In this article:

SOC 3 Report: What It Is and How to Get One

Compliance
/
August 16, 2026
SOC 3 Report: What It Is and How to Get One

A SOC 3 report is the general-use version of a SOC 2 Type 2. The same CPA firm performs the same examination, against the same Trust Services Criteria, over the same review period. The difference is the report itself: a SOC 3 contains the auditor's opinion and management's assertion, drops the detailed system description and the test tables, and carries no distribution restriction. You can post it on your website. You cannot buy one on its own, because a SOC 3 is issued with or after a SOC 2 Type 2, usually for a small addition to the examination fee. If prospects keep asking whether you have SOC 2 before they will sign an NDA, a SOC 3 is the document that answers them.

What a SOC 3 report contains

Three things. First, the independent auditor's opinion on whether controls operated effectively against the applicable Trust Services Criteria over the period. Second, management's assertion, the formal claim that the description is fair and the controls were effective. Third, a short overview of the system: what service the report covers and where its boundaries sit.

A SOC 2 Type 2 report carries the same opinion and assertion, then adds the material that makes it useful for diligence: the full system description covering people, processes, technology, and boundaries, and the control-by-control record of every test the auditor performed with every result, including exceptions. Complementary user entity controls, the things your customers must do on their side, live there too.

That difference decides the audience. A reader of your SOC 2 learns how your controls work, where they were tested, and what the auditor found. A reader of your SOC 3 learns one thing: an independent CPA firm examined the system over a defined period and reached an opinion. For a security reviewer that is not enough. For a prospect deciding whether to book a demo, it usually is.

SOC 3 vs SOC 2: distribution is the point

A SOC 2 report is a restricted-use document. It is intended for specified parties, in practice your customers, their auditors, and prospects far enough into diligence to sign an NDA. A SOC 3 is a general-use report. You can publish it on a trust page, attach it to a proposal, hand it out at a conference, or link it from a partner directory, with no NDA and no tracking of who received it.

One structural rule follows from this: a SOC 3 is derived only from a Type 2 examination. The SOC 3 opinion speaks to operating effectiveness over a review period, which is what a Type 2 tests. A Type 1, which reports on control design at a single point in time, has no SOC 3 equivalent. If the Type 1 versus Type 2 distinction is the decision you are working through, we cover it in SOC 2 Type 1 vs Type 2.

Who actually uses a SOC 3

Companies with wide funnels get the most from it. A self-serve SaaS product, an SMB-heavy customer base, or a partner ecosystem generates hundreds of light-touch security questions from people who will never sign an NDA just to read an audit report. A published SOC 3 answers most of them without a sales call. Trust pages are the common home: the SOC 3 sits next to the ISO certificate summary and the penetration test attestation letter, and procurement teams doing a first pass can self-serve.

Enterprise-only sellers get less. When every deal runs through a security review with an NDA on file, buyers skip the SOC 3 and request the SOC 2 directly, because their reviewers need the test detail. In those sales motions the SOC 3 mostly serves the top of the funnel: it lets a prospect confirm the examination exists before the NDA stage, which shortens the first conversation.

What a SOC 3 cannot do

It will not satisfy a real security review. Customer security teams and their auditors rely on the system description and the test results, and the SOC 3 omits both by design. Expect every serious buyer to ask for the SOC 2 under NDA regardless of what you publish.

It is not a certification. SOC reports are attestation opinions issued by a CPA firm under AICPA standards, and there is no such thing as SOC 3 certified, no matter how many vendor badges imply otherwise. The AICPA governs how the related logo may be used, and the report speaks only for the period it covers.

It also cannot rescue a bad result. An auditor can technically issue a SOC 3 carrying a qualified opinion, but nobody publishes a general-use report that says controls fell short. In practice a SOC 3 only exists downstream of a clean SOC 2 Type 2, which is one more reason the Type 2 examination deserves the attention.

How you get one

Ask the firm performing your SOC 2 Type 2 to issue a SOC 3 alongside it, and put it in the engagement letter up front. The SOC 3 covers the same system and the same period, and the auditor issues both reports at the same time. Management's description gets condensed to a general-use overview, the opinion is drafted on the SOC 3 form, and the rest of the work is already done, because the examination behind it is the Type 2 you were getting anyway.

Adding a SOC 3 after the Type 2 report date is possible but slower and more expensive, since the firm has to reopen a closed engagement. If there is any chance you will want one, scope it with the Type 2 rather than after it.

What a SOC 3 costs

Scoped with the Type 2, a SOC 3 typically adds $2,000 to $8,000 to the examination fee, and some firms fold it in at little or no increment. Two things drive the number: whether it was in the original engagement letter, and how much rework the general-use description needs. Against the cost of the underlying examination, which we break down in How Much Does SOC 2 Cost?, the SOC 3 is a rounding item. The expensive way to get one is to decide six months after your report ships.

Should you add one?

Add it when strangers evaluate you before any paperwork exists: self-serve signups, SMB buyers, marketplace and partner listings, or a public trust page you want to carry real evidence instead of logos. Skip it when your entire pipeline reaches procurement with an NDA already signed, because those buyers will read the SOC 2 and nothing else. If you are between those cases, the low incremental cost usually settles the question in favor of adding it.

Getting the examination done

BD Emerson performs SOC 1, SOC 2, and SOC 3 examinations directly through its CPA attest arm, from scoping through the signed opinion. If you need the Type 2 that a SOC 3 is built on, start with our SOC 2 Type 2 audit page. For the full picture of which report fits which audience, our SOC audit services page walks through SOC 1, SOC 2, and SOC 3 and how to choose. Talk to an auditor and we will scope it against your reporting period.

About the author

Drew Danner is a Managing Director at BD Emerson. He leads engagements across technology strategy, enterprise AI, M&A technology diligence, and the firm's governance, risk, and security practice, advising buyers, operators, and portfolio companies on decisions where the technical call drives the commercial outcome. His work spans build vs buy decisions, platform implementations, and the security and compliance programs that keep them defensible.
Drew Danner
Drew Danner
Managing Director