A SOC 2 report describes a control environment that can involve both the service organization and its user entities, i.e., the customers.

In some cases, the service organization's controls depend on specific controls performed by customers. These controls constitute complementary user entity controls (CUECs). Without them, the service organization's own controls cannot fully achieve their stated objectives under the AICPA's Trust Services Criteria.

The AICPA Description Criteria requires management to identify applicable CUECs in the system description.

As an independent CPA firm performing SOC 2 examinations under AICPA attestation standards, CertPro evaluates whether management's description appropriately presents the assumptions. That evaluation forms part of the examination of the system description and its relationship to the applicable Trust Services Criteria.

Schedule a Meeting with CertPro
TL;DR

Concern

A SOC 2 report may assume that complementary user entity controls are performed, but the service auditor does not test whether the user entity actually performs them. The user entity's own auditors may later require evidence that these controls operate as expected. Where ownership and evidence are unclear, the gap can leave controls unaddressed and create audit risk.

Overview

Complementary user entity controls are controls that management assumes user entities will implement in combination with the service organization's controls to achieve applicable service commitments and system requirements. AICPA Description Criterion DC6 addresses these disclosures within the system description.

Solution

User entities should identify applicable CUECs immediately upon receiving a SOC 2 report, map each to an internal control owner, and maintain documented evidence of operation, so that their own auditors and downstream stakeholders can verify the shared control environment is functioning as designed.

Defining CUECs Within SOC 2 Examination Scope

CUEC Definition Under AICPA Attestation Standards

Complementary user entity controls are control activities that a service organization's management identifies as necessary for user entities to implement in order for the service organization's system to meet applicable Trust Services Criteria under AT-C Section 205 and TSP Section 100 (Source: AICPA).

Here, user entities refer to customers or other entities that use the service organization's services.

A service organization might encrypt data in transit and at rest, but its security objective cannot be fully achieved if the user entity grants its own employees unrestricted administrative access to the vendor's portal. The relevant control activities in auditing therefore extend to the user entity that is responsible for access provisioning on its side of the boundary.

Distinguishing CUECs From the Service Organization's Own Controls

Complementary user entity controls remain the responsibility of user entities. They do not become controls operated by the service organization merely because management identifies them in the SOC 2 system description. The distinction matters during an examination.

Illustrative SOC 2 reports expressly state the limitation that the service auditor's opinion is subject to the assumption that user entities have implemented the listed CUECs. A SOC 2 examination does not test whether customers actually designed or operated the listed CUECs.

This distinction also prevents a common reporting error: a CUEC does not represent a control exception at the service organization simply because a user entity fails to perform it.

CUECs vs. Complementary Subservice Organization Controls

SOC 2 complementary user entity controls differ from complementary subservice organization controls, or CSOCs. CSOCs describe controls that a subservice provider (e.g., a cloud infrastructure vendor) must operate for the primary service organization's controls to function. CUECs flow to the customer. CSOCs flow to a sub-vendor. Both appear in the same section of many SOC 2 reports, but they impose obligations on entirely different parties.

How CUECs Map to Trust Services Criteria

Every SOC 2 audit is scoped against one or more of the five Trust Services Criteria: Security (CC), Availability (A), Processing Integrity (PI), Confidentiality (C), and Privacy (P). Security is required for all SOC 2 examinations; the others are included at the service organization's election.

The table below illustrates common SOC 2 complementary user entity controls examples organized by Trust Services Criteria category.

Complementary User Entity Controls Examples by Trust Services Criteria
Trust Services Criteria Typical CUEC Obligation for User Entity
Security (CC6–CC9) Manage user access provisioning and de-provisioning; enforce MFA for vendor portal accounts; report suspected security incidents to the service organization promptly.
Availability (A1) Maintain adequate network connectivity and redundancy on the user entity side; test recovery procedures for data the user entity controls; notify the vendor of planned outages.
Processing Integrity (PI1) Validate input data accuracy before submission; review output reports for completeness; flag anomalies to the service organization within defined timeframes.
Confidentiality (C1) Restrict access to vendor-delivered confidential data to authorized personnel; enforce data classification policies that govern vendor data handling.
Privacy (P1–P8) Obtain required consents before submitting personal data; maintain records of data subject requests and relay them to the vendor per contractual timelines.

A Practical Framework for Reviewing and Documenting Vendor CUECs

Effective management of SOC 2 complementary user entity controls requires a repeatable review process:

  • Locate CUECs

    Find the CUECs in the SOC 2 report, typically within the system description. Review the related control objectives.

  • Confirm Applicability

    Identify which CUECs apply to the specific services or modules used. Not every listed CUEC applies to every user entity.

  • Assign Ownership

    Map each CUEC to a responsible role or function, such as IT, IAM, privacy, or legal.

  • Document and Evidence

    Record the control activity, owner, frequency, and required evidence. Retain evidence centrally for audit review.

  • Reassess Changes

    Review CUECs with each new SOC 2 report and after significant changes to vendor services or internal operations.

A Practical Framework for Reviewing and Documenting Vendor CUECs
A Practical Framework for Reviewing and Documenting Vendor CUECs

The Audit Implications When User Entities Ignore CUECs

When an independent CPA firm conducts a SOC 2 examination of a service organization, the auditor's opinion addresses whether the controls described, including CUECs, achieved the applicable Trust Services Criteria. It is the user entity's own auditors and risk functions who must verify their side of the equation.

This creates a gap that is easy to overlook.

A user entity may receive a clean SOC 2 Type 2 report from its vendor and conclude that the vendor relationship is fully covered from a control standpoint. But if the entity itself has not implemented the complementary user entity controls, it has accepted risk the auditor never evaluated. In a regulated environment such as financial services, healthcare, or government contracting, that gap can constitute a material control deficiency.

When a user entity undergoes its own SOC 2 examination or internal audit, the examiner will assess whether vendor-related control dependencies are addressed. Unmet CUECs from a vendor's report can surface as control deficiencies in the user entity's own audit. Internal audit teams and those conducting their own SOC 2 examinations should treat the CUEC section of every in-scope vendor's report as a direct input to their control inventory.

Conclusion

Complementary user entity controls form an important part of the relationship between a service organization's controls and the controls that user entities perform. They are explicit, auditor-documented obligations that define where a vendor's control environment ends and the customer's begins. When user entities treat them as optional, they undermine the shared assurance that the entire SOC 2 attestation model depends on.

CertPro performs independent SOC 2 examinations as a licensed CPA firm under AICPA attestation standards. When an independent audit firm such as CertPro conducts a SOC 2 examination of a service organization, the resulting report will identify any CUECs that user entities must operate. Organizations on the receiving end of a SOC 2 report carry the responsibility for their portion of the shared control environment and bear any resulting consequences to their own risk and assurance posture.

Frequently Asked Questions
Complementary user entity controls are control activities that a service organization identifies as customer responsibilities necessary for the service organization's system to meet applicable Trust Services Criteria.
No. CUECs impose obligations on the customer (user entity), while CSOCs impose obligations on a subservice provider such as a cloud infrastructure vendor.
The number varies significantly by service organization and scope. Some SOC 2 reports list fewer than five CUECs; others list thirty or more. The AICPA does not prescribe a required number. The count reflects the degree to which the service organization's controls depend on customer-side activities to achieve Trust Services Criteria objectives.
The service organization's controls cannot fully achieve their stated objectives. Unmet CUECs can surface as control deficiencies during the user entity's own internal or external audits, particularly in regulated industries where third-party control coverage is closely examined.
Yes, but the framing differs. User entity controls in a SOC 1 context are tied to the service organization's defined control objectives that impact client financial operations, not the five Trust Services Criteria categories used in SOC 2 examinations.