soc2

Featured

Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). Use this skill whenever a user mentions SOC 2, Trust Services Criteria, SOC 2 Type 1 or Type 2, audit readiness, compliance gaps, control documentation, evidence collection, vendor risk questionnaires, or anything related to AICPA service organization controls. Trigger even for adjacent topics like "we need to get audited", "a customer asked for our security report", "writing an information security policy", or "preparing for an audit". Covers gap analysis, policy writing, control documentation, audit evidence preparation, and vendor risk reviews for organizations at any maturity level — from first-time startups to seasoned compliance teams.

Data & Documents 890 stars 179 forks Updated 5 days ago MIT

Install

View on GitHub

Quality Score: 93/100

Stars 20%
98
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# SOC 2 Compliance Skill > **Last verified:** 2026-07-03 You are an expert SOC 2 compliance advisor with deep knowledge of the AICPA 2017 Trust Services Criteria (with 2022 Revised Points of Focus). You help organizations prepare for, document, and sustain SOC 2 audits across all five Trust Services Criteria. --- ## Quick Reference: Trust Services Criteria | Category | Code | Required? | Criteria Series | |---|---|---|---| | Security (Common Criteria) | CC | **Always required** | CC1–CC9 | | Availability | A | Optional | A1 | | Confidentiality | C | Optional | C1 | | Processing Integrity | PI | Optional | PI1 | | Privacy | P | Optional | P1–P8 | **CC1–CC9 breakdown:** - CC1 Control Environment ("tone at top" — governance, integrity, oversight) - CC2 Communication and Information - CC3 Risk Assessment - CC4 Monitoring Controls - CC5 Control Activities - CC6 Logical & Physical Access Controls - CC7 System Operations (monitoring, incident response, DR) - CC8 Change Management - CC9 Risk Mitigation (vendor/third-party risk) --- ## How to Help Users — Task Router Identify the user's need and follow the relevant section below: | What they ask for | Where to go | |---|---| | Gap analysis / readiness check | → [Gap Analysis](#gap-analysis--readiness-assessment) | | Write a policy or procedure | → [Policy Writing](#policy--procedure-writing) + `references/policies.md` | | Document a control | → [Control Documentation](#control-documentation) + `references/controls.md` | | Co...

Details

Author
Sushegaad
Repository
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Created
5 months ago
Last Updated
5 days ago
Language
HTML
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

Data & Documents Listed

soc2

Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). Use this skill whenever a user mentions SOC 2, Trust Services Criteria, SOC 2 Type 1 or Type 2, audit readiness, compliance gaps, control documentation, evidence collection, vendor risk questionnaires, or anything related to AICPA service organization controls. Trigger even for adjacent topics like "we need to get audited", "a customer asked for our security report", "writing an information security policy", or "preparing for an audit". Covers gap analysis, policy writing, control documentation, audit evidence preparation, and vendor risk reviews for organizations at any maturity level — from first-time startups to seasoned compliance teams.

3 Updated today
Jandyoverseas977
Data & Documents Listed

soc2-report

Use when preparing a SOC 2 report or readiness assessment — mapping controls to the Trust Services Criteria, choosing Type I vs Type II, gathering audit evidence, and tracking exceptions. Triggers on "SOC 2", "Type I", "Type II", "Trust Services Criteria", "TSC", "audit evidence", "AICPA", "control exception".

1 Updated today
noctua84
AI & Automation Listed

soc2-readiness-check

Runs a structured SOC 2 readiness gap assessment against the Trust Services Criteria and returns a prioritized remediation plan with effort estimates and sequencing. Use when someone asks how far they are from SOC 2, what they need before an audit, whether they are audit-ready, or wants a compliance gap analysis for a startup or scaling SaaS company. Assesses only against evidence provided and never assumes a control exists.

0 Updated 1 months ago
mercydeez