soc2

Guides SOC 2 gap analysis, policy writing, control documentation, and audit evidence preparation.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill soc2-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: soc2
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/soc2
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill soc2-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Preparing for a SOC 2 audit requires deep knowledge of the AICPA Trust Services Criteria, and teams often struggle to translate criteria into concrete controls, policies, and evidence. This Skill provides structured guidance across all five Trust Services Criteria so organizations can assess readiness, document controls, and prepare for Type 1 or Type 2 audits. ## Core Features & Use Cases - Gap Analysis & Readiness Assessment: RAG-status self-assessment framework mapped to CC1–CC9, A1, C1, PI1, and P1–P8, with remediation plan templates. - Policy & Control Documentation: Templates and writing standards for the 13 core SOC 2 policies plus a full control matrix with test procedures per criterion. - Audit Evidence & Vendor Risk: Evidence catalogs organized by criterion, sampling guidance for Type 2 audits, vendor risk questionnaires, SOC 2 report review checklists, and CUEC tracking. - Use Case: A startup receives a customer request for a SOC 2 report. Use this Skill to scope the audit, run a gap analysis against the Common Criteria, draft the required policies, and organize an evidence folder before engaging an auditor. ## Quick Start Ask the assistant to run a SOC 2 Type 2 gap analysis for the Security and Availability criteria and produce a remediation plan.

Frequently Asked Questions about soc2

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a SOC 2 gap analysis?

A SOC 2 gap analysis assesses each in-scope Trust Services Criterion for design, implementation, and evidence, assigning a Met, Partial, or Gap status. This Skill provides a step-by-step framework covering scoping, common gaps per criterion, and a remediation plan template with owners and deadlines.

What policies are required for SOC 2 compliance?

SOC 2 typically requires 13 core policies including Information Security, Access Control, Incident Response, Change Management, Risk Assessment, Vendor Management, Business Continuity, Data Classification, Acceptable Use, Privacy, Encryption, and Vulnerability Management. Each policy must map to specific TSC criteria and include ownership and annual review.

What is the difference between SOC 2 Type 1 and Type 2?

Type 1 tests whether controls are designed correctly at a single point in time, while Type 2 tests operating effectiveness over a period of typically 6 to 12 months. Type 2 requires evidence sampled across the full audit period, such as quarterly access reviews and change tickets.

What evidence do auditors request for SOC 2 access controls?

Auditors typically request user access list exports, access request and approval tickets, termination de-provisioning records, quarterly access review sign-offs, MFA configuration screenshots, and privileged access reviews. Evidence must be dated, attributable to individuals, and cover the full audit period for Type 2.

How do I review a vendor's SOC 2 report?

Review the report type, audit period, auditor opinion, exceptions in the test results section, and Complementary User Entity Controls. Document the review in a log with the opinion, notable exceptions, identified CUECs, and any follow-up actions, and re-review annually for critical vendors.

Does this Skill replace a licensed CPA firm for SOC 2 audits?

No. Formal SOC 2 audits must be performed by a licensed CPA firm, and this Skill explicitly flags when one is required. It provides preparation guidance, templates, and general compliance information, not legal advice or an official attestation.