Quick answer
All three are AICPA reports but for different purposes. SOC 1 covers controls that affect a client's financial reporting. SOC 2 covers data-security controls (security, availability, processing integrity, confidentiality, privacy) and is shared under NDA. SOC 3 is a short, public version of a SOC 2 you can post on your website.
SOC 1 vs SOC 2 vs SOC 3 comparison table
| SOC 1 | SOC 2 | SOC 3 | |
|---|---|---|---|
| Focus | Financial-reporting controls (ICFR) | Security & privacy controls | Security & privacy controls |
| Based on | Trust in financial data | Trust Services Criteria | Trust Services Criteria |
| Detail level | Detailed | Detailed | High-level summary |
| Audience | Clients' auditors & finance | Customers, prospects (under NDA) | Anyone public |
| Distribution | Restricted | Restricted | General use / shareable |
| Type I & II? | Yes | Yes | Period only (no Type I/II split) |
What is SOC 1?
A SOC 1 report covers controls at a service organization that are relevant to its clients' internal control over financial reporting (ICFR). It exists so your customers' financial auditors can rely on your controls. It is the right report when what you do flows into someone else's books.
- Typical for: payroll processors, payment platforms, billing and ERP providers
- Answers: 'Could this vendor's controls affect our financial statements?'
- Comes in Type I (design) and Type II (operating effectiveness), like SOC 2
What is SOC 2?
A SOC 2 report covers controls mapped to the five Trust Services Criteria Security, Availability, Processing Integrity, Confidentiality, and Privacy. It is detailed and restricted-use, shared with customers and prospects under NDA. For most SaaS and cloud companies, this is the report that matters. Learn more in What is SOC 2?
What is SOC 3?
A SOC 3 report is built from the same audit as a SOC 2 but strips out the detailed control descriptions and test results, leaving a short, easy-to-read summary. Because it contains no sensitive detail, it is general-use: you can publish it on your website or hand it to any prospect as a trust seal.
SOC 2 for buyers, SOC 3 for the public
A common setup is to run a SOC 2 Type II for enterprise procurement (shared under NDA) and publish a SOC 3 openly so anyone can verify you passed without exposing your control details.
Which SOC report do I need?
- Your service affects customers' financial statements → SOC 1
- Customers want assurance you protect their data → SOC 2 (start here if you're SaaS)
- You want a public, shareable trust badge → add SOC 3 on top of your SOC 2
Still deciding on the SOC 2 report format? Compare Type I vs Type II next.

