AuditXYZ

Compliance Framework

SOC 3 — Trust Services Criteria Report for General Use

SOC 3 is the publicly shareable version of SOC 2, providing a general-use trust services report. Learn when SOC 3 adds value and how it differs from SOC 2.

$20,000–$100,0003–9 monthsAudit Required2017 Trust Services Criteria
Issuing BodyAmerican Institute of Certified Public Accountants (AICPA)
First Published2011-06-15
Latest Version2017 Trust Services Criteria
Typical Cost$20,000–$100,000
Typical Timeline3–9 months
Audit RequiredYes
Audit FrequencyAnnual, typically aligned with SOC 2 Type II audit cycle
Geographyunited-states, canada, global

SOC 3: Public Trust Services Report Guide

SOC 3 is the publicly distributable counterpart to SOC 2. It uses the same Trust Services Criteria and undergoes the same rigorous audit, but the resulting report is a high-level summary suitable for general use — meaning it can be shared freely on your website, in marketing materials, and with anyone who asks.

What SOC 3 Covers

SOC 3 evaluates the same five Trust Services Criteria as SOC 2: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The audit procedures and testing are identical. The difference is purely in the report format — SOC 3 provides an auditor's opinion without the detailed system description, control listings, and test results that make SOC 2 reports restricted-use documents.

Who Needs SOC 3

SOC 3 is valuable for organizations that want to publicly demonstrate their compliance posture. While SOC 2 reports are shared under NDA with specific customers, SOC 3 can be posted on your website and referenced in sales materials.

Common use cases include marketing differentiation for SaaS companies, public trust signals for consumer-facing services, and situations where prospects want compliance assurance before entering an NDA relationship.

SOC 3 vs. SOC 2

AspectSOC 2SOC 3
DistributionRestricted use (under NDA)General use (public)
Detail levelComprehensive — includes system description, controls, and test resultsSummary — auditor's opinion only
Customer acceptanceWidely accepted for due diligenceUseful for marketing, but customers typically still request SOC 2
Incremental costBase engagementMinimal additional cost when paired with SOC 2

Practical Considerations

Most organizations produce a SOC 3 report as a byproduct of their SOC 2 engagement. The incremental cost is minimal — typically $2,000 to $5,000 on top of the SOC 2 audit fee. Very few organizations pursue SOC 3 without also completing SOC 2, since enterprise customers almost universally want the detailed SOC 2 report.

The primary value of SOC 3 is as a marketing tool and public trust signal. It allows you to say "we are SOC 2 audited" with proof that anyone can verify, without exposing the detailed control information in your SOC 2 report.

Get the SOC 3 starter pack

By submitting, you agree to our privacy policy.

Framework Mappings

Related frameworks

Get matched with a SOC 3 auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.

Recommended Tools