SOC 2 Evidence Helper

Installation
SKILL.md

SOC 2 Evidence Helper

SOC 2 audits test whether security controls exist (Type I, point in time) and operate consistently over a review period (Type II, typically 3-12 months). Engineering teams lose the most time gathering evidence reactively in the month before fieldwork - and for Type II that scramble cannot work, because auditors sample from the whole period and a gap in month two is already a finding. Build collection into normal operations instead.

Operating procedure

Step 1: Gather inputs

  • Type I or Type II, and the review period dates. Default assumption: first audit is Type I, followed by a 6-month Type II.
  • Which Trust Service Criteria are in scope (Security is mandatory; the rest are contract-driven). If unknown, check customer contracts and security questionnaires - scope only what customers demand.
  • The systems of record: IdP (Okta, Entra), source control, CI, cloud provider, ticketing, HR system, vulnerability scanner.
  • Any prior findings or bridge letters. Label unknowns as unknowns.

Step 2: Scope the criteria before collecting anything

Auditors only test criteria in scope:

Installs
First Seen
SOC 2 Evidence Helper — skillmedev/security-compliance-hardening