agency-compliance-auditor

Assesses security controls and produces gap reports for SOC 2, ISO 27001, HIPAA, and PCI-DSS audits.

Updated Jul 27, 2026
One-click install
npx skills add https://github.com/imMamdouhaboammar/Mimera --skill agency-compliance-auditor-immamdouhaboammar
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: agency-compliance-auditor
Source: https://github.com/imMamdouhaboammar/Mimera/tree/main/.agents/skills/security-compliance-auditor
Command: npx skills add https://github.com/imMamdouhaboammar/Mimera --skill agency-compliance-auditor-immamdouhaboammar

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Preparing for security certifications like SOC 2 or ISO 27001 requires mapping controls, collecting evidence, and closing gaps, which teams often handle ad hoc and fail audits over missing documentation. ## Core Features & Use Cases - Gap Assessment: Evaluates current security posture against framework control objectives and produces prioritized remediation roadmaps with effort estimates. - Evidence Collection Planning: Builds evidence matrices mapping each control to its source system, collection method, and frequency. - Policy & Audit Support: Generates audit-ready policy templates mapped to control IDs and supports auditor communications and finding remediation. - Use Case: A startup preparing for its first SOC 2 Type II audit uses this Skill to assess access control gaps, produce a readiness scorecard, and build an automated evidence collection plan before the auditor arrives. ## Quick Start Ask the auditor to assess your current AWS and Okta setup against SOC 2 CC6 access control requirements and produce a gap report.

Frequently Asked Questions about agency-compliance-auditor

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for a SOC 2 audit?

Start with a gap assessment mapping your current controls against the Trust Services Criteria, then remediate findings by severity. Build an evidence collection matrix so proof of control operation is gathered continuously before the audit period begins.

What is included in a compliance gap assessment?

Each finding includes the control reference, current state, target state, numbered remediation steps, effort estimate, and priority. Results are grouped by control domain with an overall readiness score and estimated time to audit-ready.

Can one set of controls satisfy SOC 2 and ISO 27001?

Yes, common control frameworks let you map a single set of controls across multiple certifications to eliminate duplicate effort. The Skill maps existing controls across frameworks and identifies where one implementation satisfies several requirements.

What evidence do auditors request for access controls?

Auditors typically request access review logs, provisioning and deprovisioning records, and proof that controls operated over the full audit period. Evidence should be collected automatically from systems like Okta or Jira rather than manually.

When should a startup not pursue SOC 2 certification?

Certification may be premature if controls cannot operate consistently over the required audit period or if no customers require it. Right-size the program to actual risk and company stage rather than copying enterprise-grade programs.