← ClaudeAtlas

soc2-readiness-checklisted

Runs a structured SOC 2 readiness gap assessment against the Trust Services Criteria and returns a prioritized remediation plan with effort estimates and sequencing. Use when someone asks how far they are from SOC 2, what they need before an audit, whether they are audit-ready, or wants a compliance gap analysis for a startup or scaling SaaS company. Assesses only against evidence provided and never assumes a control exists.
mercydeez/claude-compliance-skills · ★ 0 · AI & Automation · score 67
Install: claude install-skill mercydeez/claude-compliance-skills
# SOC 2 readiness check The question "how far are we from SOC 2?" usually gets answered with either a sales pitch or a 40-page consultant deck. Neither tells a founder what to do on Monday. This skill produces a scoped gap assessment and an ordered remediation plan. ## When to use this Use when someone wants to know their gap to SOC 2, Type I or Type II, or asks for a compliance readiness assessment, a pre-audit gap analysis, or "what do we need before we can start an audit". Do **not** use when: - The framework is ISO 27001, NIST, or HIPAA. The criteria differ and the reference file here is SOC 2 only. Say so rather than mapping across. - The user is answering a customer's questions about existing posture, which is `security-questionnaire-responder`. - The user is mid-audit and collecting requested evidence, which is `evidence-request-tracker`. - The user wants an audit opinion. This skill cannot give one and must say so. ## Inputs **Required** - Company profile: headcount, product and architecture in one paragraph, cloud provider, what customer data is processed. - Current state, whatever exists: policy documents, tooling list (IdP, MDM, ticketing, monitoring, HR system), and any prior assessment. **Optional** - Target: Type I or Type II, and target date. This changes sequencing significantly, because Type II requires an observation window and control operation must start early. - Trust Services Categories in scope. Default is Security only, the common starting scope