- What they do
- Enterprise multi-framework
- Who they help
- Tevora is an enterprise multi-framework based in Irvine, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework Assurance Reports
SOC 3
SOC 3 is the general-use version of a SOC 2 examination. It covers the same AICPA Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy) and is performed by the same CPA firm under the same attestation standards, but the published report contains only management's assertion, the auditor's opinion and a short system overview.
Because it omits the control list and test results, the organization can post it publicly, which is why it is used as a marketing and procurement document.
A SOC 3 is only issued as a Type 2 (operating effectiveness over a period), and it is normally produced alongside the SOC 2 from the same testing rather than as a separate audit. The written obligations are the same as SOC 2: a system description, documented policies and controls for each criterion in scope, and a management assertion the auditor can test against.
help
Who has to comply
Voluntary. Service organizations that already undergo SOC 2 and want a public-facing summary for prospects and partners. There is no legal or contractual mandate for SOC 3 by itself.
What the assessor asks to see
Identical to the SOC 2 Type 2 evidence set: system description and assertion; policies for each in-scope trust services category; control matrix mapped to the criteria; populations and samples for access, change, incident, vendor and monitoring controls; evidence of the controls operating over the period.
Assessors
Who assesses SOC 3
A licensed CPA firm performing the SOC 2 examination; the SOC 3 is issued by the same service auditor. Accredited by State board CPA licensure and the AICPA peer review program. No scheme-level accreditor.
No firm has claimed a SOC 3 assessor listing yet. Claim yours →
Consultants
Who helps with SOC 3
Same ecosystem as SOC 2: readiness consultants and GRC platform vendors prepare policies, controls and evidence; the SOC 3 is then a deliverable option added to the SOC 2 engagement with the CPA firm.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- Full-service GRC + vCISO
- Who they help
- Truvantis is a full-service GRC + vCISO based in San Francisco, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- vCISO.com is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- ISO 27001 / SOC 2
- Who they help
- Isecurion is an ISO 27001 / SOC 2 based in Bangalore, India. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- Pentest + SOC 2 readiness
- Who they help
- Illume Intelligence is a pentest + SOC 2 readiness based in Calicut, Kerala, India. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- ISO 27001 + CREST pentest
- Who they help
- Precursor Security is an ISO 27001 + CREST pentest based in Leeds, UK. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for SOC 3
Tools that name this framework in their own material.
Related reading
- SOC 2 vs SOC 3 compliance: what's the differenceExplains why a SOC 3 exists only on top of a SOC 2 examination and what gets stripped out of the public version.Withum
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for SOC 3
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with SOC 3
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.