Attestation · Last verified
SOC 3
SOC 3 is an AICPA attestation report: a general-use summary that, unlike SOC 2, can be freely distributed without the same level of detail. It belongs to the AICPA's SOC suite of service offerings CPAs may provide in connection with an organization's controls.
- Class
- Attestation
- Owner
- AICPA
- Last verified
What it is
SOC 3 sits in the AICPA's SOC reporting suite alongside SOC 1 and SOC 2. The AICPA's SOC 3 page does not carry a one-line definition, but it sets out the report's content and how it may be used: "Like SOC 2, SOC 3 reports address controls relevant to security, availability, processing integrity, confidential and privacy. However, they do not provide the same level of detail." Distribution is the practical difference — "they are considered general use reports and can be freely distributed". The output is a report, not a certificate.
Who owns it
SOC 3 is owned and maintained by the AICPA, which states that it "promulgates the professional standards for SOC engagements".
Who assesses it
The AICPA describes System and Organization Controls as "a suite of service offerings CPAs may provide in connection with system-level controls of a service organization or entity-level controls of other organizations". The AICPA's SOC 3 page itself names no assessor, and whether a SOC 3 examination may only be performed by a licensed CPA firm was not verified in the sources reviewed as of 29 August 2026.
Sources
- AICPA — SOC 3 (scheme owner) ↗ — accessed
- AICPA — System and Organization Controls: SOC Suite of Services ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.