skip to content

In a SOC 2 report, what are complementary user entity controls and subservice organizations, and how do the carve-out and inclusive methods differ?

level: middleimportance: should knowfreq 45%

answer

  1. what the customer must do
  2. what the vendor's vendors do
  3. carved out means not tested
  4. inclusive means tested in scope
  5. CSOCs link them

basics

~20 s

Complementary user entity controls are controls the customer must operate for the vendor's controls to meet the criteria. Subservice organizations are the vendor's own providers; under carve-out their controls are excluded, under the inclusive method they are described and tested in the report.

solid answer

~50 s

A SOC 2 report describes a **system boundary**, and two lists tell a reader what sits outside it. **Complementary user entity controls (CUECs)** are controls the vendor assumes its customers operate — managing their own users' access, protecting their API keys, reviewing audit logs — without which the vendor's controls cannot meet some criteria. **Subservice organizations** are providers the vendor relies on, such as its hosting provider. Under the **carve-out method**, the subservice organization's controls are excluded from the description and testing; the report instead lists the **complementary subservice organization controls** the vendor expects that provider to operate, and the customer must get assurance on the provider separately, usually its own SOC 2. Under the **inclusive method**, the provider's relevant controls are included and tested, which needs its cooperation and a written assertion from it. Carve-out is the norm for large cloud providers.

go deeper

for a junior

Recall that CUECs are the customer's duties and subservice organizations are the vendor's own providers, and that carve-out excludes their controls from testing.

for a middle

Explain how carve-out and inclusive differ in description, testing and cooperation, and why complementary subservice organization controls are listed under carve-out.

for a senior

Show how you would review a vendor report's CUECs and carved-out providers, obtain the providers' reports and check period overlap and follow-up.

for a principal

Discuss how dependence on carved-out providers shapes third-party risk strategy across a vendor portfolio and when to demand inclusive coverage.

## Why these sections matter A SOC 2 report gives an opinion about the controls **within a defined system boundary**. Much of what protects the customer's data sits outside that boundary: in the customer's own hands, or at the vendor's own suppliers. A procurement team that skips these sections misreads what the opinion covers. ## Complementary user entity controls **Complementary user entity controls (CUECs)** are controls that management's system description assumes **user entities** (the vendor's customers) have in place. They are needed because some criteria can only be met by the vendor and customer together. Typical CUECs for a B2B SaaS vendor: - The customer provisions and removes its own users in the application and reviews their access. - The customer protects API keys and credentials issued to it. - The customer configures single sign-on and multi-factor authentication for its tenant where offered. - The customer reviews the audit logs and notifications the service provides. - The customer notifies the vendor of security incidents it detects involving the service. The auditor's opinion is typically worded so that controls operated effectively **if** the user entities applied the complementary controls. A customer must map each CUEC to its own controls; an unmet CUEC is a gap the vendor's report cannot close. ## Subservice organizations A **subservice organization** is a vendor used by the service organization whose controls are likely relevant to the service organization's commitments: a cloud hosting provider, a managed database service, an outsourced support desk. There are two ways to present one: | | Carve-out method | Inclusive method | |---|---|---| | **Subservice controls in description** | Excluded; services described, controls not | Included | | **Tested by the service auditor** | No | Yes | | **Complementary subservice organization controls** | Listed: what the vendor expects the provider to do | Not needed as a separate list, since those controls are in scope | | **Provider's cooperation** | Not needed | Needed, including a written assertion from its management | | **Customer's follow-up** | Obtain the provider's own report | Covered in the one report | **Carve-out** is by far the more common, particularly for large cloud providers that publish their own SOC 2 reports and will not take part in each customer's audit. **Inclusive** appears where the vendor and its provider are closely linked, such as affiliates. ## Monitoring the carved-out provider Under carve-out, the vendor is still expected to monitor its subservice organizations, which falls under criteria such as CC9.2 (the entity assesses and manages risks associated with vendors and business partners). Auditors test that the vendor obtained and reviewed the provider's report, checked its CUECs from the provider's side, and followed up on exceptions. ## Reading these sections as the customer 1. List every **CUEC** and confirm your organization operates it; assign an owner if not. 2. List every **subservice organization** and its method. 3. For carve-out providers, obtain their reports and check their periods overlap the vendor's. 4. Check the vendor's monitoring of those providers is described and tested. 5. Note any service the vendor relies on that appears in neither list. ## Common misreadings - Assuming the hosting provider's controls were tested because the vendor runs on it. - Treating CUECs as boilerplate; some, like access reviews of your own users, carry most of the real risk. - Believing carve-out hides a weakness; it is the normal method, but it shifts work to the reader.

  • What should a customer do if it cannot operate one of the vendor's CUECs?
    Treat it as a gap in its own control environment: assess the risk the unmet CUEC leaves, look for a compensating control on its side, or ask the vendor whether a product feature or configuration closes it. The vendor's opinion assumes the CUEC operates, so without it the customer cannot rely on the related criteria being met.
  • Why do large hosting providers almost always appear under the carve-out method?
    The inclusive method needs the provider to allow its controls to be tested within each customer's examination and to give a written assertion, which is impractical for a provider with many customers. Instead, such providers issue their own SOC reports, and the vendor's report lists the complementary subservice organization controls it expects them to operate.

A SOC 2 is like a building inspection of an apartment. CUECs are the tenant's duties — lock your own door. A carved-out subservice organization is the building's lift, inspected under a separate certificate the tenant should ask to see.

saying these in an interview costs you the question

  • The hosting provider's controls are tested because the vendor runs on it.
  • CUECs are boilerplate that customers can safely ignore.
  • Carve-out means the vendor is hiding a weakness from the auditor.
  • Under carve-out the vendor has no duty to monitor its providers.
  • The inclusive method needs no cooperation from the subservice organization.