Compliance · Public report
A SOC 2 you can actually put on your website.
SOC 3 is a general-use report built on the same Trust Services examination as SOC 2 — but without the detailed control descriptions and test results. That makes it safe to publish publicly, which is exactly what it's for.
Public
Distribution
Same TSC
Basis as SOC 2
No NDA
To share
SOC 3 is a marketing-safe byproduct of SOC 2 — not a separate compliance program.
A SOC 3 comes from the same examination against the Trust Services Criteria. If you have a SOC 2 Type II, a SOC 3 is largely an additional deliverable — not a second audit.
SOC 2 reports are restricted-use and normally require an NDA. SOC 3 contains no detailed testing or control descriptions, so you can post it publicly and hand it to anyone.
SOC 3 answers 'are they audited?' It won't satisfy a security team doing deep diligence — those buyers still want the SOC 2.
Companies that want public proof without shipping their control matrix to strangers.
We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.
SOC 3 rides on a SOC 2 examination — we get that right first, because everything else follows from it.
We coordinate with your CPA firm so the SOC 3 deliverable is included, rather than bolted on later at extra cost.
We review the system description so what you publish is accurate but doesn't hand attackers a control inventory.
We help you publish the report and seal where buyers actually look, and keep it current.
We pair the SOC 3 with a questionnaire response kit so light-touch buyers self-serve.
Keep the underlying SOC 2 controls healthy so the SOC 3 renews without drama.
Readiness and examination against the Trust Services Criteria.
Add the general-use deliverable to the engagement.
Make the public description accurate and safe.
Post the report and seal on your trust page.
Refresh alongside each SOC 2 cycle.
Not practically. SOC 3 is produced from the same Trust Services examination — the CPA firm has to do that work regardless. In practice you pursue SOC 2 and take SOC 3 as an additional deliverable.
Usually not on its own. SOC 3 deliberately omits control detail and test results, which is exactly what a serious reviewer wants to see. Use SOC 3 publicly and share the SOC 2 under NDA when diligence gets real.
If you sell self-serve or to SMB, often yes — it deflects questionnaires and gives marketing something concrete. If every deal already goes through deep security review, the SOC 2 is doing the work and SOC 3 adds little.
Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.
Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.