SOC 2 Type I and Type II readiness patterns — Trust Service Criteria (Security / Availability / Processing Integrity / Confidentiality / Privacy), control-to-evidence mapping, and the operational evidence collection patterns that survive a continuous-period audit.
Installs into .claude/skills of the current project.
Are you the author of Soc2 Readiness?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/nmor-soc2-readiness-the-council)
---
name: soc2-readiness
description: SOC 2 Type I and Type II readiness patterns — Trust Service Criteria (Security / Availability / Processing Integrity / Confidentiality / Privacy), control-to-evidence mapping, and the operational evidence collection patterns that survive a continuous-period audit.
disable-model-invocation: true
---
# SOC 2 Readiness
> **Size budget: 8 KB** — `token-budget.mjs --check`.
SOC 2 Type I and Type II readiness patterns — Trust Service Criteria (Security / Availability / Processing Integrity / Confidentiality / Privacy), control-to-evidence mapping, and the operational evidence collection patterns that survive a continuous-period audit.
## Working procedure
1. Establish the relevant mode and existing evidence; do not repeat completed intake.
2. Define system scope, trust-service criteria, observation period and evidence owners. Separate implemented controls from tested operating effectiveness; checklist completion is not an auditor opinion.
3. Read only the corresponding sections below before applying their examples.
4. Verify the result with meaningful positive, negative and failure controls. Record actual outcomes, limitations and next action.
## Selected references
- [Purpose](references/procedure.md#purpose) — read when this part of the task applies.
- [Standards Cited](references/procedure.md#standards-cited) — read when this part of the task applies.
- [When to Fire](references/procedure.md#when-to-fire) — read when this part of the task applies.
- [Core Patterns](references/procedure.md#core-patterns) — read when this part of the task applies.
- [Anti-Patterns](references/procedure.md#anti-patterns) — read when this part of the task applies.
- [Verification Checklist](references/procedure.md#verification-checklist) — read when this part of the task applies.
- [Cross-References](references/procedure.md#cross-references) — read when this part of the task applies.
- [Why This Skill Exists](references/procedure.md#why-this-skill-exists) — read when this part of the task applies.
- [Compliance & Standards Mapping](references/procedure.md#compliance--standards-mapping) — read when this part of the task applies.
- [Learning hooks](references/procedure.md#learning-hooks) — read when this part of the task applies.
The [full procedure](references/procedure.md) preserves detailed examples and standards.
Load relevant excerpts rather than the entire reference. Runtime capabilities and higher-priority instructions govern imported templates.