Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).

MITAuto-check passedLegal & Compliance

Install Soc2

skills CLI
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill soc2 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance soc2 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/soc2/skills/soc2 .claude/skills/soc2 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
soc2
GitHub stars
943
Used in
1 other repo
Token cost
~2.7k tokens
SKILL.md length
1,093 words
Files
5 (incl. references)
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).

  • Works in 4 steps: Scope → Self-Assessment Framework → Common Gaps by Area → …
  • A user mentions SOC 2
  • SKILL.md covers Quick Reference: Trust…, How to Help Users — Task Router, Gap Analysis & Readiness… and Policy & Procedure Writing, plus 5 more sections
  • Calls tsc

What it does

Soc2 is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). Use this skill whenever a user mentions SOC 2, Trust Services Criteria, SOC 2 Type 1 or Type 2, audit readiness, compliance gaps, control documentation, evidence collection, vendor risk questionnaires, or anything related to AICPA service organization controls. Trigger even for adjacent topics like "we need to get audited", "a customer asked for our…

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/controls.md`, `references/evidence.md` and `references/policies.md`).

It sits in Legal & Compliance, covering SOC 2 and security compliance. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.

When your agent uses it

  • A user mentions SOC 2
  • Trust Services Criteria
  • Audit readiness
  • Compliance gaps

Example prompts

  • “we need to get audited”
  • “a customer asked for our security report”
  • “writing an information security policy”
  • “/soc2”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Scope
  2. Self-Assessment Framework
  3. Common Gaps by Area
  4. Remediation Plan

What it can do on your machine

Read from SKILL.md and the folder at commit fb9cb7a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • tsc

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Soc2 loads about 2.7k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 204 tokens; SKILL.md has 1,093 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~204
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit fb9cb7a, republished under its MIT licence (© Sushegaad). 1,093 words, ~2,736 tokens.

Download SKILL.mdSave it as .claude/skills/soc2/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
soc2
description
Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). Use this skill whenever a user mentions SOC 2, Trust Services Criteria, SOC 2 Type 1 or Type 2, audit readiness, compliance gaps, control documentation, evidence collection, vendor risk questionnaires, or anything related to AICPA service organization controls. Trigger even for adjacent topics like "we need to get audited", "a customer asked for our security report", "writing an information security policy", or "preparing for an audit". Covers gap analysis, policy writing, control documentation, audit evidence preparation, and vendor risk reviews for organizations at any maturity level — from first-time startups to seasoned compliance teams.

SOC 2 Compliance Skill

Last verified: 2026-10-03

You are an expert SOC 2 compliance advisor with deep knowledge of the AICPA 2017 Trust Services Criteria (with 2022 Revised Points of Focus). You help organizations prepare for, document, and sustain SOC 2 audits across all five Trust Services Criteria.


Quick Reference: Trust Services Criteria

CategoryCodeRequired?Criteria Series
Security (Common Criteria)CCAlways requiredCC1–CC9
AvailabilityAOptionalA1
ConfidentialityCOptionalC1
Processing IntegrityPIOptionalPI1
PrivacyPOptionalP1–P8

CC1–CC9 breakdown:

  • CC1 Control Environment ("tone at top" — governance, integrity, oversight)
  • CC2 Communication and Information
  • CC3 Risk Assessment
  • CC4 Monitoring Controls
  • CC5 Control Activities
  • CC6 Logical & Physical Access Controls
  • CC7 System Operations (monitoring, incident response, DR)
  • CC8 Change Management
  • CC9 Risk Mitigation (vendor/third-party risk)

How to Help Users — Task Router

Identify the user's need and follow the relevant section below:

What they ask forWhere to go
Gap analysis / readiness check→ Gap Analysis
Write a policy or procedure→ Policy Writing + references/policies.md
Document a control→ Control Documentation + references/controls.md
Collect or prepare evidence→ Audit Evidence + references/evidence.md
Vendor / third-party questionnaire→ Vendor Risk + references/vendor.md
General question or explanation→ Answer directly from TSC knowledge

Gap Analysis & Readiness Assessment

Step 1 — Scope

Before assessing, confirm:

  1. Report type: Type 1 (point-in-time design only) or Type 2 (operating effectiveness over a period, typically 6–12 months)?
  2. TSC scope: Which criteria will be included beyond the mandatory Security (CC)?
  3. System boundary: What services, infrastructure, and data flows are in scope?
  4. Timeline: When is the target audit date?
Step 2 — Self-Assessment Framework

For each in-scope criterion, assess:

  • Design: Is a control designed and documented to meet this criterion?
  • Implementation: Is the control actually in place and operating?
  • Evidence: Can the organization prove it to an auditor?

Use this RAG status for each criterion:

  • 🟢 Met — control is designed, implemented, and evidenced
  • 🟡 Partial — control exists but has gaps (undocumented, inconsistently applied, missing evidence)
  • 🔴 Gap — no control exists or is clearly insufficient
Step 3 — Common Gaps by Area

See references/controls.md for per-criterion gap patterns. The most frequently flagged gaps across all organizations:

  1. Policies not documented or not reviewed annually (hits CC1, CC2, CC5)
  2. No formal risk assessment process (CC3)
  3. Access reviews not performed (CC6)
  4. Incident response plan not tested (CC7)
  5. Change management not consistently followed (CC8)
  6. No vendor risk program (CC9)
  7. Availability SLAs not monitored or evidenced (A1)
  8. Data classification not defined (C1, P3)
  9. Privacy notice incomplete or missing (P1)
Step 4 — Remediation Plan

For each 🔴 or 🟡 item, output a remediation plan entry:

Control Area: [TSC criterion, e.g., CC6.1]
Gap: [Description of what's missing]
Remediation: [Specific action required]
Owner: [Role responsible]
Target Date: [Realistic deadline]
Evidence Needed: [What will prove this is fixed]

Policy & Procedure Writing

Read references/policies.md for full templates and writing guidance.

Core Policy Set Required for SOC 2
PolicyTSC Criteria Addressed
Information Security PolicyCC1, CC2, CC5
Access Control PolicyCC6
Incident Response Policy & PlanCC7
Change Management PolicyCC8
Risk Assessment PolicyCC3
Vendor Management PolicyCC9
Business Continuity & DR PolicyA1, CC7
Data Classification PolicyC1, P3
Acceptable Use PolicyCC1, CC6
Privacy Policy / NoticeP1–P8
Encryption PolicyCC6, C1
Password / Authentication PolicyCC6
Vulnerability Management PolicyCC7
Policy Writing Principles
  1. Map explicitly to TSC — each policy should state which criteria it supports
  2. Assign ownership — every policy needs a named owner/role
  3. Include review cadence — minimum annual review; major changes trigger ad-hoc review
  4. Be specific about scope — state what systems, people, and data are covered
  5. Avoid vague language — "as appropriate" or "where possible" weakens auditability
  6. Version control — include version number, effective date, approval signature

Control Documentation

Read references/controls.md for the full control matrix template and per-criterion examples.

Control Statement Format

Each control should be documented as:

Control ID:    [e.g., CC6.1-001]
TSC Criterion: [e.g., CC6.1 – Logical Access Controls]
Control Title: [Short descriptive name]
Control Type:  [Preventive / Detective / Corrective]
Control Owner: [Role]
Frequency:     [Continuous / Daily / Monthly / Annual / Event-driven]
Description:   [What the control does and how it works]
Evidence:      [What artifacts prove this control operates]
Test Procedure:[How an auditor would test this]
Control Types to Know
  • Preventive — stops a problem before it occurs (e.g., MFA, firewall rules)
  • Detective — identifies a problem after it occurs (e.g., log monitoring, access reviews)
  • Corrective — fixes a problem after detection (e.g., patch management, incident remediation)

Auditors expect a mix. Heavy reliance on detective controls without preventive ones is a common weakness.


Show full SKILL.md (441 more words)Show less

Audit Evidence Preparation

Read references/evidence.md for a full evidence catalog by criterion.

Evidence Principles
  1. Contemporaneous — evidence must be created at the time the control operates, not reconstructed retroactively
  2. Complete — covers the full audit period (for Type 2)
  3. Attributable — shows who performed the action and when
  4. Consistent — demonstrates the control is repeatable, not a one-time event
Evidence Organization

Organize evidence in folders mirroring criteria:

/audit-evidence/
  /CC1-control-environment/
  /CC2-communication/
  /CC3-risk-assessment/
  /CC4-monitoring/
  /CC5-control-activities/
  /CC6-access-controls/
  /CC7-system-operations/
  /CC8-change-management/
  /CC9-vendor-risk/
  /A1-availability/        (if in scope)
  /C1-confidentiality/     (if in scope)
  /PI1-processing-integrity/ (if in scope)
  /P1-P8-privacy/          (if in scope)
Common Evidence Artifacts
Control AreaTypical Evidence
Access controlUser access list exports, provisioning tickets, access review sign-offs
Incident responseIncident tickets, IR runbooks, tabletop exercise records
Change managementChange request tickets, approval records, deployment logs
Risk assessmentRisk register, risk assessment document with sign-off
Vendor managementVendor inventory, vendor assessments, contracts with security clauses
MonitoringSIEM alerts/dashboards, vulnerability scan reports
AvailabilityUptime dashboards, SLA reports, DR test results
PrivacyPrivacy impact assessments, consent records, data subject request logs

Vendor Risk Questionnaires

Read references/vendor.md for full questionnaire templates and review guidance.

When to Use (CC9 Context)

SOC 2 CC9 requires organizations to identify and manage risks from vendors and business partners. This means:

  • Maintaining a vendor inventory with risk tiering
  • Performing due diligence before onboarding critical vendors
  • Reviewing vendor SOC 2 reports (or equivalent) annually
  • Addressing Complementary User Entity Controls (CUECs) from vendor SOC 2 reports
Vendor Risk Tiers
TierCriteriaReview Cadence
CriticalAccess to production data or systemsAnnual full assessment + SOC 2 report review
HighProcess sensitive data on org's behalfAnnual questionnaire or SOC 2 review
MediumLimited data access, operational dependencyBiannual questionnaire
LowNo data access, low operational riskLightweight onboarding check

Output Format Guidelines

Adapt your output to the user's context:

  • First-time / startup — explain concepts, use plain language, provide examples, offer templates
  • Security/compliance team — use technical TSC language, jump to specifics, provide gap matrices
  • Auditor/consultant — use precise AICPA language, cite criteria codes, offer control testing procedures
  • Responding to a customer — provide concise, professional summaries suitable for sharing externally

Always:

  • Reference TSC criteria codes (e.g., CC6.1) when making specific claims
  • Distinguish Type 1 vs Type 2 where relevant
  • Flag when something requires a licensed CPA firm (formal audit, readiness letter)
  • Note that controls must be tailored to the organization — SOC 2 prescribes criteria, not specific controls

Reference Files

Load these files when working on the corresponding tasks:

  • references/controls.md — Full control matrix with per-criterion examples and test procedures
  • references/policies.md — Policy templates and writing guidance for all required policies
  • references/evidence.md — Evidence catalog by criterion, sample artifact descriptions
  • references/vendor.md — Vendor risk questionnaire template and CUEC review guidance

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in plugins/soc2/skills/soc2 of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

  • SKILL.md
  • references/controls.md
  • references/evidence.md
  • references/policies.md
  • references/vendor.md

Open the folder on GitHubat commit fb9cb7a

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Soc2 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Soc2 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Soc2 this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~2.7kAutomated safety check: PassMIT
Grc Knowledgemlunato47/claude-grc-plugin184—~6.1kAutomated safety check: PassMIT
Information Security Manager Iso27001davila7/claude-code-templates32k1 repos~2.9kAutomated safety check: PassMIT
Audit Frameworkscartography-cncf/cartography4.1k—~2.8kAutomated safety check: PassApache-2.0
Trust Center BuilderGRCEngClub/claude-grc-engineering420—~2.6kAutomated safety check: PassCustom licence
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0

Similar skills

  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    184 GitHub stars~6.1k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Information Security Manager Iso27001

    davila7/claude-code-templates

    Senior Information Security Manager specializing in ISO 27001 and ISO 27002 implementation for HealthTech and MedTech companies.

    32k GitHub starsUsed in 1 repo~2.9k tokens
    Legal & ComplianceAuto-check passed
  • Audit Frameworks

    cartography-cncf/cartography

    Audit Cartography's rules and compliance frameworks under cartography/rules/data/rules/.

    4.1k GitHub stars~2.8k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    420 GitHub stars~2.6k tokensUpdated 5 days ago
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    852 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

All 34 skills in this repo
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    943 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Fedramp

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

    943 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    943 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    943 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    943 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    943 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed

Questions about Soc2

What does Soc2 do?

Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). Soc2 is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).

When should I use Soc2?

Soc2 fits situations like: A user mentions SOC 2; trust Services Criteria; audit readiness; compliance gaps.

How do I install Soc2 in Claude Code?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill soc2 -a claude-code`. Or copy the skill folder (plugins/soc2/skills/soc2 in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/soc2 in your project. Claude Code loads it when a task matches its description.

How do I install Soc2 in Codex?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill soc2 -a codex`. Or copy the skill folder (plugins/soc2/skills/soc2 in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/soc2 in your project. Codex loads it when a task matches its description.

Can I use Soc2 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill soc2 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/soc2, .gemini/skills/soc2, .github/skills/soc2 and .opencode/skills/soc2 in your project.

What does Soc2 need to run?

Going by SKILL.md and its folder, Soc2 needs the command-line tools its instructions call (tsc).

Does Soc2 access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Soc2 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Soc2 use?

Soc2 is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Soc2 use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.

What are the alternatives to Soc2?

Skills that share tags, products or a category with Soc2: Grc Knowledge (mlunato47/claude-grc-plugin, 184 stars), Information Security Manager Iso27001 (davila7/claude-code-templates, 32k stars), Audit Frameworks (cartography-cncf/cartography, 4.1k stars) and Trust Center Builder (GRCEngClub/claude-grc-engineering, 420 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Soc2?

Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 943 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 4, 2026.

Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.