Studio Edition

SOC 2 Readiness Kit

Scope, gap-assess and prepare for a SOC 2 audit with policies, controls and a plan

$399.00

SOC 2 Readiness Kit gives your agent a structured way to prepare a company for its first (or next) SOC 2 examination. It is built for founders, CTOs and the first security or compliance hire at a SaaS company who have been asked for a SOC 2 report and need to get ready without a consultant on every step.

How it works

The agent starts from what your customers actually asked for, then recommends a report type (Type I or Type II), Trust Services Criteria categories, system boundary, carve-out vendors and dates, and writes a scope memo with open questions for your auditor. It interviews you domain by domain against a 76-control matrix, fills a gap-assessment sheet, and runs a small Python script that scores it into a P1/P2/P3 remediation plan with readiness by criteria series. It then tailors policy templates to how your team really works, sets up evidence collection, and helps you pick an auditor and run audit week.

What you get

  • Readiness questionnaire with a shared policy-parameters table
  • Controls matrix (CSV) mapped to 2017 TSC CC1-CC9, A1 and C1 identifiers, marked for verification against the current AICPA TSC
  • Gap-assessment sheet and a stdlib Python scoring script (no packages)
  • 12 policy templates, from information security to logging and monitoring
  • Scoping guide, gap workflow, evidence checklist, auditor-selection and audit-week guide
  • Two worked examples for a fictional SaaS company

Important: this kit helps you prepare. It is not audit, legal or accounting advice and does not make a company compliant or certified. Only a licensed CPA firm can examine your controls and issue a SOC 2 report.

Highlights

  • 76-control matrix mapped to 2017 TSC CC1-CC9, A1 and C1 identifiers
  • 12 policy templates with one shared set of parameters
  • Gap-scoring script turns your assessment into a P1/P2/P3 plan
  • Scoping guide: Type I vs II, criteria, boundary, carve-out vendors
  • Evidence checklist, auditor selection and audit-week runbook

Example

Type I or Type II?
You

Our first enterprise deal needs SOC 2 by March. We have MFA and code review but nothing written down. Should we do Type 1 or Type 2?

Agent + skill
> Readiness support only - not audit, legal or accounting advice. Only a licensed CPA firm can examine your controls and issue a SOC 2 report.

Recommendation: Type I as of mid-January, then a Type II period starting the same day.

Why: MFA and code review are real, but with no written policies, no access-request records and no offboarding trail, a Type II period starting now would collect exceptions from day one. A Type I tests design at a point in time, so it fits a March deadline once P1 gaps are closed.

Before committing, ask the customer in writing:
1. Will they sign on a Type I plus a signed Type II engagement letter?
2. Which categories do they need? Their questionnaire mentions uptime, so Availability is likely; Confidentiality only if they ask.
3. By when do they need the Type II report?

Next: a 45-minute gap assessment against the controls matrix, then policies 01 and 02 this week.
Gap assessment to plan
You

Here's our filled gap sheet. We're doing Security and Availability. Score it and tell me what to fix first.

Agent + skill
# SOC 2 remediation plan
Categories: Security, Availability | Controls scored: 74 (N/A: 1, out of scope: 1)

- Weighted readiness: 34%
- P1: 19 | P2: 28 | P3: 22 | Not assessed: 1 | Ready: 4

| # | Control | Current state | Wt | Effort | Owner | Target |
| 1 | AC-03 Access provisioning approval (CC6.2) | not implemented; not documented; no evidence | 3 | S | Marco (Eng) | 2026-10-31 |
| 3 | GOV-01 Security policy approval (CC1.1; CC2.2; CC5.3) | not implemented; not documented; no evidence | 3 | S | Priya (CTO) | 2026-10-31 |
| 15 | AC-02 Multi-factor authentication (CC6.1) | partially implemented; not documented; some evidence | 3 | S | Marco (Eng) | 2026-10-24 |

Fix this month: enforce MFA on the remaining AWS IAM users and turn on branch protection on the 3 unprotected repos (by Oct 24); approve policies 01 and 02 (Oct 31); move access requests from Slack to a ticket form with an approver field.
Flag: IR-03 and BCP-04 targets fall after the Type I date - fine only if the plans are approved by then; confirm with the auditor.
Tailor a policy
You

Write our access control policy. We use Google SSO, 1Password, Rippling for HR, and we disable accounts within a day when someone leaves.

Agent + skill
## 8. Changes and removal
1. HR (or the hiring manager for contractors) notifies the CTO of a termination on or before the last working day, through the offboarding checklist in Rippling.
2. All access is removed within 1 business day of the end of employment or contract. Involuntary terminations are actioned at the time of notice.
3. When someone changes role, access no longer needed is removed within 5 business days.

---
Open placeholders: {{INACTIVE_ACCOUNT_DAYS}} (section 8.4), {{SUPPORT_ACCESS_MECHANISM}} (section 12).
Depends on remediation: AC-03 (ticket-based access requests, due Oct 31) and AC-06 (offboarding timestamps). Until those run, sections 5 and 8 describe target practice - keep their dates before the audit period starts.
Next: approval by the CEO, then acknowledgment by all staff (evidence for GOV-05).

What's inside

soc2-readiness-kit/
├── agents/
│   └── openai.yaml
├── examples/
│   ├── worked-example-01-scoping-a-seed-stage-saas.md
│   └── worked-example-02-gap-assessment-to-plan.md
├── references/
│   ├── auditor-selection-and-audit-week.md
│   ├── gap-assessment-workflow.md
│   └── scoping-guide.md
├── scripts/
│   └── gap_score.py
├── templates/
│   ├── policies/
│   │   ├── 01-information-security-policy.md
│   │   ├── 02-access-control-policy.md
│   │   ├── 03-change-management-policy.md
│   │   ├── 04-incident-response-plan.md
│   │   ├── 05-vendor-management-policy.md
│   │   ├── 06-business-continuity-disaster-recovery-plan.md
│   │   ├── 07-data-classification-retention-policy.md
│   │   ├── 08-acceptable-use-policy.md
│   │   ├── 09-risk-assessment-policy.md
│   │   ├── 10-encryption-key-management-policy.md
│   │   ├── 11-hr-security-policy.md
│   │   └── 12-logging-monitoring-policy.md
│   ├── 01-readiness-questionnaire.md
│   ├── 02-controls-matrix.csv
│   ├── 03-gap-assessment.csv
│   └── 04-evidence-collection-checklist.md
├── LICENSE.txt
├── README.md
└── SKILL.md

Install by unzipping into your agent's skills folder. Install guide →