When the user needs to prepare for SOC 2, build a compliance roadmap, assess security posture, quantify security risk, or says "we need SOC 2", "security audit", "compliance", "enterprise customer…

MITAuto-check passedLegal & Compliance

Install Soc2 Prep

skills CLI
$ npx skills add shawnpang/startup-founder-skills --skill soc2-prep -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install shawnpang/startup-founder-skills soc2-prep --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/shawnpang/startup-founder-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/soc2-prep .claude/skills/soc2-prep && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
soc2-prep
GitHub stars
341
Token cost
~2.5k tokens
SKILL.md length
1,204 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

When the user needs to prepare for SOC 2, build a compliance roadmap, assess security posture, quantify security risk, or says "we need SOC 2", "security audit", "compliance", "enterprise customer…

  • Works in 9 steps: Quantify the business case — Frame… → Scope definition — Determine which Trust… → Current state assessment — Inventory… → …
  • Needs to prepare for SOC 2
  • SKILL.md covers When to Use, Context Required, Workflow and Output Format, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Soc2 Prep is an agent skill from shawnpang/startup-founder-skills. When the user needs to prepare for SOC 2, build a compliance roadmap, assess security posture, quantify security risk, or says "we need SOC 2", "security audit", "compliance", "enterprise customer wants SOC 2", "CISO advice".

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering SOC 2 and security compliance and Security review. The repository describes itself as: AI agent skills for tech startup founders — fundraising, sales, product, recruiting, engineering, legal, ops, and growth. Works with Claude Code, Cursor, Codex, and any Agent… The licence is MIT.

When your agent uses it

  • Needs to prepare for SOC 2
  • Build a compliance roadmap
  • Assess security posture
  • Quantify security risk

Example prompts

  • “we need SOC 2”
  • “security audit”
  • “compliance”
  • “/soc2-prep”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Quantify the business case — Frame security investment in dollars using ALE (Annual Loss Expectancy = Single Loss Expectancy x Annual Rate…
  2. Scope definition — Determine which Trust Service Criteria are in scope. Security (Common Criteria) is always required. Availability…
  3. Current state assessment — Inventory existing policies, controls, and tooling. Identify what exists, what partially exists, and what is…
  4. Gap analysis — Map current state against each applicable TSC criterion. Produce a gap matrix showing compliant, partially compliant, and…
  5. Compliance roadmap — Sequence for business value: SOC 2 Type I (3-6 months) then SOC 2 Type II (12 months from start) then ISO 27001 or…
  6. Policy generation — Draft required policies tailored to the company's size. Early-stage startups need practical 2-5 page policies, not…
  7. Control implementation plan — For each gap, define the control, the owner, the tooling, and the timeline.
  8. Evidence collection guidance — Define what the auditor will request for each control and how to collect it systematically.
  9. Readiness review — Perform a mock assessment before engaging the auditor.

What it can do on your machine

Read from SKILL.md and the folder at commit 4ad31b4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Soc2 Prep loads about 2.5k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 1,204 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from shawnpang/startup-founder-skills at commit 4ad31b4, republished under its MIT licence (© shawnpang). 1,204 words, ~2,513 tokens.

Download SKILL.mdSave it as .claude/skills/soc2-prep/SKILL.md (or your agent's skills folder).
name
soc2-prep
description
When the user needs to prepare for SOC 2, build a compliance roadmap, assess security posture, quantify security risk, or says "we need SOC 2", "security audit", "compliance", "enterprise customer wants SOC 2", "CISO advice".
related
privacy-policy, security-review
reads
startup-context

SOC 2 Prep

When to Use

Activate when a founder is preparing for SOC 2 certification, has been asked by a customer or prospect for a SOC 2 report, needs to quantify security risk for board or budget discussions, wants to build a compliance roadmap sequenced for business value, or needs to assess overall security posture. Also activate when the user mentions "SOC 2," "compliance audit," "trust service criteria," "security budget," "we need SOC 2 to close this deal," or "CISO."

Context Required

  • From startup-context: product type, tech stack, cloud infrastructure provider, team size, current security practices, business model, customer segments (enterprise customers often require SOC 2).
  • From the user: which Trust Service Criteria are in scope, current state of documentation and policies, existing security tooling (SSO, MDM, monitoring), whether targeting Type I or Type II, desired timeline, budget constraints, whether an auditor is selected, and top 3 prospects' compliance requirements.

Workflow

  1. Quantify the business case — Frame security investment in dollars using ALE (Annual Loss Expectancy = Single Loss Expectancy x Annual Rate of Occurrence). Translate to board language: "This risk has $X expected annual loss. Mitigation costs $Y." Security is a sales enabler, not a checkbox.
  2. Scope definition — Determine which Trust Service Criteria are in scope. Security (Common Criteria) is always required. Availability, Processing Integrity, Confidentiality, and Privacy are optional. Scope based on customer requirements and product type.
  3. Current state assessment — Inventory existing policies, controls, and tooling. Identify what exists, what partially exists, and what is completely absent. Check the red flags list below.
  4. Gap analysis — Map current state against each applicable TSC criterion. Produce a gap matrix showing compliant, partially compliant, and non-compliant areas.
  5. Compliance roadmap — Sequence for business value: SOC 2 Type I (3-6 months) then SOC 2 Type II (12 months from start) then ISO 27001 or HIPAA based on customer demand. Do not pursue certifications before basic hygiene is in place.
  6. Policy generation — Draft required policies tailored to the company's size. Early-stage startups need practical 2-5 page policies, not 50-page enterprise documents.
  7. Control implementation plan — For each gap, define the control, the owner, the tooling, and the timeline.
  8. Evidence collection guidance — Define what the auditor will request for each control and how to collect it systematically.
  9. Readiness review — Perform a mock assessment before engaging the auditor.

Output Format

markdown
# Security & Compliance Assessment: [Company Name]

## Risk Quantification — top risks with ALE, mitigation cost, expected value
## Gap Analysis Matrix — TSC criterion, requirement, current state, gap, priority, remediation
## Compliance Roadmap — sequenced timeline: SOC 2 Type I > Type II > ISO 27001/HIPAA
## Policy Documents — generated as needed, each with purpose/scope/roles/statements/procedures
## Implementation Timeline — phased checklist with milestones
## Evidence Collection Checklist — per-control artifacts, storage location, refresh cadence
## Security Metrics Dashboard — table of key metrics with current values and targets

Frameworks & Best Practices

Risk Quantification (CISO Approach)

Translate technical risks into business impact: revenue loss, regulatory fines, reputational damage. Use ALE to prioritize.

Formula: ALE = SLE x ARO (Single Loss Expectancy x Annual Rate of Occurrence)

Board language: "A $200K security program preventing a $2M breach at 40% annual probability has $800K expected value. The program pays for itself 4x over."

Frame security spend as risk transfer cost, not overhead.

Security Metrics
CategoryMetricTarget
RiskALE coverage (mitigated / total)> 80%
DetectionMean Time to Detect (MTTD)< 24 hours
ResponseMean Time to Respond (MTTR)< 4 hours
ComplianceControls passing audit> 95%
HygieneCritical patches within SLA> 99%
AccessPrivileged accounts reviewed quarterly100%
VendorTier 1 vendors assessed annually100%
TrainingPhishing simulation click rate< 5%
Trust Service Criteria Overview

Security (Common Criteria -- always in scope): CC1-CC2 (control environment, communication), CC3 (risk assessment), CC4-CC5 (monitoring, control activities), CC6 (logical/physical access, encryption), CC7-CC8 (system ops, vulnerability mgmt, incident response, change mgmt), CC9 (vendor management, business continuity).

Optional: Availability (A1), Processing Integrity (PI1), Confidentiality (C1), Privacy (P1-P8).

Essential Policies (10 minimum)

Information Security, Access Control (MFA, least privilege, access reviews), Change Management (code review, rollback), Incident Response (detection through post-mortem), Risk Assessment (annual, with register), Vendor Management, Data Classification, Business Continuity/DR (RTO/RPO, backup testing), Acceptable Use, HR Security (background checks, onboarding/offboarding).

Vendor Security Assessment Tiers
TierData AccessAssessment Level
Tier 1PII/PHI accessFull assessment annually
Tier 2Business dataQuestionnaire + review
Tier 3No sensitive dataSelf-attestation
Red Flags to Surface Proactively
  • Security budget justified by benchmarks rather than risk analysis
  • Certifications pursued before basic hygiene (patching, MFA, backups)
  • No documented asset inventory -- cannot protect what you do not know you have
  • IR plan exists but never tested; security reports to IT, not executive level
  • Security questionnaire backlog > 30 days -- silently losing enterprise deals
  • Vendor with sensitive data access has not been assessed
Show full SKILL.md (499 more words)Show less
Startup-Specific Guidance

Type I vs Type II: Type I examines control design at a point in time (3-6 months, good for closing the first enterprise deal). Type II examines control operation over 3-12 months (what sophisticated buyers want, plan 12 months total). Start Type I immediately; begin Type II observation once controls are in place.

Right-Sizing by Stage: Seed (5-15): foundational controls, automation-heavy, concise policies, one part-time owner. Series A (15-50): dedicated compliance owner or fractional CISO, formal access reviews. Series B+ (50+): full-time security team, internal audit, GRC platform.

Cost-Effective Tooling: Compliance automation (Vanta, Drata, Secureframe — significantly reduces manual effort), SSO (Google Workspace or Okta), MDM (Kandji or Jamf), monitoring (Datadog, PagerDuty), vulnerability scanning (Dependabot, Snyk, Trivy).

Timeline Templates
  • Type I Aggressive (3 months): Month 1 scope/gap/policies, Month 2 implementation, Month 3 readiness + audit.
  • Type I Standard (6 months): Months 1-2 scope/policies, 3-4 implementation, 5 evidence, 6 audit.
  • Type II (12 months): Months 1-6 complete Type I, 6-12 observation + evidence, Month 12 audit.
Output Confidence Tagging

All findings tagged before reaching decision-makers: Verified (confirmed against evidence), Medium (reported but not independently verified), Assumed (inferred, needs validation).

  • privacy-policy — SOC 2 Privacy criteria (P1-P8) align directly with privacy policy commitments. Ensure consistency.
  • security-review — Technical security controls from security-review map to SOC 2 Common Criteria (CC6, CC7, CC8). Use findings to inform gap analysis.

Examples

Example 1: Enterprise deal requires SOC 2

User: "A prospect wants SOC 2 before signing a $200K contract. We have nothing."

Good output excerpt:

Business case: This $200K deal justifies a $30-50K compliance investment. At your stage, every enterprise deal blocked by missing SOC 2 has an opportunity cost.

AreaStatusKey Gaps
Access ControlPartialMFA not enforced on AWS root, no SSO, no formal reviews
Change ManagementPartialGitHub PRs used but no documented policy
Incident ResponseMissingNo documented plan, no on-call rotation
Risk AssessmentMissingNo formal risk assessment conducted

Recommended approach: Type I in 3 months, then begin Type II observation. Immediate actions: (1) Sign up for compliance automation. (2) Enforce MFA everywhere. (3) Select an auditor with startup experience. Interim response to prospect: Share security questionnaire response, SOC 2 Type I commitment timeline, and a signed mutual NDA with security addendum.

Example 2: Security posture assessment

User: "We already use Okta for SSO and do code reviews. Where are we relative to SOC 2?"

Good output excerpt:

Gap Analysis Summary: 55% ready

Compliant: CC6.1 Okta SSO with MFA, CC8.1 code reviews via PRs. Partial: CC6.2 no quarterly access reviews documented, CC7.2 IRP never tested, CC6.3 no formal offboarding checklist. Missing: CC3.1 no annual risk assessment, CC2.1 no security training, CC9.2 no vendor management, CC4.1 no control monitoring, all 10 required policies need drafting.


Disclaimer: This skill provides SOC 2 preparation guidance for planning purposes only. It does not constitute legal, audit, or professional compliance advice. SOC 2 reports can only be issued by a licensed CPA firm. Engage a qualified auditor to confirm readiness before scheduling an audit.

© shawnpang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/soc2-prep of shawnpang/startup-founder-skills.

Open the folder on GitHubat commit 4ad31b4

Compare with similar skills

Soc2 Prep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Soc2 Prep compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Soc2 Prep this skillshawnpang/startup-founder-skills341—~2.5kAutomated safety check: PassMIT
Infrastructure Compliance Auditorborghei/Claude-Skills881—~2.1kAutomated safety check: PassMIT
Cursor Compliance Auditjeremylongshore/tons-of-skills-marketplace2.8k—~2.3kAutomated safety check: NotesMIT
Isms Audit Expertdavila7/claude-code-templates32k1 repos~3.1kAutomated safety check: PassMIT
Senior Secopsalirezarezvani/claude-skills28k1 repos~4kAutomated safety check: PassMIT
Vendor Security Reviewmohitagw15856/pm-claude-skills1.4k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Cross-framework infrastructure security audit across cloud, network, and CI/CD.

    881 GitHub stars~2.1k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Cursor Compliance Audit

    jeremylongshore/tons-of-skills-marketplace

    Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation.

    2.8k GitHub stars~2.3k tokensUpdated yesterday
    Legal & ComplianceAuto-check: notes
  • Isms Audit Expert

    davila7/claude-code-templates

    Senior ISMS Audit Expert for internal and external information security management system auditing.

    32k GitHub starsUsed in 1 repo~3.1k tokens
    SecurityAuto-check passed
  • Senior Secops

    alirezarezvani/claude-skills

    Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices.

    28k GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed
  • Vendor Security Review

    mohitagw15856/pm-claude-skills

    Run a third-party / vendor security review and assign a risk tier with required controls.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Fondo Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Apply security best practices for Fondo including OAuth token management, financial data protection, SOC 2 compliance, and access control.

    2.8k GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from shawnpang/startup-founder-skills

All 50 skills in this repo
  • Accelerator Application

    shawnpang/startup-founder-skills

    When the user wants to apply to startup accelerators, incubators, or fellowship programs.

    341 GitHub stars~2.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Architecture Design

    shawnpang/startup-founder-skills

    When the user needs to design or evaluate system architecture — service boundaries, data models, API contracts, infrastructure topology, database selection, or dependency analysis.

    341 GitHub stars~2.1k tokensUpdated 6 mo ago
    Auto-check passed
  • Board Update

    shawnpang/startup-founder-skills

    When the user needs to write a monthly or quarterly investor update, prepare a board deck, or communicate company progress to stakeholders.

    341 GitHub stars~2.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Churn Analysis

    shawnpang/startup-founder-skills

    When the user needs to identify at-risk accounts, understand why customers are leaving, reduce churn rate, build health scores, design save plays, or create win-back campaigns.

    341 GitHub stars~2.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Cicd Setup

    shawnpang/startup-founder-skills

    When the user needs to set up or improve CI/CD pipelines — GitHub Actions, GitLab CI, deployment automation, or says "set up CI", "automate deployment", "add tests to pipeline", "fix my build".

    341 GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Code Review

    shawnpang/startup-founder-skills

    When the user asks for a code review, shares code for feedback, or says "review this", "check my code", "what's wrong with this".

    341 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed

Questions about Soc2 Prep

What does Soc2 Prep do?

When the user needs to prepare for SOC 2, build a compliance roadmap, assess security posture, quantify security risk, or says "we need SOC 2", "security audit", "compliance", "enterprise customer…. Soc2 Prep is an agent skill from shawnpang/startup-founder-skills. When the user needs to prepare for SOC 2, build a compliance roadmap, assess security posture, quantify security risk, or says "we need SOC 2", "security audit", "compliance", "enterprise customer wants SOC 2", "CISO advice".

When should I use Soc2 Prep?

Soc2 Prep fits situations like: needs to prepare for SOC 2; build a compliance roadmap; assess security posture; quantify security risk.

How do I install Soc2 Prep in Claude Code?

Run `npx skills add shawnpang/startup-founder-skills --skill soc2-prep -a claude-code`. Or copy the skill folder (skills/soc2-prep in shawnpang/startup-founder-skills) into .claude/skills/soc2-prep in your project. Claude Code loads it when a task matches its description.

How do I install Soc2 Prep in Codex?

Run `npx skills add shawnpang/startup-founder-skills --skill soc2-prep -a codex`. Or copy the skill folder (skills/soc2-prep in shawnpang/startup-founder-skills) into .agents/skills/soc2-prep in your project. Codex loads it when a task matches its description.

Can I use Soc2 Prep in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add shawnpang/startup-founder-skills --skill soc2-prep -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/soc2-prep, .gemini/skills/soc2-prep, .github/skills/soc2-prep and .opencode/skills/soc2-prep in your project.

What does Soc2 Prep need to run?

SKILL.md names no scripts, command-line tools or credentials: Soc2 Prep is instructions for the agent only.

Does Soc2 Prep access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Soc2 Prep safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Soc2 Prep use?

Soc2 Prep is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Soc2 Prep use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Soc2 Prep?

Skills that share tags, products or a category with Soc2 Prep: Infrastructure Compliance Auditor (borghei/Claude-Skills, 881 stars), Cursor Compliance Audit (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Isms Audit Expert (davila7/claude-code-templates, 32k stars) and Senior Secops (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Soc2 Prep?

shawnpang (a GitHub user) maintains it in shawnpang/startup-founder-skills, which has 341 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on March 16, 2026.

Source: shawnpang/startup-founder-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.