For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it. Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting
Importantly, anyone can get SOC2 (Type 1) by claiming some controls they figure they'll look at themselves. SOC2 (Type 2) in theory requires an audit that you're actually doing what you said you'd do in (Type 1). Both may also allow general lag time. Note that firms decide on their own which controls to include, meaning, they get to decide to include or exclude various controls, the audit is on only the ones they pic…
For context, this is how easy it is to get a SOC2: https://deepdelver.substack.com/p/delve-fake-compliance-as-a...