SOC 3 Reports — Public Trust Attestation for Marketing & Sales
SOC 3 is the general-use, public companion to a SOC 2 report — issued by the same licensed CPA firm, tested against the same AICPA Trust Services Criteria, and typically produced alongside a SOC 2 Type II engagement rather than pursued on its own. Where a SOC 2 report is a restricted-use document shared under NDA with specific customers and prospects, a SOC 3 report omits the detailed description of tests and results and can be freely published — most commonly as a downloadable PDF and a "SOC 3" trust seal on a company's website.
Mutex Systems prepares SOC 3 reports as part of a combined SOC 2 Type II engagement, giving sales and marketing teams a publicly shareable trust artefact without exposing the detailed control-testing narrative reserved for the restricted-use SOC 2 report.
- Category
- Compliance Framework
- Jurisdiction
- United States
- Issuing Body
- American Institute of Certified Public Accountants (AICPA)
- Current Version
- 2017 Trust Services Criteria, as revised — the same criteria set underlying SOC 2
- Who It's For
- SaaS and technology companies that already hold, or are pursuing, a SOC 2 Type II report and want a public-facing trust signal for their website, sales collateral, and top-of-funnel prospect conversations, without sharing the full restricted-use report before an NDA is in place.
Core Domains
A Practical Compliance Path
- 01
Run Alongside a SOC 2 Type II Engagement
SOC 3 is derived from the same underlying testing as a SOC 2 Type II report, so it is almost always scoped and delivered as a companion output rather than a standalone audit.
- 02
Public-Facing System Description
Prepare a system description suitable for general audiences, since the SOC 3 report is written knowing it will be read outside a restricted, NDA-protected context.
- 03
Auditor Opinion Issuance
The CPA firm issues the SOC 3 opinion alongside the SOC 2 Type II report, based on the same observation-period testing.
- 04
Publish & Distribute
Post the SOC 3 report and trust seal publicly — commonly on a trust centre page, in sales collateral, and in response to lightweight prospect due-diligence requests that do not warrant the full SOC 2 report.
A Public Trust Artefact, Built as a By-Product of Real SOC 2 Work
SOC 3 preparation is scoped as a natural output of the same SOC 2 Type II readiness and audit engagement, rather than sold as a separate stripped-down alternative to a real attestation.
- Delivered alongside a genuine SOC 2 Type II engagement, not as a shortcut around the underlying control testing
- Public-facing system description written for a general audience, distinct from the restricted-use SOC 2 report's more technical detail
- Positioned specifically for sales and marketing use — a trust-centre asset and top-of-funnel proof point, not a substitute for the SOC 2 report enterprise buyers will still ask for during procurement
The Same Live Evidence Base, One Public Output and One Restricted
Because SOC 3 rides on the same Trust Services Criteria evidence as SOC 2, grComply generates both outputs from one continuously updated evidence base rather than running two separate collection efforts for what is ultimately the same underlying control testing.
- Trust Services Criteria evidence collected once during the Type II observation period supports both the restricted-use SOC 2 report and the general-use SOC 3 report
- A public-facing trust centre summary can be generated directly from live completion and audit-trail data, kept current between annual SOC 3 renewals
- Cross-framework mapping means the same evidence continues to satisfy ISO 27001 or NIST CSF controls where those frameworks are also in scope
grComply is Mutex Systems' own multi-tenant GRC automation platform — the framework library, hybrid scanning, risk and audit workflow, and AI-assisted compliance behind every point above are live in production today.
See How grComply WorksCommon Questions About SOC 3
What is the actual difference between SOC 2 and SOC 3?
Both are built on the same AICPA Trust Services Criteria and, in practice, are usually tested through the same audit engagement. The difference is in the report itself and how it can be shared: a SOC 2 report includes a detailed description of the system, the specific controls tested, and the results of each test, and is restricted-use — shared only with existing and prospective customers, typically under NDA. A SOC 3 report gives a general summary and the auditor's overall opinion without the detailed test-by-test narrative, and is general-use — it can be freely published with no NDA required.
Can we get a SOC 3 report without also doing SOC 2?
Technically a SOC 3 can be scoped on its own, but in practice it is almost always produced as a by-product of a genuine SOC 2 Type II engagement, since the underlying control testing is identical. Pursuing SOC 3 in isolation offers little practical benefit — the value of a SOC 3 seal comes from it being backed by real Type II-grade testing, and most enterprise buyers will eventually ask for the full SOC 2 report during procurement regardless.
Is SOC 3 Type I or Type II?
SOC 3 does not carry a separate Type I / Type II distinction the way SOC 2 does, but it is typically produced from a SOC 2 Type II engagement, since a Type II report — testing operating effectiveness over an observation period — is what most SOC 3 reports in the market are actually derived from.
Where should a SOC 3 report be published?
Most commonly on a dedicated "Trust Centre" or "Security" page on the company website, as a downloadable PDF alongside the associated trust seal graphic, and referenced in sales and marketing collateral as a top-of-funnel proof point ahead of the more detailed SOC 2 report shared later in a sales cycle.
Can Mutex Systems prepare a SOC 3 report for us?
Yes. Mutex Systems prepares SOC 3 reports as a companion output of a SOC 2 Type II readiness and audit engagement, giving sales and marketing teams a publicly shareable trust artefact alongside the restricted-use SOC 2 report.
Ready to Start Your SOC 3 Programme?
Send us your current posture and timeline. Within two working days you will receive a written response and a proposed scoping call.