soc2-readiness

v2026.09.25

Prepare an organization for a SOC 2 Type I or II audit — trust services criteria mapping, evidence collection, control implementation, and remediation planning. Use when starting a SOC 2 journey or preparing for an audit window.

GitHub
Install command
npx skhub add securityskills/soc2-readiness
Markdown
SKILL.md

SOC 2 Readiness

Drive an organization from "no controls documented" to audit-ready.

1. Scoping

  • Determine report type: Type I (point-in-time) vs Type II (period of time — start the observation window early)
  • Define the system description: services in scope, infrastructure, boundaries (subprocessors, cloud providers)
  • Select Trust Services Criteria: Security (required) + Availability, Confidentiality, Processing Integrity, Privacy as applicable

2. Gap Assessment

Map current practices to the criteria:

AreaTypical CriteriaCommon Gaps
Access controlCC6.1–CC6.3No MFA, no role-based access, shared accounts
Change managementCC8.1No peer review on deploys, no environment separation
Risk assessmentCC3.1–CC3.4No annual risk assessment or vendor reviews
MonitoringCC7.1–CC7.3No log review, no alerting on anomalies
Incident responseCC7.4–CC7.5No IR plan or tabletop evidence
BC/DRA1.2–A1.3Untested backups, no documented RTO/RPO
Vendor managementCC9.2No subprocessor due diligence
Onboarding/offboardingCC6.1Access removal not timely or evidenced

3. Remediation

  • Prioritize by audit-blocker status first, then risk
  • Implement policy + practice + evidence together: a policy without execution evidence fails
  • Typical timeline: 2–4 months for a Type I; Type II needs 2–12 months of operating evidence

4. Evidence Package

Per control: policy documents, implementation artifacts (screenshots, configs), and dated operating evidence over the review period (access reviews, change tickets, training logs, IR exercises)

5. Audit Logistics

  • Choose auditor; confirm scope wording matches your system description
  • Readiness assessment (optional but useful) → fieldwork → draft report review
  • Track findings/exceptions honestly; management responses documented

Output

Gap register with owners and dates, control matrix mapped to criteria, evidence repository structure, and auditor-ready system description.

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.25

Published

Sep 25, 2026

Category

Uncategorized

License

Not specified

Source path

compliance/soc2/soc2-readiness

Default branch

main

Latest commit

b2b6b52

Tree SHA

8db485b