Agent skill

Soc2 Audit Prep

by borghei in borghei/Claude-Skills

SOC 2 audit-prep playbook: the 4/8/12-week sprint to audit-ready for a Type I or Type II observation.

MITAuto-check passedLegal & Compliance

Install Soc2 Audit Prep

skills CLI
$ npx skills add borghei/Claude-Skills --skill soc2-audit-prep -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills soc2-audit-prep --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/audit-prep/soc2-audit-prep .claude/skills/soc2-audit-prep && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
soc2-audit-prep
GitHub stars
881
Token cost
~2.1k tokens
SKILL.md length
742 words
Files
5 (incl. scripts, references)
Skills in repo
349
Repo updated
First seen
Licence
MIT

At a glance

SOC 2 audit-prep playbook: the 4/8/12-week sprint to audit-ready for a Type I or Type II observation.

  • Works in 5 steps: Run readiness score: python3… → Identify evidence gaps: python3… → Pick sprint length based on score → …
  • The audit is scheduled
  • SKILL.md covers When to use this skill, The audit-prep sprint at a…, The pre-audit punch list and Clarify First, plus 5 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Soc2 Audit Prep is an agent skill from borghei/Claude-Skills. SOC 2 audit-prep playbook: the 4/8/12-week sprint to audit-ready for a Type I or Type II observation. Use when the audit is scheduled, when readiness assessment surfaced gaps and you need a sprint plan, or when evidence is missing or stale.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/evidence-collection-sprint-plan.md`, `references/soc2-pre-audit-punch-list.md` and `scripts/evidence_gap_finder.py`).

It sits in Legal & Compliance, covering SOC 2 and security compliance, Sprint planning and agile and Audit readiness. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • The audit is scheduled
  • Readiness assessment surfaced gaps and you need a sprint plan
  • Evidence is missing

Example prompts

  • “/soc2-audit-prep”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Run readiness score: python3 scripts/soc2_readiness_score.py --config controls.yaml
  2. Identify evidence gaps: python3 scripts/evidence_gap_finder.py --evidence evidence.yaml --tsc CC6
  3. Pick sprint length based on score
  4. Execute sprint per references/evidence-collection-sprint-plan.md
  5. Pre-audit checkpoint with auditor 1 week before

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Soc2 Audit Prep loads about 2.1k tokens when it runs, and up to ~7.5k if it reads all its reference files. Until then it costs about 64 tokens; SKILL.md has 742 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 742 words, ~2,095 tokens.

Download SKILL.mdSave it as .claude/skills/soc2-audit-prep/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
soc2-audit-prep
description
SOC 2 audit-prep playbook: the 4/8/12-week sprint to audit-ready for a Type I or Type II observation. Use when the audit is scheduled, when readiness assessment surfaced gaps and you need a sprint plan, or when evidence is missing or stale.
license
MIT + Commons Clause
metadata.version
1.0.0
metadata.author
borghei
metadata.category
compliance
metadata.domain
ra-qm-team
metadata.updated
2026-05-27
metadata.tags
soc2, audit-prep, trust-services-criteria, evidence-collection, sprint-planning, compliance

SOC 2 Audit Prep

Operational playbook for SOC 2 audit preparation. Designed to be picked up 4-12 weeks before an audit and run as a sprint to closure. Pairs with our deep ra-qm-team/soc2-compliance-expert skill (which builds the program from scratch).

When to use this skill vs. soc2-compliance-expert:

  • This skill: audit scheduled in 4-12 weeks; gaps known; need to execute the sprint
  • soc2-compliance-expert: building the SOC 2 program; designing controls; multi-quarter effort

When to use this skill

SituationSkill applies
SOC 2 audit scheduled, need readiness sprintYes — start here
Type I audit in 4-12 weeksYes — use 4 or 8-week sprint plan
Type II observation period closing soonYes — use 12-week sprint plan
Readiness assessment surfaced gapsYes — scripts/soc2_readiness_score.py + evidence_gap_finder.py
Building SOC 2 program from scratchUse ra-qm-team/soc2-compliance-expert instead

The audit-prep sprint at a glance

4-week sprint (Type I, mostly ready)
Week 1: Inventory + scoping
  - Confirm Trust Services Criteria scope (always Security; plus chosen others)
  - Pull current evidence per criterion
  - Identify gaps via scripts/evidence_gap_finder.py
  - Auditor kickoff scheduled

Week 2: Gap closure
  - Policy updates / approvals
  - Technical control fixes (MFA universal, logging coverage, etc.)
  - Evidence retrieval (access reviews, change tickets, on-call records)
  - Auditor information request preparation

Week 3: Evidence finalization
  - All evidence packets compiled per criterion
  - Walkthroughs / interviews scheduled with key control owners
  - Findings remediation
  - Pre-audit checkpoint with auditor (informal)

Week 4: Audit week
  - Walkthroughs executed
  - Sample testing
  - Q&A
  - Management responses to findings
8-week sprint (Type I, gaps remaining)
Weeks 1-2: Inventory + scoping + gap identification (same as 4-week W1)
Weeks 3-5: Gap closure (policies, technical, process)
Weeks 6-7: Evidence finalization + walkthroughs
Week 8: Audit week
12-week sprint (Type II observation prep)
Weeks 1-2: Inventory + scope + gap identification + auditor kickoff
Weeks 3-4: Gap closure
Weeks 5-12: Observation period (controls operating; evidence accumulating)
After observation period: audit week

See references/evidence-collection-sprint-plan.md for the detailed week-by-week plans.


The pre-audit punch list

Standard pre-audit punch list, organized by Trust Services Criterion:

CC1-CC5 (Common Criteria — control environment)
  • Information security policy approved + dated within 12 months
  • Org chart current (reflects actual reporting lines)
  • Risk assessment performed + documented within 12 months
  • Board / leadership oversight evidence (minutes referencing security)
  • Code of conduct signed by all employees
  • Background checks documented for all hires
CC6 (Logical and Physical Access)
  • SSO enforced for all production systems
  • MFA universal (no exceptions documented for production access)
  • Access review evidence (quarterly minimum)
  • Privileged access management (PAM) for admin/root accounts
  • Physical security evidence (office badge logs, data center attestation)
  • Encryption at rest / in transit verified
CC7 (System Operations)
  • Vulnerability management evidence (scans, remediation tracking)
  • Monitoring and alerting documented + tested
  • Incident response plan + documented incidents from past period
  • Business continuity / DR plan + test evidence
  • Backup verification (not just configured — tested restore)
CC8 (Change Management)
  • Code change tickets with peer review + approval
  • Production deployment evidence (who, what, when, approvers)
  • Emergency change process documented + sample tickets
CC9 (Risk Mitigation / Vendors)
  • Vendor inventory current
  • Vendor due diligence evidence per vendor
  • Vendor SOC 2 reports collected (annual)
A1 (Availability — if in scope)
  • SLA monitoring + actuals
  • Capacity planning evidence
  • Recovery objective testing (RTO/RPO)
PI1 (Processing Integrity — if in scope)
  • Data validation controls documented
  • Error handling + reconciliation evidence
C1 (Confidentiality — if in scope)
  • Data classification + handling procedures
  • Encryption verified
P1 (Privacy — if in scope)
  • Privacy notice published + dated
  • Data subject rights process documented
  • Consent management evidence

See references/soc2-pre-audit-punch-list.md for the detailed punch list with evidence templates per item.


Show full SKILL.md (330 more words)Show less

Clarify First

Before running the audit-prep sprint, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Audit type — Type I (point-in-time) vs Type II (observation period) (sets the 4/8 vs 12-week sprint and the evidence-over-time requirement)
  • TSC scope — which Trust Services Criteria beyond mandatory Security (Availability, Processing Integrity, Confidentiality, Privacy) (determines which punch-list sections apply)
  • Readiness score / gap level — picks the 4-week vs 8-week vs 12-week sprint (or postpone)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the sprint plan.

Quick start

  1. Run readiness score: python3 scripts/soc2_readiness_score.py --config controls.yaml
  2. Identify evidence gaps: python3 scripts/evidence_gap_finder.py --evidence evidence.yaml --tsc CC6
  3. Pick sprint length based on score:
    • Score > 90: 4-week sprint
    • Score 75-90: 8-week sprint
    • Score < 75: 12-week sprint or postpone audit
  4. Execute sprint per references/evidence-collection-sprint-plan.md
  5. Pre-audit checkpoint with auditor 1 week before

Common audit-prep failures

  • No designated audit owner. Sprint flounders. Assign one person Day 1.
  • Treating evidence as one-time. Type II requires controls operating over observation period. Evidence must accumulate continuously, not just at the end.
  • Untested backups. Configuring backups isn't enough; you need restore test evidence.
  • Access review checked but not enforced. Reviews happen; access not actually removed when flagged.
  • Vendor SOC 2 reports missing or stale. Audit checks subservice org evidence.
  • No incident in observation period. Looks suspicious to auditors. Either you had none (unusual) or you're not detecting them.
  • Late discovery of carve-out vs inclusive subservice orgs. Re-scoping mid-sprint is painful.

Tooling

ScriptPurpose
scripts/soc2_readiness_score.pyScore current state (0-100) per TSC; identify pillars needing attention
scripts/evidence_gap_finder.pyCross-reference required evidence vs collected; output gap list with priorities

References


  • ra-qm-team/soc2-compliance-expert — deep SOC 2 program management (multi-quarter)
  • ra-qm-team/audit-prep/compliance-readiness — multi-framework readiness (SOC 2 + ISO 27001 + NIST)
  • ra-qm-team/infrastructure-compliance-auditor — automated infra scanning for evidence
  • engineering/observability-designer — logging / monitoring evidence

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in ra-qm-team/audit-prep/soc2-audit-prep of borghei/Claude-Skills.

  • SKILL.md
  • references/evidence-collection-sprint-plan.md
  • references/soc2-pre-audit-punch-list.md
  • scripts/evidence_gap_finder.py
  • scripts/soc2_readiness_score.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Soc2 Audit Prep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Soc2 Audit Prep compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Soc2 Audit Prep this skillborghei/Claude-Skills881—~2.1kAutomated safety check: PassMIT
Trust Center BuilderGRCEngClub/claude-grc-engineering419—~2.6kAutomated safety check: PassCustom licence
Isms Audit Expertalirezarezvani/claude-skills28k1 repos~1.9kAutomated safety check: PassMIT
Performing Soc2 Type2 Audit Preparationmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
Compliance Osalirezarezvani/claude-skills28k—~3.3kAutomated safety check: PassMIT
Implementing Complianceancoleman/ai-design-components526—~4kAutomated safety check: PassMIT

Similar skills

  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    419 GitHub stars~2.6k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Isms Audit Expert

    alirezarezvani/claude-skills

    Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support.

    28k GitHub starsUsed in 1 repo~1.9k tokens
    Legal & ComplianceAuto-check passed
  • Performing Soc2 Type2 Audit Preparation

    mukul975/Anthropic-Cybersecurity-Skills

    Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing…

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Compliance Os

    alirezarezvani/claude-skills

    Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…

    28k GitHub stars~3.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    526 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Assisting With Soc2 Audit Preparation

    jeremylongshore/tons-of-skills-marketplace

    Execute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification.

    2.8k GitHub stars~1.6k tokensUpdated today
    Legal & ComplianceAuto-check passed

More from borghei/Claude-Skills

All 349 skills in this repo
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    881 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    881 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    881 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    881 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    881 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Brainstorm Okrs

    borghei/Claude-Skills

    OKR brainstorming and validation using the Radical Focus framework — outcome objectives, measurable key results, counter-metrics.

    881 GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Questions about Soc2 Audit Prep

What does Soc2 Audit Prep do?

SOC 2 audit-prep playbook: the 4/8/12-week sprint to audit-ready for a Type I or Type II observation. Soc2 Audit Prep is an agent skill from borghei/Claude-Skills. SOC 2 audit-prep playbook: the 4/8/12-week sprint to audit-ready for a Type I or Type II observation.

When should I use Soc2 Audit Prep?

Soc2 Audit Prep fits situations like: the audit is scheduled; readiness assessment surfaced gaps and you need a sprint plan; evidence is missing.

How do I install Soc2 Audit Prep in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill soc2-audit-prep -a claude-code`. Or copy the skill folder (ra-qm-team/audit-prep/soc2-audit-prep in borghei/Claude-Skills) into .claude/skills/soc2-audit-prep in your project. Claude Code loads it when a task matches its description.

How do I install Soc2 Audit Prep in Codex?

Run `npx skills add borghei/Claude-Skills --skill soc2-audit-prep -a codex`. Or copy the skill folder (ra-qm-team/audit-prep/soc2-audit-prep in borghei/Claude-Skills) into .agents/skills/soc2-audit-prep in your project. Codex loads it when a task matches its description.

Can I use Soc2 Audit Prep in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill soc2-audit-prep -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/soc2-audit-prep, .gemini/skills/soc2-audit-prep, .github/skills/soc2-audit-prep and .opencode/skills/soc2-audit-prep in your project.

What does Soc2 Audit Prep need to run?

Going by SKILL.md and its folder, Soc2 Audit Prep needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Soc2 Audit Prep access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Soc2 Audit Prep safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Soc2 Audit Prep use?

Soc2 Audit Prep is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Soc2 Audit Prep use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.4k tokens, read only when the agent opens those files.

What are the alternatives to Soc2 Audit Prep?

Skills that share tags, products or a category with Soc2 Audit Prep: Trust Center Builder (GRCEngClub/claude-grc-engineering, 419 stars), Isms Audit Expert (alirezarezvani/claude-skills, 28k stars), Performing Soc2 Type2 Audit Preparation (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Compliance Os (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Soc2 Audit Prep?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 881 GitHub stars. The repository holds 349 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.