soc2-readiness-checklisted
Install: claude install-skill mercydeez/claude-compliance-skills
# SOC 2 readiness check
The question "how far are we from SOC 2?" usually gets answered with either a sales pitch or a 40-page consultant deck. Neither tells a founder what to do on Monday. This skill produces a scoped gap assessment and an ordered remediation plan.
## When to use this
Use when someone wants to know their gap to SOC 2, Type I or Type II, or asks for a compliance readiness assessment, a pre-audit gap analysis, or "what do we need before we can start an audit".
Do **not** use when:
- The framework is ISO 27001, NIST, or HIPAA. The criteria differ and the reference file here is SOC 2 only. Say so rather than mapping across.
- The user is answering a customer's questions about existing posture, which is `security-questionnaire-responder`.
- The user is mid-audit and collecting requested evidence, which is `evidence-request-tracker`.
- The user wants an audit opinion. This skill cannot give one and must say so.
## Inputs
**Required**
- Company profile: headcount, product and architecture in one paragraph, cloud provider, what customer data is processed.
- Current state, whatever exists: policy documents, tooling list (IdP, MDM, ticketing, monitoring, HR system), and any prior assessment.
**Optional**
- Target: Type I or Type II, and target date. This changes sequencing significantly, because Type II requires an observation window and control operation must start early.
- Trust Services Categories in scope. Default is Security only, the common starting scope