Maps engineering controls to SOC 2 Trust Service Criteria, builds a continuous evidence-collection plan with cadences per control family, and produces the control-to-evidence table auditors work from. Use when someone asks "what evidence do we need for SOC 2", "map our controls to the Trust Service Criteria", "how do we prepare for Type II fieldwork", "the auditor asked for access reviews", or is closing findings or standing up a compliance program. Do NOT use for building an incident postmortem - use postmortem-writer instead; do NOT use for finding and prioritizing actual vulnerabilities - use vulnerability-triage instead; this skill organizes proof that controls operate, it does not implement the controls.
Click to play with sound.
---
name: SOC 2 Evidence Helper
description: Maps engineering controls to SOC 2 Trust Service Criteria, builds a continuous evidence-collection plan with cadences per control family, and produces the control-to-evidence table auditors work from. Use when someone asks "what evidence do we need for SOC 2", "map our controls to the Trust Service Criteria", "how do we prepare for Type II fieldwork", "the auditor asked for access reviews", or is closing findings or standing up a compliance program. Do NOT use for building an incident postmortem - use postmortem-writer instead; do NOT use for finding and prioritizing actual vulnerabilities - use vulnerability-triage instead; this skill organizes proof that controls operate, it does not implement the controls.
---
# SOC 2 Evidence Helper
SOC 2 audits test whether security controls exist (Type I, point in time) and operate consistently over a review period (Type II, typically 3-12 months). Engineering teams lose the most time gathering evidence reactively in the month before fieldwork - and for Type II that scramble cannot work, because auditors sample from the whole period and a gap in month two is already a finding. Build collection into normal operations instead.
## Operating procedure
### Step 1: Gather inputs
- Type I or Type II, and the review period dates. Default assumption: first audit is Type I, followed by a 6-month Type II.
- Which Trust Service Criteria are in scope (Security is mandatory; the rest are contract-driven). If unknown, check customer contracts and security questionnaires - scope only what customers demand.
- The systems of record: IdP (Okta, Entra), source control, CI, cloud provider, ticketing, HR system, vulnerability scanner.
- Any prior findings or bridge letters. Label unknowns as unknowns.
### Step 2: Scope the criteria before collecting anything
Auditors only test criteria in scope:
- Security (CC - required): logical access, change management, risk assessment, incident response, monitoring.
- Availability (A): uptime commitments, capacity planning, backup and recovery.
- Processing Integrity (PI): complete and accurate processing, error handling.
- Confidentiality (C): data classification, encryption in transit and at rest, NDA controls.… load the full skill through Skill Me