Publish a SOC 3 from your SOC 2 program
What is SOC 3?
SOC 3 is a public, general-use report based on the AICPA's Trust Services Criteria — the same criteria that underpin SOC 2. The difference is the audience and the level of detail: a SOC 2 report is restricted and includes the auditor's detailed description of controls and test results, shared with customers under NDA, while a SOC 3 is a short, summary-level report you can freely distribute — post it on your website, hand it to any prospect, no NDA required.
How it relates to SOC 2
A SOC 3 is built on the same controls, evidence, and audit period as a SOC 2 Type 2 and is issued by the same CPA firm. In practice, organizations that already pursue SOC 2 add SOC 3 as a public-facing companion at little additional cost — it is not a separate program.
Why publish one
SOC 3 is a practical trust and marketing asset. It lets you demonstrate that an independent CPA firm examined your controls against the Trust Services Criteria without exposing the sensitive detail in your SOC 2. That makes it ideal for top-of-funnel sales, public trust pages, and buyers who want assurance early.
How episki helps
A SOC 3 report is the public face of your SOC 2 work, and episki keeps both fed from the same controls and evidence. The Trust module adds a branded trust center where the report sits alongside NDA-gated documents and agent-answered questionnaires, with the portal theme inlined into the first paint so it never flashes episki's colors. Start a free trial or book a demo.
SOC 3 outcomes with episki
Why teams choose episki for SOC 3
- Same Trust Services Criteria as SOC 2
- Summary report without detailed test results
- Freely distributable to anyone
- Post it publicly on your trust page
- Speeds up early sales conversations
- Backs up your SOC 2 for buyers who can't see it
- Same controls and evidence as SOC 2
- Issued by the same CPA firm
- Crosswalk to ISO 27001 and CSA STAR
SOC 3 readiness inside episki
Plug episki into your stack and work directly from this checklist during the free trial.
- ✓ SOC 2 Type 2 program in place
- ✓ Trust Services Criteria scoped (Security + any others)
- ✓ Control evidence current and complete
- ✓ CPA firm engaged for SOC 2 / SOC 3
- ✓ Public trust-page placement for the report
- ✓ Crosswalks to ISO 27001 and CSA STAR