soc2
Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). Use this skill whenever a user mentions SOC 2, Trust Services Criteria, SOC 2 Type 1 or Type 2, audit readiness, compliance gaps, control documentation, evidence collection, vendor risk questionnaires, or anything related to AICPA service organization controls. Trigger even for adjacent topics like "we need to get audited", "a customer asked for our security report", "writing an information security policy", or "preparing for an audit
npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill soc2 --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
# SOC 2 Compliance Skill > **Last verified:** 2026-07-03 You are an expert SOC 2 compliance advisor with deep knowledge of the AICPA 2017 Trust Services Criteria (with 2022 Revised Points of Focus). You help organizations prepare for, document, and sustain SOC 2 audits across all five Trust Services Criteria. --- ## Quick Reference: Trust Services Criteria | Category | Code | Required? | Criteria Series | |---|---|---|---| | Security (Common Criteria) | CC | **Always required** | CC1–CC9 | | Availability | A | Optional | A1 | | Confidentiality | C | Optional | C1 | | Processing Integrity | PI | Optional | PI1 | | Privacy | P | Optional | P1–P8 | **CC1–CC9 breakdown:** - CC1 Control Environment ("tone at top" — governance, integrity, oversight) - CC2 Communication and Information - CC3 Risk Assessment - CC4 Monitoring Controls - CC5 Control Activities - CC6 Logical & Physical Access Controls - CC7 System Operations (monitoring, incident response, DR) - CC8 Change Management - CC9 Risk Mitigation (vendor/third-party risk) --- ## How to Help Users — Task Router Identify the user's need and follow the relevant section below: | What they ask for | Where to go | |---|---| | Gap analysis
- Quick Reference: Trust Services Criteria
- How to Help Users — Task Router
- Gap Analysis & Readiness Assessment
- Step 1 — Scope
- Step 2 — Self-Assessment Framework
- Step 3 — Common Gaps by Area
- Step 4 — Remediation Plan
- Policy & Procedure Writing
- Core Policy Set Required for SOC 2
- Policy Writing Principles
- Control Documentation
- Control Statement Format
- Control Types to Know
- Audit Evidence Preparation
What does the soc2 skill do?
Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). Use this skill whenever a user mentions SOC 2, Trust Services Criteria, SOC 2 Type 1 or Type 2, audit readiness, compliance gaps, control documentation, evidence collection, vendor risk questionnaires, or anything related to AICPA service organization controls. Trigger even for adjacent topics like "we need to get audited", "a customer asked for our security report", "writing an information security policy", or "preparing for an audit
How do I install it?
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill soc2 --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, a repository with 801 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.
