Skip to content

[REVIEW] soc2-gap: add critical vendor concentration and exit evidence gates #2239

@malb200710-dev

Description

@malb200710-dev

Review target

skills/compliance/soc2-gap

Gap

The SOC 2 gap skill covers vendor inventory and SOC report collection under CC9.2, but it does not require evidence for vendor concentration risk, exit readiness, portability tests, or subservice dependency monitoring for critical vendors.

Why this matters

For SOC 2 readiness, third-party risk is not only about collecting annual SOC reports. A critical vendor can create audit and operational risk when:

  • multiple in-scope services depend on the same provider or region;
  • customer commitments rely on a sole-source vendor;
  • customer data cannot be exported or restored elsewhere;
  • termination/deletion procedures are not tested;
  • subservice organizations change without review;
  • there is no owner, cadence, or risk acceptance for unresolved concentration risk.

Proposed evidence gates

Add CC9.2 evidence for:

  • critical vendor tiering;
  • concentration analysis;
  • exit plan and fallback procedure;
  • portability/export/restore test evidence;
  • subservice dependency review;
  • owner, review frequency, trigger events, and risk acceptance.

Also add a Critical Vendor Exit Matrix deliverable to the SOC 2 output.

Bounty request

Reviewer tier ($25) if this review is accepted. I can provide payment details if accepted.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions