soc2-compliance

Map SOC 2 Trust Service Criteria to controls and generate control matrices.

Updated Apr 16, 2026
One-click install
npx skills add https://github.com/devCharuzu/philfida-taskmanage --skill soc2-compliance-devcharuzu
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: soc2-compliance
Source: https://github.com/devCharuzu/philfida-taskmanage/tree/main/.windsurf/skills/soc2-compliance
Command: npx skills add https://github.com/devCharuzu/philfida-taskmanage --skill soc2-compliance-devcharuzu

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

SOC 2 readiness and evidence management for SaaS companies, mapping Trust Service Criteria to controls, generating control matrices, and guiding evidence collection and audit readiness.

Core Features & Use Cases

  • SOC 2 mapping: map criteria to controls and evidence requirements for Type I/II readiness.
  • Control Matrix: generate SOC 2 control matrices from selected criteria with owners and frequencies.
  • Evidence Management: guide automated collection, documentation, and evidence maintenance across the observation window.
  • Gap Analysis: identify missing, partial, and fully covered criteria to drive remediation.

Quick Start

Run a gap analysis against your current controls to drive SOC 2 readiness.

Frequently Asked Questions about soc2-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map Trust Service Criteria to existing controls for SOC 2 readiness?

A SOC 2 gap analysis compares your current controls against Trust Service Criteria to identify missing, partial, and fully covered requirements. This process drives targeted remediation efforts to achieve audit readiness.

What is the difference between SOC 2 Type I and Type II control matrix requirements?

For SaaS platforms, SOC 2 mapping applies Trust Service Criteria to your environment, generating control matrices with assigned owners and frequencies. This ensures your cloud infrastructure meets audit requirements.

How do I collect and manage SOC 2 audit evidence across the observation window?

To prepare for a SOC 2 audit, run a gap analysis against your current controls to identify missing criteria. Then generate a control matrix and apply evidence collection guidance to drive readiness.

How do I identify missing controls during a SOC 2 gap analysis?

SOC 2 readiness applies to SaaS platforms by mapping Trust Service Criteria directly to your cloud infrastructure controls. It generates control matrices and guides evidence collection tailored to your SaaS environment.