Compliance · Public report

SOC 3 — public assurance for Trust Services controls

A SOC 2 you can actually put on your website.

SOC 3 is a general-use report built on the same Trust Services examination as SOC 2 — but without the detailed control descriptions and test results. That makes it safe to publish publicly, which is exactly what it's for.

Public

Distribution

Same TSC

Basis as SOC 2

No NDA

To share

What SOC 3 is (and isn't)

SOC 3 is a marketing-safe byproduct of SOC 2 — not a separate compliance program.

Built on SOC 2

A SOC 3 comes from the same examination against the Trust Services Criteria. If you have a SOC 2 Type II, a SOC 3 is largely an additional deliverable — not a second audit.

General use

SOC 2 reports are restricted-use and normally require an NDA. SOC 3 contains no detailed testing or control descriptions, so you can post it publicly and hand it to anyone.

Less detail, less friction

SOC 3 answers 'are they audited?' It won't satisfy a security team doing deep diligence — those buyers still want the SOC 2.

Who benefits from SOC 3

Companies that want public proof without shipping their control matrix to strangers.

  • SaaS vendors who want a trust badge and public report
  • Companies fielding high volumes of light-touch security questionnaires
  • Providers selling to SMB where full SOC 2 diligence is rare
  • Anyone who already has SOC 2 and wants marketing leverage from it

How intSignal gets you there

We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.

SOC 2 first

SOC 3 rides on a SOC 2 examination — we get that right first, because everything else follows from it.

Add SOC 3 to scope

We coordinate with your CPA firm so the SOC 3 deliverable is included, rather than bolted on later at extra cost.

Public-safe wording

We review the system description so what you publish is accurate but doesn't hand attackers a control inventory.

Trust page

We help you publish the report and seal where buyers actually look, and keep it current.

Questionnaire deflection

We pair the SOC 3 with a questionnaire response kit so light-touch buyers self-serve.

Maintenance

Keep the underlying SOC 2 controls healthy so the SOC 3 renews without drama.

How the engagement runs

1

Establish SOC 2

Readiness and examination against the Trust Services Criteria.

2

Include SOC 3

Add the general-use deliverable to the engagement.

3

Review wording

Make the public description accurate and safe.

4

Publish

Post the report and seal on your trust page.

5

Renew

Refresh alongside each SOC 2 cycle.

Frequently asked questions

Can we get a SOC 3 without a SOC 2?

Not practically. SOC 3 is produced from the same Trust Services examination — the CPA firm has to do that work regardless. In practice you pursue SOC 2 and take SOC 3 as an additional deliverable.

Will a SOC 3 satisfy enterprise security reviews?

Usually not on its own. SOC 3 deliberately omits control detail and test results, which is exactly what a serious reviewer wants to see. Use SOC 3 publicly and share the SOC 2 under NDA when diligence gets real.

Is a SOC 3 worth the extra cost?

If you sell self-serve or to SMB, often yes — it deflects questionnaires and gives marketing something concrete. If every deal already goes through deep security review, the SOC 2 is doing the work and SOC 3 adds little.

Other frameworks we support

Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.

SOC 3 for your environment

Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.