SOC 3

The SOC report you can publish publicly

A SOC 3 report addresses the same Trust Services Criteria as a SOC 2, but without the detailed description of tests and results. That makes it a general-use report you can distribute freely, publish on your website, and hand to any prospect who asks, without the need for an NDA. ControlCase delivers SOC 3 attestations through a CPA partner, so the examination is performed and the report is issued by licensed practitioners.

Assess Once, Comply to Many

Freely Distributable

Because SOC 3 reports do not carry the same level of detail as SOC 2, they are considered general-use reports and can be freely distributed.

The SOC 3 is essentially a publicly accessible version of the SOC 2

SOC 3 addresses controls relevant to security, availability, processing integrity, confidentiality, and privacy, the same Trust Services Criteria that underpin a SOC 2, so your clients can preview your SOC 2 via the SOC 3.

A Recognized Standard

SOC 3 sits within the AICPA SOC suite alongside SOC 1 and SOC 2, so the assurance it provides is understood by buyers and their advisors.

Shorten Your Sales Cycle

A publishable report answers the security question before a prospect has to ask it, rather than waiting on an NDA to share a SOC 2.

What is a SOC 3 Report?

What is a SOC 3 Report?

SOC 3 is formally titled SOC for Service Organizations: Trust Services Criteria for General Use Report. Like SOC 2, a SOC 3 report addresses controls relevant to security, availability, processing integrity, confidentiality, and privacy. The difference is depth. SOC 3 does not provide the same level of detail as SOC 2, and for that reason, it is considered a general-use report that can be freely distributed.

In practice, this means the two reports serve different audiences from the same underlying work. A SOC 2 gives your customers and their auditors a detailed description of your system, the tests performed, and the results. A SOC 3 provides everyone else with the practitioner's opinion without the underlying details. AICPA publishes an Illustrative SOC 3 Report showing the expected form, and its CPE catalog treats SOC 2 and SOC 3 planning, execution, and reporting as a single subject.

Why Choose ControlCase for SOC 3?

A CPA Partnership Built for Attestation Work
SOC 3 reports must be issued by licensed CPAs. ControlCase works hand-in-hand with our CPA partners to handle the attestation portion of SOC engagements by leveraging the Information Technology experts within ControlCase with the Accounting and Assurance experts who are CPAs, and the report comes from practitioners who are qualified to sign it.
One Examination, Two Reports
SOC 3 addresses the same Trust Services Criteria as SOC 2. A single examination supports the detailed report your customers' auditors need and the publishable report your marketing team wants.
One Audit Across Your Framework Set
Most organizations pursuing a SOC 3 also carry SOC 2, ISO 27001, or PCI DSS obligations. ControlCase’s technology offering, Compliance Hub, provides control mapping for other standards and regulations out of the box, so evidence gathered once supports multiple reports through the “One Audit” approach instead of running each engagement in isolation. Compliance Hub is part of the service offering at no additional cost.
A Dedicated Point of Contact
ControlCase assigns a named point of contact to each engagement who provides support and coordination from kickoff through report issuance.

Where SOC 3 Fits

Path 1
SOC 2 Only

Appropriate when your customers and their auditors require detailed assurance, and you have no need for a publishable report.

Path 2
SOC 2 and SOC 3

The common pairing. SOC 2 satisfies customer due diligence under an NDA, and SOC 3 gives sales and marketing something to publish.

ControlCase SOC 3 Process

STEP 01
Scoping and Criteria Selection
Confirm whether you need SOC 3 alongside your SOC 2, select which Trust Services Criteria are in scope, define the system boundary, and assign your point of contact.
STEP 02
System Description Support
A SOC engagement rests on management's description of the system. ControlCase advises on structure and ultimate completeness, while the description is written by and remains management's own.
STEP 03
Examination Fieldwork
The CPA conducts the examination alongside your ControlCase assessor.
STEP 04
Report Issuance
ControlCase issues via the CPA partner, the SOC 3 report with the practitioner's opinion, ready to share with customers and prospects under NDA, and agrees the timing of your next annual cycle.
STEP 01
Scoping and Criteria Selection
Confirm whether you need SOC 3 alongside your SOC 2, select which Trust Services Criteria are in scope, define the system boundary, and assign your point of contact.
STEP 02
System Description Support
A SOC engagement rests on management's description of the system. ControlCase advises on structure and ultimate completeness, while the description is written by and remains management's own.
STEP 03
Examination Fieldwork
The CPA conducts the examination alongside your ControlCase assessor.
STEP 04
Report Issuance
ControlCase issues via the CPA partner, the SOC 3 report with the practitioner's opinion, ready to share with customers and prospects under NDA, and agrees the timing of your next annual cycle.

Ready to Publish Your Security Assurance?

Book Expert Time
Chat with an Advisor Available now
Chat with our representative
Compliance Advisor
Compliance Advisor HUMAN · LIVE
Online now · Replies within 2 minutes