SOC 2 Compliance Accelerator
Your agent for achieving and maintaining SOC 2 Type I and Type II compliance — from readiness assessment through audit completion.
What This Does
Guides organizations through the full SOC 2 lifecycle: gap analysis, control implementation, evidence collection, audit prep, and continuous monitoring. Covers all 5 Trust Service Criteria with practical implementation steps.
How to Use
Tell your agent what stage you're at:
- "Run SOC 2 readiness assessment" — 64-point gap analysis across all Trust Service Criteria
- "Build SOC 2 control matrix" — Maps controls to criteria with ownership and evidence requirements
- "Create SOC 2 evidence collection plan" — Automated and manual evidence gathering schedule
- "Prepare for SOC 2 audit" — Auditor-ready documentation package checklist
- "SOC 2 continuous monitoring dashboard" — Ongoing compliance tracking after certification
Trust Service Criteria Coverage
CC — Common Criteria (Security) — Required
- CC1: Control Environment (tone at top, org structure, accountability)
- CC2: Communication & Information (internal/external, system boundaries)
- CC3: Risk Assessment (risk identification, fraud risk, change impact)
- CC4: Monitoring Activities (ongoing evaluations, deficiency reporting)
- CC5: Control Activities (policies, technology controls, deployment)
- CC6: Logical & Physical Access (access management, authentication, physical security)
- CC7: System Operations (vulnerability management, incident response, recovery)
- CC8: Change Management (change authorization, testing, approval)
- CC9: Risk Mitigation (vendor management, business continuity)
Optional Criteria
- Availability (A1): Uptime SLAs, DR/BCP, capacity planning
- Processing Integrity (PI1): Data accuracy, completeness, timeliness
- Confidentiality (C1): Classification, encryption, retention, disposal
- Privacy (P1): Notice, consent, collection, use, disclosure, access
Readiness Assessment Framework
Phase 1: Scoping (Week 1)
System Description Checklist:
□ Infrastructure components (cloud, on-prem, hybrid)
□ Software stack (applications, databases, middleware)
□ People (roles, responsibilities, third parties)
□ Procedures (operational, security, change management)
□ Data flows (ingress, processing, storage, egress)
□ Trust Service Criteria selection (Security + which optional?)
□ Subservice organizations (cloud providers, SaaS tools)
□ Carve-out vs inclusive method for subservice orgs
Phase 2: Gap Analysis (Weeks 2-3)
Score each control area 1-5:
- 1 — Not Started: No policy, no process, no evidence
- 2 — Ad Hoc: Informal processes exist but undocumented
- 3 — Defined: Documented but inconsistent execution
- 4 — Managed: Documented, executed, some evidence
- 5 — Optimized: Automated, monitored, auditable evidence
Priority Matrix:
| Gap Score |
Action |
Timeline |
| 1-2 |
Critical — implement immediately |
2-4 weeks |
| 3 |
Important — formalize and document |
1-2 weeks |
| 4 |
Minor — fill evidence gaps |
3-5 days |
| 5 |
Maintain — continue monitoring |
Ongoing |
Phase 3: Remediation (Weeks 3-10)
For each gap:
1. Assign control owner (by name, not role)
2. Define implementation steps
3. Set evidence collection method (automated preferred)
4. Establish testing cadence
5. Document exception handling process
Control Implementation Priorities
Must-Have Controls (Week 1-4)
- Access Management: SSO, MFA on all systems, quarterly access reviews
- Encryption: TLS 1.2+ in transit, AES-256 at rest, key management
- Logging: Centralized logging, 90-day retention minimum, tamper-evident
- Incident Response: Documented plan, defined roles, tested annually
- Change Management: Approval workflows, code review, deployment gates
- Vendor Management: Vendor inventory, risk assessments, SOC 2 reports from critical vendors
- Employee Security: Background checks, security awareness training, acceptable use policy
- Vulnerability Management: Regular scanning, patch cadence (critical <72hrs), penetration testing
Should-Have Controls (Week 4-8)
- Business Continuity: DR plan, RTO/RPO defined, tested semi-annually
- Data Classification: 4-tier model (Public, Internal, Confidential, Restricted)
- Network Security: Segmentation, IDS/IPS, WAF for web applications
- Endpoint Protection: EDR, device encryption, MDM for mobile
Nice-to-Have Controls (Week 8+)
- Security Metrics Dashboard: Real-time compliance posture
- Automated Compliance Monitoring: Continuous control testing
- Zero Trust Architecture: Beyond perimeter security
Evidence Collection Guide
Automated Evidence (Set Once, Collect Forever)
| Control |
Evidence Source |
Tool Examples |
| Access Reviews |
IAM exports |
Okta, Azure AD, AWS IAM |
| Encryption |
Config snapshots |
AWS Config, CloudTrail |
| Logging |
Log aggregation |
Datadog, Splunk, ELK |
| Vulnerability Scans |
Scan reports |
Qualys, Nessus, Snyk |
| Change Management |
PR/deploy history |
GitHub, GitLab, Jira |
| Uptime |
Monitoring dashboards |
Datadog, PagerDuty |
Manual Evidence (Scheduled Collection)
| Control |
Evidence Type |
Frequency |
| Background Checks |
HR records |
Per hire |
| Security Training |
Completion certificates |
Annual |
| Risk Assessment |
Assessment document |
Annual |
| Pen Testing |
Report |
Annual |
| DR Testing |
Test results |
Semi-annual |
| Board/Mgmt Review |
Meeting minutes |
Quarterly |
| Vendor Reviews |
Assessment records |
Annual |
| Policy Reviews |
Version history |
Annual |
Audit Timeline
Type I (Point-in-Time) — 8-12 weeks total
Week 1-2: Auditor selection + engagement letter
Week 2-4: System description draft
Week 4-6: Control documentation + evidence prep
Week 6-8: Fieldwork (auditor testing)
Week 8-10: Draft report review
Week 10-12: Final report issued
Type II (Period of Time) — 3-12 month observation + 4-6 weeks fieldwork
Month 1: Observation period begins (minimum 3 months, recommend 6-12)
Ongoing: Evidence collection, control operation
Month 3-12: Observation period ends
+Week 1-2: Fieldwork scheduling
+Week 2-4: Fieldwork (testing over observation period)
+Week 4-6: Draft report + final report
Cost Framework
| Company Size |
Type I |
Type II |
Annual Maintenance |
| Startup (<50) |
$20K-$50K |
$30K-$80K |
$15K-$40K |
| Mid-Market (50-500) |
$40K-$100K |
$60K-$150K |
$30K-$80K |
| Enterprise (500+) |
$80K-$200K |
$120K-$300K |
$60K-$150K |
Includes: auditor fees, tooling, personnel time, remediation costs.
Hidden costs to budget:
- Compliance automation platform: $10K-$50K/year
- Additional security tooling: $5K-$30K/year
- Personnel time (internal): 200-800 hours
- Policy/procedure writing (if outsourced): $5K-$20K
Common Audit Findings (Avoid These)
- Access not revoked within 24 hours of termination — #1 finding
- Missing or incomplete risk assessment — annual requirement
- No evidence of management review — need meeting minutes
- Incomplete vendor management — missing SOC reports from critical vendors
- Inconsistent change management — emergency changes without retroactive approval
- Security training gaps — new hires not trained within 30 days
- Logging gaps — not all in-scope systems sending to central logging
AI Agent SOC 2 Considerations (2026)
When deploying AI agents in SOC 2 environments:
- Data boundaries: Agents must not access data outside their defined scope
- Audit trail: All agent actions must be logged and attributable
- Access controls: Agent service accounts need same rigor as human accounts
- Model governance: Document which models process customer data
- Prompt injection defense: Part of CC7 (system operations) controls
- Output validation: Processing integrity controls for agent outputs
Industry-Specific Requirements
| Industry |
Extra Criteria |
Key Controls |
| Fintech |
All 5 TSC typical |
SOX mapping, encryption everywhere, PCI if payments |
| Healthcare |
Privacy, Confidentiality |
HIPAA crosswalk, BAAs, PHI handling |
| SaaS |
Availability, Confidentiality |
Multi-tenant isolation, SLA compliance |
| Legal |
Confidentiality, Privacy |
Privilege protection, matter isolation |
| Construction |
Security, Availability |
Field data protection, offline capability |
| E-commerce |
All 5 TSC typical |
PCI DSS alignment, transaction integrity |
7 SOC 2 Mistakes That Cost Companies 6+ Months
- Starting with Type II — Get Type I first, prove controls work, then observe
- Scoping too broadly — Only include systems that touch customer data
- Choosing the wrong auditor — Pick one who knows your industry
- Manual evidence collection — Automate from day 1 or drown in spreadsheets
- Treating it as a project, not a program — SOC 2 is continuous
- Ignoring subservice organizations — Your cloud provider's SOC 2 matters
- No executive sponsor — Compliance without budget authority = failure
Get the Full Implementation Package
This skill gives you the framework. For industry-specific compliance playbooks with regulatory crosswalks, cost models, and vendor selection guides:
🔗 AfrexAI Context Packs — $47 per industry vertical
Available packs: Fintech, Healthcare, Legal, Construction, E-commerce, SaaS, Real Estate, Recruitment, Manufacturing, Professional Services
🔗 AI Revenue Leak Calculator — Find where compliance gaps cost you money
🔗 Agent Setup Wizard — Deploy compliance monitoring agents in minutes
Bundle pricing:
- Pick 3 packs: $97
- All 10 packs: $197
- Everything bundle: $247
1---2name: soc-2-compliance-accelerator3description: Your agent for achieving and maintaining SOC 2 Type I and Type II compliance — from readiness assessment through audit completion.4---5
6# SOC 2 Compliance Accelerator
7
8Your agent for achieving and maintaining SOC 2 Type I and Type II compliance — from readiness assessment through audit completion.
9
10## What This Does
11
12Guides organizations through the full SOC 2 lifecycle: gap analysis, control implementation, evidence collection, audit prep, and continuous monitoring. Covers all 5 Trust Service Criteria with practical implementation steps.
13
14## How to Use
15
16Tell your agent what stage you're at:
17
18- **"Run SOC 2 readiness assessment"** — 64-point gap analysis across all Trust Service Criteria
19- **"Build SOC 2 control matrix"** — Maps controls to criteria with ownership and evidence requirements
20- **"Create SOC 2 evidence collection plan"** — Automated and manual evidence gathering schedule
21- **"Prepare for SOC 2 audit"** — Auditor-ready documentation package checklist
22- **"SOC 2 continuous monitoring dashboard"** — Ongoing compliance tracking after certification
23
24## Trust Service Criteria Coverage
25
26### CC — Common Criteria (Security) — Required
27- CC1: Control Environment (tone at top, org structure, accountability)
28- CC2: Communication & Information (internal/external, system boundaries)
29- CC3: Risk Assessment (risk identification, fraud risk, change impact)
30- CC4: Monitoring Activities (ongoing evaluations, deficiency reporting)
31- CC5: Control Activities (policies, technology controls, deployment)
32- CC6: Logical & Physical Access (access management, authentication, physical security)
33- CC7: System Operations (vulnerability management, incident response, recovery)
34- CC8: Change Management (change authorization, testing, approval)
35- CC9: Risk Mitigation (vendor management, business continuity)
36
37### Optional Criteria
38- **Availability (A1)**: Uptime SLAs, DR/BCP, capacity planning
39- **Processing Integrity (PI1)**: Data accuracy, completeness, timeliness
40- **Confidentiality (C1)**: Classification, encryption, retention, disposal
41- **Privacy (P1)**: Notice, consent, collection, use, disclosure, access
42
43## Readiness Assessment Framework
44
45### Phase 1: Scoping (Week 1)
46```
47System Description Checklist:
48□ Infrastructure components (cloud, on-prem, hybrid)
49□ Software stack (applications, databases, middleware)
50□ People (roles, responsibilities, third parties)
51□ Procedures (operational, security, change management)
52□ Data flows (ingress, processing, storage, egress)
53□ Trust Service Criteria selection (Security + which optional?)
54□ Subservice organizations (cloud providers, SaaS tools)
55□ Carve-out vs inclusive method for subservice orgs
56```
57
58### Phase 2: Gap Analysis (Weeks 2-3)
59Score each control area 1-5:
60- **1 — Not Started**: No policy, no process, no evidence
61- **2 — Ad Hoc**: Informal processes exist but undocumented
62- **3 — Defined**: Documented but inconsistent execution
63- **4 — Managed**: Documented, executed, some evidence
64- **5 — Optimized**: Automated, monitored, auditable evidence
65
66Priority Matrix:
67| Gap Score | Action | Timeline |
68|-----------|--------|----------|
69| 1-2 | Critical — implement immediately | 2-4 weeks |
70| 3 | Important — formalize and document | 1-2 weeks |
71| 4 | Minor — fill evidence gaps | 3-5 days |
72| 5 | Maintain — continue monitoring | Ongoing |
73
74### Phase 3: Remediation (Weeks 3-10)
75```
76For each gap:
771. Assign control owner (by name, not role)
782. Define implementation steps
793. Set evidence collection method (automated preferred)
804. Establish testing cadence
815. Document exception handling process
82```
83
84## Control Implementation Priorities
85
86### Must-Have Controls (Week 1-4)
871. **Access Management**: SSO, MFA on all systems, quarterly access reviews
882. **Encryption**: TLS 1.2+ in transit, AES-256 at rest, key management
893. **Logging**: Centralized logging, 90-day retention minimum, tamper-evident
904. **Incident Response**: Documented plan, defined roles, tested annually
915. **Change Management**: Approval workflows, code review, deployment gates
926. **Vendor Management**: Vendor inventory, risk assessments, SOC 2 reports from critical vendors
937. **Employee Security**: Background checks, security awareness training, acceptable use policy
948. **Vulnerability Management**: Regular scanning, patch cadence (critical <72hrs), penetration testing
95
96### Should-Have Controls (Week 4-8)
979. **Business Continuity**: DR plan, RTO/RPO defined, tested semi-annually
9810. **Data Classification**: 4-tier model (Public, Internal, Confidential, Restricted)
9911. **Network Security**: Segmentation, IDS/IPS, WAF for web applications
10012. **Endpoint Protection**: EDR, device encryption, MDM for mobile
101
102### Nice-to-Have Controls (Week 8+)
10313. **Security Metrics Dashboard**: Real-time compliance posture
10414. **Automated Compliance Monitoring**: Continuous control testing
10515. **Zero Trust Architecture**: Beyond perimeter security
106
107## Evidence Collection Guide
108
109### Automated Evidence (Set Once, Collect Forever)
110| Control | Evidence Source | Tool Examples |
111|---------|---------------|---------------|
112| Access Reviews | IAM exports | Okta, Azure AD, AWS IAM |
113| Encryption | Config snapshots | AWS Config, CloudTrail |
114| Logging | Log aggregation | Datadog, Splunk, ELK |
115| Vulnerability Scans | Scan reports | Qualys, Nessus, Snyk |
116| Change Management | PR/deploy history | GitHub, GitLab, Jira |
117| Uptime | Monitoring dashboards | Datadog, PagerDuty |
118
119### Manual Evidence (Scheduled Collection)
120| Control | Evidence Type | Frequency |
121|---------|--------------|-----------|
122| Background Checks | HR records | Per hire |
123| Security Training | Completion certificates | Annual |
124| Risk Assessment | Assessment document | Annual |
125| Pen Testing | Report | Annual |
126| DR Testing | Test results | Semi-annual |
127| Board/Mgmt Review | Meeting minutes | Quarterly |
128| Vendor Reviews | Assessment records | Annual |
129| Policy Reviews | Version history | Annual |
130
131## Audit Timeline
132
133### Type I (Point-in-Time) — 8-12 weeks total
134```
135Week 1-2: Auditor selection + engagement letter
136Week 2-4: System description draft
137Week 4-6: Control documentation + evidence prep
138Week 6-8: Fieldwork (auditor testing)
139Week 8-10: Draft report review
140Week 10-12: Final report issued
141```
142
143### Type II (Period of Time) — 3-12 month observation + 4-6 weeks fieldwork
144```
145Month 1: Observation period begins (minimum 3 months, recommend 6-12)
146Ongoing: Evidence collection, control operation
147Month 3-12: Observation period ends
148+Week 1-2: Fieldwork scheduling
149+Week 2-4: Fieldwork (testing over observation period)
150+Week 4-6: Draft report + final report
151```
152
153## Cost Framework
154
155| Company Size | Type I | Type II | Annual Maintenance |
156|-------------|--------|---------|-------------------|
157| Startup (<50) | $20K-$50K | $30K-$80K | $15K-$40K |
158| Mid-Market (50-500) | $40K-$100K | $60K-$150K | $30K-$80K |
159| Enterprise (500+) | $80K-$200K | $120K-$300K | $60K-$150K |
160
161Includes: auditor fees, tooling, personnel time, remediation costs.
162
163Hidden costs to budget:
164- Compliance automation platform: $10K-$50K/year
165- Additional security tooling: $5K-$30K/year
166- Personnel time (internal): 200-800 hours
167- Policy/procedure writing (if outsourced): $5K-$20K
168
169## Common Audit Findings (Avoid These)
170
1711. **Access not revoked within 24 hours of termination** — #1 finding
1722. **Missing or incomplete risk assessment** — annual requirement
1733. **No evidence of management review** — need meeting minutes
1744. **Incomplete vendor management** — missing SOC reports from critical vendors
1755. **Inconsistent change management** — emergency changes without retroactive approval
1766. **Security training gaps** — new hires not trained within 30 days
1777. **Logging gaps** — not all in-scope systems sending to central logging
178
179## AI Agent SOC 2 Considerations (2026)
180
181When deploying AI agents in SOC 2 environments:
182- **Data boundaries**: Agents must not access data outside their defined scope
183- **Audit trail**: All agent actions must be logged and attributable
184- **Access controls**: Agent service accounts need same rigor as human accounts
185- **Model governance**: Document which models process customer data
186- **Prompt injection defense**: Part of CC7 (system operations) controls
187- **Output validation**: Processing integrity controls for agent outputs
188
189## Industry-Specific Requirements
190
191| Industry | Extra Criteria | Key Controls |
192|----------|---------------|-------------|
193| **Fintech** | All 5 TSC typical | SOX mapping, encryption everywhere, PCI if payments |
194| **Healthcare** | Privacy, Confidentiality | HIPAA crosswalk, BAAs, PHI handling |
195| **SaaS** | Availability, Confidentiality | Multi-tenant isolation, SLA compliance |
196| **Legal** | Confidentiality, Privacy | Privilege protection, matter isolation |
197| **Construction** | Security, Availability | Field data protection, offline capability |
198| **E-commerce** | All 5 TSC typical | PCI DSS alignment, transaction integrity |
199
200## 7 SOC 2 Mistakes That Cost Companies 6+ Months
201
2021. **Starting with Type II** — Get Type I first, prove controls work, then observe
2032. **Scoping too broadly** — Only include systems that touch customer data
2043. **Choosing the wrong auditor** — Pick one who knows your industry
2054. **Manual evidence collection** — Automate from day 1 or drown in spreadsheets
2065. **Treating it as a project, not a program** — SOC 2 is continuous
2076. **Ignoring subservice organizations** — Your cloud provider's SOC 2 matters
2087. **No executive sponsor** — Compliance without budget authority = failure
209
210---
211
212## Get the Full Implementation Package
213
214This skill gives you the framework. For industry-specific compliance playbooks with regulatory crosswalks, cost models, and vendor selection guides:
215
216🔗 **[AfrexAI Context Packs](https://afrexai-cto.github.io/context-packs/)** — $47 per industry vertical
217
218Available packs: Fintech, Healthcare, Legal, Construction, E-commerce, SaaS, Real Estate, Recruitment, Manufacturing, Professional Services
219
220🔗 **[AI Revenue Leak Calculator](https://afrexai-cto.github.io/ai-revenue-calculator/)** — Find where compliance gaps cost you money
221
222🔗 **[Agent Setup Wizard](https://afrexai-cto.github.io/agent-setup/)** — Deploy compliance monitoring agents in minutes
223
224**Bundle pricing:**
225- Pick 3 packs: $97
226- All 10 packs: $197
227- Everything bundle: $247