How to review a vendor's SOC 2 report: a 9-step checklist (and what CUECs mean for you)
When a vendor sends you their SOC 2 report, receiving it is not the same as reviewing it. Here's how to actually read one in your third-party risk process — including the complementary user entity controls (CUECs) that quietly make you responsible for part of their security.
Last updated July 20, 2026
Getting a SOC 2 report is step one, not the finish line
Asking a vendor for their SOC 2 report is now routine third-party risk hygiene, but too many teams file the PDF and check a box. A report can be out of date, scoped to exclude the service you use, carry a qualified opinion, or push controls back onto you. Reviewing it properly takes 20 minutes and protects you from inheriting a vendor's gaps. If you're the one being reviewed instead, see what a SOC 2 report looks like and what a SOC 2 report contains.
The 9-step vendor SOC 2 review checklist
Work down these in order — the early ones can disqualify a report before you spend time on the details:
- Confirm it's Type 2, not Type 1. Type 1 only attests controls were designed at a point in time; Type 2 tests they operated over a period. Enterprise risk teams generally want Type 2.
- Check the report period and its age. The observation window should be recent (typically within the last 12 months). If there's a gap between the period end and today, ask for a bridge letter.
- Read the auditor's opinion first. An unqualified ('clean') opinion is what you want; a qualified, adverse, or disclaimer opinion means the auditor found material problems — read why.
- Verify the scope covers the service you actually use. A company may hold SOC 2 for one product but not the one you're buying. Confirm the system description names it.
- Check which Trust Services Criteria are included. Security (Common Criteria) is the baseline; if you depend on uptime or data privacy, look for Availability or Confidentiality/Privacy too.
- Review the exceptions (test results). Section 4 lists any control failures the auditor found. A few minor exceptions are normal; assess whether any touch controls that matter to your data.
- Read the Complementary User Entity Controls (CUECs) — the part most people skip. See the next section.
- Check subservice organizations and the carve-out vs inclusive method. If the vendor relies on subprocessors (e.g. AWS), the report may 'carve out' those controls, meaning you should review their SOC 2 too.
- Save it with an expiry reminder. SOC 2 reports lapse; set a reminder to re-request one when the period ends so your risk file stays current.
What CUECs are, and why they make you responsible
Complementary User Entity Controls are the controls the vendor's SOC 2 assumes YOU operate on your side for the system to be secure end to end. A payroll platform's report might list CUECs like 'user entities are responsible for provisioning and deprovisioning their own users' or 'user entities are responsible for reviewing access reports.' If you don't do those, the vendor's clean report does not cover the resulting risk — it's now on you. Read the CUEC list (usually in the system description or Section 3), map each to a control you actually run, and flag any you can't satisfy. CUECs are also why a vendor's SOC 2 never fully transfers risk: part of the control environment is always yours. If the vendor relies on subprocessors, the subservice organization section tells you whether those controls were tested or carved out.
Turn the review into a repeatable process
Standardize this so every vendor gets the same treatment: keep a short rubric (Type 2? recent? clean opinion? scope match? CUECs mapped?), record the answers in your vendor inventory, and re-request reports on a schedule. If you're building your own SOC 2 program on the other side of these reviews, our compliance checklist covers the vendor-management controls auditors will test in your report — and you can get matched with auditors when you're ready.
Frequently asked questions
What is a CUEC in a SOC 2 report?
A Complementary User Entity Control (CUEC) is a control the vendor's SOC 2 assumes you, the customer, perform for the system to be fully secure — for example, managing your own user access or reviewing access reports. If you don't operate the CUECs, the vendor's report doesn't cover that gap; the responsibility is yours.
Should I accept a Type 1 SOC 2 report from a vendor?
A Type 1 report only confirms controls were designed correctly at a single point in time, not that they operated over a period. For a critical vendor, prefer a Type 2. A Type 1 may be acceptable for a low-risk vendor or as an interim while their first Type 2 window runs.
How recent does a vendor's SOC 2 report need to be?
The observation period should generally end within the last 12 months. If there's a gap between the report's period end and today, ask for a bridge letter — a signed statement from the vendor that nothing material has changed since the report.
What does a qualified SOC 2 opinion mean for me as a customer?
A qualified opinion means the auditor found one or more controls that didn't operate effectively. It isn't an automatic disqualifier, but you should read exactly which controls failed and decide whether they affect the data or service you rely on.
Does a vendor's SOC 2 report cover their subprocessors?
Not always. If the vendor uses the 'carve-out' method, their subservice organizations' controls (like AWS or a payment processor) are excluded from the report, and you should review those providers' own SOC 2 reports. The 'inclusive' method covers them within the report.