Skip to main content
Image coming soon

AICPA SOC 3 Trust Services Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
AICPA SOC 3 · Trust Services Criteria · Evidence & Implementation Kit
Earn a public SOC 3 report on the Trust Services Criteria, without decoding the criteria yourself.
Every part of a SOC 3 handed to you as an adopt-ready control, from the common criteria and the optional trust services categories to the assertion and public use, with the evidence your auditor examines.
SOC-3-ready in a weekend, not a quarter.

Here is the honest situation. A SOC 3 is the trust seal you can post publicly: a general-use report on the same Trust Services Criteria as SOC 2, security always, plus optional availability, processing integrity, confidentiality and privacy, but without the confidential test detail, so you can share it with anyone. Earning it means implementing the common criteria, mapped to the COSO framework, and any additional categories, and passing a CPA examination. Building that and the evidence is weeks of work, and a control with no operating evidence is exactly where the SOC report qualifies.

This Kit removes that build. It is every part of a SOC 3 written as an adopt-ready control you personalize in a weekend, with the evidence your auditor examines.

What you get, the moment you buy

35
Criteria as adopt-ready controls. Every part of a SOC 3, from the common criteria and the optional availability, processing integrity, confidentiality and privacy categories to the assertion, written so you personalize and apply it.
35
Evidence-they-examine checklists. For each control, exactly what your auditor examines, plus where the SOC report qualifies, so you close the gap before the examination.
1
SOC 3 Control Matrix, pre-built. Every criterion in a working spreadsheet, ready to record status and evidence location across the service organization.
1
Gap & Readiness Assessment. Score each criterion and the workbook returns your SOC 3 readiness as a single percentage, and exactly what to fix next.

Grounded in the AICPA Trust Services Criteria and the SOC 3 general-use report, with the common criteria mapped to the COSO framework and the optional availability, processing integrity, confidentiality and privacy categories called out. Editable Word and Excel files.

A SOC 3 is a trust seal you can post publicly
Unlike a SOC 2, a SOC 3 report is general-use: you can put it on your website and hand it to any prospect. It runs on the same criteria, so the work you do for one supports the other. This Kit builds those criteria, so you earn a report you can actually share.

What one control looks like

This is scoping the SOC 3 and selecting the trust services categories, where readiness begins. All 35 are built to this depth.

SOC3-1 Distinguish SOC 3 from SOC 2 and select the report type SCOPE
Put this in place

[Service Organization] shall formally decide to pursue a SOC 3 examination, document that a SOC 3 is a general-use report suitable for public distribution and trust-seal use, and record that it shares the underlying examination and Trust Services Criteria with a SOC 2 while excluding the detailed description of tests performed and the results of those tests.

Practitioner note.

The SOC 3 examination follows the same attestation standard as SOC 2 type 2; only the level of reported detail differs.

Evidence your auditor examines
  • Board or management decision memo authorizing a SOC 3 examination
  • Comparison document contrasting SOC 2 restricted-use and SOC 3 general-use reports
  • Engagement letter with the CPA firm naming the SOC 3 report type
  • Communication plan describing intended public posting of the report
Common finding they raise: Organizations often assume a SOC 3 can be swapped for a SOC 2 with enterprise buyers who require the detailed test results, or conversely restrict a SOC 3 unnecessarily.

Why this is not another template pack

  • The evidence is the point. A control with no operating evidence qualifies the report. This tells you what your auditor examines and where the report qualifies, for every criterion.
  • Common criteria and categories built in. The COSO-mapped common criteria (security) and the optional categories are written into the controls, so you scope and prepare for the report you want.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. The Trust Services Criteria underpin SOC 2 and align with ISO 27001, so this work supports your wider assurance program.

Who buys this

Service organizations that want a public trust report, the compliance and security leads who own it, and consultants preparing for a SOC examination. Whether it is a first report or an annual cycle, you save weeks and walk in with the criteria and evidence ready.

By the end of the weekend you will have
✓  An adopt-ready control for all 35 criteria
✓  A completed SOC 3 control matrix
✓  The evidence your auditor examines
✓  Your common criteria and categories anchored
✓  A readiness percentage and a fix list
✓  The qualifications designed out

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

What is the difference from SOC 2? A SOC 3 uses the same Trust Services Criteria and examination but is general-use and high-level, so you can post it publicly. A SOC 2 is restricted-use and detailed.

Is security always required? Yes. The security common criteria are always in scope; availability, processing integrity, confidentiality and privacy are optional.

Does it cover privacy? Yes. The privacy category, notice, choice, collection, use, access, disclosure, quality and enforcement, is built as controls.

What if it is not for me? A 30-day money-back guarantee.

Do not go into a SOC examination with controls but no evidence.
Every SOC 3 criterion is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and earn a report you can share this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com