soc2-readiness
Installation
SKILL.md
SOC 2 Readiness
Drive an organization from "no controls documented" to audit-ready.
1. Scoping
- Determine report type: Type I (point-in-time) vs Type II (period of time — start the observation window early)
- Define the system description: services in scope, infrastructure, boundaries (subprocessors, cloud providers)
- Select Trust Services Criteria: Security (required) + Availability, Confidentiality, Processing Integrity, Privacy as applicable
2. Gap Assessment
Map current practices to the criteria: