AICPA · SOC 3 (SOC for Service Organizations: Trust Services Criteria for General Use Report)
Does SOC 3 require a penetration test?
A SOC 3 is a short, general-use report built from the same audit work as a SOC 2. It contains no detailed control descriptions or test results, which is exactly why it can be published on a public website.
The short answer
A SOC 3 imposes no additional testing requirement. It is derived from a SOC 2 Type II engagement, so whatever testing supported the SOC 2 supports the SOC 3.
Who it applies to
Companies that already have a SOC 2 and want something they can post publicly without an NDA.
In detail
The distinction is audience, not rigor. A SOC 2 report contains the system description, the control matrix, the auditor's tests and the results, and is distributed under NDA to customers who ask. A SOC 3 contains the auditor's opinion and a short system overview, and can be handed to anyone.
Because the underlying engagement is the same, adding a SOC 3 to an existing SOC 2 Type II is usually a small incremental cost. It is worth it for companies whose sales motion is self-serve or whose buyers want to see assurance before they will talk.
What to have in scope
- Nothing beyond the SOC 2 Type II engagement it derives from
Questions people ask
What is the difference between SOC 2 and SOC 3?
Both use the Trust Services Criteria and come from the same audit. A SOC 2 includes the system description, control matrix and detailed test results, and is shared under NDA. A SOC 3 is a short general-use summary with the auditor's opinion and no test detail, and can be published openly.
Related frameworks
This page describes published standards and regulations and is not legal advice. Where a rule is proposed rather than in force, it is labelled as such. Confirm obligations with your auditor or counsel.
Get a scoped price without a discovery call
Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.