Glossary

SOC 3

A SOC 3 is a general-use report derived from the same audit as a SOC 2 Type II. It states the auditor’s opinion — that your controls met the trust services criteria over the review period — but omits the confidential detail: the control descriptions, test procedures, and results that make a SOC 2 report sensitive.

What it’s for

Marketing, essentially. A SOC 2 report requires an NDA to share; a SOC 3 can sit on your public trust page for anyone to download. It lets prospects verify you passed a Type II audit before ever talking to sales, which shortens security conversations.

What it won’t do

A SOC 3 rarely satisfies an actual security review. Enterprise buyers want the full SOC 2 with its control detail and test results — the SOC 3 just tells them the SOC 2 exists and came back clean. Think of the pairing as public proof plus private detail: publish the SOC 3, share the SOC 2 under NDA on request.

Cost consideration

Since a SOC 3 comes from the same audit engagement as the SOC 2 Type II, adding one is a modest incremental fee, not a second audit. If you’re already doing a Type II and sell to security-conscious buyers, it’s usually worth requesting.

Related Terms

Bridge Letter — A bridge letter covers the gap between your last SOC 2 report period and today, letting customers rely on your report between annual audits.

SOC 2 Type I vs Type II — Type I attests your controls are designed properly at a point in time. Type II attests they operated over a period. Here's which one customers accept.

Trust Services Criteria — The five Trust Services Criteria — security, availability, processing integrity, confidentiality, privacy — and how they define your SOC 2 scope.