SOC 3 reporting services background

SOC Reporting

SOC 3 Report Assurance You Can Publish

A SOC 3 report is the public, general-use companion to your SOC 2 Type II: same Trust Services Categories, same testing, same independent CPA opinion, in a version you can post on your website without an NDA.

Connect with an Expert

Your SOC 2 report can only be shared under NDA. A SOC 3 report carries the same independent opinion, from the same examination, in a form you can hand to anyone: post it on your website, link it in a sales deck, publish it to your trust center. If you are already pursuing a SOC 2 Type II, adding a SOC 3 is one of the least expensive credibility upgrades available.

Share It Publicly

A SOC 3 is a general-use report. No NDA, no access request, no gatekeeping. Post it anywhere a prospect might look.

Same Rigor as SOC 2

Same Trust Services Categories, same audit period, same testing, same licensed CPA opinion. Only the level of published detail differs.

Reassure Prospects Early

Give buyers independent assurance before an NDA is signed, and shorten the path from first call to security review.

A Modest Add-On

The SOC 3 draws entirely on your SOC 2 Type II fieldwork, so it adds modest cost and no extra evidence requests.

Already in a SOC 2 Type II engagement with us? A SOC 3 is available as an optional paid add-on to your current engagement. Let your auditor know, or just ask us.

AICPA SOC for Service Organizations seal

Licensed AICPA CPA Firm
SOC 3 examinations issued under AICPA SSAE No. 18 attestation standards, alongside your SOC 2 Type II

The General-Use Report

What Is a SOC 3 Report?

A SOC 3 report is a general-use report on the controls at a service organization, issued by a licensed CPA firm under AICPA SSAE No. 18 attestation standards. It evaluates the same Trust Services Categories as a SOC 2 examination, security, availability, processing integrity, confidentiality, and privacy, as scoped for your environment.

What makes a SOC 3 different is what it leaves out. A SOC 2 Type II report contains a detailed system description and the auditor's full description of tests and results, which is why it is a restricted-use document shared under NDA. A SOC 3 report contains management's assertion, a high-level overview of the system, and the independent auditor's opinion, without the detailed testing content. Because nothing sensitive remains, the report can be distributed to anyone.

There is no standalone SOC 3 audit and no Type I variant. The SOC 3 opinion covers a period and relies on the evidence gathered during a SOC 2 Type II examination, so it is issued alongside or shortly after the Type II report for the same period. Think of it as the public summary of work already performed, not a separate compliance project.

Know the Difference

SOC 3 vs SOC 2

The two reports come from the same examination. Your SOC 2 Type II is the full technical document your customers' security teams review under NDA. Your SOC 3 is the public summary you use before that conversation starts. Companies that publish a SOC 3 maintain both, refreshed together each annual audit cycle.

Learn about SOC 2 Explore all SOC reporting
SOC 2

Restricted Use, Full Detail

Contains the complete system description and the auditor's tests and results. Intended for customers and prospects who need to evaluate your controls in depth, typically after signing an NDA.

Distribution: Shared privately with customers and their assessors
SOC 3

General Use, Public Summary

Contains management's assertion, a system overview, and the CPA firm's opinion, with the detailed testing omitted. Written for anyone who wants to know an independent examination was performed.

Distribution: Post it publicly: website, trust center, sales collateral

Why It Matters

Put your audit to work in public

Most of the value of a SOC 2 examination stays invisible until late in the sales cycle. A SOC 3 report moves that proof to the front, where prospects, partners, and procurement teams can see it on day one.

The AWS Playbook

Amazon Web Services publishes its SOC 3 report for anyone to download, while its SOC 2 stays behind AWS Artifact and an NDA. The same two-tier approach works for a 40-person SaaS company: public SOC 3 for reach, private SOC 2 for depth.

Reassurance Before the NDA

Early-stage buyers want a signal that security review will not be a dead end. A published SOC 3 answers the question before it is asked and keeps deals moving toward the deeper SOC 2 conversation.

Marketing You Can Substantiate

Claims like enterprise-grade security are easy to make. A SOC 3 report backs the message with a licensed CPA firm's opinion, which competitors cannot copy without doing the work.

Our Process

How to Get a SOC 3 Report

SOC 3 services are an extension of our SOC 2 practice. Tell us you want one and we handle the rest inside the same engagement: partner-led, fixed fee, no separate fieldwork. Learn more about our firm

Already have a SOC 2 Type II underway or renewing soon? A SOC 3 can usually be added to your next examination cycle. Reach out and we'll walk you through it.

Complete a SOC 2 Type II Examination

The SOC 3 is built on Type II evidence, so the engagement starts there. New to SOC 2? Begin with a readiness assessment, or go straight to scoping your SOC 2 Type II.

Add the SOC 3 to the Engagement

Tell us during planning, or after fieldwork wraps. Because we already tested your controls for the Type II, preparing the SOC 3 requires no additional evidence from your team.

Assertion and Opinion

Your management provides its written assertion, and we issue our general-use opinion covering the same period as the Type II. Both reports arrive together.

Publish It

Post the report on your website or trust center and put it in front of prospects. Refresh it each year alongside your annual Type II so the public version stays current with the private one.

On pricing: we treat the SOC 3 as a modest add-on to the SOC 2 Type II fee, quoted in the same fixed-fee proposal before work begins. There is no second audit and no separate fieldwork to pay for. For a Type II estimate, try our pricing calculator, then ask us to include the SOC 3.

SOC 3 Frequently Asked Questions

Common questions about SOC 3 reports, how they relate to SOC 2, and what publishing one involves.

A SOC 3 report is a general-use report on a service organization's controls, issued by a licensed CPA firm under AICPA SSAE No. 18 attestation standards. It covers the same Trust Services Categories and the same audit period as a SOC 2 Type II examination, but omits the detailed description of the auditor's tests and their results. Because the sensitive detail is removed, the report can be shared publicly without an NDA.

They are two outputs of the same examination. The SOC 2 Type II report is restricted use: it contains the full system description and the auditor's detailed testing, and is shared with customers under NDA. The SOC 3 is general use: it contains management's assertion, a system overview, and the auditor's opinion, and can be published anywhere. SOC 2 is for evaluating your controls in depth; SOC 3 is for public distribution.

No. There is no standalone SOC 3 path. The SOC 3 opinion relies on the evidence gathered during a SOC 2 Type II examination, so it is issued alongside or shortly after the Type II covering the same period. There is also no SOC 3 Type I: every SOC 3 covers a period of time, the way a Type II does. If a vendor offers you a SOC 3 with no underlying SOC 2 Type II, ask questions.

Only a licensed CPA firm can perform the examination and sign the opinion in a SOC 3 report, the same requirement that applies to SOC 1 and SOC 2. Compliance platforms and consultants can help you prepare, but the opinion itself must come from an independent CPA firm. Sage Audits LLP is a Colorado-licensed CPA firm (license FRM.5000785) issuing SOC reports under AICPA attestation standards.

Anywhere you like: your website, a public trust center, sales proposals, partner portals, or investor materials. General use means exactly that, no NDA and no distribution restrictions. The one rule of thumb is to publish the report as issued, complete and unaltered, so readers see the opinion in its full context.

As an add-on to a SOC 2 Type II engagement, a SOC 3 adds modest cost because it requires no separate fieldwork: the examination work is already done for the Type II. We quote it in the same fixed-fee proposal as the Type II so there are no surprises. Use our pricing calculator for a Type II estimate, or contact us for a proposal that includes both reports.

A SOC 3 covers the same period as the SOC 2 Type II it accompanies, so its useful life matches your annual audit cycle. Most companies replace the published report each year when the new Type II is issued, which keeps the public version current with the private one. A SOC 3 sitting on a website with a two-year-old period end sends the wrong message.

Transparent Pricing

Get Your
Custom Quote

Our pricing is structured and fixed-fee. What it costs comes down to your size, your environment, and which Trust Services Categories you put in scope, since those controls are what really drive the work. Share a few details about your situation and we will follow up personally, usually with a quick call, to walk through scope and get you a clear fixed quote you can plan around.

Rethinking the IT Audit Experience

Big Four training. Boutique access. An end-to-end perspective that makes the difference.

Meet the Team
Tasya Novak, Managing Director, Sage Audits
01

Focused on IT Assurance

From SOC 1, 2, and 3 to SOX, our niche is IT audit. We understand risk, controls, and how to make compliance work for you.

02

Real World Expertise

With experience across Big Four firms and in-house internal audit roles, our team understands audits from both sides, with technical certification backed by practical insight. Meet the team →

03

Built for Business

No cookie-cutter compliance. Our audit process is designed around your operations, timelines, and goals because efficient audits begin with alignment. See how it works →

04

Client First Approach

Our assurance services help you gain insight into your security posture and build confidence with stakeholders. We use technology to streamline the process without sacrificing quality.

Latest from Sage Audits

View All Posts