soc2-compliance

Installation
SKILL.md

SOC 2 Compliance

Overview

SOC 2 (System and Organization Controls 2) is an auditing standard developed by the AICPA for service organizations. A SOC 2 Type II report covers a period of 6-12 months, demonstrating controls are operating effectively — not just designed. Enterprise buyers almost universally require SOC 2 before signing contracts.

Trust Service Criteria (TSC)

Criteria Abbrev Required? Description
Security CC ✅ Always Protection against unauthorized access
Availability A Optional System available for operation and use
Confidentiality C Optional Information designated as confidential is protected
Processing Integrity PI Optional Processing is complete, valid, accurate, timely
Privacy P Optional Personal information collected, used, retained, disclosed properly

Most SaaS companies start with Security + Availability. Add Confidentiality if handling sensitive data; add Privacy if handling personal data covered by GDPR/CCPA.

Common Controls Framework (CC)

Installs
3
GitHub Stars
155
First Seen
12 days ago
soc2-compliance — terminalskills/skills