What is SOC 3? Everything You Need to Know

Once you’ve understood the importance of security, let’s say you’ve taken the necessary steps to achieve SOC 1 or SOC 2 reports, but what more can you do to bolster up this achievement? This is where a SOC 3 report comes in.
When everything happens online, nothing matters more than building and maintaining customer trust. If your organization handles any kind of sensitive data, you can’t afford to be wishy-washy about protecting it. Once you’ve understood the importance of security, let’s say you’ve taken the necessary steps to achieve SOC 1 or SOC 2 reports, but what more can you do to bolster up this achievement? This is where a SOC 3 report comes in.
What is SOC 3?
A SOC 3 report is specifically meant to be a public facing document that provides a summary of an organizations controls. It is a general-use report, unlike the more restricted SOC 1 or SOC 2 reports. Organizations can use a SOC 3 report to assure customers, stakeholders, and general public that their systems meet specific trust service criteria.
READ MORE: SOC 1 vs SOC 2 vs SOC 3: Understanding the Differences
The report confirms the effectiveness of controls relevant to the 5 trust service criteria. This assurance is based on an independent auditor’s opinion following an evaluation of the controls over a specified period, usually 12 months. It’s a testament to operational excellence and a strategic tool for marketing and business development.
Components of a SOC 3 Report
The structure of a SOC 3 report is designed for clarity and broad distribution. It includes several key components:
- Management’s Assertion: A declaration by the service organization's management detailing their responsibility for the system and the fairness of the control description. They assert that the controls were effective throughout the reporting period.
- Independent Service Auditor’s Report: This is the core of the report. The CPA firm (auditor) provides their opinion on whether management's assertion is fairly stated. This opinion is unqualified (clean) when the controls were effective, providing the highest level of assurance.
- System Description (General): A concise, non-technical overview of the service organization's system, its services, the principal controls, and the applicable Trust Service Criteria. Unlike the detailed SOC 2 description, the SOC 3 version is brief and focuses on the scope.
- Applicable Trust Service Criteria: The report identifies which of the five criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy) were addressed by the audit. Security is a mandatory baseline criterion for all SOC 2 and SOC 3 reports.
Who Needs a SOC 3 Report?
The SOC 3 report serves specific strategic needs:
- Service Organizations Targeting the Public: Any service provider, particularly those in the SaaS (Software as a Service), data center, managed IT services, or cloud computing sectors, benefits immensely from a SOC 3.
- Organizations Seeking Public Credibility: Companies wanting to publicly display their adherence to high standards of internal control often choose the SOC 3. It's an excellent inclusion for a company's website or marketing materials.
- Service Organizations That Already Have a SOC 2: Since a SOC 3 is essentially a summarized, general-use version of a successful SOC 2 (Type 2) report, organizations that have already undergone the rigorous SOC 2 audit find the SOC 3 a straightforward, value-added deliverable.
When Should You Consider a SOC 3 Report?
Timing the decision to pursue a SOC 3 aligns with business strategy and maturity:
- After Achieving SOC 2 Type 2 Success: A SOC 3 report is issued only after a successful SOC 2 Type 2 audit. Organizations should first complete the in-depth, restricted-use SOC 2 Type 2. The SOC 3 then becomes the logical next step for public communication.
- During Competitive Bidding: When potential customers require proof of control assurance but don't need the detailed, proprietary information contained within a SOC 2, the SOC 3 serves as a perfect, easily shareable validation.
- For Marketing and Transparency Initiatives: Consider the SOC 3 when launching major marketing campaigns emphasizing trust, security, and compliance. Its public nature reinforces a strong commitment to transparency and operational integrity.

Johanson Group Can Help Obtain a SOC 3 Report
Securing a SOC 3 report requires expert guidance through the complex audit process. Johanson Group specializes in helping service organizations achieve their assurance goals. As a qualified CPA firm, we perform the necessary SOC 2 Type 2 examination. Upon a successful, unqualified opinion, we prepare the resulting SOC 3 report.
Related articles

What is the difference between SOC 2 Type 1 and SOC 2 Type 2
SaaS companies are popular, but not all of them are able to stay compliant. An annual SOC 2 audit is one way to ensure organizational security and compliance.
The AICPA defines a SOC 2 Type 1 report as - a report on the fairness of the presentation of management's description of the service organization's system and the suitability of the design of the controls to achieve the related control objectives included in the description as of a specified date.
To translate that to layman's terms - Is the company set up for success with its current controls and does the system description accurately reflect the company’s operations?
The AICPA defines a SOC 2 Type 2 report as - a report on the fairness of the presentation of management’s description of the service organization’s system and the suitability of the design and operating effectiveness of the controls to achieve the related control objectives included in the description throughout a specified period.
To translate that to layman's terms - Did the company do what it said it was going to do when it said they were going to do it and does the system description accurately reflect the company’s operations?
SOC 2 Type 1
The SOC 2 Type 1 audit looks at one day (point in time) and gives the opinion that everything is set up correctly. The auditor will look at the system description and the controls to make sure that they match the SOC 2 criteria. The auditor will also look at the evidence to verify that the control is in place.
A SOC 2 Type 1 report will give you the peace of mind that you have designed your controls appropriately to meet defined Trust Services Criteria.
SOC 2 Type 2
All the work that you did for SOC 2 Type 1 applies to Type 2. Now you just need to follow those policies and do what you said you were going to do and collect the evidence to prove it. You have moved from the setup mode to the maintenance mode. A Type 2 report is demonstrating that the controls you designed and implemented in Type 1 are now operating effectively over the period chosen for the Type 2 audit.
Usually, the minimum audit period for a SOC 2 Type 2 is 3 months. You should talk with your customers to see if this will meet their needs. You might find one that will only take a minimum of 6 months. If your customers just need a report, then we would suggest going with the shorter period so that you can get out in the marketplace with the report and start winning new customers.
How To Decide What You Need
At the end of the day, your customers are going to want a SOC 2 Type 2 report.
If you need something quick to keep sales conversations going or as an internal milestone then a SOC 2 Type 1 is a great starting point. We would also suggest doing a SOC 2 Type 1 first if you are not using a readiness platform and are trying to do it by yourself. This will make sure that you are set up for a successful SOC 2 Type 2. You would hate to find out after your SOC 2 Type 2 audit period ended that your controls didn’t match the SOC 2 criteria. The SOC 2 Type 1 provides that safety net for you to know you are on the right path.
Deciding to do a SOC 2 Type 1 will not slow you down in obtaining a SOC 2 Type 2. While the audit is being performed on your Type 1 you can start the audit period for Type 2. That way you will already be part way through the audit period by the time you receive the SOC 2 Type 1 report.
The additional cost for a SOC 2 Type 1 report is usually fairly small. Most CPA firms will give you a bundled cost for a Type 1 and a Type 2 that provide the two audits at a significantly lower price.
If none of those cases fit your needs, then we would suggest you go straight for Type 2.
A readiness platform will make sure that all of your controls match the SOC 2 criteria and that you are set up for success.
If your customers will only take a SOC 2 Type 2 and you need something to prove you are taking it seriously and are working on your SOC 2, you can also ask your auditors for an engagement letter to share with your potential customers to show that you are working on your SOC 2 Type 2. That will have enough weight with potential clients to keep sales conversations moving forward.
SOC 2 Compliance Audit Readiness
No matter which path you take, you will end up at the SOC 2 Type 2 report. There isn’t a wrong way to approach it. As you are making your choice, talk to your customers (if you can) and talk to your auditor about what is going on. Your auditor can walk you through both paths and help you make the best decision for your company.
You’re dealing with private data and information, so suffice it to say, yes, a self-audit is a great way to ensure your organization takes its responsibilities for security seriously.
After a SOC 2 compliance self-audit and remediation, your organization is ready for its SOC 2 compliance audit from an experienced and specialized CPA like Johanson Group.

SOC 1 vs SOC 2 vs SOC 3 — Which Report Does Your Company Actually Need?
SOC 1, SOC 2, SOC 3 — same family, very different reports. Here's how to know which one your customers are actually asking for.
The short version
All three reports are issued under the AICPA's System and Organization Controls framework. Where they differ is what they evaluate and who they're written for.
- SOC 1 — Controls relevant to your customers' financial reporting. Restricted-use report.
- SOC 2 — Controls relevant to security, availability, processing integrity, confidentiality, and privacy. Restricted-use report.
- SOC 3 — A public-facing summary of your SOC 2. General-use report.
If your customers care about how you handle their data, you're looking at SOC 2 (and possibly SOC 3). If they care about how you affect their financial statements, you're looking at SOC 1.
SOC 1: built for financial reporting
A SOC 1 report exists for one reason: to give your customer's auditors the comfort they need when your services impact your customer's financial statements.
Classic examples of who needs SOC 1:
- Payroll processors
- Loan servicing platforms
- Medical claims processing
- Fund administrators
- SaaS platforms that handle billing, revenue recognition, or accounting workflows on behalf of customers
The controls in scope are the ones that, if they failed, could cause a misstatement in your customer's books. Think: change management for billing logic, access controls around financial data, completeness and accuracy of transaction processing.
SOC 1 reports come in two flavors:
- Type 1 — Design of controls at a point in time.
- Type 2 — Design and operating effectiveness over a period (usually 6–12 months).
SOC 1 is a restricted-use report. It's written for your customers and their auditors — not for marketing.
SOC 2: the one most SaaS companies need
SOC 2 is the report procurement teams ask for when they're evaluating a vendor that touches their data. It evaluates your controls against the AICPA's Trust Services Criteria:
- Security (required in every SOC 2)
- Availability (optional)
- Processing Integrity (optional)
- Confidentiality (optional)
- Privacy (optional)
Most SaaS companies start with Security only and add Availability or Confidentiality based on customer pressure or contractual commitments.
Like SOC 1, SOC 2 has a Type 1 and a Type 2 version. Type 1 covers a point in time; Type 2 covers a period — typically a minimum of three months for a first audit, then twelve months going forward. Most enterprise customers will eventually want a Type 2.
SOC 2 is also a restricted-use report. You can share it with prospects under NDA — and you absolutely should — but you can't post it on your website.
Which is exactly the gap SOC 3 fills.
SOC 3: the public version of SOC 2
SOC 3 is essentially a marketing-friendly version of your SOC 2. It uses the same Trust Services Criteria and is based on the same audit work, but it strips out the detailed control descriptions and test results. What's left is a high-level attestation you can publish on your website, hand out at trade shows, or include in sales decks without an NDA.
A few things worth knowing:
- You can only get a SOC 3 if a SOC 2 Type 2 has been (or is being) performed. SOC 3 isn't a standalone audit — it's a derivative report.
- SOC 3 is general-use. Anyone can read it.
- SOC 3 doesn't replace SOC 2. Enterprise procurement teams still want the full SOC 2 Type 2.
Think of SOC 3 as the trust badge on the homepage and SOC 2 as the document you send when a security questionnaire lands in your inbox.
Side-by-side comparison
How to choose
The decision usually comes down to three questions:
1. What do your customers' contracts and security questionnaires actually ask for?
Ninety percent of the time, this answers it for you. Read the requests instead of guessing.
2. Does your service affect your customers' financial statements?
If yes — payroll, billing, accounting, claims, fund services — you likely need SOC 1. If your customers' auditors are calling you, that's a strong signal.
3. Do your customers care about how you handle their data?
If yes, you need SOC 2. This covers most SaaS, hosting, managed services, and infrastructure providers.
Some companies need both SOC 1 and SOC 2 — for example, a billing SaaS that processes financial transactions and stores sensitive customer data. That's not unusual, just more work.
SOC 3 is rarely a starting point. It's something you add once your SOC 2 Type 2 is in place and marketing wants something they can publish.
What about ISO 27001, HIPAA, or PCI?
These often come up in the same conversation, but they're separate frameworks with their own audits and certifications. SOC reports don't replace them and they don't replace SOC reports. If you're juggling multiple frameworks, a good auditor can help you map overlapping controls so you're not doing the same work three times.
Bottom line
SOC 1 is for financial reporting. SOC 2 is for everything else customers worry about — security, uptime, data handling. SOC 3 is the public-facing version of SOC 2 you can share without an NDA.
The cleanest path for most SaaS companies: start with SOC 2 Type 1 to validate your control design, move into a SOC 2 Type 2 audit period, and add SOC 3 once you want a public-facing trust signal. If you process financial transactions on behalf of customers, layer in SOC 1.
Not sure which path fits your business? That's the kind of conversation a 30-minute call with a specialized auditor can resolve faster than another week of internal debate.



