soc2

Solid

Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). Use this skill whenever a user mentions SOC 2, Trust Services Criteria, SOC 2 Type 1 or Type 2, audit readiness, compliance gaps, control documentation, evidence collection, vendor risk questionnaires, or anything related to AICPA service organization controls. Trigger even for adjacent topics like "we need to get audited", "a customer asked for our security report", "writing an information security policy", or "preparing for an audit". Covers gap analysis, policy writing, control documentation, audit evidence preparation, and vendor risk reviews for organizations at any maturity level — from first-time startups to seasoned compliance teams.

Data & Documents 780 stars 162 forks Updated 1 weeks ago MIT

Install

View on GitHub

Quality Score: 90/100

Stars 20%
96
Recency 20%
90
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# SOC 2 Compliance Skill > **Last verified:** 2026-07-03 You are an expert SOC 2 compliance advisor with deep knowledge of the AICPA 2017 Trust Services Criteria (with 2022 Revised Points of Focus). You help organizations prepare for, document, and sustain SOC 2 audits across all five Trust Services Criteria. --- ## Quick Reference: Trust Services Criteria | Category | Code | Required? | Criteria Series | |---|---|---|---| | Security (Common Criteria) | CC | **Always required** | CC1–CC9 | | Availability | A | Optional | A1 | | Confidentiality | C | Optional | C1 | | Processing Integrity | PI | Optional | PI1 | | Privacy | P | Optional | P1–P8 | **CC1–CC9 breakdown:** - CC1 Control Environment ("tone at top" — governance, integrity, oversight) - CC2 Communication and Information - CC3 Risk Assessment - CC4 Monitoring Controls - CC5 Control Activities - CC6 Logical & Physical Access Controls - CC7 System Operations (monitoring, incident response, DR) - CC8 Change Management - CC9 Risk Mitigation (vendor/third-party risk) --- ## How to Help Users — Task Router Identify the user's need and follow the relevant section below: | What they ask for | Where to go | |---|---| | Gap analysis / readiness check | → [Gap Analysis](#gap-analysis--readiness-assessment) | | Write a policy or procedure | → [Policy Writing](#policy--procedure-writing) + `references/policies.md` | | Document a control | → [Control Documentation](#control-documentation) + `references/controls.md` | | Co...

Details

Author
Sushegaad
Repository
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Created
4 months ago
Last Updated
1 weeks ago
Language
HTML
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

Data & Documents Listed

soc2

Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). Use this skill whenever a user mentions SOC 2, Trust Services Criteria, SOC 2 Type 1 or Type 2, audit readiness, compliance gaps, control documentation, evidence collection, vendor risk questionnaires, or anything related to AICPA service organization controls. Trigger even for adjacent topics like "we need to get audited", "a customer asked for our security report", "writing an information security policy", or "preparing for an audit". Covers gap analysis, policy writing, control documentation, audit evidence preparation, and vendor risk reviews for organizations at any maturity level — from first-time startups to seasoned compliance teams.

3 Updated yesterday
Jandyoverseas977
Data & Documents Listed

soc2-report

Use when preparing a SOC 2 report or readiness assessment — mapping controls to the Trust Services Criteria, choosing Type I vs Type II, gathering audit evidence, and tracking exceptions. Triggers on "SOC 2", "Type I", "Type II", "Trust Services Criteria", "TSC", "audit evidence", "AICPA", "control exception".

0 Updated today
noctua84
Data & Documents Listed

iso27001

Expert ISO 27001 compliance assistant for security and compliance teams. Use this skill whenever a user asks about ISO 27001 or ISO/IEC 27001, including any of the following: gap analysis, auditing, compliance assessments, control checklists, policy writing, document generation, Statement of Applicability (SoA), risk assessment, risk registers, risk treatment plans, Annex A controls, ISMS implementation, clause requirements, certification readiness, transitioning from 2013 to 2022, control implementation guidance, incident response policies, access control policies, supplier security, or any information security management system (ISMS) topic. Trigger even if the user doesn't say "skill" — any ISO 27001 or ISMS question should use this skill.

3 Updated yesterday
Jandyoverseas977