User Entity
In a SOC 2 context, a user entity is the customer organization that uses a service provider's system and relies on the service provider's controls. Because some controls needed to achieve the overall objectives sit with the customer rather than the service provider, the user entity is typically expected to implement its own complementary controls. In other words, the security of the outsourced service depends partly on what the user entity does on its own side.
A user entity is the organization (or, more generally, an individual, organization, device, or process) that uses a service organization's system and whose control environment interacts with the controls covered by a SOC 2 examination. In service organization reporting, certain objectives can only be met when the user entity operates its own controls; these are documented as Complementary User Entity Controls (CUECs), which reside with the user entity to ensure appropriate use of and access to the service. The user entity's responsibilities are typically identified in the service organization's SOC 2 report so that the user entity can assess how the service organization's controls, in combination with its own complementary controls, support the applicable Trust Services Criteria. The precise CUECs and the boundary of user entity responsibility depend on the service, scope, and the service organization's system description, and vary from engagement to engagement.
Why it matters
The concept of the user entity captures a critical reality of outsourced services: a SOC 2 report attests to the service organization's controls, but the overall security objectives typically cannot be met by the service organization alone. Some controls necessarily sit with the customer. When a user entity fails to implement the complementary controls expected of it, gaps can emerge that neither party fully owns, even when the service organization's own controls are operating effectively over the period covered.
For this reason, a user entity should not treat a service organization's SOC 2 report as a guarantee of security or as evidence that its own responsibilities have been discharged. The report attests only to the controls and period it covers, and it does not guarantee freedom from breaches. The Complementary User Entity Controls (CUECs) documented in the report signal precisely where the user entity must act on its own side, for example by managing access appropriately and using the service as intended. Overlooking these responsibilities is a common source of misplaced reliance.
Because the exact CUECs and the boundary of user entity responsibility depend on the service, scope, and the service organization's system description, they vary from engagement to engagement. A user entity that reviews these responsibilities carefully is better positioned to assess how the service organization's controls, in combination with its own, support the applicable Trust Services Criteria.
Who it's relevant to
Inside User Entity
Common questions
Answers to the questions practitioners most commonly ask about User Entity.