Agent skill

Compliance Readiness

by borghei in borghei/Claude-Skills

Cross-framework compliance readiness orchestrator. An agent skill from borghei/Claude-Skills.

MITAuto-check passedLegal & Compliance

Install Compliance Readiness

skills CLI
$ npx skills add borghei/Claude-Skills --skill compliance-readiness -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills compliance-readiness --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/audit-prep/compliance-readiness .claude/skills/compliance-readiness && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
compliance-readiness
GitHub stars
886
Token cost
~2.3k tokens
SKILL.md length
843 words
Files
7 (incl. scripts, references)
Skills in repo
354
Repo updated
First seen
Licence
MIT

At a glance

Cross-framework compliance readiness orchestrator. An agent skill from borghei/Claude-Skills.

  • Works in 5 steps: Customer demand — what blocks deals? → Regulatory mandate — what's required by… → Time to certify — SOC 2 Type I (3-6 mo)… → …
  • Preparing for multi-framework certification (SOC 2 + ISO 27001 + NIST CSF)
  • SKILL.md covers When to use this skill, The strategic insight, Sequencing decisions and Shared evidence strategy, plus 7 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Compliance Readiness is an agent skill from borghei/Claude-Skills. Cross-framework compliance readiness orchestrator. Use when preparing for multi-framework certification (SOC 2 + ISO 27001 + NIST CSF), building a shared-evidence strategy, sequencing certifications, or mapping a control across frameworks.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `references/control-mapping-soc2-iso27001-nist.md`, `references/multi-framework-readiness-matrix.md` and `references/shared-evidence-strategy.md`).

It sits in Legal & Compliance, covering SOC 2 and security compliance. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • Preparing for multi-framework certification (SOC 2 + ISO 27001 + NIST CSF)
  • Building a shared-evidence strategy
  • Sequencing certifications
  • Mapping a control across frameworks

Example prompts

  • “/compliance-readiness”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Customer demand — what blocks deals?
  2. Regulatory mandate — what's required by law?
  3. Time to certify — SOC 2 Type I (3-6 mo) vs ISO 27001 (6-12 mo)
  4. Shared-evidence opportunity — frameworks that overlap (SOC 2 + ISO 27001)
  5. Cost — certification + ongoing surveillance

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Compliance Readiness loads about 2.3k tokens when it runs, and up to ~9k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 843 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 843 words, ~2,275 tokens.

Download SKILL.mdSave it as .claude/skills/compliance-readiness/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
compliance-readiness
description
Cross-framework compliance readiness orchestrator. Use when preparing for multi-framework certification (SOC 2 + ISO 27001 + NIST CSF), building a shared-evidence strategy, sequencing certifications, or mapping a control across frameworks.
license
MIT + Commons Clause
metadata.version
1.0.0
metadata.author
borghei
metadata.category
compliance
metadata.domain
ra-qm-team
metadata.updated
2026-05-27
metadata.tags
compliance-readiness, multi-framework, shared-evidence, control-mapping, soc2, iso27001, nist, gdpr, hipaa

Compliance Readiness (Cross-Framework)

The orchestrator skill for organizations pursuing multiple compliance frameworks. Reduces duplication, accelerates certification, and shares evidence across SOC 2, ISO 27001, NIST CSF, GDPR, HIPAA, and others.

When to use this skill vs. framework-specific audit-prep:

  • This skill: 2+ frameworks pursued in parallel; need shared-evidence strategy
  • Framework-specific (soc2-audit-prep, gdpr-audit-prep, etc.): single-framework sprint

When to use this skill

SituationSkill applies
Pursuing SOC 2 + ISO 27001 + NIST CSF in parallelYes — start here
Healthcare org pursuing SOC 2 + HIPAA + ISO 27001Yes
Building shared-evidence platformYes — see shared evidence strategy
Mapping one control to multiple frameworksYes — scripts/shared_evidence_finder.py
Deciding which framework to certify firstYes — see sequencing decisions
Generating multi-framework roadmapYes — scripts/readiness_roadmap_generator.py
Single-framework audit prepUse framework-specific skill

The strategic insight

Most controls are shared across compliance frameworks. A well-designed control catalog satisfies multiple frameworks simultaneously. Without coordination, you build separate evidence + procedures per framework — 3x the work, 3x the maintenance, 3x the auditor confusion.

Common shared controls:

Control areaSOC 2ISO 27001NIST CSFNIS2DORAPCI-DSSHIPAAGDPR
Access controlCC6.1A.8.5PR.AAArt.21.2.jArt.9.4Req 7-8§164.312(d)Art.32
EncryptionCC6.7A.8.24PR.DSArt.21.2.hArt.9.2Req 3-4§164.312(a)(2)(iv)Art.32
Incident responseCC7.4A.5.24RS.MAArt.23Art.17Req 12.10§164.308(a)(6)Art.33
Risk assessmentCC3.1Cl.6.1ID.RAArt.21.1Art.6Req 12.2§164.308(a)(1)Art.35
LoggingCC7.2A.8.15DE.CMArt.21.2.bArt.10Req 10§164.312(b)Art.30
Vendor managementCC9.2A.5.19GV.SCArt.21.2.dArt.28Req 12.8§164.308(b)Art.28

See references/control-mapping-soc2-iso27001-nist.md for the full mapping.


Sequencing decisions

Which framework to pursue first?

Common patterns

SaaS / Tech (B2B enterprise customers):

  • SOC 2 Type I first (3-6 months) — customer-demanded entry ticket
  • SOC 2 Type II (next 6-12 months after Type I)
  • ISO 27001 (often after SOC 2 Type II; substantial overlap)
  • NIST CSF (as internal framework; supports SOC 2 / ISO 27001)
  • GDPR (separately, ongoing)

Healthcare (US):

  • HIPAA (immediately if covered entity / BA)
  • SOC 2 (for tech-side customer requirements)
  • ISO 27001 (for international expansion)

FinTech / financial services (EU):

  • DORA (mandatory effective Jan 2025)
  • NIS2 (mandatory)
  • PCI-DSS (if handling card data)
  • ISO 27001 (standard)
  • SOC 2 (for B2B customers)

Medical devices:

  • ISO 13485 / 14971 / MDR / FDA (industry mandatory)
  • ISO 27001 (for digital health components)
  • SOC 2 (for SaaS components)
Sequencing factors
  1. Customer demand — what blocks deals?
  2. Regulatory mandate — what's required by law?
  3. Time to certify — SOC 2 Type I (3-6 mo) vs ISO 27001 (6-12 mo)
  4. Shared-evidence opportunity — frameworks that overlap (SOC 2 + ISO 27001)
  5. Cost — certification + ongoing surveillance

Shared evidence strategy

Strategy 1: Common control catalog

Build one control catalog covering all in-scope frameworks. Each control maps to multiple frameworks. One implementation; one evidence trail.

Control: Access Reviews (Quarterly)
- SOC 2: CC6.3
- ISO 27001: A.5.18
- NIST CSF: PR.AA-04
- HIPAA: §164.308(a)(4)
- GDPR: Art.32 (security of processing)

Evidence: Quarterly access-review records, signed by team lead
Frequency: Quarterly
Owner: IT Security

One artifact satisfies five frameworks.

Strategy 2: Unified evidence collection

Single source-of-truth for evidence (Drata / Vanta / Thoropass / Sprinto / homegrown):

  • Configurations + access reviews + change records auto-collected
  • Tagged per framework
  • Auditor (per framework) gets relevant subset
Strategy 3: Single management review

Annual management review covers all frameworks:

  • SOC 2 management review
  • ISO 27001 management review (Clause 9.3)
  • ISO 42001 management review (if AIMS)
  • Internal audit findings
  • Risk register update
  • Continual improvement decisions
Show full SKILL.md (338 more words)Show less
Strategy 4: Single internal audit

Plan internal audit to cover overlapping clauses:

  • ISO 27001 Clause 9.2 internal audit
  • SOC 2 controls testing
  • NIST CSF self-assessment
  • All produce one audit report; distributed per framework

Multi-framework readiness sprint

16-week sprint (initial: SOC 2 + ISO 27001 in parallel)
Weeks 1-4: Common control catalog build; gap analysis per framework
Weeks 5-8: Gap remediation (technical + procedural)
Weeks 9-12: Evidence collection + walkthroughs
Weeks 13-14: SOC 2 audit
Weeks 15-16: ISO 27001 Stage 1
(then ISO 27001 Stage 2 ~4-8 weeks later)
12-week sprint (annual: SOC 2 + ISO 27001 surveillance)
Weeks 1-2: Audit readiness assessment per framework
Weeks 3-6: Gap remediation
Weeks 7-9: Walkthroughs + evidence finalization
Weeks 10-12: Audits (sequential or parallel depending on auditor capacity)

Clarify First

Before generating the roadmap, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Target frameworks — which set (SOC 2, ISO 27001, NIST CSF, GDPR, HIPAA, DORA…) is pursued in parallel (drives the control mapping and shared-evidence strategy)
  • Industry and region — determines which frameworks are legally mandated vs customer-demanded, and the sequencing
  • Initial vs renewal — first-time certification vs annual surveillance (picks the 16-week vs 12-week sprint)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the roadmap.

Quick start

  1. Score multi-framework readiness: python3 scripts/multi_framework_scorer.py --config controls.yaml
  2. Find shared evidence opportunities: python3 scripts/shared_evidence_finder.py --frameworks SOC2,ISO27001
  3. Generate roadmap: python3 scripts/readiness_roadmap_generator.py --target-frameworks SOC2,ISO27001,GDPR
  4. Execute sprint per references/multi-framework-readiness-matrix.md

Common multi-framework readiness failures

  • Separate teams per framework — duplicates work, inconsistent decisions, wasted time
  • Separate evidence collection — same screenshot taken 3x for 3 frameworks
  • Auditor doesn't accept overlap — push back; most accept SOC 2 evidence for ISO 27001 controls
  • Framework-specific tooling — one tool per framework instead of unified GRC platform
  • No control owner — control exists across frameworks but no single owner
  • Mapping not maintained — control changes; mappings go stale
  • Auditor cycles cause crunches — schedule auditors not to overlap (or do overlap by design)

Tooling

ScriptPurpose
scripts/multi_framework_scorer.pyScore readiness across multiple frameworks
scripts/shared_evidence_finder.pyIdentify shared controls; map evidence to frameworks
scripts/readiness_roadmap_generator.pyGenerate multi-framework readiness roadmap

References


  • ra-qm-team/soc2-compliance-expert — deep SOC 2 program
  • ra-qm-team/information-security-manager-iso27001 — deep ISO 27001 program
  • ra-qm-team/nist-csf-specialist — deep NIST CSF program
  • ra-qm-team/gdpr-dsgvo-expert — deep GDPR program
  • ra-qm-team/fda-consultant-specialist — deep FDA program
  • ra-qm-team/infrastructure-compliance-auditor — cross-framework infra audit
  • ra-qm-team/audit-prep/* — framework-specific audit-prep skills

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in ra-qm-team/audit-prep/compliance-readiness of borghei/Claude-Skills.

  • SKILL.md
  • references/control-mapping-soc2-iso27001-nist.md
  • references/multi-framework-readiness-matrix.md
  • references/shared-evidence-strategy.md
  • scripts/multi_framework_scorer.py
  • scripts/readiness_roadmap_generator.py
  • scripts/shared_evidence_finder.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Compliance Readiness next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Compliance Readiness compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Compliance Readiness this skillborghei/Claude-Skills886—~2.3kAutomated safety check: PassMIT
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~3.3kAutomated safety check: PassMIT
Soc2Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~2.7kAutomated safety check: PassMIT
Grc Knowledgemlunato47/claude-grc-plugin184—~6.1kAutomated safety check: PassMIT
Information Security Manager Iso27001davila7/claude-code-templates32k1 repos~2.9kAutomated safety check: PassMIT
Audit Frameworkscartography-cncf/cartography4.1k—~2.8kAutomated safety check: PassApache-2.0

Similar skills

  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    943 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Soc2

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).

    943 GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed
  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    184 GitHub stars~6.1k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Information Security Manager Iso27001

    davila7/claude-code-templates

    Senior Information Security Manager specializing in ISO 27001 and ISO 27002 implementation for HealthTech and MedTech companies.

    32k GitHub starsUsed in 1 repo~2.9k tokens
    Legal & ComplianceAuto-check passed
  • Audit Frameworks

    cartography-cncf/cartography

    Audit Cartography's rules and compliance frameworks under cartography/rules/data/rules/.

    4.1k GitHub stars~2.8k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    420 GitHub stars~2.6k tokensUpdated 5 days ago
    Legal & ComplianceAuto-check passed

More from borghei/Claude-Skills

All 354 skills in this repo
  • Agent Harness

    borghei/Claude-Skills

    Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.

    886 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    886 GitHub stars~4.2k tokensUpdated 2 days ago
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    886 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    886 GitHub stars~3.6k tokensUpdated 2 days ago
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    886 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    886 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed

Questions about Compliance Readiness

What does Compliance Readiness do?

Cross-framework compliance readiness orchestrator. An agent skill from borghei/Claude-Skills. Compliance Readiness is an agent skill from borghei/Claude-Skills. Cross-framework compliance readiness orchestrator.

When should I use Compliance Readiness?

Compliance Readiness fits situations like: preparing for multi-framework certification (SOC 2 + ISO 27001 + NIST CSF); building a shared-evidence strategy; sequencing certifications; mapping a control across frameworks.

How do I install Compliance Readiness in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill compliance-readiness -a claude-code`. Or copy the skill folder (ra-qm-team/audit-prep/compliance-readiness in borghei/Claude-Skills) into .claude/skills/compliance-readiness in your project. Claude Code loads it when a task matches its description.

How do I install Compliance Readiness in Codex?

Run `npx skills add borghei/Claude-Skills --skill compliance-readiness -a codex`. Or copy the skill folder (ra-qm-team/audit-prep/compliance-readiness in borghei/Claude-Skills) into .agents/skills/compliance-readiness in your project. Codex loads it when a task matches its description.

Can I use Compliance Readiness in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill compliance-readiness -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/compliance-readiness, .gemini/skills/compliance-readiness, .github/skills/compliance-readiness and .opencode/skills/compliance-readiness in your project.

What does Compliance Readiness need to run?

Going by SKILL.md and its folder, Compliance Readiness needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Compliance Readiness access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Compliance Readiness safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Compliance Readiness use?

Compliance Readiness is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Compliance Readiness use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.7k tokens, read only when the agent opens those files.

What are the alternatives to Compliance Readiness?

Skills that share tags, products or a category with Compliance Readiness: Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars), Soc2 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars), Grc Knowledge (mlunato47/claude-grc-plugin, 184 stars) and Information Security Manager Iso27001 (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Compliance Readiness?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 886 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.