Agent skill

Soc2 Compliance

by alirezarezvani in alirezarezvani/claude-skills

A skill your agent uses when the user asks to prepare for SOC 2 audits, map Trust Service Criteria, build control matrices, collect audit evidence, perform gap analysis, or assess SOC 2 Type I vs…

MITAuto-check passedLegal & Compliance

Install Soc2 Compliance

skills CLI
$ npx skills add alirezarezvani/claude-skills --skill soc2-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-skills soc2-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/skills/soc2-compliance .claude/skills/soc2-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
soc2-compliance
GitHub stars
28k
Token cost
~4.7k tokens
SKILL.md length
1,833 words
Files
8 (incl. scripts, references)
Skills in repo
342
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when the user asks to prepare for SOC 2 audits, map Trust Service Criteria, build control matrices, collect audit evidence, perform gap analysis, or assess SOC 2 Type I vs…

  • Works in 4 steps: Current State Assessment → Gap Identification → Remediation Planning → …
  • The user asks to prepare for SOC 2 audits
  • SKILL.md covers Table of Contents, Overview, Trust Service Criteria and Control Matrix Generation, plus 3 more sections
  • Runs Python scripts from its folder; calls python

What it does

Soc2 Compliance is an agent skill from alirezarezvani/claude-skills. Use when the user asks to prepare for SOC 2 audits, map Trust Service Criteria, build control matrices, collect audit evidence, perform gap analysis, or assess SOC 2 Type I vs Type II readiness.

Its SKILL.md is about 4.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `references/evidence_collection_guide.md`, `references/soc2_audit_playbook.md` and `references/trust_service_criteria.md`).

It sits in Legal & Compliance, covering SOC 2 and security compliance. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.

When your agent uses it

  • The user asks to prepare for SOC 2 audits
  • Map Trust Service Criteria
  • Build control matrices
  • Collect audit evidence

Example prompts

  • “/soc2-compliance”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Current State Assessment
  2. Gap Identification
  3. Remediation Planning
  4. Timeline Planning

What it can do on your machine

Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Soc2 Compliance loads about 4.7k tokens when it runs, and up to ~17k if it reads all its reference files. Until then it costs about 53 tokens; SKILL.md has 1,833 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~4.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~17k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 1,833 words, ~4,701 tokens.

Download SKILL.mdSave it as .claude/skills/soc2-compliance/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
soc2-compliance
description
Use when the user asks to prepare for SOC 2 audits, map Trust Service Criteria, build control matrices, collect audit evidence, perform gap analysis, or assess SOC 2 Type I vs Type II readiness.

SOC 2 Compliance

SOC 2 Type I and Type II compliance preparation for SaaS companies. Covers Trust Service Criteria mapping, control matrix generation, evidence collection, gap analysis, and audit readiness assessment.

Table of Contents


Overview

What Is SOC 2?

SOC 2 (System and Organization Controls 2) is an auditing framework developed by the AICPA that evaluates how a service organization manages customer data. It applies to any technology company that stores, processes, or transmits customer information — primarily SaaS, cloud infrastructure, and managed service providers.

Type I vs Type II
AspectType IType II
ScopeDesign of controls at a point in timeDesign AND operating effectiveness over a period
DurationSnapshot (single date)Observation window (3-12 months, typically 6)
EvidenceControl descriptions, policiesControl descriptions + operating evidence (logs, tickets, screenshots)
Cost$20K-$50K (audit fees)$30K-$100K+ (audit fees)
Timeline1-2 months (audit phase)6-12 months (observation + audit)
Best ForFirst-time compliance, rapid market needMature organizations, enterprise customers
Who Needs SOC 2?
  • SaaS companies selling to enterprise customers
  • Cloud infrastructure providers handling customer workloads
  • Data processors managing PII, PHI, or financial data
  • Managed service providers with access to client systems
  • Any vendor whose customers require third-party assurance
Typical Journey
Gap Assessment → Remediation → Type I Audit → Observation Period → Type II Audit → Annual Renewal
    (4-8 wk)      (8-16 wk)     (4-6 wk)       (6-12 mo)          (4-6 wk)       (ongoing)

Trust Service Criteria

SOC 2 is organized around five Trust Service Criteria (TSC) categories. Security is required for every SOC 2 report; the remaining four are optional and selected based on business need.

Security (Common Criteria CC1-CC9) — Required

The foundation of every SOC 2 report. Maps to COSO 2013 principles.

CriteriaDomainKey Controls
CC1Control EnvironmentIntegrity/ethics, board oversight, org structure, competence, accountability
CC2Communication & InformationInternal/external communication, information quality
CC3Risk AssessmentRisk identification, fraud risk, change impact analysis
CC4Monitoring ActivitiesOngoing monitoring, deficiency evaluation, corrective actions
CC5Control ActivitiesPolicies/procedures, technology controls, deployment through policies
CC6Logical & Physical AccessAccess provisioning, authentication, encryption, physical restrictions
CC7System OperationsVulnerability management, anomaly detection, incident response
CC8Change ManagementChange authorization, testing, approval, emergency changes
CC9Risk MitigationVendor/business partner risk management
Availability (A1) — Optional
CriteriaFocusKey Controls
A1.1Capacity managementInfrastructure scaling, resource monitoring, capacity planning
A1.2Recovery operationsBackup procedures, disaster recovery, BCP testing
A1.3Recovery testingDR drills, failover testing, RTO/RPO validation

Select when: Customers depend on your uptime; you have SLAs; downtime causes direct business impact.

Confidentiality (C1) — Optional
CriteriaFocusKey Controls
C1.1IdentificationData classification policy, confidential data inventory
C1.2ProtectionEncryption at rest and in transit, DLP, access restrictions
C1.3DisposalSecure deletion procedures, media sanitization, retention enforcement

Select when: You handle trade secrets, proprietary data, or contractually confidential information.

Processing Integrity (PI1) — Optional
CriteriaFocusKey Controls
PI1.1AccuracyInput validation, processing checks, output verification
PI1.2CompletenessTransaction monitoring, reconciliation, error handling
PI1.3TimelinessSLA monitoring, processing delay alerts, batch job monitoring
PI1.4AuthorizationProcessing authorization controls, segregation of duties

Select when: Data accuracy is critical (financial processing, healthcare records, analytics platforms).

Privacy (P1-P8) — Optional
CriteriaFocusKey Controls
P1NoticePrivacy policy, data collection notice, purpose limitation
P2Choice & ConsentOpt-in/opt-out, consent management, preference tracking
P3CollectionMinimal collection, lawful basis, purpose specification
P4Use, Retention, DisposalPurpose limitation, retention schedules, secure disposal
P5AccessData subject access requests, correction rights
P6Disclosure & NotificationThird-party sharing, breach notification
P7QualityData accuracy verification, correction mechanisms
P8Monitoring & EnforcementPrivacy program monitoring, complaint handling

Select when: You process PII and customers expect privacy assurance (complements GDPR compliance).


Control Matrix Generation

A control matrix maps each TSC criterion to specific controls, owners, evidence, and testing procedures.

Matrix Structure
FieldDescription
Control IDUnique identifier (e.g., SEC-001, AVL-003)
TSC MappingWhich criteria the control addresses (e.g., CC6.1, A1.2)
Control DescriptionWhat the control does
Control TypePreventive, Detective, or Corrective
OwnerResponsible person/team
FrequencyContinuous, Daily, Weekly, Monthly, Quarterly, Annual
Evidence TypeScreenshot, Log, Policy, Config, Ticket
Testing ProcedureHow the auditor verifies the control
Control Naming Convention
{CATEGORY}-{NUMBER}
SEC-001 through SEC-NNN  → Security
AVL-001 through AVL-NNN  → Availability
CON-001 through CON-NNN  → Confidentiality
PRI-001 through PRI-NNN  → Processing Integrity
PRV-001 through PRV-NNN  → Privacy
Workflow
  1. Select applicable TSC categories based on business needs
  2. Run control_matrix_builder.py to generate the baseline matrix
  3. Customize controls to match your actual environment
  4. Assign owners and evidence requirements
  5. Validate coverage — every selected TSC criterion must have at least one control

Gap Analysis Workflow

Phase 1: Current State Assessment
  1. Document existing controls — inventory all security policies, procedures, and technical controls
  2. Map to TSC — align existing controls to Trust Service Criteria
  3. Collect evidence samples — gather proof that controls exist and operate
  4. Interview control owners — verify understanding and execution
Phase 2: Gap Identification

Run gap_analyzer.py against your current controls to identify:

  • Missing controls — TSC criteria with no corresponding control
  • Partially implemented — Control exists but lacks evidence or consistency
  • Design gaps — Control designed but does not adequately address the criteria
  • Operating gaps (Type II only) — Control designed correctly but not operating effectively
Phase 3: Remediation Planning

For each gap, define:

FieldDescription
Gap IDReference identifier
TSC CriteriaAffected criteria
Gap DescriptionWhat is missing or insufficient
Remediation ActionSpecific steps to close the gap
OwnerPerson responsible for remediation
PriorityCritical / High / Medium / Low
Target DateCompletion deadline
DependenciesOther gaps or projects that must complete first
Phase 4: Timeline Planning
PriorityTarget Remediation
Critical2-4 weeks
High4-8 weeks
Medium8-12 weeks
Low12-16 weeks

Evidence Collection

Evidence Types by Control Category
Control AreaPrimary EvidenceSecondary Evidence
Access ManagementUser access reviews, provisioning ticketsRole matrix, access logs
Change ManagementChange tickets, approval recordsDeployment logs, test results
Incident ResponseIncident tickets, postmortemsRunbooks, escalation records
Vulnerability ManagementScan reports, patch recordsRemediation timelines
EncryptionConfiguration screenshots, certificate inventoryKey rotation logs
Backup & RecoveryBackup logs, DR test resultsRecovery time measurements
MonitoringAlert configurations, dashboard screenshotsOn-call schedules, escalation records
Policy ManagementSigned policies, version historyTraining completion records
Vendor ManagementVendor assessments, SOC 2 reportsContract reviews, risk registers
Automation Opportunities
AreaAutomation Approach
Access reviewsIntegrate IAM with ticketing (automatic quarterly review triggers)
Configuration evidenceInfrastructure-as-code snapshots, compliance-as-code tools
Vulnerability scansScheduled scanning with auto-generated reports
Change managementGit-based audit trail (commits, PRs, approvals)
Uptime monitoringAutomated SLA dashboards with historical data
Backup verificationAutomated restore tests with success/failure logging
Continuous Monitoring

Move from point-in-time evidence collection to continuous compliance:

  1. Automated evidence gathering — scripts that pull evidence on schedule
  2. Control dashboards — real-time visibility into control status
  3. Alert-based monitoring — notify when a control drifts out of compliance
  4. Evidence repository — centralized, timestamped evidence storage

Audit Readiness Checklist

Show full SKILL.md (744 more words)Show less
Pre-Audit Preparation (4-6 Weeks Before)
  • All controls documented with descriptions, owners, and frequencies
  • Evidence collected for the entire observation period (Type II)
  • Control matrix reviewed and gaps remediated
  • Policies signed and distributed within the last 12 months
  • Access reviews completed within the required frequency
  • Vulnerability scans current (no critical/high unpatched > SLA)
  • Incident response plan tested within the last 12 months
  • Vendor risk assessments current for all subservice organizations
  • DR/BCP tested and documented within the last 12 months
  • Employee security training completed for all staff
Readiness Scoring
ScoreRatingMeaning
90-100%Audit ReadyProceed with confidence
75-89%Minor GapsAddress before scheduling audit
50-74%Significant GapsRemediation required
< 50%Not ReadyMajor program build-out needed
Common Audit Findings
FindingRoot CausePrevention
Incomplete access reviewsManual process, no remindersAutomate quarterly review triggers
Missing change approvalsEmergency changes bypass processDefine emergency change procedure with post-hoc approval
Stale vulnerability scansScanner misconfiguredAutomated weekly scans with alerting
Policy not acknowledgedNo tracking mechanismAnnual e-signature workflow
Missing vendor assessmentsNo vendor inventoryMaintain vendor register with review schedule

Vendor Management

Third-Party Risk Assessment

Every vendor that accesses, stores, or processes customer data must be assessed:

  1. Vendor inventory — maintain a register of all service providers
  2. Risk classification — categorize vendors by data access level
  3. Due diligence — collect SOC 2 reports, security questionnaires, certifications
  4. Contractual protections — ensure DPAs, security requirements, breach notification clauses
  5. Ongoing monitoring — annual reassessment, continuous news monitoring
Vendor Risk Tiers
TierData AccessAssessment FrequencyRequirements
CriticalProcesses/stores customer dataAnnual + continuous monitoringSOC 2 Type II, penetration test, security review
HighAccesses customer environmentAnnualSOC 2 Type II or equivalent, questionnaire
MediumIndirect access, support toolsAnnual questionnaireSecurity certifications, questionnaire
LowNo data accessBiennial questionnaireBasic security questionnaire
Subservice Organizations

When your SOC 2 report relies on controls at a subservice organization (e.g., AWS, GCP, Azure):

  • Inclusive method — your report covers the subservice org's controls (requires their cooperation)
  • Carve-out method — your report excludes their controls but references their SOC 2 report
  • Most companies use carve-out and include complementary user entity controls (CUECs)

Continuous Compliance

From Point-in-Time to Continuous
AspectPoint-in-TimeContinuous
Evidence collectionManual, before auditAutomated, ongoing
Control monitoringPeriodic reviewReal-time dashboards
Drift detectionFound during auditAlert-based, immediate
RemediationReactiveProactive
Audit preparation4-8 week scrambleAlways ready
Implementation Steps
  1. Automate evidence gathering — cron jobs, API integrations, IaC snapshots
  2. Build control dashboards — aggregate control status into a single view
  3. Configure drift alerts — notify when controls fall out of compliance
  4. Establish review cadence — weekly control owner check-ins, monthly steering
  5. Maintain evidence repository — centralized, timestamped, auditor-accessible
Annual Re-Assessment Cycle
QuarterActivities
Q1Annual risk assessment, policy refresh, vendor reassessment launch
Q2Internal control testing, remediation of findings
Q3Pre-audit readiness review, evidence completeness check
Q4External audit, management assertion, report distribution

Anti-Patterns

Anti-PatternWhy It FailsBetter Approach
Point-in-time complianceControls degrade between audits; gaps found during auditImplement continuous monitoring and automated evidence
Manual evidence collectionTime-consuming, inconsistent, error-proneAutomate with scripts, IaC, and compliance platforms
Missing vendor assessmentsAuditors flag incomplete vendor due diligenceMaintain vendor register with risk-tiered assessment schedule
Copy-paste policiesGeneric policies don't match actual operationsTailor policies to your actual environment and technology stack
Security theaterControls exist on paper but aren't followedVerify operating effectiveness; build controls into workflows
Skipping Type IJumping to Type II without foundational readinessStart with Type I to validate control design before observation
Over-scoping TSCIncluding all 5 categories when only Security is neededSelect categories based on actual customer/business requirements
Treating audit as a projectCompliance degrades after the report is issuedBuild compliance into daily operations and engineering culture

Tools

Control Matrix Builder

Generates a SOC 2 control matrix from selected TSC categories.

bash
# Generate full security matrix in markdown
python scripts/control_matrix_builder.py --categories security --format md

# Generate matrix for multiple categories as JSON
python scripts/control_matrix_builder.py --categories security,availability,confidentiality --format json

# All categories, CSV output
python scripts/control_matrix_builder.py --categories security,availability,confidentiality,processing-integrity,privacy --format csv
Evidence Tracker

Tracks evidence collection status per control.

bash
# Check evidence status from a control matrix
python scripts/evidence_tracker.py --matrix controls.json --status

# JSON output for integration
python scripts/evidence_tracker.py --matrix controls.json --status --json
Gap Analyzer

Analyzes current controls against SOC 2 requirements and identifies gaps.

bash
# Type I gap analysis
python scripts/gap_analyzer.py --controls current_controls.json --type type1

# Type II gap analysis (includes operating effectiveness)
python scripts/gap_analyzer.py --controls current_controls.json --type type2 --json

References


Cross-References

  • gdpr-dsgvo-expert — SOC 2 Privacy criteria overlaps significantly with GDPR requirements; use together when processing EU personal data
  • information-security-manager-iso27001 — ISO 27001 Annex A controls map closely to SOC 2 Security criteria; organizations pursuing both can share evidence
  • isms-audit-expert — Audit methodology and finding management patterns transfer directly to SOC 2 audit preparation

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references) in ra-qm-team/skills/soc2-compliance of alirezarezvani/claude-skills.

  • SKILL.md
  • references/evidence_collection_guide.md
  • references/soc2_audit_playbook.md
  • references/trust_service_criteria.md
  • references/type1_vs_type2.md
  • scripts/control_matrix_builder.py
  • scripts/evidence_tracker.py
  • scripts/gap_analyzer.py

Open the folder on GitHubat commit 19392f7

Compare with similar skills

Soc2 Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Soc2 Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Soc2 Compliance this skillalirezarezvani/claude-skills28k—~4.7kAutomated safety check: PassMIT
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~3.3kAutomated safety check: PassMIT
Soc2Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~2.7kAutomated safety check: PassMIT
Grc Knowledgemlunato47/claude-grc-plugin184—~6.1kAutomated safety check: PassMIT
Information Security Manager Iso27001davila7/claude-code-templates32k1 repos~2.9kAutomated safety check: PassMIT
Audit Frameworkscartography-cncf/cartography4.1k—~2.8kAutomated safety check: PassApache-2.0

Similar skills

  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    943 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Soc2

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).

    943 GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed
  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    184 GitHub stars~6.1k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Information Security Manager Iso27001

    davila7/claude-code-templates

    Senior Information Security Manager specializing in ISO 27001 and ISO 27002 implementation for HealthTech and MedTech companies.

    32k GitHub starsUsed in 1 repo~2.9k tokens
    Legal & ComplianceAuto-check passed
  • Audit Frameworks

    cartography-cncf/cartography

    Audit Cartography's rules and compliance frameworks under cartography/rules/data/rules/.

    4.1k GitHub stars~2.8k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    420 GitHub stars~2.6k tokensUpdated 5 days ago
    Legal & ComplianceAuto-check passed

More from alirezarezvani/claude-skills

All 342 skills in this repo
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Product Strategist

    alirezarezvani/claude-skills

    OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.

    28k GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • App Store Optimization

    alirezarezvani/claude-skills

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.

    28k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Campaign Analytics

    alirezarezvani/claude-skills

    Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.

    28k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Code to PRD

    alirezarezvani/claude-skills

    Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.

    28k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed

Questions about Soc2 Compliance

What does Soc2 Compliance do?

A skill your agent uses when the user asks to prepare for SOC 2 audits, map Trust Service Criteria, build control matrices, collect audit evidence, perform gap analysis, or assess SOC 2 Type I vs…. Soc2 Compliance is an agent skill from alirezarezvani/claude-skills. Use when the user asks to prepare for SOC 2 audits, map Trust Service Criteria, build control matrices, collect audit evidence, perform gap analysis, or assess SOC 2 Type I vs Type II readiness.

When should I use Soc2 Compliance?

Soc2 Compliance fits situations like: the user asks to prepare for SOC 2 audits; map Trust Service Criteria; build control matrices; collect audit evidence.

How do I install Soc2 Compliance in Claude Code?

Run `npx skills add alirezarezvani/claude-skills --skill soc2-compliance -a claude-code`. Or copy the skill folder (ra-qm-team/skills/soc2-compliance in alirezarezvani/claude-skills) into .claude/skills/soc2-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Soc2 Compliance in Codex?

Run `npx skills add alirezarezvani/claude-skills --skill soc2-compliance -a codex`. Or copy the skill folder (ra-qm-team/skills/soc2-compliance in alirezarezvani/claude-skills) into .agents/skills/soc2-compliance in your project. Codex loads it when a task matches its description.

Can I use Soc2 Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill soc2-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/soc2-compliance, .gemini/skills/soc2-compliance, .github/skills/soc2-compliance and .opencode/skills/soc2-compliance in your project.

What does Soc2 Compliance need to run?

Going by SKILL.md and its folder, Soc2 Compliance needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Soc2 Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Soc2 Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Soc2 Compliance use?

Soc2 Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Soc2 Compliance use?

About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.

What are the alternatives to Soc2 Compliance?

Skills that share tags, products or a category with Soc2 Compliance: Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars), Soc2 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars), Grc Knowledge (mlunato47/claude-grc-plugin, 184 stars) and Information Security Manager Iso27001 (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Soc2 Compliance?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,891 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.

Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.