Overview
A SOC 3 report confirms the successful audit of your information security and is a general-use assurance report on controls relevant to security, availability, processing integrity, confidentiality or privacy. Unlike a detailed SOC 2 report, it does not contain a comprehensive description of the individual controls and audit procedures. It can therefore be made publicly available and used, for example, in customer communications.
To whom is the standard relevant?
A SOC 3 report provides a compact, generally understandable confirmation of the successfully completed audit. This makes it ideal for marketing, sales and tenders. It can be shared publicly with clients, prospects and business partners.
- Typical use cases
- Publication on the corporate website
- Sales and marketing
- Tenders
- Investor communications
- Building trust with potential new clients
Scope of services
- Summary of the SOC 2 audit
- General-use assurance report
- No confidential details
Benefits
- Publicly usable assurance report
- Greater trust among prospects
- Support for sales and marketing
- Transparent communication of information security
- Complement to the detailed SOC 2 report
