SOC 2 Evidence Helper
Installation
SKILL.md
SOC 2 Evidence Helper
SOC 2 audits test whether security controls exist (Type I, point in time) and operate consistently over a review period (Type II, typically 3-12 months). Engineering teams lose the most time gathering evidence reactively in the month before fieldwork - and for Type II that scramble cannot work, because auditors sample from the whole period and a gap in month two is already a finding. Build collection into normal operations instead.
Operating procedure
Step 1: Gather inputs
- Type I or Type II, and the review period dates. Default assumption: first audit is Type I, followed by a 6-month Type II.
- Which Trust Service Criteria are in scope (Security is mandatory; the rest are contract-driven). If unknown, check customer contracts and security questionnaires - scope only what customers demand.
- The systems of record: IdP (Okta, Entra), source control, CI, cloud provider, ticketing, HR system, vulnerability scanner.
- Any prior findings or bridge letters. Label unknowns as unknowns.
Step 2: Scope the criteria before collecting anything
Auditors only test criteria in scope: