Install
openclaw skills install afrexai-soc2-complianceGuides organizations through SOC 2 compliance lifecycle with gap analysis, control implementation, evidence collection, audit prep, and continuous monitoring.
openclaw skills install afrexai-soc2-complianceYour agent for achieving and maintaining SOC 2 Type I and Type II compliance — from readiness assessment through audit completion.
Guides organizations through the full SOC 2 lifecycle: gap analysis, control implementation, evidence collection, audit prep, and continuous monitoring. Covers all 5 Trust Service Criteria with practical implementation steps.
Tell your agent what stage you're at:
System Description Checklist:
□ Infrastructure components (cloud, on-prem, hybrid)
□ Software stack (applications, databases, middleware)
□ People (roles, responsibilities, third parties)
□ Procedures (operational, security, change management)
□ Data flows (ingress, processing, storage, egress)
□ Trust Service Criteria selection (Security + which optional?)
□ Subservice organizations (cloud providers, SaaS tools)
□ Carve-out vs inclusive method for subservice orgs
Score each control area 1-5:
Priority Matrix:
| Gap Score | Action | Timeline |
|---|---|---|
| 1-2 | Critical — implement immediately | 2-4 weeks |
| 3 | Important — formalize and document | 1-2 weeks |
| 4 | Minor — fill evidence gaps | 3-5 days |
| 5 | Maintain — continue monitoring | Ongoing |
For each gap:
1. Assign control owner (by name, not role)
2. Define implementation steps
3. Set evidence collection method (automated preferred)
4. Establish testing cadence
5. Document exception handling process
| Control | Evidence Source | Tool Examples |
|---|---|---|
| Access Reviews | IAM exports | Okta, Azure AD, AWS IAM |
| Encryption | Config snapshots | AWS Config, CloudTrail |
| Logging | Log aggregation | Datadog, Splunk, ELK |
| Vulnerability Scans | Scan reports | Qualys, Nessus, Snyk |
| Change Management | PR/deploy history | GitHub, GitLab, Jira |
| Uptime | Monitoring dashboards | Datadog, PagerDuty |
| Control | Evidence Type | Frequency |
|---|---|---|
| Background Checks | HR records | Per hire |
| Security Training | Completion certificates | Annual |
| Risk Assessment | Assessment document | Annual |
| Pen Testing | Report | Annual |
| DR Testing | Test results | Semi-annual |
| Board/Mgmt Review | Meeting minutes | Quarterly |
| Vendor Reviews | Assessment records | Annual |
| Policy Reviews | Version history | Annual |
Week 1-2: Auditor selection + engagement letter
Week 2-4: System description draft
Week 4-6: Control documentation + evidence prep
Week 6-8: Fieldwork (auditor testing)
Week 8-10: Draft report review
Week 10-12: Final report issued
Month 1: Observation period begins (minimum 3 months, recommend 6-12)
Ongoing: Evidence collection, control operation
Month 3-12: Observation period ends
+Week 1-2: Fieldwork scheduling
+Week 2-4: Fieldwork (testing over observation period)
+Week 4-6: Draft report + final report
| Company Size | Type I | Type II | Annual Maintenance |
|---|---|---|---|
| Startup (<50) | $20K-$50K | $30K-$80K | $15K-$40K |
| Mid-Market (50-500) | $40K-$100K | $60K-$150K | $30K-$80K |
| Enterprise (500+) | $80K-$200K | $120K-$300K | $60K-$150K |
Includes: auditor fees, tooling, personnel time, remediation costs.
Hidden costs to budget:
When deploying AI agents in SOC 2 environments:
| Industry | Extra Criteria | Key Controls |
|---|---|---|
| Fintech | All 5 TSC typical | SOX mapping, encryption everywhere, PCI if payments |
| Healthcare | Privacy, Confidentiality | HIPAA crosswalk, BAAs, PHI handling |
| SaaS | Availability, Confidentiality | Multi-tenant isolation, SLA compliance |
| Legal | Confidentiality, Privacy | Privilege protection, matter isolation |
| Construction | Security, Availability | Field data protection, offline capability |
| E-commerce | All 5 TSC typical | PCI DSS alignment, transaction integrity |
This skill gives you the framework. For industry-specific compliance playbooks with regulatory crosswalks, cost models, and vendor selection guides:
🔗 AfrexAI Context Packs — $47 per industry vertical
Available packs: Fintech, Healthcare, Legal, Construction, E-commerce, SaaS, Real Estate, Recruitment, Manufacturing, Professional Services
🔗 AI Revenue Leak Calculator — Find where compliance gaps cost you money
🔗 Agent Setup Wizard — Deploy compliance monitoring agents in minutes
Bundle pricing: