Attestation · Last verified

SOC 3

SOC 3 is an AICPA attestation report: a general-use summary that, unlike SOC 2, can be freely distributed without the same level of detail. It belongs to the AICPA's SOC suite of service offerings CPAs may provide in connection with an organization's controls.

Class
Attestation
Owner
AICPA
Last verified

What it is

SOC 3 sits in the AICPA's SOC reporting suite alongside SOC 1 and SOC 2. The AICPA's SOC 3 page does not carry a one-line definition, but it sets out the report's content and how it may be used: "Like SOC 2, SOC 3 reports address controls relevant to security, availability, processing integrity, confidential and privacy. However, they do not provide the same level of detail." Distribution is the practical difference — "they are considered general use reports and can be freely distributed". The output is a report, not a certificate.

Who owns it

SOC 3 is owned and maintained by the AICPA, which states that it "promulgates the professional standards for SOC engagements".

Who assesses it

The AICPA describes System and Organization Controls as "a suite of service offerings CPAs may provide in connection with system-level controls of a service organization or entity-level controls of other organizations". The AICPA's SOC 3 page itself names no assessor, and whether a SOC 3 examination may only be performed by a licensed CPA firm was not verified in the sources reviewed as of 29 August 2026.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"SOC 3." Certifidex, FutureTechnologies. Last verified 29 August 2026. https://certifidex.com/frameworks/soc-3

All frameworks & audits →