Complementary User Entity Controls
Complementary User Entity Controls (CUECs) are security and operational controls that a service provider expects its customers to put in place on their own side so that the overall service works as intended. In other words, a vendor's controls only fully protect the customer if the customer also implements certain controls at their end. These are commonly identified in SOC reports to clarify which security responsibilities belong to the customer rather than the service provider.
CUECs are control activities that reside at the user entity level and are identified by a service organization as necessary complements to its own controls in order to achieve stated control objectives or applicable trust services criteria. They are typically enumerated within SOC 1 or SOC 2 reports, signaling that the effectiveness of the service organization's control environment depends in part on the user entity implementing and operating specified controls (for example, access provisioning, review of output, or configuration on the customer side). CUECs delineate the shared-responsibility boundary between provider and customer; a user entity reviewing a SOC report should map each CUEC to its own internal controls, since failure to implement them may create gaps that the service organization's controls do not address. Note that CUECs describe expected customer-side controls and do not, by themselves, guarantee compliance or transfer accountability to the service provider.
Why it matters
CUECs matter because they define the shared-responsibility boundary between a service provider and its customers. When an organization relies on a vendor's SOC 1 or SOC 2 report as assurance, it is easy to assume the vendor's controls cover the full risk surface. In reality, the service organization's control objectives are only achieved if the customer implements the complementary controls the provider expects on the customer side, such as access provisioning, review of output, or configuration. Overlooking these expectations can leave gaps that neither party's controls address.
Who it's relevant to
Inside CUECs
Common questions
Answers to the questions practitioners most commonly ask about CUECs.