SOC 3 – Publicly usable report based on a SOC 2 audit

Overview 

A SOC 3 report confirms the successful audit of your information security and is a general-use assurance report on controls relevant to security, availability, processing integrity, confidentiality or privacy. Unlike a detailed SOC 2 report, it does not contain a comprehensive description of the individual controls and audit procedures. It can therefore be made publicly available and used, for example, in customer communications. 

To whom is the standard relevant? 

A SOC 3 report provides a compact, generally understandable confirmation of the successfully completed audit. This makes it ideal for marketing, sales and tenders. It can be shared publicly with clients, prospects and business partners. 

  • Typical use cases
    • Publication on the corporate website
    • Sales and marketing
    • Tenders
    • Investor communications
    • Building trust with potential new clients

Scope of services 

  • Summary of the SOC 2 audit
  • General-use assurance report
  • No confidential details


Benefits 

    • Publicly usable assurance report
    • Greater trust among prospects
    • Support for sales and marketing
    • Transparent communication of information security
    • Complement to the detailed SOC 2 report


FAQ