Soc2 Audit

Execute a comprehensive, framework-agnostic SOC 2 readiness audit of an entire repository or application. Detects project type and stack at runtime and adapts evidence gathering accordingly. Inspects the whole project for observable evidence of AICPA Trust Services Criteria controls (Common Criteria CC1-CC9 plus the optional Availability, Confidentiality, Processing Integrity, and Privacy categories), organized around eleven control families (A-K). For every control it records a Status (met / partial / gap / organizational) with concrete evidence and an ownership lane (platform-auditable / organizational / client-CUEC), scores readiness per control family, lists gaps mapped to criteria references, and produces a prioritized remediation plan with an overall readiness score /100 and a readiness band. Read-only and evidence-based: never invents controls; absent evidence is a Gap; secret values are always redacted. Use when the user asks for a SOC 2 audit, SOC 2 readiness assessment, Trust Services Criteria revie

somnio-software ea560e1 22 files · 124.5 KB Updated

File contents

somnio-software/somnio-ai-tools/tree/main/skills/soc2-audit commit ea560e19ca

Frequently asked questions

npx skillmds@latest add somnio-software/soc2-audit