18, A.8.2-8.5 | CC6 | 164.312(a) | 3.1, 3.5 | Art. 21(2)(i),(j) | 7.5.3 | 7.5.3 | Annex I(1) |
| Acceptable use of assets | A.5.10 | CC6.1 | 164.310(b) | 3.1.22, 3.8 | Art. 21(2)(g) | 7.1.3 | 8.1 | Annex I |
| Asset and configuration management | A.5.9, A.8.9 | CC6.1, CC7.1 | 164.310(d) | 3.4 | Art. 21(2)(e) | 7.1.5 | 8.1 | Annex I(2) |
| Change management | A.8.32 | CC8 | 164.308(a)(8) | 3.4.3 | Art. 21(2)(e) | 6.3, 8.5.6 | 8.1 | Annex I(2) |
| Incident response and reporting | A.5.24-5.28 | CC7.3-7.5 | 164.308(a)(6) | 3.6, DFARS 7012 (72h) | Art. 23 (24h / 72h / 1 month) | 10.2 | 8.2, 10.2 | Art. 14 (24h) |
| Business continuity and backup | A.5.29-5.30, A.8.13-8.14 | A1 | 164.308(a)(7) | 3.8.9 | Art. 21(2)(c) | 8.7 | 8.2 | Annex I |
| Supplier and third-party security | A.5.19-5.23 | CC9.2 | 164.308(b) | 3.1.20, flow-down | Art. 21(2)(d) | 8.4 | 8.1 | Art. 13(5) |
| Human resources security and training | A.6.1-6.8 | CC1.4, CC2.2 | 164.308(a)(5) | 3.2, 3.9 | Art. 21(2)(g) | 7.2, 7.3 | 7.2, 7.3 | Annex I |
| Data classification, handling and retention | A.5.12-5.14, A.5.33 | C1, P (privacy) | 164.312(c), 164.316(b) | 3.8, 3.13 | Art. 21(2)(h) | 7.5 | 7.5 | Annex I |
| Cryptography and key management | A.8.24 | CC6.1, CC6.7 | 164.312(a)(2)(iv) | 3.13.11 (FIPS) | Art. 21(2)(h) | n/a | n/a | Annex I(1) |
| Logging, monitoring and vulnerability management | A.8.8, A.8.15-8.16 | CC7.1-7.2 | 164.312(b) | 3.3, 3.11.2 | Art. 21(2)(e),(f) | 9.1 | 9.1 | Art. 13, Annex I(2) |
| Physical and environmental security | A.7.1-7.14 | CC6.4 | 164.310 | 3.10 | Art. 21(2)(e) | 7.1.4 | 8.1 | n/a |
| Secure development and product security | A.8.25-8.31 | CC8.1 | n/a | 3.14 | Art. 21(2)(e) | 8.3 | 8.1 | Annex I, Art. 13 |
| Document control, internal audit and management review | 7.5, 9.2, 9.3 | CC4 | 164.316 | 3.12.1, 3.12.3 | Art. 20(2) | 7.5, 9.2, 9.3 | 7.5, 9.2, 9.3 | Art. 13 |
| Corrective action and continual improvement | 10.1, 10.2 | CC4.2 | 164.308(a)(8) | POA&M | Art. 21(2)(f) | 10.2, 10.3 | 10.2, 10.3 | Art. 13 |
Seventeen documents, eight frameworks, one baseline. When you select ISO 27001 and SOC 2 together, or CMMC and NIS2 together, you do not pay for the overlap twice. Each document carries a mapping table that shows the auditor exactly which clause or control it satisfies in every framework you chose.
The 40% that has to be written for you
This is the part template packs get wrong and auditors notice immediately. A policy that does not name your systems, your people and your regulator’s deadlines is not evidence of anything. The customised layer we write for every client includes:
- Scope statement and context: your legal entities, sites, cloud tenants, products and the interested parties each framework requires you to identify.
- Risk register and treatment plan: real assets, real threats, real owners, and for ISO 27001 the Statement of Applicability against the 93 Annex A controls.
- Roles and RACI: who approves, who operates, who reviews. For CMMC this feeds the System Security Plan; for NIS2 it documents management-body accountability under Article 20.
- Incident escalation with your deadlines: NIS2 early warning within 24 hours and notification within 72 hours, HIPAA breach notification within 60 days, DFARS 252.204-7012 reporting within 72 hours, EU CRA actively exploited vulnerability reporting within 24 hours, GDPR supervisory authority notice within 72 hours. Written with your named contacts and your national authority.
- Environmental aspects and quality objectives: for ISO 14001 and ISO 9001, the aspects register, legal register and measurable objectives that make those systems auditable.
- Supplier tiers and flow-down clauses: your critical suppliers, what you require of them, and the contract language you need for CMMC flow-down and NIS2 supply-chain security.
- Retention schedule by jurisdiction: what you keep, for how long, under which law, in which country.
- AI use policy: increasingly requested by customers and required by ISO 42001. Which tools are allowed, what data may enter them, and who approves new ones.
How the one-week process works
| Day | What happens | What we need from you |
|---|---|---|
| Day 1 | Intake: frameworks, scope, systems, org chart, existing documents, audit date. We confirm the document list and fixed price. | One 45-minute call, or the intake form on this page plus a few uploads. |
| Days 2-3 | Baseline assembly and AI-assisted customisation. Our GRC tooling drafts the custom 40% from your intake against the audited baseline, producing first drafts of every document with framework mapping. | Nothing. We may send 3-5 clarifying questions by email. |
| Day 4 | Senior consultant review. A CISA-certified consultant rewrites anything the tooling got generic, checks every regulatory deadline and cross-references the mapping table. | Nothing. |
| Day 5 | Review call. We walk your compliance lead through the set, capture corrections and agree owners for each document. | One 60-minute call. |
| Days 6-7 | Final set delivered in Word and PDF, plus the approval register, distribution record and review calendar. Optional: we load everything into your GRC platform or SharePoint. | Management sign-off. |
Why it costs up to 80% less than a compliance consultancy
The saving is structural, not a discount. Consultancies draft from a blank page and bill by the hour, so the same information security policy is written for the hundredth time at full rate. Compliance-automation platforms give you templates, then leave the customisation to you, which is where the audit findings come from. ITSECOPS sits between the two:
- Maintained baseline: the shared 60% is written once, kept current with every standard revision (ISO 27001:2022, NIS2 national laws, CMMC 32 CFR 170, the HIPAA Security Rule update) and reused across clients.
- AI-assisted GRC drafting: the custom layer is generated from your intake in hours rather than billed in days, then finished by a human who has sat through audits.
- Fixed price: you know the number before we start. No hourly meter, no scope creep.
- Two-office delivery: senior review from Norway and India means audit-grade quality at rates that do not carry a US or Western European overhead.
| Compliance consultancy | Template pack | ITSECOPS policy pack | |
|---|---|---|---|
| Time to complete set | 4-8 weeks | 1 day to download, weeks to customise | 1 week, delivered and approved |
| Pricing model | Hourly or day rate | One-off, per pack | Fixed, per framework set |
| Customised to your organisation | Yes | No, you do it | Yes, 40% written for you |
| Multi-framework mapping | Sometimes, at extra cost | Rarely | Included |
| Reviewed by certified consultant | Yes | No | Yes (CISA) |
| Typical relative cost | 100% | 5-10%, plus your time | 20-40% |
What auditors actually check on a policy
Whether the auditor is a certification body, a CPA firm for SOC 2, a C3PAO, or a NIS2 supervisory authority, the checklist is the same. Every document we deliver satisfies all six:
- Ownership: a named owner and a named approver, with the approval date and signature or workflow record.
- Version control: version number, change history, and a review date no more than 12 months out.
- Specificity: your systems, roles and thresholds, not “the organisation shall”.
- Communication: evidence that the people bound by the policy have seen it (distribution record, training log, acknowledgement).
- Mapping: a table showing which clause or control the document satisfies, per framework.
- Operation: a procedure or record that proves the policy is followed. We flag where that evidence needs to come from and, if you want, our AI GRC automation collects it continuously.
Framework notes
ISO 27001:2022
Clauses 4-10 plus the 93 Annex A controls. Mandatory documents include the ISMS scope, information security policy, risk assessment and treatment methodology, Statement of Applicability, risk treatment plan and the records in clauses 7.5, 9 and 10. See our ISO 27001 guide and implementation plan.
SOC 2
Policies map to the Trust Services Criteria (Security plus any of Availability, Confidentiality, Processing Integrity, Privacy). The CPA firm tests that policies exist, are approved and are operating. Shared documents with ISO 27001 are near-total, which is why we recommend doing both at once. See SOC 2 readiness.
HIPAA
The Security Rule requires written policies for administrative, physical and technical safeguards (45 CFR 164.308-164.316), retained for six years, with the risk analysis as the anchor document OCR asks for first. See our HIPAA compliance page.
CMMC Level 2 and NIST SP 800-171
Assessors expect a policy and a procedure for each of the 14 control families, a System Security Plan, and a Plan of Action and Milestones. Our set is written per family and ties directly to the 110 practices in our controls list. See CMMC compliance.
NIS2
Article 21(2) lists ten minimum measures that must be documented, and Article 20 makes management bodies personally accountable for approving them. National transpositions (Cyberbeveiligingswet in the Netherlands, NIS2UmsuCG in Germany, digitalsikkerhetsloven in Norway) add registration and reporting detail we write into your incident procedure. See NIS2 compliance and the NIS2 scope checker.
EU Cyber Resilience Act
Manufacturers of products with digital elements need a vulnerability-handling policy, a coordinated disclosure policy, an SBOM process and a reporting procedure that meets the 24-hour early-warning duty that applies from 11 September 2026. See EU CRA readiness.
ISO 9001 and ISO 14001
Both share the Annex SL structure with ISO 27001, so context, leadership, planning, support, operation, evaluation and improvement documents are written once and specialised: quality objectives and customer-focus procedures for 9001, aspects and impacts, legal register and emergency preparedness for 14001. An integrated management system manual is included when you select more than one ISO standard.
ISO 42001 and AI governance
The AI management system standard reuses the same structure and adds AI-specific policies: acceptable AI use, AI risk and impact assessment, data governance for training and prompts, and human oversight. Increasingly requested in customer questionnaires. See ISO 42001.
Frequently asked questions
How many policies do I actually need for ISO 27001?
The standard mandates a handful of documents explicitly (scope, policy, risk methodology, Statement of Applicability, treatment plan, and defined records), but certification bodies expect the Annex A control themes to be covered by policy. A practical ISO 27001 set is 18-24 documents. Ours is 22 for a single-entity company, fewer if you already have HR or supplier policies we can reference.
Can you write policies for two or three frameworks at the same time?
Yes, and it is cheaper than doing them one at a time. ISO 27001 plus SOC 2, CMMC plus NIS2, or ISO 9001 plus 14001 plus 27001 as an integrated system are the most common combinations. Overlapping documents are written once with a mapping table for each framework.
What do you need from us to start?
The frameworks you are targeting, an org chart, a list of your main systems and cloud services, any existing policies (even outdated ones), and your audit or customer deadline. The quote form on this page collects the essentials; the rest is covered in a 45-minute intake call.
Are AI-written policies accepted by auditors and C3PAOs?
Auditors assess the document, not the drafting tool. What fails audits is a generic policy that does not describe your organisation, has no owner and has never been communicated. Every document we deliver is customised, reviewed and signed off by a CISA-certified consultant, version-controlled and accompanied by an approval record.
Do you also implement the controls the policies describe?
Yes, if you want that. Policies are the first deliverable in our readiness consulting, and many clients continue with a fractional CISO engagement, managed security tooling or continuous evidence collection. The policy pack stands on its own if you only need the documents.
I already have a quote from a compliance firm. Can you beat it?
Usually, and we say so quickly if we cannot. Include the quoted amount and scope in the form and you get a like-for-like fixed price within one business day, typically 60-80% lower for the same document list and a faster delivery date.
Get your policies sent within one week
Tell us your frameworks and your deadline. You receive a fixed quote, the complete document list and the one-week delivery plan within one business day. Already have a quote? Include it and we tell you whether we can beat it.