Compliance templates, ready to adapt.
Downloadable policy, legal, and audit-evidence templates to start (or fill the gaps in) your program. Every file is Markdown so you can drop it straight into your own docs. Replace the placeholders, assign an owner, and you have a defensible first draft.
These are starting points, not finished documents — and the legal contracts in particular must be reviewed by a qualified attorney before you rely on them. Nothing here is legal or compliance advice.
Compliance policies
Starting-point policies for a defensible security program. Adopt, tailor to your environment, assign an owner, approve.
The umbrella policy every program needs — roles, control statements, and enforcement.
Download .md ↓Least-privilege provisioning, MFA, periodic review, deprovisioning. Maps to PCI 7/8, ISO A.5.15–5.18, SOC 2 CC6.
Download .md ↓What users may and may not do with company systems, devices, and data.
Download .md ↓Methodology, scoring, treatment, and the risk register. Maps to ISO Clause 6, SOC 2 CC3, PCI 12.3.
Download .md ↓Sensitivity levels and the handling rules for each. Maps to ISO A.5.12–5.14, PCI Req 3.
Download .md ↓Roles, severity tiers, the response process, and testing. Satisfies PCI 12.10, SOC 2 CC7, ISO A.5.24–5.26.
Download .md ↓RTO/RPO targets, backups, recovery runbooks, and testing. Maps to ISO A.5.29–5.30, SOC 2 A1.
Download .md ↓Authorized, tested, traceable changes to production. Maps to ISO A.8.32, SOC 2 CC8.1, PCI Req 6.
Download .md ↓Risk-tiered diligence, contracts, and ongoing monitoring. Maps to ISO A.5.19–5.23, PCI 12.8.
Download .md ↓Encryption in transit/at rest, secrets handling, and key lifecycle. Maps to PCI 3/4, ISO A.8.24.
Download .md ↓What to log, how to protect logs, retention, and review. Maps to PCI Req 10, ISO A.8.15–8.16, SOC 2 CC7.
Download .md ↓Secure design, code review, CI security scanning, and remediation SLAs. Maps to PCI Req 6, ISO A.8.25–8.29.
Download .md ↓Legal contracts
Generic, jurisdiction-neutral starting points. Have a qualified attorney review before you rely on them.
A balanced two-way NDA for exploring a relationship.
Download .md ↓GDPR Article 28 clauses, subprocessors, transfers, and security annexes.
Download .md ↓Subscription terms: access, fees, term, liability, and data protection.
Download .md ↓Required when a vendor handles PHI — permitted uses, safeguards, breach reporting.
Download .md ↓SAQ & audit evidence
Worksheets and evidence templates that pair with the free SAQ wizard and your audit.
Document your payment channels and cardholder-data flows before picking an SAQ type.
Download .md ↓Record a periodic access review — the signed log is your audit evidence.
Download .md ↓One register mapping each control to its evidence, owner, cadence, and the frameworks it satisfies.
Download .md ↓Describe how a control is designed and operated, so auditors can test it.
Download .md ↓Want these filled in automatically?
The SentinelPanda platform tracks owners, approvals, reviews, and evidence for each policy — so "is this current?" is a lookup, not an investigation.