/cs:soc2-audit-prep <scope> โ SOC 2 Type II readiness 6-question forcing interrogation. Observation-period focused. Use before Type II observation begins, mid-period checkpoint, or pre-field-test month-10 readiness.
Installs just this skill. Get the whole plugin for auto-invocation.
โก How it fires
How this skill gets triggered: by you, by Claude, or both.
Fires itselfClaude auto-loads it when your prompt matches the work.
You can call itInvoke it directly when you want it.
Slash command/soc2-audit-prep
๐๏ธ Context preview
The summary Claude sees to decide when to auto-load this skill.
/cs:soc2-audit-prep <scope> โ SOC 2 Type II readiness 6-question forcing interrogation. Observation-period focused. Use before Type II observation begins, mid-period checkpoint, or pre-field-test month-10 readiness.
๐ Stats
Stars23,056
Forks3,139
LanguagePython
LicenseMIT
๐ฆ Ships with claude-skills
</> SKILL.md
soc2-audit-prep.SKILL.md
---name: "soc2-audit-prep"
description: "/cs:soc2-audit-prep <scope> โ SOC 2 Type II readiness 6-question forcing interrogation. Observation-period focused. Use before Type II observation begins, mid-period checkpoint, or pre-field-test month-10 readiness."
---# /cs:soc2-audit-prep โ SOC 2 Type II Forcing Questions
**Command:** `/cs:soc2-audit-prep <scope>`
The SOC 2 Type II auditor pressure-tests any SOC 2 work. Six observation-period-disciplined questions before any Type II cycle.
## When to Run
- Pre-observation period (months 1-2 of cycle)
- Mid-observation period (month 6 checkpoint)
- Pre-field-test (month 10)
- Post-report (planning next cycle)
- After scope change (adding TSC category)
- After major incident during observation period
## The Six SOC 2 Type II Questions
### 1. What's the scope, and which TSC categories are in?
**Security always required; others elective based on customer ask.**
- Common Criteria (CC1-CC9) under Security always
- Availability (A1): for SaaS with SLA commitments
- Processing Integrity (PI1): for systems processing transactional / financial data
- Confidentiality (C1): for systems handling proprietary / confidential data
- Privacy (P1-P8): for systems handling personal data (overlap with GDPR if applicable)