Complementary user entity controls, and how to word yours
The definition is one sentence. The wording is the part with consequences, because a vague CUEC transfers nothing and a precise one reads like a contract term.
Complementary user entity controls are the things your customer has to do for your controls to work the way your report says they work. Your auditor tests yours. Nobody tests theirs. So you write the assumption down, and that written assumption is a CUEC.
CSOCs are the same mechanism aimed the other way, at the vendors underneath you. You write one list and you inherit the other, and both get read by somebody with the authority to reject your report.
Search this and you get definitions. Here is the acronym, here is a bulleted list, here is a demo booking. What you need is how to write your own so they hold up when a customer skips one, and how to work through somebody else’s when their report lands in your inbox.
What a CUEC actually is
Your SOC 2 covers your system. It does not cover the customer sitting on top of it. Along that boundary there are controls only they can operate, and if they skip one, your control no longer achieves what you said it achieves. Access provisioning is the classic case: you built the role model, they decide who gets which role.
You cannot test those controls. No access, no evidence, no authority to ask. So instead of testing them you disclose them, and the disclosure sits in Section 3 of the report, inside the system description you wrote and management asserted.1 The auditor reads it as a stated condition on your assertion rather than as advice.
- What it is not
- Not a recommendation, not a hardening guide, not an appendix of security tips. Those belong in your documentation. A CUEC is a limit on what your own description claims.
- Where it lives
- Section 3, the system description, usually as a short list near the end. It is management language, not auditor language, which means you own every word of it.
- Who reads it
- The security reviewer at every company you send the report to, and their auditor after them. On the buying side it is one of the few parts of a report that generates work.
CSOCs, the same mechanism pointed at your vendors
Flip the direction. You run on a cloud provider, you send mail through somebody, you move money through somebody else. Those are subservice organizations, and their controls are load bearing for yours. What they have to operate for your description to hold is a complementary subservice organization control.
Your customer works through your CUEC list; you work through your vendors’. Physical and environmental security is the usual example. You claim your production data sits in a facility with controlled access, and you have never been to that facility, so the control belongs to the provider and you name it as theirs.
Carve out or inclusive, and which one you will use
There are two ways to handle a subservice organization in your description, and the choice changes what your auditor tests and what your report looks like to a buyer.2 The names sound procedural. What decides it is how much influence you have over the vendor.
| Carve out method | Inclusive method | |
|---|---|---|
| What the description covers | Your controls only. The vendor is named and its controls are excluded | Your controls and the vendor’s controls, described together as one system |
| What the auditor tests | Your controls, including how you select and monitor the vendor | Both sets, at both organizations |
| What the vendor has to agree to | Nothing. You read their report the same as any other customer | Its own management assertion, and testing alongside you |
| What appears in your report | A CSOC list: the controls you assume the vendor operates | The vendor’s controls and test results, printed inside your report |
You will carve out. The inclusive method needs your vendor to sign a management assertion and sit for testing beside you, so ask yourself who at your cloud provider signs that document. Nobody does, and you do not need them to. Carving out is the normal treatment for a company buying commodity infrastructure, and it leaves you with one real obligation: reading the vendor’s own report and doing what its CUEC list tells you.
It moves who operates it. Your auditor still tests whether you chose the vendor deliberately, whether you read their report, and whether you noticed when it expired. A carve out that is really an unread PDF in a folder is a finding waiting for a sample.
How to word a CUEC so it does something
A CUEC is a condition on your assertion. Read that with a lawyer in mind, because if the condition is vague then you have conditioned nothing, and the sentence you wrote will not help you the day a customer says your service let their intern into production.
The weak version
Weak CUECs share one habit: they name a responsibility instead of an action. Nobody can tell whether the customer did it, so nothing has been transferred. They read like a terms of service page pasted into an audit document.
The strong version
A strong CUEC could be handed to the customer’s own auditor as a test procedure. Actor, action, timing, and the control of yours it protects.
| Weak, and common | Strong, and testable |
|---|---|
| Users are responsible for the security of their accounts | The user entity assigns each of its users the least privileged role that permits their job, and removes access within one business day of a departure |
| Customers should implement appropriate controls over their data | The user entity classifies data before upload and does not place cardholder or regulated health data in the service, which is outside the boundary of this description |
| User entities are responsible for monitoring their activity | The user entity reviews the administrator activity export at least quarterly and investigates any entry it does not recognize |
| Users must keep their credentials confidential | The user entity enrolls every administrator in multi factor authentication and connects its own identity provider where the service supports it |
Notice what changed. Every strong version names somebody, names a verb, and names a moment. None of them are longer than a sentence. The vague ones are not shorter, they are just emptier.
- Name the actor precisely. The user entity, not users. A CUEC addressed to an individual employee of your customer is addressed to nobody with authority to act.
- Use a verb the customer performs. Reviews, removes, enrolls, classifies, approves. Responsible for is not a verb anyone can be tested against.
- State a frequency or a trigger. Quarterly, or within one business day of a departure. Without a clock, there is no instance to sample and no failure to point at.
- Name the control of yours it protects. If you cannot say which of your controls stops working when the customer skips this, the CUEC is decoration and belongs in your documentation instead.
If a criterion in your scope requires you to operate a control, writing it into the CUEC list does not move the obligation.3 Auditors push back on this. Buyers notice it too, and a reviewer who finds your encryption obligations in the customer column will read the rest of the description far less generously. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Reading somebody else’s CUECs
That is half the subject. The other half arrives when a vendor sends you their report and you skim Section 1, see an unqualified opinion, and file it. Section 1 is a paragraph of standard attestation language. Once you have run the checks that tell you the report is real, the list you actually need is buried in Section 3, and it is a set of tasks with your name on it.
- Find the list. Section 3, usually near the end of the system description, often titled complementary user entity controls with no fanfare at all.
- Give every item a named owner in your company. A person, not a team. A team owner means the task gets done by whoever notices, which is how it stops getting done.
- Check whether you actually do it. Work down the list honestly. There is usually at least one you assumed the vendor handled, and that assumption is the reason the list exists.
- Keep the evidence where your own examination can reach it. Their CUECs become your controls, and your auditor can ask you to demonstrate them during your own period.
- Write down the ones you cannot meet and what you do instead. A documented compensating control is defensible. Silence is not.
While the report is open, check the period it covers and whether it is still current, because a CUEC list from a report that lapsed eighteen months ago is telling you about a system that may have changed. How long a SOC 2 report stays valid covers what to look for and what a bridge letter does. If the vendor’s Section 4 carries deviations, what an exception actually means is the piece to read before you escalate anything.
Where this lands in your own report
Your CUEC list is written once, during the system description, and then it is quoted back at you by every customer for as long as the report circulates. That is a good reason to write it carefully and a better reason to keep it short. Four to eight precise items beat twenty vague ones.
Scope decides most of the content. Polara G.R.C. scopes Security only, which keeps the boundary tight and the CUEC list correspondingly small. The Trust Services Criteria guide walks through what each criterion actually asks for, and the scoping tool shows which criteria your buyer is likely to be asking about. Type 1 is $4,000 one time with the examination and the independent partner auditor fee included, and the full cost breakdown sets out the rest.
Questions
What are complementary user entity controls?
What is the difference between a CUEC and a CSOC?
Should a startup carve out its subservice organizations or include them?
Who has to follow the CUECs listed in a SOC 2 report?
Can I use CUECs to move my own responsibilities to the customer?
Sources
Get audit-ready without a compliance team.
$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Get startedPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.