SOC 3 Report: What is it?
Trust Services Report for Service
Organization: SOC 3 engagements use the
predefined criteria in Trust Services Principles,
Criteria and Illustrations that also are used in
SOC 2 engagements.
The key difference between a SOC 2 report
and a SOC 3 report is that a SOC 2 report,
which is generally a restricted-use report,
contains a detailed description of the service
auditor’s tests of controls and results of those
tests as well as the service auditor’s opinion
on the description of the service organization’s
system. A SOC 3 report is a general-use report
that provides only the auditor’s report on
whether the system achieved the trust services
criteria (no description of tests and results or
opinion on the description of the system).
It also permits the service organization to
use the SOC 3 seal on its website. For more
information about the SysTrust for Service
Organization seal program go to webtrust.org.
For more details on difference between a
SOC 2 report and a SOC 3 report, refer to
Guide: Reporting on Controls at a Service
Organization (SOC 2SM
).
SOC 3 reports can be issued on one or multiple
Trust Services principles (security, availability,
processing integrity, confidentiality and privacy).