soc2-compliance

Guides SOC 2 Type 1 and Type 2 readiness with TSC gap analysis and audit evidence checklists.

1|Updated Aug 10, 2026
One-click install
npx skills add https://github.com/TheViziusGroup/vibe-engineering-skills --skill soc2-compliance-theviziusgroup
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: soc2-compliance
Source: https://github.com/TheViziusGroup/vibe-engineering-skills/tree/main/plugins/compliance-frameworks/skills/soc2-compliance
Command: npx skills add https://github.com/TheViziusGroup/vibe-engineering-skills --skill soc2-compliance-theviziusgroup

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Preparing for a SOC 2 audit requires understanding the Trust Services Criteria, building a minimum policy set, and collecting dated evidence of control operation, which is difficult without structured guidance. ## Core Features & Use Cases - TSC Framework Guidance: Explains the five Trust Service Categories (Security, Availability, Processing Integrity, Confidentiality, Privacy) and the CC1-CC9 Common Criteria subcriteria. - Minimum Policy Set: Defines the 12 policies required for SOC 2 Type 2, including access control, incident response, change management, and vendor management. - Control Mapping & Evidence Checklists: Maps SOC 2 criteria to NIST 800-53 control families and provides auditor-ready evidence collection checklists for access, change management, monitoring, vendors, and DR. - Use Case: A SaaS company preparing for its first Type 2 audit uses this Skill to identify gaps like missing access reviews and untested backup restoration, then builds a remediation plan before engaging an auditor. ## Quick Start Ask the AI to run a SOC 2 Type 2 readiness assessment for your SaaS product and list the gaps against the Common Criteria.

Frequently Asked Questions about soc2-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for a SOC 2 Type 2 audit?

SOC 2 Type 2 preparation requires implementing the 12 minimum policies, operating controls over a 6-12 month period, and collecting dated evidence such as access reviews, change tickets, and incident logs. A readiness checklist verifies governance, access controls, monitoring, and vendor management before engaging an auditor.

What is the difference between SOC 2 Type 1 and Type 2?

Type 1 is a point-in-time assessment confirming controls are suitably designed as of a specific date, typically taking 2-4 months. Type 2 evaluates whether controls operated effectively over a 6-12 month period and is required by most enterprise customers.

Which Trust Services Criteria are required for SOC 2?

Security (Common Criteria CC1-CC9) is always required in every SOC 2 report. Availability, Processing Integrity, Confidentiality, and Privacy are optional and should be included based on SLA commitments, transaction processing, confidential data handling, or privacy obligations.

How do SOC 2 controls map to NIST 800-53?

The AICPA publishes a mapping from Trust Services Criteria to NIST 800-53 families. For example, CC6 logical access maps to AC and IA, CC7 incident response maps to IR, and CC8 change management maps to CM and SA.

What are the most common SOC 2 gaps in SaaS companies?

Common gaps include missing formal access reviews, developers deploying directly to production without separation of duties, untested incident response plans, uninvestigated monitoring alerts, uncollected vendor SOC reports, and backups never verified through restoration tests.