Because SOC 3 reports do not carry the same level of detail as SOC 2, they are considered general-use reports and can be freely distributed.
SOC 3 addresses controls relevant to security, availability, processing integrity, confidentiality, and privacy, the same Trust Services Criteria that underpin a SOC 2, so your clients can preview your SOC 2 via the SOC 3.
SOC 3 sits within the AICPA SOC suite alongside SOC 1 and SOC 2, so the assurance it provides is understood by buyers and their advisors.
A publishable report answers the security question before a prospect has to ask it, rather than waiting on an NDA to share a SOC 2.
Appropriate when your customers and their auditors require detailed assurance, and you have no need for a publishable report.
The common pairing. SOC 2 satisfies customer due diligence under an NDA, and SOC 3 gives sales and marketing something to publish.