Install any skill in seconds. Free to start, no credit card required.
Get Started Free →/cs:soc2-audit-prep <scope> — SOC 2 Type II readiness 6-question forcing interrogation. Observation-period focused. Use before Type II observation begins, mid-period checkpoint, or pre-field-test month-10 readiness.
.claude/skills/alirezarezvani-soc2-audit-prep/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-04 | ✗→✓ | ▲ Improved | 284% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 63% | 0% |
| case-08 | ✗→✓ | ▲ Improved | 72% | 0% |
| case-09 | ✗→✓ | ▲ Improved | -40% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 106% | 0% |
Command: /cs:soc2-audit-prep <scope>
The SOC 2 Type II auditor pressure-tests any SOC 2 work. Six observation-period-disciplined questions before any Type II cycle.
Security always required; others elective based on customer ask.
Type II requires consistent operation — single skipped cycle = likely exception.
Mid-period changes = high audit risk.
Real-time exception logging — not retroactive.
Not the last week — the first month.
75% control overlap — the canonical pair.
cross_framework_mapper.py for HIGH-confidence overlap themesbash# 1. Scoping + gap analysis (pre-observation) python ra-qm-team/skills/soc2-compliance/scripts/gap_analyzer.py current_state.json # 2. Control matrix with ISO 27001 cross-walk python ra-qm-team/skills/soc2-compliance/scripts/control_matrix_builder.py program.json # 3. Continuous evidence tracking (during observation) python ra-qm-team/skills/soc2-compliance/scripts/evidence_tracker.py evidence_log.json # 4. Mock audit (pre-field-test month 10) python ../../skills/compliance-os/scripts/audit_simulator.py soc2_scope.json
markdown# SOC 2 Type II Audit Prep: <scope> **Date:** YYYY-MM-DD **Observation Period:** YYYY-MM-DD to YYYY-MM-DD ## The Decision Being Made [scoping | pre-observation | observation-status | pre-field | report-response] ## TSC Scope - Security: included - Availability: <yes/no> - Processing Integrity: <yes/no> - Confidentiality: <yes/no> - Privacy: <yes/no> ## Observation Period Status - Months elapsed: N / 12 - Controls operated consistently: % of total - Cycle skips identified: <list> - Mid-period control changes: N (each documented with change-mgmt: yes/no) ## Exception Log - Total exceptions logged: N - Per-control max exceptions: M (audit firm tolerance: typically 1-2) - Material exceptions (overall control affected): <list> - Remediation status per exception: complete/in-progress ## Sample Evidence Coverage - Month 1-3 evidence: complete/gaps - Month 4-6 evidence: complete/gaps - Month 7-9 evidence: complete/gaps - Month 10-12 evidence: complete/gaps (only for pre-report status) ## ISO 27001 Cross-Walk Reuse - HIGH-confidence overlap themes: N - Shared artefacts in evidence pool: <count> - Duplicate evidence collection avoided: % savings ## Audit Firm Readiness - Scoping discussion: complete/pending - Description of system per AT-C 205: complete/pending - Walkthrough rehearsal: complete/pending - Sample preparation: complete/pending ## Verdict 🟢 ON-TRACK | 🟡 NEEDS-ATTENTION | 🔴 MATERIAL-RISK ## Top 3 Actions [3 concrete next steps with owner + observation-period timing]
/cs:compliance-readiness — for multi-framework view/cs:iso27001-audit-prep — for ISO 27001 cross-walk pair (75% overlap)/cs:gdpr-audit-prep — for Privacy TSC overlap/cs:ciso-review — for executive cybersecurity strategycs-soc2-auditorsoc2-compliance../iso27001-audit-prep/, ../gdpr-audit-prep/, ../compliance-readiness/Version: 1.0.0
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | pass→pass | 18,613 | 15,924 | -14% | 1 | 1 | 0% | 3,482 | 4,497 | +29% | 0 | 0 | — |
case-02 | pass→pass | 31,876 | 21,001 | -34% | 1 | 1 | 0% | 5,739 | 5,327 | -7% | 0 | 0 | — |
case-03 | pass→pass | 34,019 | 25,675 | -25% | 1 | 1 | 0% | 6,179 | 6,157 | -0% | 0 | 0 | — |
case-04 | fail→pass | 6,760 | 14,149 | +109% | 1 | 1 | 0% | 1,062 | 4,074 | +284% | 0 | 0 | — |
case-05 | pass→pass | 12,531 | 12,791 | +2% | 1 | 1 | 0% | 1,967 | 3,559 | +81% | 0 | 0 | — |
case-06 | fail→fail | 14,048 | 15,924 | +13% | 1 | 1 | 0% | 2,315 | 4,233 | +83% | 0 | 0 | — |
case-07 | fail→pass | 14,708 | 13,771 | -6% | 1 | 1 | 0% | 2,329 | 3,785 | +63% | 0 | 0 | — |
case-08 | fail→pass | 11,786 | 11,554 | -2% | 1 | 1 | 0% | 1,945 | 3,349 | +72% | 0 | 0 | — |
case-09 | fail→pass | 18,211 | 3,723 | -80% | 1 | 1 | 0% | 3,714 | 2,232 | -40% | 0 | 0 | — |
case-10 | fail→pass | 7,554 | 7,673 | +2% | 1 | 1 | 0% | 1,395 | 2,872 | +106% | 0 | 0 | — |
case-11 | fail→pass | 15,711 | 3,037 | -81% | 1 | 1 | 0% | 924 | 2,073 | +124% | 0 | 0 | — |
case-12 | fail→pass | 19,123 | 2,614 | -86% | 1 | 1 | 0% | 944 | 2,076 | +120% | 0 | 0 | — |
case-13 | fail→pass | 6,357 | 2,787 | -56% | 1 | 1 | 0% | 1,133 | 2,025 | +79% | 0 | 0 | — |
case-14 | fail→pass | 16,479 | 2,936 | -82% | 1 | 1 | 0% | 1,024 | 2,164 | +111% | 0 | 0 | — |
case-15 | fail→pass | 9,756 | 5,165 | -47% | 1 | 1 | 0% | 1,564 | 2,492 | +59% | 0 | 0 | — |
case-16 | fail→pass | 9,416 | 3,379 | -64% | 1 | 1 | 0% | 1,576 | 2,137 | +36% | 0 | 0 | — |
case-17 | fail→pass | 9,349 | 5,609 | -40% | 1 | 1 | 0% | 1,542 | 2,533 | +64% | 0 | 0 | — |
case-18 | fail→pass | 9,979 | 3,080 | -69% | 1 | 1 | 0% | 1,712 | 2,115 | +24% | 0 | 0 | — |
case-19 | fail→fail | 26,705 | 25,291 | -5% | 1 | 1 | 0% | 4,828 | 6,604 | +37% | 0 | 0 | — |
case-20 | pass→pass | 19,822 | 13,416 | -32% | 1 | 1 | 0% | 3,628 | 3,844 | +6% | 0 | 0 | — |
case-21 | fail→fail | 19,636 | 23,115 | +18% | 1 | 1 | 0% | 3,541 | 5,305 | +50% | 0 | 0 | — |
case-22 | fail→pass | 12,189 | 14,698 | +21% | 1 | 1 | 0% | 1,914 | 4,205 | +120% | 0 | 0 | — |
case-23 | fail→pass | 6,125 | 1,448 | -76% | 1 | 1 | 0% | 1,067 | 1,806 | +69% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted, and 20 counted toward the lift figure. The other 3 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +65 percentage points is the difference between those two pass rates over the 20 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.