What problem does it solve? Preparing for a SOC 2 audit requires deep knowledge of the AICPA Trust Services Criteria, and teams often struggle to translate criteria into concrete controls, policies, and evidence. This Skill provides structured guidance across all five Trust Services Criteria so organizations can assess readiness, document controls, and prepare for Type 1 or Type 2 audits. ## Core Features & Use Cases - Gap Analysis & Readiness Assessment: RAG-status self-assessment framework mapped to CC1–CC9, A1, C1, PI1, and P1–P8, with remediation plan templates. - Policy & Control Documentation: Templates and writing standards for the 13 core SOC 2 policies plus a full control matrix with test procedures per criterion. - Audit Evidence & Vendor Risk: Evidence catalogs organized by criterion, sampling guidance for Type 2 audits, vendor risk questionnaires, SOC 2 report review checklists, and CUEC tracking. - Use Case: A startup receives a customer request for a SOC 2 report. Use this Skill to scope the audit, run a gap analysis against the Common Criteria, draft the required policies, and organize an evidence folder before engaging an auditor. ## Quick Start Ask the assistant to run a SOC 2 Type 2 gap analysis for the Security and Availability criteria and produce a remediation plan.