What does SOC 3 report mean on the CPA exam?
SOC 3 report. A general use report on the same trust services criteria as a SOC 2, without the system description or the tests and results. The lighter report is the one that may be handed out freely.
Defined against AICPA SOC 3 Guide; TSP Section 100.
Which CPA exam sections use SOC 3 report?
SOC 3 report appears in the AUD section of the CPA exam.
Related terms
- SOC 2 report: A report on a service organization's controls against the trust services criteria, covering security plus any of availability, processing integrity, confidentiality, and privacy that are selected.
- general use: A report anyone may read, such as a SOC 3.
- SOC 1 Type 1 report: A report on the fairness of the description and the suitability of the design of controls, at a point in time.
- SOC 1 Type 2 report: A report covering the description, the suitability of design, and the operating effectiveness of controls over a period.
- trust services criteria: The AICPA's control criteria for a SOC 2 engagement, in five categories: security, availability, processing integrity, confidentiality and privacy.
- auditor's report: The document carrying the opinion, with its sections in a fixed order.