AuditXYZ

Compliance Framework

SOC 3 — Trust Services Criteria Report for General Use (SOC 3)

SOC 3 is the publicly shareable version of SOC 2, providing a general-use trust services report. Learn when SOC 3 adds value and how it differs from SOC 2.

$20,000–$100,0003–9 monthsAudit Required2017 Trust Services Criteria
Issuing BodyAmerican Institute of Certified Public Accountants (AICPA)
First Published2011-06-15
Latest Version2017 Trust Services Criteria
Typical Cost$20,000–$100,000
Typical Timeline3–9 months
Audit RequiredYes
Audit FrequencyAnnual, typically aligned with SOC 2 Type II audit cycle
Geographyunited-states, canada, global

SOC 3: Public Trust Services Report Guide

SOC 3 is the publicly distributable counterpart to SOC 2. It uses the same Trust Services Criteria and undergoes the same rigorous audit, but the resulting report is a high-level summary suitable for general use — meaning it can be shared freely on your website, in marketing materials, and with anyone who asks.

What SOC 3 Covers

SOC 3 evaluates the same five Trust Services Criteria as SOC 2: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The audit procedures and testing are identical. The difference is purely in the report format — SOC 3 provides an auditor's opinion without the detailed system description, control listings, and test results that make SOC 2 reports restricted-use documents.

Who Needs SOC 3

SOC 3 is valuable for organizations that want to publicly demonstrate their compliance posture. While SOC 2 reports are shared under NDA with specific customers, SOC 3 can be posted on your website and referenced in sales materials.

Common use cases include marketing differentiation for SaaS companies, public trust signals for consumer-facing services, and situations where prospects want compliance assurance before entering an NDA relationship.

SOC 3 vs. SOC 2

AspectSOC 2SOC 3
DistributionRestricted use (under NDA)General use (public)
Detail levelComprehensive — includes system description, controls, and test resultsSummary — auditor's opinion only
Customer acceptanceWidely accepted for due diligenceUseful for marketing, but customers typically still request SOC 2
Incremental costBase engagementMinimal additional cost when paired with SOC 2

Practical Considerations

Most organizations produce a SOC 3 report as a byproduct of their SOC 2 engagement. The incremental cost is minimal — typically $2,000 to $5,000 on top of the SOC 2 audit fee. Very few organizations pursue SOC 3 without also completing SOC 2, since enterprise customers almost universally want the detailed SOC 2 report.

The primary value of SOC 3 is as a marketing tool and public trust signal. It allows you to say "we are SOC 2 audited" with proof that anyone can verify, without exposing the detailed control information in your SOC 2 report.

Who Issues SOC 3 and What It Covers

SOC 3 is issued by the American Institute of Certified Public Accountants (AICPA) as part of the SOC reporting suite, alongside SOC 1 and SOC 2. The Trust Services Criteria (TSC) underlying all three SOC reports were updated in 2017.

The five Trust Service Criteria — Security (CC), Availability (A), Processing Integrity (PI), Confidentiality (C), and Privacy (P) — are tested in exactly the same way as in a SOC 2 engagement. The distinction is entirely in what the final report contains. A SOC 3 report includes:

  • The independent auditor's report with an unqualified or qualified opinion
  • A brief description of the service organization's system
  • The management assertion that controls were effective

What it does not include: the detailed system description, the list of controls, the testing procedures performed, the testing results, or any noted exceptions. This is what makes it shareable.

Who Needs SOC 3

Marketing-forward SaaS companies that want a compliance signal they can reference freely in sales decks, on their trust page, and in RFP responses use SOC 3 as a public credibility marker. Many buyers will not engage in an NDA conversation just to evaluate whether a vendor is worth evaluating — a publicly posted SOC 3 removes that friction.

Consumer-facing products where users expect evidence of security without entering formal vendor agreements benefit from SOC 3. A consumer healthcare app, for example, might post its SOC 3 report to demonstrate to individual users that it is audited and trustworthy.

Organizations responding to RFPs where a quick compliance credential is needed before a formal security review is initiated find SOC 3 useful as a first-pass response. Most procurement teams accept a public SOC 3 report as evidence of an audit program before requesting the full SOC 2 under NDA.

The Audit Process

Since SOC 3 is produced from the same audit engagement as SOC 2, the process is identical through the audit fieldwork phase. The only additions are:

  • Requesting your CPA firm to produce the SOC 3 report in addition to the SOC 2 report (a standard option)
  • Having management prepare the management assertion for the SOC 3 format

The incremental effort is typically a few hours for the auditing firm and minimal effort internally. Most auditing firms charge $2,000 to $5,000 additionally for the SOC 3 report alongside a SOC 2 engagement.

Costs and Timeline

ComponentLow EstimateHigh Estimate
SOC 2 Type II engagement (required)$20,000$100,000
SOC 3 incremental cost$2,000$5,000
Total for SOC 2 + SOC 3$22,000$105,000

Timeline: Identical to the SOC 2 Type II engagement — 6 to 9 months for an initial report. SOC 3 is typically issued simultaneously with the SOC 2 report.

SOC 3 vs. SOC 2 — SOC 3 is publicly shareable; SOC 2 is restricted-use shared under NDA. Enterprise buyers almost always request the SOC 2 report for detailed due diligence. SOC 3 is a marketing tool, not a substitute for SOC 2 in procurement contexts.

SOC 3 vs. ISO 27001 — ISO 27001 has roughly 65% control overlap with SOC 3's Trust Service Criteria. ISO 27001 is internationally recognized and certifiable; SOC 3 is U.S.-centric and specific to service organizations. Companies serving both U.S. and international markets often pursue both.

SOC 3 vs. Cyber EssentialsCyber Essentials is the UK's public-facing baseline security certification. SOC 3 serves a similar marketing purpose for U.S.-centric audiences. Both are meant to be visible signals rather than detailed evidence packages.

How Automation Helps

Because SOC 3 is derived from the SOC 2 engagement, any automation that improves your SOC 2 program directly benefits your SOC 3 output as well. Continuous evidence collection and control monitoring reduce the audit burden and improve report quality.

LowerPlane supports SOC 2 Trust Service Criteria across its evidence automation platform — which means SOC 3 evidence needs are covered as part of the same workflow. At $4,000/year entry pricing with a free tier, it is accessible at the earliest stages of your compliance program. AuditXYZ rates LowerPlane 9.4/10 for SOC 2/3 workflows. Compare platforms at Best Compliance Automation Platforms and Vanta vs. LowerPlane.

Frequently Asked Questions

Can I post my SOC 3 report on my website? Yes. That is the primary purpose of a SOC 3 report. Unlike the SOC 2 report, the SOC 3 is a general-use document with no NDA or distribution restriction. Many companies post it as a PDF on their security or trust page.

Does a SOC 3 report replace the need for a SOC 2 report? No. Enterprise buyers who require SOC 2 for their vendor due diligence will still request the full SOC 2 report under NDA. SOC 3 is useful for initial trust signals but does not satisfy formal procurement requirements.

How often do I need to renew my SOC 3? SOC 3 reports are tied to the observation period of the underlying SOC 2 engagement. As you renew your SOC 2 annually, you update your SOC 3 at the same time. Keep your posted SOC 3 report current — a report with an end date more than 12 months ago raises questions rather than building confidence.

What Trust Service Criteria should I include in my SOC 3? Mirror your SOC 2 criteria selection. Security is always required. Availability matters if your customers depend on your uptime. Confidentiality and Privacy matter if you handle sensitive data or consumer PII. Including criteria you cannot sustainably evidence creates audit risk without adding meaningful marketing benefit.

Can a startup get a SOC 3 without SOC 2 Type II? No. SOC 3 requires the same audit as SOC 2 Type II. There is no shortcut to the public trust signal without completing the underlying rigorous audit. The AICPA does not permit SOC 3 reports based on Type I engagements.

Request a SOC 3 consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

SOC 2High95%
ISO 27001Medium65%

Related frameworks

Get matched with a SOC 3 auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.