soc2-audit

Map SOC 2 controls to evidence sources and generate auditor-ready findings.

13|3|Updated Mar 27, 2026
One-click install
npx skills add https://github.com/heaptracetechnology/heaptrace-skills --skill soc2-audit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: soc2-audit
Source: https://github.com/heaptracetechnology/heaptrace-skills/tree/main/compliance/soc2-audit
Command: npx skills add https://github.com/heaptracetechnology/heaptrace-skills --skill soc2-audit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Audit-readiness and evidence collection for SOC 2, enabling teams to map Trust Service Criteria to concrete evidence sources, identify gaps, and generate auditor-ready findings.

Core Features & Use Cases

  • Maps SOC 2 criteria (CC1-CC9, A1, PI1, C1, P1-P8) to concrete evidence sources in your codebase, infrastructure, and processes.
  • Provides end-to-end readiness workflow: control mapping, evidence collection, gap analysis, and auditor-ready reporting.
  • Use Case: A SaaS company prepares for a SOC 2 audit by running a Type I readiness assessment across CI/CD pipelines and cloud configurations, then iterates on evidence gaps before the audit window.

Quick Start

Configure the SOC 2 audit skill with your audit period, evidence sources, and control mappings, then run readiness to generate findings.

Frequently Asked Questions about soc2-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for a SOC 2 audit and map evidence to Trust Service Criteria?

To prepare for a SOC 2 audit, map Trust Service Criteria controls to concrete evidence sources in your codebase, infrastructure, and processes. This identifies gaps and generates auditor-ready findings for Type I and Type II readiness.

What is the difference between SOC 2 Type I and Type II evidence collection requirements?

SOC 2 Type I readiness assesses control design at a single point in time, while Type II requires evidence collection over a defined audit period to verify operational effectiveness. Both require mapping infrastructure and process controls to Trust Service Criteria.

How do I conduct a SOC 2 gap analysis across CI/CD pipelines and cloud infrastructure?

Conduct a SOC 2 gap analysis by mapping Security (CC1-CC9), Availability (A1), Confidentiality (C1), and Privacy (P1-P8) controls to your CI/CD pipelines and cloud configurations. This process highlights missing evidence required for auditor-ready reporting.

Can I use this approach to map SOC 2 controls for operational processes and codebases?

Yes, you can map SOC 2 controls to operational processes and codebases. The readiness workflow evaluates change management and infrastructure configurations against Trust Service Criteria to document evidence requirements and pinpoint compliance gaps.

What is the best way to generate auditor-ready findings for SOC 2 compliance?

The best way to generate auditor-ready findings is to run an end-to-end SOC 2 readiness workflow. This workflow performs control mapping, collects evidence from defined sources, executes gap analysis, and outputs documented findings for the auditor.

When do I need to start SOC 2 audit readiness and evidence collection?

You need to start SOC 2 audit readiness before your defined audit window begins. Early evidence collection across codebases and operational processes allows time to iterate on identified control gaps and ensure Type II operational effectiveness.