Almost every SOC 2 report depends on other providers — cloud infrastructure, payment processors, managed services. How those providers appear in your report is a choice with real consequences, and it sits in a section most readers skim.
The two methods
- Carve-out. The subservice organisation's controls are excluded from your report. Your report describes what you do and notes that you rely on the provider, whose controls were not tested by your auditor. This is by far the most common approach.
- Inclusive. The provider's relevant controls are pulled into your scope and tested as part of your examination. Rare, because it needs the provider's cooperation and no major cloud provider will grant it.
The practical consequence: if you use a major cloud provider, your report almost certainly carves them out. Your report proves nothing about their controls — you are expected to obtain and review their SOC 2 separately, and your auditor will check that you do.
What a carve-out obliges you to do
Carving out does not remove responsibility; it relocates it into your vendor management process. You are expected to obtain the provider's report, review it, check that the period covers yours, read the exceptions, and — the step most often skipped — check the complementary user entity controls.
Track provider assurance where it belongs
GRC Copilot records vendor assurance reports, their periods and expiry, and links them to the controls that depend on them.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Complementary user entity controls
Every SOC 2 report contains a section listing controls the reader must operate for the provider's controls to be effective. A cloud provider secures the infrastructure on the condition that you configure access properly, manage your own keys, and enable logging.
These are obligations transferred to you, and they are routinely ignored. Two things follow: read the CUEC section of every provider report you rely on and confirm you actually perform those controls — and when writing your own report, state your CUECs explicitly so your customers know what remains theirs.
Reading the scope section properly
When a vendor gives you a SOC 2, establish: which system is covered (often narrower than the company); whether it is Type I or Type II and over what period; which trust services criteria are included — Security only, or more; which subservice organisations are carved out; what exceptions the auditor recorded; and whether the opinion is unqualified.
A clean-looking report covering a product you are not buying, for a period that ended a year ago, with Security only and three carved-out providers, is far weaker than it appears at a glance.
Frequently asked questions
Is carve-out worse than inclusive?
Not worse — different, and near-universal. It shifts responsibility for provider assurance into your vendor management process, where it is entirely manageable.
Can we force a provider to be inclusive?
Realistically no for large cloud providers. Smaller specialist providers occasionally agree.
What if a subservice provider has no SOC 2?
You need alternative assurance — another certification, a questionnaire, contractual commitments — and your auditor will ask what you relied on.
Do we have to list our own CUECs?
Yes, if your customers must operate controls for yours to work. Omitting them creates a gap nobody owns.
Key takeaways
- Carve-out is the norm — your report proves nothing about your providers.
- Carving out moves the obligation into vendor management, not out of existence.
- Complementary user entity controls are obligations transferred to the reader.
- Read scope, period, criteria, carve-outs and exceptions before trusting any report.