Complementary User Entity Controls Reliance
Complementary User Entity Controls (CUECs) are security practices that a service provider expects its customers to put in place so that the provider's services work as intended. CUEC reliance refers to the way a service provider's control objectives depend on customers carrying out those responsibilities on their own side. In other words, some controls are shared: the provider handles part, and the customer must handle the rest.
In a SOC report, Complementary User Entity Controls are controls that the service organization assumes will be implemented by user entities (its customers) in order for the service organization's control objectives or applicable Trust Services Criteria to be met. CUEC reliance describes the dependency embedded in the report: the service organization's described controls, and the auditor's evaluation of them, presume that these user-side controls are operating. Because the SOC report attests only to the service organization's controls over the period and scope covered, it does not provide assurance over CUECs themselves; user entities are typically expected to review the listed CUECs and confirm they have implemented equivalent controls within their own environment as part of their third-party or vendor risk management. The specific CUECs, and the extent to which control objectives depend on them, vary by service organization, engagement scope, and the criteria in play.
Why it matters
Complementary User Entity Controls Reliance matters because a SOC 2 report rarely tells the whole story of how a service is secured. The service organization's control objectives and applicable Trust Services Criteria are typically designed with an assumption that customers will perform certain controls on their own side. If a user entity reads a SOC 2 report and treats it as a guarantee that the provider covers every risk, it may overlook responsibilities that were never the provider's to fulfill. The report attests only to the service organization's controls over the period and scope covered; it does not provide assurance over the CUECs themselves.
The practical consequence is that gaps can open at the boundary between provider and customer. A provider might implement encryption or access controls competently, but if a CUEC calls for the customer to manage its own user provisioning, enforce strong authentication, or configure services appropriately, and the customer fails to do so, the intended control outcome may not be achieved. Because the specific CUECs and the degree to which control objectives depend on them vary by service organization, engagement scope, and criteria in play, there is no universal checklist that applies to every relationship.
For this reason, reviewing CUECs is generally treated as an important part of third-party and vendor risk management. User entities are typically expected to read the listed CUECs and confirm they have implemented equivalent controls within their own environment. Skipping this step can leave a shared control only half-implemented, undermining the assurance the report was intended to support.
Who it's relevant to
Inside CUEC Reliance
Common questions
Answers to the questions practitioners most commonly ask about CUEC Reliance.