HomeServices › SOC 3 Audit
Licensed CPA Firm · SSAE 18 · AICPA

SOC 3 Audit
under SSAE 18

A public, summarized report, based on your SOC 2 audit, that you can freely publish on your website to demonstrate your security compliance — without exposing confidential technical detail.

SaaS Cloud Fintech Trust Center Marketing & Sales
SOC 3 Report — Public SSAE 18 Audit
AICPA Member CPA Licensed Firm SSAE 18 · AT-C Section 320 USA & LATAM Based on SOC 2 Type II
SOC 2 vs SOC 3

How is SOC 3 different from SOC 2?

SOC 3 is based on the same audit as your SOC 2, but it's designed to be shared freely — without exposing the technical detail of your controls.

Swipe to see the full table
CriteriaSOC 2FullSOC 3Public
Audit BasisA full audit of the Trust Services Criteria (security, availability, integrity, confidentiality, privacy).The same audit as the SOC 2 — not a separate or additional process.
Level of DetailIncludes the full system description, the tests performed, and detailed results for each control.A high-level summary with the auditor's opinion, without the technical detail of the tests.
AudienceClients and prospects, typically under a non-disclosure agreement (NDA).The general public — no distribution restrictions.
Where Is It Used?Security questionnaires, vendor reviews, procurement teams.Website, "Trust & Security" page (Trust Center), sales materials.
Does It Replace the Other?No — it remains the document that clients with stricter security requirements will ask for.No — it's a public-facing complement, not a substitute for SOC 2.
Use Cases

What types of companies use a SOC 3 report?

Any organization that already has a SOC 2 in place and wants to publicly demonstrate compliance, without exposing the confidential detail of its controls.

Swipe to see the full table
Company TypeWhy SOC 3 HelpsWhere It's UsedNeeds SOC 2 First?
SaaS CompaniesSpeeds up the sales cycle by answering prospects' security questions upfront."Trust & Security" page (Trust Center)Yes
Cloud / Hosting ProvidersShows enterprise clients that the infrastructure meets recognized standards.Corporate website and master agreementsYes
Fintech & Payment ProcessorsBuilds trust with end users and banking partners without publishing sensitive technical details.App, website, regulatory materialsYes
Marketing & Sales TeamsUse the SOC 3 seal as proof of compliance in sales proposals and RFPs.Proposals, landing pages, initial questionnairesYes
Growth-Stage StartupsAnswers basic security questions from investors and early enterprise clients.Investment data room, websiteYes
Frequently Asked Questions

Everything you need to know about SOC 3

It's a public attestation report, under the same AICPA SSAE 18 framework, that summarizes the auditor's opinion on an organization's Trust Services Criteria — without including the confidential technical detail of the control tests.
No. SOC 3 is issued from the same SOC 2 Type II audit — it's not an independent audit process, but a summarized, publicly shareable version of the same work.
Practically none. Since it's issued from the same audit, SOC 3 is delivered alongside the SOC 2 Type II, with no additional observation period or execution required.
The full SOC 2 includes the detailed system description and the results of each control test, and is shared under confidentiality. SOC 3 summarizes that same opinion without the sensitive detail, so it can be published freely.
The most common place is a "Trust & Security" page (Trust Center) on your website, and to use it as supporting material in sales proposals, RFPs, and initial security questionnaires.
Yes. Since it's based on the same AICPA SSAE 18 framework as SOC 2, it's recognized in the United States, Latin America, and other markets where service providers are asked for security assurances.

Need a SOC 3 report?

If you already have or are about to start your SOC 2, we can include SOC 3 as part of the same process — at no additional execution cost.