SOC 3
A SOC 3 is a general-use report derived from the same audit as a SOC 2 Type II. It states the auditor’s opinion — that your controls met the trust services criteria over the review period — but omits the confidential detail: the control descriptions, test procedures, and results that make a SOC 2 report sensitive.
What it’s for
Marketing, essentially. A SOC 2 report requires an NDA to share; a SOC 3 can sit on your public trust page for anyone to download. It lets prospects verify you passed a Type II audit before ever talking to sales, which shortens security conversations.
What it won’t do
A SOC 3 rarely satisfies an actual security review. Enterprise buyers want the full SOC 2 with its control detail and test results — the SOC 3 just tells them the SOC 2 exists and came back clean. Think of the pairing as public proof plus private detail: publish the SOC 3, share the SOC 2 under NDA on request.
Cost consideration
Since a SOC 3 comes from the same audit engagement as the SOC 2 Type II, adding one is a modest incremental fee, not a second audit. If you’re already doing a Type II and sell to security-conscious buyers, it’s usually worth requesting.
Bridge Letter — A bridge letter covers the gap between your last SOC 2 report period and today, letting customers rely on your report between annual audits.
SOC 2 Type I vs Type II — Type I attests your controls are designed properly at a point in time. Type II attests they operated over a period. Here's which one customers accept.
Trust Services Criteria — The five Trust Services Criteria — security, availability, processing integrity, confidentiality, privacy — and how they define your SOC 2 scope.