Skip to main content
Category: Supplier and Third-Party

Subservice Organization Criteria

Also known as: Subservice Organization
Simply put

A subservice organization is a vendor that a service organization relies on to perform certain functions whose controls matter to the services being delivered, most commonly a cloud hosting provider. Because the vendor's own controls contribute to the overall service, they become relevant when a service organization undergoes a SOC examination. In practice, a service organization decides how to address these vendors in its report, which affects how much of the vendor's control environment is considered within scope.

Formal definition

In SOC reporting, a subservice organization is a third-party vendor engaged by a service organization to perform services that are relevant to the controls and service commitments covered by the service organization's system. The controls at the subservice organization typically supplement those at the service organization, so their treatment must be disclosed in the SOC report, commonly through either the inclusive method (the subservice organization's relevant controls are incorporated into the description and testing) or the carve-out method (the subservice organization's controls are excluded from the description and testing but its use is disclosed). The method chosen and the resulting scope depend on scoping decisions made in the engagement, and the SOC report attests only to the controls and period actually covered; it does not assess controls that fall outside the defined scope or the carved-out subservice organization's own controls, which would generally be evidenced by that vendor's separate SOC report.

Why it matters

Most modern service organizations do not operate in isolation, they depend on other vendors, most commonly cloud hosting providers, whose own controls are necessary to meet the service organization's commitments. Because those vendor controls contribute directly to how a service is delivered, they cannot simply be ignored when a service organization undergoes a SOC examination. How these subservice organizations are represented in the report determines how much of the overall control environment a reader can actually rely on, which is why the concept is central to interpreting scope correctly.

For users of SOC reports, the treatment of subservice organizations affects the level of assurance they receive. If a subservice organization's controls are carved out, the report discloses the vendor's use but excludes its controls from the description and testing, meaning a reader typically needs the vendor's own separate SOC report to gain comfort over that portion of the environment. If controls are included via the inclusive method, the vendor's relevant controls are incorporated into the description and tested as part of the engagement. Misreading which method was applied can lead to a false sense of coverage.

It is important to remember that a SOC report attests only to the controls and period actually covered. It does not assess controls that fall outside the defined scope, and under the carve-out method it does not evaluate the carved-out subservice organization's own controls. Recognizing where those boundaries fall is essential for compliance managers, auditors, and vendor-risk teams who must decide whether additional evidence, such as a subservice organization's separate SOC report, is needed to complete their assessment.

Who it's relevant to

Compliance and GRC Managers
Those preparing for a SOC examination must identify which vendors qualify as subservice organizations, commonly cloud hosting providers, and decide, in coordination with their auditor, whether to apply the inclusive or carve-out method. This decision shapes the scope of the description and testing and determines what additional vendor evidence, such as a subservice organization's own SOC report, may need to be gathered.
SOC Report Readers and Vendor-Risk Teams
User entities relying on a service organization's SOC report need to understand how subservice organizations are treated to know the true boundaries of their assurance. Under the carve-out method, the report discloses the vendor's use but excludes its controls, so these teams typically must obtain the subservice organization's separate SOC report to assess that portion of the environment.
Service Organization Auditors
The CPA firm performing the examination must confirm that subservice organizations are properly identified and disclosed, and that the chosen method is accurately reflected in the system description and testing. Because the report attests only to the controls and period actually covered, auditors must be clear about which controls fall inside scope and which are carved out.
Cloud Providers and Other Outsourced Vendors
Vendors that function as subservice organizations, such as tech companies and process outsourcers, are affected because their controls become relevant to their customers' SOC reports. Maintaining their own SOC report supports customers who apply the carve-out method and need separate evidence of the vendor's control environment.

Inside Subservice Organization Criteria

Subservice Organization
A vendor or third party to which the service organization outsources functions relevant to the services covered by the SOC 2 examination. Because these outsourced functions may be relevant to user entities' internal control, they are addressed explicitly in the report rather than treated as fully out of scope.
Carve-Out Method
A presentation approach in which the subservice organization's controls are excluded from the description of the service organization's system. The report identifies the functions performed by the subservice organization and the relevant controls expected to be in place there, but the CPA firm does not test those controls as part of the engagement.
Inclusive Method
A presentation approach in which the subservice organization's relevant controls are incorporated into the description of the system and are subject to testing within the examination. This typically requires cooperation from the subservice organization and appropriate representations.
Complementary Subservice Organization Controls (CSOCs)
Controls that the service organization assumes are implemented at the subservice organization and that are necessary, in combination with the service organization's own controls, to meet the applicable Trust Services Criteria. Under the carve-out method these are described so readers understand the reliance placed on the subservice organization.
Scope and Boundary Definition
The delineation of which functions are performed internally versus by subservice organizations, informing how the system description is drawn and which controls fall within the CPA firm's testing responsibility for the period or point in time covered.

Common questions

Answers to the questions practitioners most commonly ask about Subservice Organization Criteria.

Does using the carve-out method mean a subservice organization's controls are excluded from the SOC 2 examination entirely?
Not quite. Under the carve-out method, the description identifies the subservice organization and the functions it performs, and the service organization's own controls are examined, but the subservice organization's controls are excluded from the description and the scope of the service auditor's testing. The complementary subservice organization controls (CSOCs) that are expected to be in place are typically identified so report users understand what the service organization relies on. The subservice organization's controls are not tested by the service auditor, but they are not simply ignored either, users are directed to obtain assurance over them separately, often through the subservice organization's own SOC 2 report.
Is a SOC 2 report meaningless if a critical vendor is carved out rather than included?
No. Carving out a subservice organization is a common and accepted scoping decision, and it does not invalidate the report. It does, however, shift responsibility to the report user to evaluate the carved-out organization separately. A carved-out report attests only to the controls and period covered at the service organization; it does not provide assurance over the subservice organization's controls. Report users typically address this by reviewing the subservice organization's own attestation and confirming that the identified complementary subservice organization controls are operating.
How do we decide between the inclusive and carve-out method for a subservice organization?
The choice generally depends on scope, the availability of the subservice organization's cooperation, and the assurance needs of report users. The inclusive method incorporates the subservice organization's relevant controls into the description and the service auditor's testing, which typically requires the subservice organization's willingness to participate and be examined. The carve-out method excludes those controls from testing and instead identifies expected complementary controls. In most engagements the decision is made during scoping with the service auditor, weighing feasibility against the level of transparency users expect.
What are complementary subservice organization controls (CSOCs) and where do they appear in the report?
CSOCs are the controls the service organization assumes are in place at a carved-out subservice organization for the overall control objectives or applicable Trust Services Criteria to be met. They are typically documented in the description alongside the service organization's controls, so that report users can see which control responsibilities rest with the subservice organization. Their presentation and level of detail depend on scope and the service auditor's judgment; they signal to users what additional assurance to seek from the subservice organization.
How should a report user obtain assurance over a carved-out subservice organization?
Report users typically request the subservice organization's own attestation, often its SOC 2 report, covering the relevant criteria and a period that aligns with the user's needs. Users then map the complementary subservice organization controls identified in the original report to the controls tested in the subservice organization's report to confirm coverage. Because attestations cover only defined controls and periods, users generally check that the scope, criteria, and review period are appropriate rather than assuming coverage.
Can a subservice organization arrangement affect how SOC 2 and ISO 27001 scoping are handled together?
The two frameworks treat outsourced functions differently, so the arrangements do not map automatically. In SOC 2, subservice organizations are addressed through the inclusive or carve-out method within the attestation. Under ISO 27001, reliance on external providers is handled within the ISMS scope and Statement of Applicability, informed by risk assessment. Satisfying subservice organization handling in one framework does not by itself satisfy the corresponding treatment in the other; mapping is possible but partial and depends on the defined scope of each.

Common misconceptions

Using the carve-out method means the subservice organization is entirely irrelevant to the SOC 2 report.
Even under the carve-out method, the report typically identifies the subservice organization's functions and the complementary controls expected to be in place there. The controls are not tested by the CPA firm, but readers are still directed to consider that reliance when evaluating the overall control environment.
A service organization's SOC 2 report provides assurance over its subservice organizations' controls.
A SOC 2 report attests only to the controls and period covered by that engagement. Under the carve-out method the subservice organization's controls are not examined; user entities generally need to obtain separate assurance, such as the subservice organization's own SOC 2 report, to address that reliance.
The inclusive and carve-out methods are interchangeable and produce equivalent coverage.
They differ meaningfully. The inclusive method brings the subservice organization's relevant controls into the system description and subjects them to testing, whereas the carve-out method excludes them from testing. The choice depends on scoping decisions and typically on the subservice organization's willingness to participate.

Best practices

Inventory outsourced functions early in scoping to determine which vendors qualify as subservice organizations relevant to the applicable Trust Services Criteria.
Decide between the carve-out and inclusive methods deliberately, documenting the rationale and, for the inclusive method, confirming the subservice organization's willingness to participate and provide representations.
When using the carve-out method, clearly describe the complementary subservice organization controls so report readers understand the reliance placed on the subservice organization.
Obtain and review the subservice organization's own assurance evidence, such as a SOC 2 report covering the relevant functions, and assess whether its coverage and period align with your reliance.
Reconcile the review periods and scopes between your report and any subservice organization reports, noting gaps rather than assuming continuous coverage.
Communicate to user entities the boundaries of what your report covers, making clear that carved-out subservice organization controls are not tested within your engagement.