Skip to main content
Category: Supplier and Third-Party

Subprocessor

Also known as: Sub-processor, Downstream processor
Simply put

A subprocessor is a third-party vendor or service provider that a data processor engages to help carry out part of the work it performs on behalf of a customer, often involving the handling of personal data. For example, when a software company you use relies on another vendor to store or process customer information, that vendor is acting as a subprocessor. In short, it is a downstream provider that supports the primary processor's activities.

Formal definition

A subprocessor is a downstream third-party processor engaged by a primary data processor to perform part of the processing activity conducted on behalf of a controller (the customer). In practice, the subprocessor has or may have access to, or otherwise processes, personal data received from the primary processor. Because subprocessor relationships extend the chain of data handling beyond the primary processor, they are typically relevant to vendor management, contractual flow-down obligations, and the disclosure requirements that arise in compliance engagements; the specific obligations depend on scope, applicable criteria, and the governing agreements.

Why it matters

Subprocessors extend the chain of data handling beyond the primary processor that a customer directly engages, which means personal data may flow to parties the customer never selected or contracted with directly. Because this downstream access can introduce risk that is not immediately visible, subprocessor relationships are a recurring focus of vendor and third-party management programs and of the disclosure obligations that arise in compliance engagements.

In a SOC 2 examination, controls related to vendor and subprocessor oversight commonly fall within the Common Criteria addressing risk management and monitoring of third parties, though the specific controls tested depend on scope and the criteria selected. Under ISO/IEC 27001, the management of supplier and downstream relationships is typically addressed through the risk assessment process and the reference controls in Annex A that concern supplier relationships, with applicability determined by the Statement of Applicability. In both cases, an unmanaged subprocessor can represent a gap between the assurances an organization provides to its customers and the actual reach of its data-handling arrangements.

Contractual flow-down is central to managing this risk: obligations the primary processor owes its customer generally need to be reflected in agreements with subprocessors so that protections are preserved down the chain. It is important to note, however, that a SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS; neither guarantees that every subprocessor in a supply chain meets the same standards unless those relationships fall within the assessed scope.

Who it's relevant to

GRC and Compliance Managers
Compliance managers track subprocessor relationships as part of vendor and third-party management, ensuring that contractual flow-down obligations are in place and that disclosures accurately reflect the parties in the data-handling chain. What must be documented depends on scope, applicable criteria, and the governing agreements.
Auditors and Assessors
In a SOC 2 examination, assessors may evaluate controls over how an organization selects, contracts with, and monitors subprocessors, typically within the Common Criteria for risk management and third-party oversight. Under ISO/IEC 27001, assessors consider how supplier and downstream relationships are addressed through the risk assessment and the reference controls selected via the Statement of Applicability. The specific controls examined vary by scope and engagement.
Vendor and Procurement Teams
Teams responsible for onboarding and managing vendors need to identify when a vendor will itself engage subprocessors, so that downstream access to personal data is understood and appropriate contractual protections flow through the chain.
Security and Data Protection Engineers
Engineers who design and operate systems that handle personal data need visibility into where that data flows, including to subprocessors, so that access, monitoring, and controls extend appropriately across the downstream chain within the assessed scope.

Inside Subprocessor

Subprocessor
A third party engaged by a service organization (the primary processor) to process data on its behalf in support of the services delivered to its customers. Subprocessors sit downstream in the supply chain and may themselves handle customer or personal data covered by the service organization's own commitments.
Contractual flow-down obligations
Requirements that a service organization typically passes down to its subprocessors through agreements, so that the subprocessor's practices support the commitments the service organization has made to its own customers. The specifics depend on scope and the applicable criteria.
Vendor and supplier management controls
Under SOC 2, oversight of subprocessors is generally addressed through the Common Criteria related to vendor and third-party risk management. Under ISO 27001, supplier relationships are addressed through Annex A reference controls (in the 2022 revision organized within the four themes) that are selected via the Statement of Applicability and informed by risk assessment.
Scope boundary considerations
Whether a subprocessor's controls are examined directly or relied upon indirectly affects the scope of an engagement. In some SOC 2 engagements, subservice organizations are addressed using the carve-out or inclusive method, which determines how their controls are treated relative to the service organization's report.
Privacy and data protection relevance
For engagements where the Privacy or Confidentiality categories are in scope for SOC 2, or where an ISMS covers personal data handling under ISO 27001, subprocessor arrangements are typically relevant to demonstrating that data protection commitments extend through the supply chain.

Common questions

Answers to the questions practitioners most commonly ask about Subprocessor.

Does a subprocessor need its own SOC 2 report or ISO 27001 certificate for me to use it?
Not necessarily. There is no universal rule requiring a subprocessor to hold either. In many engagements, organizations do seek assurance over subprocessors, and a SOC 2 Type II report or an ISO 27001 certificate covering the relevant scope is one common way to obtain it. However, other forms of assurance, contractual commitments, or direct assessment may be used depending on scope, risk, and the expectations of your auditor or certification body. Remember that a SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only the defined scope of the subprocessor's ISMS.
If my subprocessor is compliant, does that automatically make my own environment compliant?
No. A subprocessor's SOC 2 report or ISO 27001 certificate does not extend compliance to your organization. Each covers only that subprocessor's defined scope, controls, and (for SOC 2) the review period. Your own controls over selecting, contracting with, and monitoring subprocessors are typically what an auditor or certification body evaluates. You generally remain responsible for demonstrating how you manage the risks associated with the subprocessor within your own scope.
How do subprocessors typically get addressed in a SOC 2 examination?
In most SOC 2 engagements, subprocessors are addressed through the service organization's vendor management and monitoring controls, which fall within the Security (Common Criteria) category. Where a subprocessor's controls are relevant to the service being examined, the CPA firm may use either the inclusive method (incorporating the subprocessor's controls into the report) or the carve-out method (excluding them and describing them as the responsibility of the subprocessor). Which approach applies depends on scoping decisions made for the engagement.
How are subprocessors handled under an ISO 27001 ISMS?
Subprocessors are typically managed through the risk assessment and the supplier-relationship controls selected via the Statement of Applicability, informed by the ISMS requirements in clauses 4 through 10. The specific Annex A reference controls chosen depend on the version in use and the results of the risk assessment, so the exact controls applied vary by organization. The certificate covers only the defined scope of the ISMS, which should reflect how subprocessor relationships fall inside or outside that boundary.
What should I evaluate when relying on a subprocessor's assurance documentation?
Review the scope of the assurance to confirm it covers the services and locations you actually use. For a SOC 2 report, check whether it is a Type I (suitability of design at a point in time) or Type II (design and operating effectiveness over a review period), note the period covered, and review any exceptions and complementary user entity controls. For an ISO 27001 certificate, confirm the defined scope and the certification body, and consider requesting the Statement of Applicability where appropriate. Confirming these boundaries helps you understand what the documentation does and does not assure.
Should I track subprocessors on an ongoing basis rather than at onboarding only?
In most engagements, ongoing monitoring is expected rather than a one-time check. This typically includes maintaining an inventory of subprocessors, re-reviewing assurance documentation as reports and certificates are renewed, tracking changes to scope or subprocessor arrangements, and confirming that contractual commitments remain in place. The specific cadence and rigor depend on your risk assessment, scope, and the expectations of your auditor or certification body rather than a fixed rule.

Common misconceptions

A subprocessor's own SOC 2 report or ISO 27001 certificate means the service organization no longer needs to oversee that subprocessor.
A subprocessor's report or certificate covers only the controls, period, and scope it defines and does not remove the service organization's responsibility to manage and monitor the relationship. In most engagements, the service organization still needs its own vendor management controls, and a subprocessor's SOC 2 report attests only to the controls and period covered rather than guaranteeing freedom from breaches.
Naming a subprocessor in a SOC 2 report automatically brings that subprocessor's controls into the examination.
How a subservice organization is treated depends on scoping decisions. Under the carve-out method its controls are excluded from the service organization's description and testing, while under the inclusive method they are incorporated. The approach is set by scope rather than by mention alone.
Satisfying subprocessor requirements under one framework automatically satisfies the other.
Mapping between SOC 2 and ISO 27001 is possible but only partial. The Trust Services Criteria and ISO 27001 clauses 4-10 with Annex A reference controls address supplier and third-party risk differently, so meeting one framework's expectations does not automatically satisfy the other's.

Best practices

Maintain a current inventory of subprocessors, including the data they handle and the services they support, so that scope boundaries can be clearly defined for both SOC 2 examinations and the ISO 27001 Statement of Applicability.
Flow down relevant obligations through subprocessor agreements so that their practices support the commitments the service organization has made to its own customers.
Decide deliberately whether to use the carve-out or inclusive method for subservice organizations in SOC 2 engagements, and document the rationale, since this choice affects how their controls are represented and tested.
Perform and document risk assessment of subprocessors and select corresponding supplier-related Annex A reference controls when operating an ISO 27001 ISMS, specifying the version being referenced when discussing control coverage.
Obtain and review subprocessors' own SOC 2 reports or ISO 27001 certificates, noting the covered scope and period, and recognize their limitations rather than treating them as a substitute for ongoing oversight.
Address subprocessor arrangements explicitly when the Privacy or Confidentiality categories are in scope for SOC 2 or when personal data handling falls within the ISMS, to demonstrate that data protection commitments extend through the supply chain.