soc2-compliance-automator

Solid

SOC 2 Trust Services Criteria compliance automation for evidence collection, control mapping, and audit preparation

AI & Automation 1,160 stars 71 forks Updated today MIT

Install

View on GitHub

Quality Score: 96/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# SOC 2 Compliance Automator Skill ## Purpose Automate SOC 2 Trust Services Criteria (TSC) compliance activities including control mapping, evidence collection, audit preparation, and continuous compliance monitoring. ## Capabilities ### Control Mapping - Map organizational controls to SOC 2 TSC requirements - Cover all five Trust Services Categories: - Security (Common Criteria) - Availability - Processing Integrity - Confidentiality - Privacy - Generate control matrices with evidence requirements - Identify control gaps and coverage ### Evidence Collection - Automate evidence gathering from cloud providers - Collect access control configurations (IAM, RBAC) - Capture security configurations and policies - Document change management processes - Archive audit logs and monitoring data - Screenshot automation for manual controls ### Audit Preparation - Generate Type I and Type II audit packages - Prepare management assertion documents - Create system description documents - Organize evidence by control objective - Generate auditor-ready reports ### Control Effectiveness Tracking - Monitor control implementation status - Track control testing results - Document control exceptions - Manage remediation activities - Calculate compliance scores ### Continuous Compliance - Monitor control drift and changes - Alert on compliance deviations - Track evidence freshness - Generate compliance dashboards - Automate periodic control testing ## Trust Services Categories ##...

Details

Author
a5c-ai
Repository
a5c-ai/babysitter
Created
4 months ago
Last Updated
today
Language
JavaScript
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

DevOps & Infrastructure Featured

performing-soc2-type2-audit-preparation

Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing validation, remediation tracking, and continuous compliance monitoring. Covers all five TSC categories (Security, Availability, Processing Integrity, Confidentiality, Privacy) with automated evidence gathering from AWS, Azure, GCP, Okta, GitHub, and Jira. Use when preparing for or maintaining SOC 2 Type II certification.

13,115 Updated today
mukul975
AI & Automation Listed

soc2-readiness

Assess SOC 2 Type II readiness. Map Trust Services Criteria to controls, identify gaps, and build a remediation plan. Uses NIST SP 800-53 (public domain) as canonical reference with SOC 2 criterion cross-mapping. Use when user says "SOC 2 readiness," "SOC 2 preparation," "SOC 2 gap analysis," or "prepare for SOC 2 audit."

35 Updated today
open-agreements
AI & Automation Listed

soc2

SOC 2 Type II prep — AICPA Trust Services Criteria (Security required plus Availability/Confidentiality/Processing Integrity/Privacy), Common Criteria CC1–CC9, Type I vs Type II choice, evidence-collection rhythm, auditor-friendly packaging, Complementary User Entity Controls.

4 Updated 1 weeks ago
roodlicht
Data & Documents Solid

soc2

Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). Use this skill whenever a user mentions SOC 2, Trust Services Criteria, SOC 2 Type 1 or Type 2, audit readiness, compliance gaps, control documentation, evidence collection, vendor risk questionnaires, or anything related to AICPA service organization controls. Trigger even for adjacent topics like "we need to get audited", "a customer asked for our security report", "writing an information security policy", or "preparing for an audit". Covers gap analysis, policy writing, control documentation, audit evidence preparation, and vendor risk reviews for organizations at any maturity level — from first-time startups to seasoned compliance teams.

490 Updated today
Sushegaad
Data & Documents Listed

soc2

Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). Use this skill whenever a user mentions SOC 2, Trust Services Criteria, SOC 2 Type 1 or Type 2, audit readiness, compliance gaps, control documentation, evidence collection, vendor risk questionnaires, or anything related to AICPA service organization controls. Trigger even for adjacent topics like "we need to get audited", "a customer asked for our security report", "writing an information security policy", or "preparing for an audit". Covers gap analysis, policy writing, control documentation, audit evidence preparation, and vendor risk reviews for organizations at any maturity level — from first-time startups to seasoned compliance teams.

2 Updated today
Jandyoverseas977