Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Audit & Certification

SOC 3

Also known as: SOC 3, SOC 3 report, SOC for Service Organizations: Trust Services Criteria for General Use Report
Simply put

SOC 3 is a type of assurance report prepared for service organizations that summarizes how well the organization's controls address matters such as security and, where relevant, availability, processing integrity, confidentiality, and privacy. Unlike a more detailed SOC 2 report, a SOC 3 report is written for general distribution, meaning it can be shared publicly, for example on a company's website. It is an attestation performed by an independent practitioner and is voluntary or contractually driven rather than legally mandated.

Formal definition

SOC 3 is a general-use attestation report within the AICPA's SOC for Service Organizations reporting framework, addressing controls relevant to one or more of the Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy). It is distinguished from SOC 2 primarily by its intended audience and level of detail: whereas a SOC 2 report is a restricted-use report containing detailed descriptions of the system, control tests, and results, a SOC 3 report is a general-use report that omits detailed control descriptions and test results and provides a summary-level attestation suitable for public distribution. SOC 3 should not be confused with SOC 1, which addresses controls relevant to user entities' internal control over financial reporting. It is a voluntary or contractual assurance mechanism, not a statutory or regulatory requirement, and it is an attestation report rather than a certification, notwithstanding informal use of certification language by some vendors. The applicable Trust Services Criteria and reporting standards are periodically revised; readers should verify scope, criteria, and current requirements against the latest authoritative AICPA materials. Application to any specific organization depends on the engagement's defined scope and requires professional judgment.

Why it matters

SOC 3 reports fill a specific communication gap for service organizations. A SOC 2 report contains detailed system descriptions, control tests, and results, and is a restricted-use report intended for a limited audience such as customers and their auditors under confidentiality terms. A SOC 3 report, by contrast, is a general-use report that omits those detailed descriptions and test results in favor of a summary-level attestation. This makes it suitable for public distribution, allowing an organization to signal to the broader market that an independent practitioner has attested to its controls without exposing sensitive detail about its systems.

For compliance and procurement teams, this distinction matters because a SOC 3 report is generally not a substitute for the assurance a SOC 2 report provides. Prospective customers performing meaningful vendor due diligence typically require the more detailed SOC 2 report, while a SOC 3 report often serves a marketing or public-trust function rather than a rigorous evaluation purpose. Treating a publicly posted SOC 3 as equivalent to a full SOC 2 review can lead to an overestimation of the assurance actually obtained.

It is also important to keep the terminology precise. A SOC 3 report is an attestation performed by an independent practitioner, not a certification, even though some vendors use certification-style language informally when describing their reports. SOC 3 is a voluntary or contractually driven mechanism rather than a statutory or regulatory requirement, so its presence or absence should be interpreted in that light rather than as evidence of legal compliance.

Who it's relevant to

Service organizations
Organizations that provide services affecting customer or consumer data may pursue a SOC 3 report to publicly demonstrate that an independent practitioner has attested to their controls over security and, where in scope, availability, processing integrity, confidentiality, or privacy. Because the report is general-use, it can support public-facing trust and marketing purposes without exposing the detailed system information contained in a SOC 2 report.
Procurement and vendor risk teams
Teams evaluating third-party service providers should understand that a publicly available SOC 3 report offers only a summary-level attestation and generally does not replace the detailed, restricted-use SOC 2 report needed for substantive due diligence. A SOC 3 can indicate that a provider has undergone an examination, but deeper assurance typically requires requesting the corresponding SOC 2 report.
Compliance officers and legal counsel
Professionals responsible for compliance positioning should note that SOC 3 is a voluntary or contractually driven attestation, not a statutory or regulatory requirement, and that it is an attestation report rather than a certification despite informal vendor usage of certification language. Its role should be characterized accurately in both internal assessments and external representations.
Independent practitioners
Practitioners performing SOC engagements apply the AICPA's SOC for Service Organizations framework and the applicable Trust Services Criteria, which are periodically revised. They should confirm the engagement scope, the criteria in scope, and the current authoritative standards, and exercise professional judgment in tailoring the report to the organization's defined system boundaries.

Inside SOC 3

General-Use Report
A SOC 3 report is designed for general distribution and public consumption, unlike a SOC 2 report, which is restricted to a specified audience. It can be freely shared, posted on a website, or used in marketing materials to demonstrate that an independent examination was performed.
Trust Services Criteria
Like SOC 2, a SOC 3 examination is performed against the Trust Services Criteria developed by the AICPA, which may address security, availability, processing integrity, confidentiality, and privacy. The security criteria are generally the baseline, with others included depending on the scope of the engagement.
Auditor's Opinion
The report includes the independent service auditor's opinion on whether the service organization maintained effective controls to meet the applicable Trust Services Criteria. It conveys the outcome of the examination without disclosing the detailed control descriptions or test results found in a SOC 2 report.
Management's Assertion
SOC 3 reports typically include a statement from the service organization's management asserting that its system and controls meet the relevant criteria, which the auditor's examination is intended to support.
Voluntary, Contractual Nature
A SOC 3 report results from a voluntary examination framework administered under AICPA attestation standards. It is not a regulatory requirement and carries no legal force in itself; organizations pursue it for business, contractual, or marketing purposes rather than to satisfy a statute.

Common questions

Answers to the questions practitioners most commonly ask about SOC 3.

Is a SOC 3 report a certification that proves my organization is compliant?
No. SOC 3 is an attestation report resulting from an examination conducted under the AICPA's attestation standards, not a certification and not a determination of compliance with any law or regulation. A CPA firm expresses an opinion on whether controls were suitably designed and, for a Type 2-style examination, operated effectively over a period against the applicable Trust Services Criteria. This is distinct from a certification scheme with a formal accredited mark, and it does not establish compliance with binding regulations such as the GDPR or HIPAA. Application of any resulting assurance to a specific obligation requires professional judgment.
Is SOC 3 just a shorter version of SOC 2 that contains the same information?
Not exactly. While SOC 2 and SOC 3 examinations can both address the AICPA Trust Services Criteria, they differ in purpose and content. A SOC 2 report is a restricted-use report that generally includes a detailed description of the system, the specific controls, and the results of the auditor's tests. A SOC 3 report is a general-use report intended for broad distribution that typically presents the auditor's opinion and a system description without the detailed control listings and test results found in SOC 2. They are related deliverables serving different audiences rather than long and short versions of an identical document. Verify current content requirements against the applicable AICPA standards.
When would an organization choose a SOC 3 report instead of, or in addition to, a SOC 2 report?
A SOC 3 report is generally chosen when an organization wants a general-use deliverable it can share publicly or with prospective customers who do not have a signed agreement in place, since SOC 2 reports are typically restricted-use. In many cases organizations obtain both: SOC 2 for existing customers, auditors, and partners who need the detail under confidentiality terms, and SOC 3 as a marketing- or public-facing summary. The choice depends on distribution needs and stakeholder expectations, and readers should confirm scope and use restrictions with their service auditor.
Who typically performs a SOC 3 examination and issues the report?
A SOC 3 examination is generally performed by a licensed CPA firm or an individual CPA in accordance with the AICPA's attestation standards. The practitioner issues an opinion on the subject matter against the applicable Trust Services Criteria. Because this is an attestation engagement, the practitioner's independence and professional standards apply. Organizations should confirm the qualifications and scope of any engaging firm and verify current requirements against the latest AICPA guidance.
How can a reader verify that a publicly distributed SOC 3 report is current and applicable?
Because SOC 3 reports generally cover a defined period or point in time, a reader should check the report's stated period or as-of date, the scope and system boundaries described, the specific Trust Services Criteria addressed, and the identity and opinion of the issuing CPA firm. Standards and criteria are periodically updated, so a report reflects the version in effect during the examination. Readers relying on a report for their own assurance purposes should confirm it against the current authoritative AICPA materials and consider whether a more recent report is available.
Does a SOC 3 report on its own satisfy a customer's or regulator's due diligence requirements?
Not necessarily. A SOC 3 report can support due diligence by providing general-use assurance about a service organization's controls, but whether it is sufficient depends on the specific requirement, risk level, and the criteria in scope. Some stakeholders require the greater detail of a SOC 2 report or evidence mapped to particular regulatory obligations. Because SOC 3 is an attestation and not a compliance determination, its adequacy for any given purpose is fact-specific and should be evaluated with professional judgment against the relevant contractual or regulatory expectations.

Common misconceptions

SOC 3 is a more rigorous or higher-level report than SOC 2.
SOC 3 is generally derived from the same examination as SOC 2 and uses the same Trust Services Criteria, but it presents a condensed, general-use summary without the detailed control descriptions and test results. It is intended for broad distribution, not to signal a more demanding standard.
Holding a SOC 3 report means an organization is legally compliant or certified.
SOC 3 results from a voluntary attestation engagement, not a legal certification or regulatory approval. The auditor issues an opinion rather than a certificate, and the report does not by itself establish compliance with any regulation such as the GDPR or HIPAA.
A SOC 3 report gives customers enough detail to evaluate a vendor's specific controls.
Because SOC 3 omits the detailed control descriptions and testing detail contained in a SOC 2 report, parties needing to assess specific controls generally require a SOC 2 report instead. SOC 3 is better suited to public assurance than to detailed due diligence.

Best practices

Confirm which Trust Services Criteria are within the scope of the examination, since a SOC 3 report may cover security alone or additional criteria such as availability, confidentiality, processing integrity, or privacy.
Use a SOC 3 report for public-facing assurance and marketing, but request the corresponding SOC 2 report when detailed control descriptions and test results are needed for vendor due diligence.
Read the auditor's opinion and management's assertion carefully to understand the outcome of the examination rather than assuming a SOC 3 report signals certification.
Verify the report against the current AICPA attestation standards and Trust Services Criteria, as these are periodically revised.
Check the period or date the report covers and whether it reflects a point-in-time or period-of-time examination, and seek the most recent report available.
Engage qualified professional judgment to determine whether SOC 3 assurance is appropriate for a given contractual or regulatory need, as its suitability is fact-specific.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide