Scores existing tests and evidence against a named compliance framework's criteria list (GDPR, CCPA/CPRA, SOC 2 Trust Services Criteria, HIPAA Security Rule, PCI DSS, ISO/IEC 27001), marking every criterion met, partial, not met, or not applicable with a stated evidence requirement per state, and recording each scope exclusion with its criterion reference, reason, named approver, and re-review date. Produces a readiness self-assessment only: not certification, not an audit opinion, not legal advice. Use when a framework version has been named and an evidence set already exists, and someone needs a per-criterion readiness score before an observation period opens, before a qualified assessor arrives, or in response to a regulator inquiry.
80
100%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Companion to compliance-coverage-scoring/SKILL.md. Detail a scoring pass needs
occasionally, kept out of the spine so the body stays a lean overview.
The scoring pass produces a readiness self-assessment. Only the parties below can attest:
| Framework | Who attests | What the attestation is |
|---|---|---|
| SOC 2 | A CPA firm performing an examination under AICPA attestation standards (the illustrative type 2 report is written to meet SSAE-21 reporting requirements) | A report on controls over a defined scope and period. Not a pass/fail certificate, and there is no such thing as being "SOC 2 certified" |
| ISO/IEC 27001 | A certification body whose competence an accreditation body has independently confirmed (iso.org) | A certificate against a stated edition |
| PCI DSS | A Qualified Security Assessor: "independent security organizations that have been qualified and trained by PCI SSC to perform PCI DSS assessments" (pcisecuritystandards.org) | An assessment against a stated version |
| GDPR | A supervisory authority, on enforcement | No routine attestation exists |
| CCPA/CPRA | The California Privacy Protection Agency and the Attorney General; consumers have been able to file CCPA complaints with the agency since July 1, 2023 (oag.ca.gov) | No routine attestation exists |
Compliance wording carries legal weight, so the matrix should say only what is true: