
SOC 2 and SOC 3 reports cover the same subject, controls relevant to security, availability, processing integrity, confidentiality or privacy, but they are written for different readers. A SOC 2 is the detailed report a customer's security team reviews, including the system description and, in a Type 2, the auditor's tests and results. A SOC 3 is the AICPA's general use version: a short report with the auditor's opinion that you can publish freely, but it leaves out the detail vendor reviews look for.
Our SOC 2 readiness services prepare the controls and evidence behind both reports; an independent CPA firm performs the examination and issues them. If you are still choosing between a Type 1 and a Type 2, start with our guide to SOC 2 Type 1 vs Type 2.
What is the difference between SOC 2 and SOC 3?
Detail and audience. The AICPA's SOC 3 page says SOC 3 reports address the same controls as SOC 2 reports but do not provide the same level of detail, which is why they are general use reports that can be freely distributed. A SOC 2 is built for readers who will study how your system and controls work.
| SOC 2 | SOC 3 | |
|---|---|---|
| Subject | Controls relevant to security, availability, processing integrity, confidentiality or privacy | The same subject |
| Criteria | The AICPA Trust Services Criteria chosen for the report | The same criteria |
| Written for | Customers, prospects and their security reviewers who need the detail | Anyone; the AICPA calls it a general use report |
| How it is shared | Given to customers and prospects on request | Freely, for example on a public trust page |
| What it contains | Management's assertion, the system description and the auditor's report; a Type 2 adds tests of controls and their results | Management's assertion, the boundaries of the system, principal service commitments and system requirements, and the auditor's report |
| Auditor's test results | Included in a Type 2 | Not part of the AICPA's illustrative SOC 3 |
| Who performs it | A CPA firm | A CPA firm, under the same AICPA guide |
| Best use | Vendor due diligence and security questionnaires | A public signal for prospects and a first check before the detailed review |
What is in a SOC 3 report?
The AICPA's illustrative SOC 3 report has four parts: management's assertion, a description of the boundaries of the system, the principal service commitments and system requirements, and the service auditor's report. Its illustrative SOC 2 Type 2 report has management's assertion, the description of the system, the service auditor's report and the tests of controls with their results.
The practical difference: a SOC 3 tells a reader that an auditor examined your controls against the criteria and what the opinion was. A SOC 2 Type 2 shows how each control works, how the auditor tested it and where it did not operate as described. Security reviewers want that second level, because exceptions in the test results are where risk shows up.
When is a SOC 3 enough, and when do customers need the SOC 2?
A SOC 3 works when the reader wants assurance without detail: a prospect checking your website, a small customer who only needs to know an audit happened, or a sales team that wants something public to show. A SOC 2 is needed when a customer runs vendor due diligence, sends a security questionnaire, or has its own auditors and regulators asking how it oversees suppliers.
The simplest test is to ask. Get the customer's security or procurement team to say in writing which report, which criteria and which period it accepts. If the answer is a SOC 2, a SOC 3 will not substitute for it.
What is the difference between SOC 1, SOC 2 and SOC 3?
The number tells you what is examined, and SOC 3 tells you who may read it:
- SOC 1 examines controls at a service organization that are likely to be relevant to its customers' internal control over financial reporting, according to the AICPA's SOC 1 page. Its readers are those customers and the CPAs who audit their financial statements. Payroll, billing and claims processing are typical services that affect customers' financial reporting.
- SOC 2 examines controls relevant to security, availability, processing integrity, confidentiality or privacy, for customers who need to know how you protect their data and keep their service running.
- SOC 3 reports on the same subject as a SOC 2, with less detail, for anyone.
A company can need more than one. A payroll provider, for example, may be asked for a SOC 1 by customers' auditors and a SOC 2 by their IT teams, and may publish a SOC 3 for everyone else.
Can you get a SOC 3 without a SOC 2?
Yes. A SOC 3 comes from its own examination by a CPA firm: the AICPA's SOC 2 guide, written for CPAs who perform SOC 2 and SOC 3 examinations, includes guidance for preparing and issuing one. The readiness work is identical either way, because both reports cover the same criteria and the same controls. If you are getting a SOC 2 anyway, ask your CPA firm whether it can issue the SOC 3 alongside it and what that adds to the fee.
Which fits a small team?
Start with whatever your customers ask for; if their security questionnaires name SOC 2, that comes first. Add a SOC 3 when you want a public document for your website and prospects, so the detailed SOC 2 only goes to customers who need it. A SOC 3 on its own usually will not satisfy a vendor review, because it omits the system description and test results reviewers check.
A small team should also keep the scope tight. Every Trust Services Criteria category you add brings more controls, more evidence and a higher fee, and a SOC 3 reports on the same scope as the examination behind it.
What drives the cost and effort of SOC 2 and SOC 3?
We publish no prices. The budget has the same lines whichever report you order:
- Readiness work: scoping, the gap assessment and evidence planning.
- Technical remediation: MFA, device management, logging, backups and recovery testing, whatever the gaps require.
- Compliance software, if you want a platform to track evidence. It watches controls; it does not configure them.
- The CPA firm's fee, which moves with the report type, the criteria and systems in scope and the length of the period, plus whatever it charges to issue a SOC 3.
Our SOC 2 audit cost guide breaks those lines down further.
How does NetSys help with SOC 2 and SOC 3?
We run readiness as an operating change, not a document exercise. We choose the criteria and systems the report should cover based on what customers ask for, draft the system description, run the gap assessment, implement the technical controls in Microsoft 365, Entra ID, Intune and your cloud platform, and write policies your team will follow. Every control gets a named owner, and an evidence calendar keeps records coming on schedule, exported from the systems we already run wherever possible.
When you are ready, we help you select an independent CPA firm, agree the scope and period, and support fieldwork by answering requests from the evidence library. We do not perform the examination or issue reports. Agreements run month to month, and you can start with our free remote external penetration test, limited to available information and an agreed external scope.
Book a call with a NetSys engineer to go through the report your customers are asking for and the scope that would satisfy them.
Frequently asked questions
What is the difference between SOC 2 and SOC 3?
Both cover controls relevant to security, availability, processing integrity, confidentiality or privacy. A SOC 2 includes the full system description and, in a Type 2, the auditor's tests and results, and goes to customers who need that detail. A SOC 3 is a shorter general use report that can be freely distributed.
Can we post our SOC 2 report on our website?
The report the AICPA designates for free distribution is the SOC 3. Publish a SOC 3 if you want a public document, and share the SOC 2 with customers and prospects who request it.
Which fits a small team?
The SOC 2 your customers ask for, kept to the smallest scope they accept, with a SOC 3 added if sales wants something public. A SOC 3 alone rarely satisfies a vendor review.
What affects the cost, implementation and support?
Readiness work, remediation, optional compliance software and the CPA firm's fee, which depends on the report type, scope and period. Support continues each year, because customers judge how current a report is.
What is the difference between SOC 1, SOC 2 and SOC 3?
SOC 1 covers controls relevant to customers' financial reporting, for those customers and their auditors. SOC 2 covers security-related controls for customers who need detail. SOC 3 covers the same ground as SOC 2 in a short report anyone can read.
Does a SOC 3 report include test results?
Not in the AICPA's illustrative SOC 3, which contains management's assertion, the system's boundaries, the principal service commitments and system requirements, and the auditor's report. Test results appear in a SOC 2 Type 2.
Discuss soc 2 readiness services for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

