soc2 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited soc2 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Disclaimer: this skill supports preparation for a SOC 2 examination but does not replace an AICPA-licensed auditor. Only a licensed CPA firm can issue a SOC 2 report. This skill helps with pre-audit readiness.
SOC 2 (System and Organization Controls 2) is an AICPA framework for service organizations that demonstrates that controls around Security and related Trust Services Criteria are effective. Popular in B2B SaaS because US customers (and increasingly EU customers) put it as a contractual requirement.
Triggers on:
iso27001 for a dual-attestation strategy.iso27001.risk-register.policy-drafter.audit-evidence.Six phases. Phase 1 (TSC selection) sets the scope of the entire audit; phase 4 (evidence rhythm) is where most Type II projects fall down.
AICPA's Trust Services Criteria (TSC) have five categories. One is required, four are optional.
Selection guidance:
Scope description: which product/service, which infrastructure, which data flows, which locations, which sub-service providers (cloud providers, payment processors, data centers). Sub-service providers require either a carve-out (their controls are not in your report) or inclusive (they are).
Strategy pattern: Type I after 3–6 months of implementation to clear initial contract gates, then immediately start the observation period for Type II in year 2. After year 2, a Type II every year.
Common Criteria (2017, updated to 2022) for Security:
Each CC has sub-criteria (e.g. CC6.1, CC6.2, ...). Recommended: download the AICPA Trust Services Criteria document for the full tree.
Additional categories add their own criteria on top of the CC base: Availability (A1.1–A1.3), Confidentiality (C1.1–C1.2), Processing Integrity (PI1.1–PI1.5), Privacy (P1.1–P8.1).
Per criterion, name a control (how you address it), plus evidence (proof the control works).
Type II stands or falls on operating-effectiveness evidence. This is where teams fail during the observation period (often without noticing).
Evidence types:
Evidence cadence per control type:
Discipline: during the observation period, centralize evidence in a repository the auditor can reach. Do not wait for audit week to gather it. Compliance platforms (Vanta, Drata, Secureframe, Anecdotes, SafeBase) automate a large part of this — consider for Type II efficiency.
Per control, an evidence description that says: what, where, who produces, how often, where stored.
Report distribution: SOC 2 Type II reports are confidential. Share with customers under NDA. For public sharing: SOC 3 is the redacted variant.
Complementary User Entity Controls (CUECs): controls your customers are responsible for (e.g. "the customer is responsible for password management of end-users within their tenant"). These appear explicitly in the report. Customers look at this to know what their side is.
Layer 1: TSC choice locked down with rationale?, all selected CCs/additional criteria address a control with an owner?, evidence repository present and populated over the entire period?, CUECs communicated to customers?. Layer 2: AICPA Trust Services Criteria naming correct, [verify] markers on CC numbering because criteria updates appear, overlap claims with ISO 27001 supported by cross-walks (not improvised), auditor-firm claims not delivered as a recommendation without qualification.
Continuous compliance: Type II is an annual cycle. The observation period does not stop before your next period starts — the evidence keeps running. Platforms automate this; without a platform it is a full-time job for at least one compliance lead in a mid-size org.
SOC 2 readiness — <service/product>
Auditor: <firm, if engaged> | Type: <I | II> | Period: <dates>
TSC selection:
Security (CC1-9): required — status per CC: ...
Availability: <yes/no>, rationale
Confidentiality: <yes/no>, rationale
Processing Integrity: <yes/no>, rationale
Privacy: <yes/no>, rationale
Scope:
Product(s): <...>
Infrastructure: <cloud provider(s) + regions>
Sub-service providers: <list + carve-out/inclusive>
Geographic: <...>
Common Criteria coverage:
CC1 Control Environment: <N/X controls, evidence status>
CC2 Communication: ...
CC3 Risk Assessment: ...
CC4 Monitoring: ...
CC5 Control Activities: ...
CC6 Access Controls: ...
CC7 System Operations: ...
CC8 Change Management: ...
CC9 Risk Mitigation: ...
Evidence status:
Centralised repo: <platform | manual | gap>
Cadence compliance: <daily/weekly/monthly/quarterly streams>
Gaps in observation period: <list>
Pre-audit readiness:
Pre-audit walkthrough: <date | planned | gap>
Interim review planned: <yes/no>
Identified findings: <list + remediation status>
CUECs for customers:
Formulated: <yes/no>
Communicated: <how>
Priorities:
<fix-now/fix-sprint/fix-quarter>
Verification-loop: ...~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.