soc2

Installation
SKILL.md

SOC 2 Type II Prep

Disclaimer: this skill supports preparation for a SOC 2 examination but does not replace an AICPA-licensed auditor. Only a licensed CPA firm can issue a SOC 2 report. This skill helps with pre-audit readiness.

When to use

SOC 2 (System and Organization Controls 2) is an AICPA framework for service organizations that demonstrates that controls around Security and related Trust Services Criteria are effective. Popular in B2B SaaS because US customers (and increasingly EU customers) put it as a contractual requirement.

Triggers on:

  • A question like "where do we start with SOC 2", "Type I or Type II", "which TSCs to select", "evidence for SOC 2", "explain CUECs to a customer", "overlap with ISO 27001".
  • A B2B SaaS that hits a SOC 2 requirement on an RFP or master service agreement.
  • A handoff from iso27001 for a dual-attestation strategy.
  • Preparation for the annual Type II cycle (observation period + report).

When NOT (handoff)

Installs
2
GitHub Stars
4
First Seen
May 18, 2026
soc2 — roodlicht/accans-sec-skills