Public Trust Assurance
If you have any questions or need assistance, please don't hesitate to contact us.

No. Type I and Type II are report distinctions used for SOC 1 and SOC 2. SOC 3 is a general-use Trust Services report designed for broad distribution and does not use Type I or Type II labels.
The SOC 3 report identifies the period covered by the examination and communicates the independent practitioners opinion on whether applicable controls were effective to meet the selected Trust Services Criteria during that period.
SOC 2 and SOC 3 address Trust Services subject matter, but the reports serve different audiences. SOC 2 contains detailed controls, tests, and results for restricted use, while SOC 3 omits that detail and is intended for general use.
SOC 3 is appropriate when an organization wants broadly distributable independent assurance. Stakeholders who need detailed control descriptions, testing procedures, or exceptions should request the appropriate SOC 2 report.
SOC 3 provides concise, general-use assurance for broad audiences while preserving the detailed control and testing information for restricted-use reporting.
SOC 3 communicates independent Trust Services assurance in a concise format intended for broad distribution.
SOC 2 provides the detailed control descriptions, auditor tests, and results needed for deeper due diligence.

Ready to learn more about Trust Services Criteria?
