Install any skill in seconds. Free to start, no credit card required.
Get Started Free →When the user needs to prepare for SOC 2, build a compliance roadmap, assess security posture, quantify security risk, or says "we need SOC 2", "security audit", "compliance", "enterprise customer wants SOC 2", "CISO advice".
.claude/skills/mkurman-soc2-prep/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 14% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 51% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 37% | 0% |
| case-05 | ✗→✓ | ▲ Improved | 65% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 17% | 0% |
----|--------|--------| | Risk | ALE coverage (mitigated / total) | > 80% | | Detection | Mean Time to Detect (MTTD) | < 24 hours | | Response | Mean Time to Respond (MTTR) | < 4 hours | | Compliance | Controls passing audit | > 95% | | Hygiene | Critical patches within SLA | > 99% | | Access | Privileged accounts reviewed quarterly | 100% | | Vendor | Tier 1 vendors assessed annually | 100% | | Training | Phishing simulation click rate | < 5% |
Security (Common Criteria -- always in scope): CC1-CC2 (control environment, communication), CC3 (risk assessment), CC4-CC5 (monitoring, control activities), CC6 (logical/physical access, encryption), CC7-CC8 (system ops, vulnerability mgmt, incident response, change mgmt), CC9 (vendor management, business continuity).
Optional: Availability (A1), Processing Integrity (PI1), Confidentiality (C1), Privacy (P1-P8).
Information Security, Access Control (MFA, least privilege, access reviews), Change Management (code review, rollback), Incident Response (detection through post-mortem), Risk Assessment (annual, with register), Vendor Management, Data Classification, Business Continuity/DR (RTO/RPO, backup testing), Acceptable Use, HR Security (background checks, onboarding/offboarding).
| Tier | Data Access | Assessment Level | |------|------------|-----------------| | Tier 1 | PII/PHI access | Full assessment annually | | Tier 2 | Business data | Questionnaire + review | | Tier 3 | No sensitive data | Self-attestation |
Type I vs Type II: Type I examines control design at a point in time (3-6 months, good for closing the first enterprise deal). Type II examines control operation over 3-12 months (what sophisticated buyers want, plan 12 months total). Start Type I immediately; begin Type II observation once controls are in place.
Right-Sizing by Stage: Seed (5-15): foundational controls, automation-heavy, concise policies, one part-time owner. Series A (15-50): dedicated compliance owner or fractional CISO, formal access reviews. Series B+ (50+): full-time security team, internal audit, GRC platform.
Cost-Effective Tooling: Compliance automation (Vanta, Drata, Secureframe — significantly reduces manual effort), SSO (Google Workspace or Okta), MDM (Kandji or Jamf), monitoring (Datadog, PagerDuty), vulnerability scanning (Dependabot, Snyk, Trivy).
All findings tagged before reaching decision-makers: Verified (confirmed against evidence), Medium (reported but not independently verified), Assumed (inferred, needs validation).
privacy-policy — SOC 2 Privacy criteria (P1-P8) align directly with privacy policy commitments. Ensure consistency.security-review — Technical security controls from security-review map to SOC 2 Common Criteria (CC6, CC7, CC8). Use findings to inform gap analysis.User: "A prospect wants SOC 2 before signing a $200K contract. We have nothing."
Good output excerpt: > Business case: This $200K deal justifies a $30-50K compliance investment. At your stage, every enterprise deal blocked by missing SOC 2 has an opportunity cost. > > | Area | Status | Key Gaps | > |------|--------|----------| > | Access Control | Partial | MFA not enforced on AWS root, no SSO, no formal reviews | > | Change Management | Partial | GitHub PRs used but no documented policy | > | Incident Response | Missing | No documented plan, no on-call rotation | > | Risk Assessment | Missing | No formal risk assessment conducted | > > Recommended approach: Type I in 3 months, then begin Type II observation. > Immediate actions: (1) Sign up for compliance automation. (2) Enforce MFA everywhere. (3) Select an auditor with startup experience. > Interim response to prospect: Share security questionnaire response, SOC 2 Type I commitment timeline, and a signed mutual NDA with security addendum.
User: "We already use Okta for SSO and do code reviews. Where are we relative to SOC 2?"
Good output excerpt: > Gap Analysis Summary: 55% ready > > Compliant: CC6.1 Okta SSO with MFA, CC8.1 code reviews via PRs. > Partial: CC6.2 no quarterly access reviews documented, CC7.2 IRP never tested, CC6.3 no formal offboarding checklist. > Missing: CC3.1 no annual risk assessment, CC2.1 no security training, CC9.2 no vendor management, CC4.1 no control monitoring, all 10 required policies need drafting.
Disclaimer: This skill provides SOC 2 preparation guidance for planning purposes only. It does not constitute legal, audit, or professional compliance advice. SOC 2 reports can only be issued by a licensed CPA firm. Engage a qualified auditor to confirm readiness before scheduling an audit.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 32,240 | 28,326 | -12% | 1 | 1 | 0% | 5,340 | 6,102 | +14% | 0 | 0 | — |
case-02 | fail→pass | 30,051 | 34,355 | +14% | 1 | 1 | 0% | 4,757 | 7,206 | +51% | 0 | 0 | — |
case-03 | fail→pass | 22,395 | 22,110 | -1% | 1 | 1 | 0% | 3,624 | 4,974 | +37% | 0 | 0 | — |
case-04 | pass→pass | 17,150 | 12,952 | -24% | 1 | 1 | 0% | 2,883 | 3,544 | +23% | 0 | 0 | — |
case-05 | fail→pass | 14,358 | 14,499 | +1% | 1 | 1 | 0% | 2,189 | 3,620 | +65% | 0 | 0 | — |
case-15 | pass→pass | 3,350 | 6,406 | +91% | 1 | 1 | 0% | 567 | 2,422 | +327% | 0 | 0 | — |
case-06 | fail→pass | 15,521 | 9,152 | -41% | 1 | 1 | 0% | 2,410 | 2,818 | +17% | 0 | 0 | — |
case-07 | pass→pass | 14,067 | 14,152 | +1% | 1 | 1 | 0% | 2,064 | 3,590 | +74% | 0 | 0 | — |
case-08 | pass→pass | 14,093 | 16,931 | +20% | 1 | 1 | 0% | 2,115 | 3,985 | +88% | 0 | 0 | — |
case-09 | pass→pass | 17,510 | 17,739 | +1% | 1 | 1 | 0% | 2,688 | 4,311 | +60% | 0 | 0 | — |
case-10 | pass→pass | 14,068 | 12,821 | -9% | 1 | 1 | 0% | 2,262 | 3,489 | +54% | 0 | 0 | — |
case-11 | fail→pass | 15,404 | 13,355 | -13% | 1 | 1 | 0% | 2,330 | 3,431 | +47% | 0 | 0 | — |
case-12 | pass→pass | 14,148 | 15,078 | +7% | 1 | 1 | 0% | 2,093 | 3,663 | +75% | 0 | 0 | — |
case-13 | fail→pass | 13,067 | 9,468 | -28% | 1 | 1 | 0% | 2,180 | 2,954 | +36% | 0 | 0 | — |
case-14 | fail→pass | 6,724 | 15,056 | +124% | 1 | 1 | 0% | 1,066 | 3,735 | +250% | 0 | 0 | — |
case-16 | pass→pass | 15,776 | 14,794 | -6% | 1 | 1 | 0% | 2,367 | 3,781 | +60% | 0 | 0 | — |
case-17 | pass→pass | 16,327 | 17,171 | +5% | 1 | 1 | 0% | 2,540 | 4,045 | +59% | 0 | 0 | — |
case-18 | pass→pass | 13,995 | 11,069 | -21% | 1 | 1 | 0% | 2,181 | 3,068 | +41% | 0 | 0 | — |
case-19 | pass→pass | 12,960 | 12,281 | -5% | 1 | 1 | 0% | 1,983 | 3,265 | +65% | 0 | 0 | — |
case-20 | pass→pass | 6,773 | 10,836 | +60% | 1 | 1 | 0% | 962 | 3,170 | +230% | 0 | 0 | — |
case-21 | pass→pass | 25,881 | 19,080 | -26% | 1 | 1 | 0% | 4,085 | 4,418 | +8% | 0 | 0 | — |
case-22 | pass→pass | 27,976 | 25,397 | -9% | 1 | 1 | 0% | 4,899 | 5,798 | +18% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +36 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.