Skip to main content
Category: SOC Reporting

User Entity

Also known as: User Organization, Customer Company (in a service organization context)
Simply put

In a SOC 2 context, a user entity is the customer organization that uses a service provider's system and relies on the service provider's controls. Because some controls needed to achieve the overall objectives sit with the customer rather than the service provider, the user entity is typically expected to implement its own complementary controls. In other words, the security of the outsourced service depends partly on what the user entity does on its own side.

Formal definition

A user entity is the organization (or, more generally, an individual, organization, device, or process) that uses a service organization's system and whose control environment interacts with the controls covered by a SOC 2 examination. In service organization reporting, certain objectives can only be met when the user entity operates its own controls; these are documented as Complementary User Entity Controls (CUECs), which reside with the user entity to ensure appropriate use of and access to the service. The user entity's responsibilities are typically identified in the service organization's SOC 2 report so that the user entity can assess how the service organization's controls, in combination with its own complementary controls, support the applicable Trust Services Criteria. The precise CUECs and the boundary of user entity responsibility depend on the service, scope, and the service organization's system description, and vary from engagement to engagement.

Why it matters

The concept of the user entity captures a critical reality of outsourced services: a SOC 2 report attests to the service organization's controls, but the overall security objectives typically cannot be met by the service organization alone. Some controls necessarily sit with the customer. When a user entity fails to implement the complementary controls expected of it, gaps can emerge that neither party fully owns, even when the service organization's own controls are operating effectively over the period covered.

For this reason, a user entity should not treat a service organization's SOC 2 report as a guarantee of security or as evidence that its own responsibilities have been discharged. The report attests only to the controls and period it covers, and it does not guarantee freedom from breaches. The Complementary User Entity Controls (CUECs) documented in the report signal precisely where the user entity must act on its own side, for example by managing access appropriately and using the service as intended. Overlooking these responsibilities is a common source of misplaced reliance.

Because the exact CUECs and the boundary of user entity responsibility depend on the service, scope, and the service organization's system description, they vary from engagement to engagement. A user entity that reviews these responsibilities carefully is better positioned to assess how the service organization's controls, in combination with its own, support the applicable Trust Services Criteria.

Who it's relevant to

Compliance and GRC managers at customer organizations
Those overseeing vendor risk need to obtain and review a service organization's SOC 2 report, identify the Complementary User Entity Controls that apply, and confirm their organization has implemented them. This is central to relying appropriately on an outsourced service rather than assuming the report covers responsibilities that actually reside with the customer.
Service organizations preparing SOC 2 reports
Service providers must accurately identify and document the CUECs their customers are expected to operate, so that user entities understand where their own controls are needed. Clearly stating these responsibilities helps set the boundary of what the report does and does not cover for the period examined.
Auditors and CPA firms performing SOC 2 examinations
Practitioners assess the service organization's system description, including how CUECs are represented, since certain objectives can only be met when the user entity operates its own controls. Accurate documentation of user entity responsibilities affects how readers of the report interpret the combined control environment.
Security engineers implementing controls at customer organizations
Engineers on the user entity side are often responsible for operationalizing the complementary controls, such as managing access to and appropriate use of the service. They translate the CUECs documented in a report into concrete configurations and processes within their own environment.

Inside User Entity

User Entity Definition
In a SOC 2 examination, a user entity is an organization (or its representative) that uses the service organization's system and relies on the service organization's controls as part of its own internal control environment. The service organization's SOC 2 report is prepared, in part, for the benefit of these user entities and their auditors.
Complementary User Entity Controls (CUECs)
Controls that the service organization assumes will be implemented by user entities and that are necessary, in combination with the service organization's own controls, to achieve the applicable Trust Services Criteria. CUECs are typically listed in the SOC 2 report so user entities understand their responsibilities within the shared control environment.
Reliance Relationship
The dependency a user entity places on the service organization's controls when the service organization performs functions that affect the user entity's operations or financial reporting. This reliance is a central reason user entities request and read SOC 2 reports.
Boundary of Responsibility
The delineation between controls operated by the service organization and controls that remain the responsibility of the user entity. A SOC 2 report attests only to the controls within the service organization's described system and covered period, so responsibilities falling to the user entity are outside that attestation's scope.

Common questions

Answers to the questions practitioners most commonly ask about User Entity.

Is a user entity the same as the service organization being audited?
No. In a SOC 2 examination, the service organization is the entity whose controls are being examined by the CPA firm, while the user entity is a customer or client that uses the service organization's system. The two roles are distinct: the service organization provides the service and its controls are the subject of the report, whereas the user entity relies on that service and typically reads the resulting report to understand the controls in place.
Does a SOC 2 report mean the user entity has no security responsibilities of its own?
No. A SOC 2 report attests only to the controls at the service organization for the period covered; it does not transfer or eliminate the user entity's own responsibilities. Reports commonly identify complementary user entity controls that the user entity is expected to implement for the overall control objectives to be met. The report also does not guarantee freedom from breaches, so the user entity typically remains responsible for controls on its side of the relationship, depending on scope.
Where in a SOC 2 report should a user entity look to understand its own obligations?
User entities typically review the section describing complementary user entity controls (often abbreviated CUECs), which sets out the controls the service organization assumes the user entity has in place. In most engagements this section is found within the description of the system or accompanying the controls listing. Reviewing it helps a user entity confirm which responsibilities remain on its side of the shared arrangement.
How can a user entity use a service organization's SOC 2 report in its own compliance program?
A user entity typically uses the report as evidence when assessing a vendor's control environment, which can support the user entity's own vendor management or third-party risk activities. Because the report attests only to the controls and period covered, a user entity generally checks that the report's scope, review period, and selected Trust Services Criteria align with the services it actually consumes before relying on it.
What should a user entity confirm about a SOC 2 report's scope before relying on it?
A user entity typically confirms that the report covers the specific system and services it uses, the relevant Trust Services Criteria for its needs (Security is always included as the Common Criteria, while Availability, Processing Integrity, Confidentiality, and Privacy are optional and depend on scope), and whether the report is a Type I (suitability of design at a point in time) or Type II (design and operating effectiveness over a defined period). It also generally reviews the period covered, since a report speaks only to that timeframe.
Does the user entity concept differ between SOC 2 and ISO 27001?
The user entity terminology is specific to the SOC reporting framework rather than ISO 27001. ISO 27001 certifies an information security management system against the defined scope of that ISMS, and a customer relying on an ISO 27001-certified provider generally reviews the certificate scope and Statement of Applicability rather than complementary user entity controls. Because the frameworks differ in structure, a customer's assurance approach typically depends on which framework the provider has undergone, and satisfying one does not automatically satisfy the other.

Common misconceptions

A SOC 2 report means the user entity has no remaining control responsibilities.
In most engagements the report identifies complementary user entity controls that the user entity is expected to implement. Achieving the Trust Services Criteria typically depends on both the service organization's controls and these user-side controls operating together, so responsibilities remain with the user entity.
A user entity receiving a SOC 2 report is protected against any breach affecting the service.
A SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches. It provides information a user entity can use in assessing risk, but it is not a warranty of security outcomes.
The concept of a user entity applies identically under ISO 27001.
The user entity and complementary user entity control concepts arise from the SOC 2 attestation model under the AICPA framework. ISO/IEC 27001 is a certification of a management system covering a defined scope and does not use these attestation-specific terms in the same way; the two frameworks should not be conflated.

Best practices

Read the complementary user entity controls section of any SOC 2 report you receive and map each listed CUEC to an internal control you actually operate.
Treat the service organization's report as covering only the controls and time period stated, and independently address responsibilities that fall to your organization as the user entity.
Confirm the scope of the report and the review period align with the services you rely on before placing reliance on the described controls.
Maintain documentation showing how your organization satisfies the complementary user entity controls, so your own auditors can evaluate the combined control environment.
Where you rely on both SOC 2 reports and ISO 27001 certificates from a vendor, evaluate each on its own terms rather than assuming one framework's coverage substitutes for the other.
Periodically request updated reports and reassess CUECs, since covered controls, scope, and identified user responsibilities can change between examination periods.