Skip to main content
Category: Supplier and Third-Party

Complementary Subservice Organization Controls

Also known as: CSOC, CSOCs, Complementary Subservice Organization Controls (CSOCs)
Simply put

Complementary Subservice Organization Controls (CSOCs) are controls that a service organization relies on but that are actually performed by another company it has outsourced work to, known as a subservice organization. Because these controls are necessary for the service organization's system to function properly, the service organization's management assumes they are in place at the subservice organization. In this way, responsibility for parts of the overall control environment is shared between the two organizations.

Formal definition

In the context of a SOC examination, complementary subservice organization controls (CSOCs) are the controls that the management of a service organization assumes, in the design of its own system, will be implemented and operating at a subservice organization to which functions have been outsourced. When a service organization uses the carve-out method to address a subservice organization, its system description typically identifies the CSOCs that are necessary, in combination with the service organization's own controls, to meet the applicable Trust Services Criteria. CSOCs delineate the boundary of responsibility between the service organization and its subservice organization, but the service organization's report does not attest to the operating effectiveness of the subservice organization's controls themselves; assurance over those controls is typically obtained separately, such as through the subservice organization's own SOC report. The specific CSOCs identified vary depending on the outsourced functions, the scope of the engagement, and scoping decisions made by the service organization and its auditor.

Why it matters

Most modern service organizations do not operate entirely on their own infrastructure; they outsource meaningful functions such as cloud hosting, data center operations, or payment processing to other companies known as subservice organizations. When a control that is essential to meeting the applicable Trust Services Criteria actually lives at one of those outsourced providers, the service organization's SOC 2 report must make that dependency explicit. Complementary subservice organization controls (CSOCs) serve this purpose: they identify the controls that the service organization's management assumes are in place and operating at the subservice organization, so that users of the report understand where the boundary of responsibility falls.

Who it's relevant to

Compliance and GRC managers
Teams responsible for a SOC 2 examination need to identify which vendors qualify as subservice organizations and determine the CSOCs their own system relies on. They also carry responsibility for the due diligence and ongoing monitoring that justify reliance on controls performed by another company, which typically includes obtaining and reviewing the subservice organization's own SOC report.
Auditors and CPA firms
Practitioners performing a SOC 2 examination help scope which functions are carved out and confirm that the system description accurately identifies the CSOCs necessary, alongside the service organization's controls, to meet the applicable Trust Services Criteria. They must ensure the report clearly reflects that operating effectiveness of the subservice organization's controls is not being attested to under the carve-out method.
Customers and users of SOC 2 reports
Organizations relying on a vendor's SOC 2 report need to read the CSOC disclosures to understand where the service organization's coverage ends and the subservice organization's responsibility begins. Recognizing these boundaries helps them decide whether additional assurance, such as reviewing the subservice organization's own report, is needed to address the carved-out controls.
Security engineers and architects
Those who design and operate systems built on outsourced infrastructure, such as cloud hosting, need to understand which controls are expected to be handled by the provider versus which remain the service organization's own responsibility. This shared-responsibility boundary directly informs how internal controls are designed to complement the assumed CSOCs.

Inside CSOC

Subservice Organization
A third-party vendor that a service organization relies on to deliver its services (for example, a cloud infrastructure provider). The controls operated by this entity may be relevant to the service organization's own control environment.
Carve-out vs. Inclusive Method
Two approaches to addressing subservice organizations in a SOC 2 report. Under the carve-out method, the subservice organization's controls are excluded from the description and the service auditor's testing but their necessity is disclosed as CSOCs. Under the inclusive method, the subservice organization's relevant controls are described and tested within the same examination. The method chosen is a scoping decision.
Complementary Subservice Organization Controls (CSOCs)
Controls that the service organization assumes are implemented and operating at the subservice organization, and which are necessary, together with the service organization's own controls, to achieve the applicable Trust Services Criteria. These are typically disclosed when the carve-out method is used.
Relationship to the Trust Services Criteria
CSOCs are identified in the context of the applicable Trust Services Criteria within the scope of the engagement. Security (the Common Criteria) is required, while Availability, Processing Integrity, Confidentiality, and Privacy are optional and included based on scope, so the CSOCs disclosed depend on which criteria are in scope.
Disclosure in the System Description
CSOCs are typically presented within the service organization's system description so that report users understand the division of responsibility between the service organization and its subservice organizations.

Common questions

Answers to the questions practitioners most commonly ask about CSOC.

Are complementary subservice organization controls (CSOCs) the same as complementary user entity controls (CUECs)?
No. They address different parties in the service chain. Complementary subservice organization controls are controls that the service organization assumes are implemented at a subservice organization (a vendor or downstream provider) for the service organization's own controls to achieve the applicable Trust Services Criteria. Complementary user entity controls, by contrast, are controls the service organization expects its customers (user entities) to implement. In a SOC 2 report, both may be described, but CSOCs point downstream to a subservice organization while CUECs point toward the report's users. Conflating the two misattributes responsibility, so the distinction matters when reading which controls each party is expected to operate.
Does the presence of complementary subservice organization controls mean the subservice organization's controls were tested in this SOC 2 examination?
Not necessarily. CSOCs typically appear when a service organization uses the carve-out method, under which the subservice organization's controls are excluded from the scope of the examination and instead described as controls assumed to be in place. Under the carve-out method, the auditor does not test those subservice organization controls as part of this report. This differs from the inclusive method, where the subservice organization's relevant controls are brought within the scope and covered by the examination. Because the approach depends on scoping decisions, readers should confirm which method was used before assuming any subservice controls were examined.
How can we tell from a SOC 2 report which method a service organization used for its subservice organizations?
The report's system description generally indicates whether the carve-out or inclusive method was applied. When complementary subservice organization controls are listed as assumed controls that the service organization relies on but did not include in scope, that typically signals the carve-out method. When the subservice organization's relevant controls are described within the system boundary and covered by the auditor's testing, that indicates the inclusive method. Reviewing the scope, system boundary, and description criteria sections helps confirm how the subservice relationship was treated.
What should we do as a user entity when a SOC 2 report lists complementary subservice organization controls under the carve-out method?
Because carved-out subservice controls are not tested in that report, user entities relying on the service organization typically seek separate assurance over those downstream controls. In many engagements this means obtaining and reviewing the subservice organization's own SOC 2 report (or equivalent), assessing whether its scope and covered period align with your needs, and evaluating any gaps. The appropriate depth of review depends on how critical the subservice organization is to the services you consume and your own risk assessment.
How do complementary subservice organization controls affect our vendor risk management process?
CSOCs can inform vendor risk management by identifying which controls a service organization depends on from its downstream providers. Depending on scope, this often prompts extending due diligence beyond the direct vendor to relevant subservice organizations in the chain. Practical steps commonly include mapping the subservice relationships disclosed in the report, requesting assurance evidence for carved-out providers, and tracking those dependencies in your vendor inventory. The extent of this activity generally scales with the significance of each subservice organization to your operations.
Do complementary subservice organization controls have an equivalent in ISO 27001?
The exact SOC 2 mechanism does not map directly, but ISO 27001 addresses supplier and third-party relationships through the ISMS requirements and related Annex A reference controls, applied according to the organization's risk assessment and Statement of Applicability. The specific controls selected and how supplier dependencies are managed depend on scope and the applicable edition of the standard. Because the frameworks structure third-party assurance differently, treating a SOC 2 CSOC concept as identical to any single ISO 27001 requirement would overstate their equivalence; mapping between them is partial and should be evaluated case by case.

Common misconceptions

CSOCs mean the subservice organization's controls have been tested by the service auditor.
When the carve-out method is used, CSOCs identify controls assumed to be in place at the subservice organization, but the service auditor does not test them. Testing of those controls would occur only under the inclusive method or through a separate report covering the subservice organization.
CSOCs are the same as complementary user entity controls (CUECs).
CSOCs are controls expected to operate at the subservice organization, whereas complementary user entity controls are controls the report expects the user entity (customer) to implement. They address different parties in the control chain.
A SOC 2 report that lists CSOCs guarantees the subservice organization is secure and free from breaches.
A SOC 2 report attests only to the controls and period covered under the applicable criteria and does not guarantee freedom from breaches. CSOCs merely note controls assumed to exist at the subservice organization; obtaining assurance over them typically requires reviewing that entity's own report or assessment.

Best practices

Determine early in scoping whether the carve-out or inclusive method will be used for each subservice organization, since this drives how their controls are described and whether they are tested.
When relying on the carve-out method, obtain and review the subservice organization's own attestation report (such as its SOC 2 report) to gain assurance that the assumed CSOCs are in place and operating for the relevant period.
Map each identified CSOC to the specific Trust Services Criteria in scope so the division of responsibility supports the criteria the service organization is being examined against.
Clearly document CSOCs in the system description so report users understand which controls are assumed to reside at the subservice organization rather than the service organization.
Reconcile CSOCs with complementary user entity controls to avoid confusing responsibilities between the subservice organization and the user entity.
Reassess the completeness and continued relevance of disclosed CSOCs whenever subservice relationships, services, or the applicable criteria change, as these depend on the engagement's scope.