Skip to main content
Category: SOC Reporting

General Use Report

Also known as: general-use report, general distribution report
Simply put

A general use report is an attestation report that can be shared freely with anyone, rather than being limited to a specific list of intended recipients. In the SOC reporting family, the SOC 3 report is designed for general use and can be distributed publicly, but it provides less detail than a restricted-use report. It offers a high-level summary about controls at a service organization without disclosing the underlying testing details.

Formal definition

A general use report is an attestation deliverable whose distribution is not restricted to specified parties, in contrast to restricted-use reports that limit use to identified users who understand the engagement's context and limitations. Within the AICPA's SOC reporting framework, the SOC 3 report is the general-use report for service organizations: it can be freely distributed because it omits the detailed description of the service auditor's tests of controls and results found in a restricted-use report. Note that SOC 2 reports are restricted-use by design and are not general use reports; the SOC 3 is the SOC report intended for general distribution. Even a report that is ordinarily general use may, depending on the engagement, be restricted at the practitioner's discretion, and any general use report attests only to the controls and criteria within its defined scope.

Why it matters

The distinction between general use and restricted-use reports directly affects how a service organization can communicate its control posture to the outside world. A restricted-use report, such as a SOC 2, limits distribution to specified parties who understand the engagement's context and limitations, which means it cannot simply be posted on a website or handed to any prospective customer. A general use report, embodied by the SOC 3, fills that gap by providing a deliverable that can be freely distributed for marketing, procurement, and public assurance purposes. Understanding which report is appropriate prevents organizations from either over-sharing a restricted deliverable or under-serving stakeholders who need a distributable summary.

The trade-off is one of detail versus reach. Because a SOC 3 omits the detailed description of the service auditor's tests of controls and the results of those tests, it can be distributed broadly but tells a reader far less than a restricted-use report would. Compliance teams and buyers should recognize that receiving a general use report does not substitute for the depth found in a restricted-use SOC 2, which conveys the underlying testing evidence needed for a rigorous vendor risk assessment.

It is also important to remember that the general use versus restricted-use status is not always fixed by report type alone. Guidance in the attestation standards recognizes that a practitioner may restrict the use of a report even when it would ordinarily be a general-use report, depending on the circumstances of the engagement. Any general use report, moreover, attests only to the controls and criteria within its defined scope and over the period or point in time covered; it does not guarantee freedom from breaches or assure control performance outside that scope.

Who it's relevant to

Sales and marketing teams
Because a SOC 3 is designed for general distribution, it is the deliverable that can be published on a website or shared with prospective customers without the constraints of restricted-use language. Teams should understand that it offers only a high-level summary and cannot replace the detail available in a restricted-use report.
Vendor risk and procurement professionals
When assessing a service organization, professionals should recognize that a general use report such as a SOC 3 omits the detailed tests of controls and their results. For a deeper evaluation, they typically need to request a restricted-use report, subject to the distribution restrictions that apply to it.
Service organizations and their compliance managers
Organizations choosing how to communicate their control posture should weigh the broad distribution of a general use report against its reduced detail. They should also confirm the intended distribution status with their service auditor, since a report that is ordinarily general use may be restricted at the practitioner's discretion depending on the engagement.
Practitioners and service auditors
Service auditors determine the appropriate report form and distribution restrictions based on the engagement. The attestation standards recognize that a practitioner may restrict the use of any report, even one that would ordinarily be a general-use report, making professional judgment central to how the deliverable is scoped and issued.

Inside General Use Report

General Use Designation
A report designated for general use may be freely distributed to any party, including the public, without restriction. This distribution intent distinguishes it from restricted-use reports, which are limited to specified parties such as management, the service organization, and knowledgeable user entities.
SOC 3 as the General Use SOC Report
Within the SOC reporting family, the SOC 3 report is the offering intended for general use. It is derived from a SOC 2 examination but presents a summarized account without the detailed description of tests of controls and results, making it suitable for broad distribution and marketing purposes.
Summarized Content
General use reports typically omit the detailed system description, the auditor's specific tests, and the granular results found in restricted-use reports. They generally convey the practitioner's overall opinion and a high-level description sufficient for a general audience, rather than the depth needed by an auditor evaluating specific controls.
Practitioner Opinion
Like other examination outputs under the AICPA framework, a general use report includes the licensed CPA firm's opinion. It remains an attestation deliverable produced under professional standards, not a certification issued by an accredited certification body.

Common questions

Answers to the questions practitioners most commonly ask about General Use Report.

Is a general use report the same as a SOC 2 report that anyone can distribute freely?
No. A SOC 2 Type I or Type II report is a restricted-use report intended for a defined audience such as management, existing customers, and their auditors, and its distribution is limited accordingly. A general use report is one designed to be distributed without such restrictions. In the SOC family, the SOC 3 report is the general use report; it is derived from a SOC 2 examination but presents a summary suitable for broad distribution rather than the detailed control descriptions and test results found in a SOC 2 report.
Does receiving a general use report mean the service organization has been certified as secure?
No. A general use report such as a SOC 3 is the product of an attestation examination performed by a licensed CPA firm, not a certification, and it does not guarantee freedom from breaches. It attests only to the controls and the period covered by the underlying examination and within the defined scope. It should not be read as a certification comparable to an ISO/IEC 27001 certificate, which is issued by an accredited certification body against a management system standard.
When should an organization choose a general use report instead of a restricted-use report?
A general use report is typically appropriate when the organization wants to share assurance broadly, such as posting it publicly on a website or providing it to prospects during marketing, without managing individual distribution restrictions. When a customer or auditor needs the detailed control descriptions, test procedures, and results to support their own assessments, the restricted-use SOC 2 report is generally the better fit. Many organizations pursue both, depending on the audience and scope.
Can a general use report be produced from an existing SOC 2 examination?
In most engagements, a SOC 3 general use report can be produced in conjunction with a SOC 2 examination, since it draws on the same underlying work performed against the applicable Trust Services Criteria. The specifics depend on the CPA firm and the scoping decisions for the engagement, so organizations should confirm with their service auditor whether both deliverables are included.
What information is typically omitted from a general use report compared to a restricted-use report?
A general use report typically omits the detailed description of the service organization's controls, the auditor's specific tests of those controls, and the results of those tests. It generally presents a summary and the practitioner's opinion rather than the granular detail found in a restricted-use SOC 2 report. Because of this, it usually offers less information for a reader who needs to perform an in-depth evaluation of specific controls.
How does the scope of a general use report affect how much reliance can be placed on it?
Reliance depends on the scope, the criteria selected, and the period covered by the underlying examination. A general use report attests only to what was within that defined scope during the covered period and, for a Type II basis, to operating effectiveness over that period. Readers should review the report to understand which Trust Services Criteria categories were included beyond the required Security category and should not assume coverage extends to areas outside the stated scope.

Common misconceptions

A SOC 2 report can be freely published as a general use report.
SOC 2 reports (both Type I and Type II) are, by definition, restricted-use and intended only for specified parties who possess sufficient knowledge of the service organization's system. The SOC report designed for general use is the SOC 3, which is based on a SOC 2 examination but summarized for broad distribution.
A general use report gives the same level of detail as a restricted-use report.
A general use report such as a SOC 3 typically omits the detailed description of the auditor's tests and results that appear in a restricted-use SOC 2 report. It is designed to communicate an overall conclusion to a general audience, not to support detailed control-level evaluation by a user's auditor.
A general use report is a certification confirming the organization is free from security breaches.
A general use report is an attestation deliverable produced by a licensed CPA firm reflecting an opinion over the controls and period covered. It is not a certification, and it does not guarantee freedom from breaches; it attests only to what was examined within the defined scope.

Best practices

When broad or public distribution is the goal, request a SOC 3 report rather than attempting to distribute a SOC 2 report, since SOC 2 reports are restricted-use by design.
Confirm the distribution designation (general use versus restricted use) with the CPA firm at the scoping stage so the deliverable matches the intended audience.
Use a general use report such as a SOC 3 for marketing and public assurance purposes, but obtain the detailed restricted-use SOC 2 report when a user entity's auditor needs to evaluate specific controls and test results.
Read the practitioner's opinion and defined scope carefully, recognizing that the report attests only to the controls and period covered and does not guarantee the absence of breaches.
Avoid treating a general use report as a certification; describe it accurately as an attestation deliverable when communicating with stakeholders.
Where a comprehensive control-level evaluation is required, verify whether the summarized general use report provides sufficient detail or whether a restricted-use report should also be requested.