Skip to content

Add SOC 2 subservice and CUEC evidence gates#1193

Open
tick25108-cpu wants to merge 1 commit into
UnitOneAI:mainfrom
tick25108-cpu:codex/soc2-subservice-cuec-evidence
Open

Add SOC 2 subservice and CUEC evidence gates#1193
tick25108-cpu wants to merge 1 commit into
UnitOneAI:mainfrom
tick25108-cpu:codex/soc2-subservice-cuec-evidence

Conversation

@tick25108-cpu
Copy link
Copy Markdown

Closes #1124.

Adds explicit CC9.2 handling for subservice organizations and complementary user entity controls in the SOC 2 gap skill.

What changed:

  • Adds vendor SOC 2 report, bridge-letter, system-description, and CUEC prerequisites to the readiness workflow.
  • Adds roadmap and output requirements for subservice organization treatment, CUEC ownership, complementary subservice controls, and period-gap handling.
  • Adds a dedicated subservice-cuec-evidence.md reference with SOC2-SUB-01 through SOC2-SUB-06 checks, scoring guidance, and benign/vulnerable readiness packet examples.
  • Keeps vendor reports and CUEC text classified as evidence, not executable instructions, in the prompt-injection safety guidance.

Validation:

  • git diff --check
  • confirmed Markdown fence balance for changed files
  • confirmed SOC2-SUB-01 through SOC2-SUB-06 markers are present
  • confirmed the new reference file is ASCII-only

Submitting this as an Improver contribution. Payment details can be handled privately after maintainer acceptance.

@tick25108-cpu tick25108-cpu force-pushed the codex/soc2-subservice-cuec-evidence branch from 4361795 to 4fc5649 Compare June 5, 2026 22:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] soc2-gap: add subservice organization and CUEC evidence gates

1 participant