nerdexam
(ISC)2

CCSP · Question #141

Which SSAE 16 report is purposefully designed for public release (for instance, to be posted on a company's website)?

The correct answer is D. SOC 3. SOC 3 reports are designed for public distribution, offering a high-level summary of a service organization's internal controls over security, availability, processing integrity, confidentiality, and privacy.

Submitted by asante_acc· Apr 18, 2026Legal, Risk and Compliance

Question

Which SSAE 16 report is purposefully designed for public release (for instance, to be posted on a company's website)?

Options

  • ASOC 1
  • BSOC 2, Type 1
  • CSOC 2, Type 2
  • DSOC 3

How the community answered

(27 responses)
  • A
    4% (1)
  • C
    4% (1)
  • D
    93% (25)

Why each option

SOC 3 reports are designed for public distribution, offering a high-level summary of a service organization's internal controls over security, availability, processing integrity, confidentiality, and privacy.

ASOC 1

SOC 1 reports focus on controls relevant to a user entity's financial reporting and are restricted in distribution, typically for auditors and management.

BSOC 2, Type 1

SOC 2, Type 1 reports focus on controls relevant to security, availability, processing integrity, confidentiality, and privacy at a specific point in time, and are restricted in distribution.

CSOC 2, Type 2

SOC 2, Type 2 reports focus on controls relevant to security, availability, processing integrity, confidentiality, and privacy over a period of time, and are also restricted in distribution.

DSOC 3Correct

A SOC 3 report is a general-use report that provides a high-level summary of a service organization's system and the suitability of the design and operating effectiveness of its controls. Unlike SOC 1 and SOC 2 reports, SOC 3 reports do not contain detailed control information, making them suitable for public disclosure and general audiences.

Concept tested: SSAE 16/18 SOC report types

Source: https://www.aicpa-cima.com/resources/download/trust-services-criteria

Topics

#SOC Reports#Compliance#Auditing#SSAE

Community Discussion

No community discussion yet for this question.

Full CCSP Practice