General Use Report
A general use report is an attestation report that can be shared freely with anyone, rather than being limited to a specific list of intended recipients. In the SOC reporting family, the SOC 3 report is designed for general use and can be distributed publicly, but it provides less detail than a restricted-use report. It offers a high-level summary about controls at a service organization without disclosing the underlying testing details.
A general use report is an attestation deliverable whose distribution is not restricted to specified parties, in contrast to restricted-use reports that limit use to identified users who understand the engagement's context and limitations. Within the AICPA's SOC reporting framework, the SOC 3 report is the general-use report for service organizations: it can be freely distributed because it omits the detailed description of the service auditor's tests of controls and results found in a restricted-use report. Note that SOC 2 reports are restricted-use by design and are not general use reports; the SOC 3 is the SOC report intended for general distribution. Even a report that is ordinarily general use may, depending on the engagement, be restricted at the practitioner's discretion, and any general use report attests only to the controls and criteria within its defined scope.
Why it matters
The distinction between general use and restricted-use reports directly affects how a service organization can communicate its control posture to the outside world. A restricted-use report, such as a SOC 2, limits distribution to specified parties who understand the engagement's context and limitations, which means it cannot simply be posted on a website or handed to any prospective customer. A general use report, embodied by the SOC 3, fills that gap by providing a deliverable that can be freely distributed for marketing, procurement, and public assurance purposes. Understanding which report is appropriate prevents organizations from either over-sharing a restricted deliverable or under-serving stakeholders who need a distributable summary.
The trade-off is one of detail versus reach. Because a SOC 3 omits the detailed description of the service auditor's tests of controls and the results of those tests, it can be distributed broadly but tells a reader far less than a restricted-use report would. Compliance teams and buyers should recognize that receiving a general use report does not substitute for the depth found in a restricted-use SOC 2, which conveys the underlying testing evidence needed for a rigorous vendor risk assessment.
It is also important to remember that the general use versus restricted-use status is not always fixed by report type alone. Guidance in the attestation standards recognizes that a practitioner may restrict the use of a report even when it would ordinarily be a general-use report, depending on the circumstances of the engagement. Any general use report, moreover, attests only to the controls and criteria within its defined scope and over the period or point in time covered; it does not guarantee freedom from breaches or assure control performance outside that scope.
Who it's relevant to
Inside General Use Report
Common questions
Answers to the questions practitioners most commonly ask about General Use Report.