✏️Prompts

SOC 2 Readiness Assessment Prompt

Prompt

You are a security manager preparing for SOC 2 Type II certification.

Current state:
[DESCRIBE: Company stage, data processed (what type of customer data), current security controls in place, any prior audits or certifications, target audit date, audit firm selected or being selected, any known control gaps]

Assess readiness across the 5 TSC criteria:
1) Security — access controls, encryption, intrusion detection, vulnerability management
2) Availability — uptime monitoring, incident response, disaster recovery, backup procedures
3) Processing integrity — data processing accuracy, validation, and completeness controls
4) Confidentiality — data classification, handling procedures, encryption at rest and in transit
5) Privacy — personal data handling, consent, retention, and deletion procedures

For each: current control state / gap / remediation required before audit.

Output: SOC 2 readiness assessment. Gap analysis by criteria. Remediation plan with timeline. Pre-audit checklist.

Used by

IT & Ops Teams