Install any skill in seconds. Free to start, no credit card required.
Get Started Free →SOC 2 audit-prep playbook: the 4/8/12-week sprint to audit-ready for a Type I or Type II observation. Use when the audit is scheduled, when readiness assessment surfaced gaps and you need a sprint plan, or when evidence is missing or stale.
.claude/skills/borghei-soc2-audit-prep/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 73% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 58% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 61% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 76% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 74% | 0% |
Operational playbook for SOC 2 audit preparation. Designed to be picked up 4-12 weeks before an audit and run as a sprint to closure. Pairs with our deep ra-qm-team/soc2-compliance-expert skill (which builds the program from scratch).
When to use this skill vs. soc2-compliance-expert:
| Situation | Skill applies | |-----------|---------------| | SOC 2 audit scheduled, need readiness sprint | Yes — start here | | Type I audit in 4-12 weeks | Yes — use 4 or 8-week sprint plan | | Type II observation period closing soon | Yes — use 12-week sprint plan | | Readiness assessment surfaced gaps | Yes — scripts/soc2_readiness_score.py + evidence_gap_finder.py | | Building SOC 2 program from scratch | Use ra-qm-team/soc2-compliance-expert instead |
Week 1: Inventory + scoping
- Confirm Trust Services Criteria scope (always Security; plus chosen others)
- Pull current evidence per criterion
- Identify gaps via scripts/evidence_gap_finder.py
- Auditor kickoff scheduled
Week 2: Gap closure
- Policy updates / approvals
- Technical control fixes (MFA universal, logging coverage, etc.)
- Evidence retrieval (access reviews, change tickets, on-call records)
- Auditor information request preparation
Week 3: Evidence finalization
- All evidence packets compiled per criterion
- Walkthroughs / interviews scheduled with key control owners
- Findings remediation
- Pre-audit checkpoint with auditor (informal)
Week 4: Audit week
- Walkthroughs executed
- Sample testing
- Q&A
- Management responses to findingsWeeks 1-2: Inventory + scoping + gap identification (same as 4-week W1)
Weeks 3-5: Gap closure (policies, technical, process)
Weeks 6-7: Evidence finalization + walkthroughs
Week 8: Audit weekWeeks 1-2: Inventory + scope + gap identification + auditor kickoff
Weeks 3-4: Gap closure
Weeks 5-12: Observation period (controls operating; evidence accumulating)
After observation period: audit weekSee references/evidence-collection-sprint-plan.md for the detailed week-by-week plans.
Standard pre-audit punch list, organized by Trust Services Criterion:
See references/soc2-pre-audit-punch-list.md for the detailed punch list with evidence templates per item.
Before running the audit-prep sprint, confirm these inputs. If any is unknown or vague, ASK — do not assume:
Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the sprint plan.
python3 scripts/soc2_readiness_score.py --config controls.yamlpython3 scripts/evidence_gap_finder.py --evidence evidence.yaml --tsc CC6| Script | Purpose | |--------|---------| | scripts/soc2_readiness_score.py | Score current state (0-100) per TSC; identify pillars needing attention | | scripts/evidence_gap_finder.py | Cross-reference required evidence vs collected; output gap list with priorities |
ra-qm-team/soc2-compliance-expert — deep SOC 2 program management (multi-quarter)ra-qm-team/audit-prep/compliance-readiness — multi-framework readiness (SOC 2 + ISO 27001 + NIST)ra-qm-team/infrastructure-compliance-auditor — automated infra scanning for evidenceengineering/observability-designer — logging / monitoring evidence| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-05 | pass→pass | 22,639 | 18,495 | -18% | 1 | 1 | 0% | 3,652 | 4,934 | +35% | 0 | 0 | — |
case-06 | pass→pass | 22,614 | 28,517 | +26% | 1 | 1 | 0% | 3,680 | 7,789 | +112% | 0 | 0 | — |
case-01 | fail→pass | 21,109 | 24,461 | +16% | 1 | 1 | 0% | 3,456 | 5,964 | +73% | 0 | 0 | — |
case-02 | fail→pass | 25,976 | 27,630 | +6% | 1 | 1 | 0% | 4,107 | 6,476 | +58% | 0 | 0 | — |
case-03 | fail→pass | 19,492 | 16,175 | -17% | 1 | 1 | 0% | 2,708 | 4,368 | +61% | 0 | 0 | — |
case-04 | pass→pass | 23,473 | 22,626 | -4% | 1 | 1 | 0% | 3,654 | 5,494 | +50% | 0 | 0 | — |
case-07 | fail→pass | 13,989 | 10,825 | -23% | 1 | 1 | 0% | 2,076 | 3,650 | +76% | 0 | 0 | — |
case-08 | pass→pass | 16,053 | 9,896 | -38% | 1 | 1 | 0% | 2,379 | 3,369 | +42% | 0 | 0 | — |
case-09 | fail→pass | 14,208 | 10,980 | -23% | 1 | 1 | 0% | 2,142 | 3,736 | +74% | 0 | 0 | — |
case-10 | fail→pass | 14,690 | 11,910 | -19% | 1 | 1 | 0% | 2,215 | 3,770 | +70% | 0 | 0 | — |
case-11 | fail→fail | 14,517 | 10,844 | -25% | 1 | 1 | 0% | 2,199 | 3,652 | +66% | 0 | 0 | — |
case-12 | pass→pass | 12,371 | 10,454 | -15% | 1 | 1 | 0% | 1,776 | 3,487 | +96% | 0 | 0 | — |
case-13 | fail→fail | 11,253 | 8,449 | -25% | 1 | 1 | 0% | 1,657 | 3,481 | +110% | 0 | 0 | — |
case-14 | pass→pass | 16,400 | 11,922 | -27% | 1 | 1 | 0% | 2,346 | 3,582 | +53% | 0 | 0 | — |
case-15 | pass→pass | 13,588 | 11,879 | -13% | 1 | 1 | 0% | 2,009 | 3,880 | +93% | 0 | 0 | — |
case-16 | pass→pass | 11,533 | 7,338 | -36% | 1 | 1 | 0% | 1,798 | 3,034 | +69% | 0 | 0 | — |
case-17 | pass→pass | 10,561 | 8,782 | -17% | 1 | 1 | 0% | 1,600 | 3,320 | +108% | 0 | 0 | — |
case-18 | pass→pass | 17,097 | 12,874 | -25% | 1 | 1 | 0% | 2,343 | 3,760 | +60% | 0 | 0 | — |
case-19 | fail→pass | 9,456 | 3,197 | -66% | 1 | 1 | 0% | 1,465 | 2,572 | +76% | 0 | 0 | — |
case-20 | pass→pass | 14,930 | 11,963 | -20% | 1 | 1 | 0% | 2,231 | 3,733 | +67% | 0 | 0 | — |
case-21 | pass→pass | 4,393 | 4,039 | -8% | 1 | 1 | 0% | 664 | 2,599 | +291% | 0 | 0 | — |
case-22 | fail→pass | 11,048 | 10,784 | -2% | 1 | 1 | 0% | 1,654 | 3,684 | +123% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +36 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.