# What is a SOC 3 Report?

> A SOC 3 report is a general-use service-auditor report on controls at a service organization relevant to the Trust Services Criteria — covering the same subject matter as SOC 2 but with less detail, so it can be shared publicly.

- Canonical URL: https://yellowcube.eu/glossary/soc-3-report/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Like SOC 2, a SOC 3 examination addresses controls relevant to security, availability, processing integrity, confidentiality, or privacy according to scope. The difference is distribution and depth: SOC 3 omits the detailed system description, test procedures, and results that make SOC 2 restricted-use.

Because the report is designed for general distribution, organizations often use a SOC 3 seal or report for public assurance marketing while providing the SOC 2 under NDA for substantive evaluation. A reviewer relying only on SOC 3 sees an auditor’s opinion and scope, not the underlying control evidence.

### Key points

- **Scope:** Confirm which Trust Services Criteria were included, the period or date covered, the system boundary, and any subservice organizations — the seal alone communicates none of this.
- **Use case:** Suitable for public-facing assurance and preliminary screening; inadequate for a customer’s own risk assessment, which needs the SOC 2’s detail.
- **Important limitation:** The general-use format means the reader cannot inspect tests, exceptions, or complementary-user-entity controls. A SOC 3 seal is a summary signal, not evidence a procurement or risk process can rest on.

### Related terms

[SOC 2 report](<https://yellowcube.eu/glossary/soc-2-report/>) · [SOC 1 report](<https://yellowcube.eu/glossary/soc-1-report/>) · [Security audit](<https://yellowcube.eu/glossary/security-audit/>) · [Third-party cyber risk](<https://yellowcube.eu/glossary/third-party-cyber-risk/>)

### Sources

[AICPA & CIMA, SOC 3 — Trust Services Criteria for General Use](https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-3) · [AICPA & CIMA, System and Organization Controls: SOC Suite of Services](https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

