← ISO and SOC Certifications

SOC 3

General use report on controls relevant to the Trust Services Criteria. Updated: September 29, 2026.

SOC 3 is the publishable version of a SOC 2. Same audit, same criteria, same auditor — but the detailed system description, the control listing and the test results are removed. What remains is the auditor's opinion and a short summary, which means it carries no confidential information and can be put on a website without an NDA.

What It Is Good For

Exactly one thing, and it does it well: demonstrating publicly that a SOC 2 audit was performed and what the opinion was. A prospect can see it without signing anything, which removes a step from early sales conversations and reduces the number of NDAs you sign in order to send a report to someone who was never going to buy.

Several large cloud providers publish theirs, which is why you can read a summary of their assurance position without a commercial relationship.

What It Is Not Good For

Assessing a supplier seriously. Because the tests and their results are removed, a SOC 3 does not tell you what was examined, what the scope boundaries were, whether any exceptions were found, or what complementary controls you are expected to operate yourselves. All of the genuinely useful content of a SOC 2 is precisely what SOC 3 leaves out.

So the rule when you are the buyer is straightforward: accept a SOC 3 as evidence that an audit exists, and ask for the SOC 2 before you depend on the service. A supplier who will only ever show a SOC 3 has told you something.

How to Get One

You do not commission a SOC 3 on its own. It is produced from the same engagement as a SOC 2 Type II, usually for a small additional fee, and the obvious approach is to ask for both when you engage the audit firm. There is no separate audit, no separate period, and no additional evidence burden.

Related

SOC 2 is the substantive report; SOC 1 covers financial reporting controls; ISO/IEC 27001 is the certification-based alternative and is itself public, which is one of its practical advantages.

Written from an infrastructure perspective. We are not a certification body, an audit firm or a legal adviser, and this is not legal advice. Standards are revised on a cycle — confirm the current edition before you commit.