What problem does it solve? Preparing for a SOC 2 audit requires understanding the Trust Services Criteria, building a minimum policy set, and collecting dated evidence of control operation, which is difficult without structured guidance. ## Core Features & Use Cases - TSC Framework Guidance: Explains the five Trust Service Categories (Security, Availability, Processing Integrity, Confidentiality, Privacy) and the CC1-CC9 Common Criteria subcriteria. - Minimum Policy Set: Defines the 12 policies required for SOC 2 Type 2, including access control, incident response, change management, and vendor management. - Control Mapping & Evidence Checklists: Maps SOC 2 criteria to NIST 800-53 control families and provides auditor-ready evidence collection checklists for access, change management, monitoring, vendors, and DR. - Use Case: A SaaS company preparing for its first Type 2 audit uses this Skill to identify gaps like missing access reviews and untested backup restoration, then builds a remediation plan before engaging an auditor. ## Quick Start Ask the AI to run a SOC 2 Type 2 readiness assessment for your SaaS product and list the gaps against the Common Criteria.