Subservice Providers and Your SOC 2: Stop Assuming AWS or Google Cloud Has You Covered

A common assumption shows up in almost every SOC 2 journey:

“We’re hosted on AWS or Google Cloud, so most of our security is already covered.”

It sounds reasonable. These platforms are secure, globally trusted, and heavily audited.

But here’s the reality.

Relying on cloud providers without understanding your responsibilities is one of the fastest ways to fail a SOC 2 audit.

Let’s break this down in simple terms.


What Are Subservice Providers in SOC 2?

In SOC 2, a subservice provider is any third party that performs part of your system operations.

This includes platforms like:

  • Amazon Web Services (AWS)
  • Google Cloud Platform (GCP)
  • Payment processors
  • Email service providers
  • CRM systems

These providers are critical to how your service works.

But they are not a replacement for your own controls.


The Biggest Misconception

Many companies believe:

“AWS is SOC 2 compliant, so we’re covered.”

That’s not how SOC 2 works.

SOC 2, defined by the AICPA, evaluates your controls, not just your vendors.

Even if your cloud provider is fully compliant, auditors will still ask:

  • How do you configure your infrastructure?
  • Who has access to your systems?
  • How do you monitor and respond to incidents?

In short, you are still accountable.


Understanding the Shared Responsibility Model

Cloud providers operate on a shared responsibility model.

What the Cloud Provider Handles

  • Physical data center security
  • Hardware and infrastructure
  • Core networking

What You Are Responsible For

  • User access management (IAM)
  • Data protection and encryption
  • Application security
  • Monitoring and logging
  • Configuration of cloud services

This is where most SOC 2 gaps happen.


How Subservice Providers Are Treated in SOC 2

There are two main approaches:

1. Inclusive Method

You include the controls of the subservice provider in your SOC 2 scope.

This is rare and complex.


2. Carve-Out Method (Most Common)

You exclude the provider’s controls but must:

  • Identify all subservice providers
  • Describe their role in your system
  • Define Complementary User Entity Controls (CUECs)

CUECs are critical.

They outline what you must do to ensure the provider’s controls remain effective.


What Are CUECs (And Why They Matter)

CUECs are often misunderstood or ignored.

They typically include things like:

  • Enforcing MFA for cloud access
  • Restricting admin privileges
  • Monitoring logs and alerts
  • Managing encryption keys
  • Performing regular access reviews

If you don’t implement these, your auditor will flag gaps.


Real-World SOC 2 Failures (Common Scenarios)

1. Misconfigured Cloud Storage

A company uses AWS but leaves an S3 bucket public.

AWS is secure. The configuration is not.


2. Weak Access Controls

Too many users have admin access.

No regular reviews are performed.


3. No Logging or Monitoring

Cloud logs exist but are not actively monitored.

No alerts. No response plan.


4. Missing Vendor Documentation

The company cannot clearly explain:

  • Which subservice providers are used
  • What they are responsible for
  • How risks are managed

What Auditors Actually Expect

Auditors are not just checking if you use AWS or GCP.

They want to see:

✔ Clear Identification of Subservice Providers

Document all third-party dependencies.


✔ Defined Responsibilities

Who handles what? Be specific.


✔ Implemented CUECs

Not just documented, but actively enforced.


✔ Evidence of Monitoring

Logs, alerts, reviews, and incident response.


✔ Vendor Risk Management

You should assess and review your providers regularly.


How to Get This Right (Practical Steps)

Here’s how to avoid surprises during your SOC 2 audit:

1. List All Subservice Providers

Include cloud, SaaS tools, APIs, and integrations.


2. Review Their SOC Reports

Ask for SOC 2 reports from your vendors.

Understand their control scope.


3. Map Responsibilities Clearly

Align your controls with the shared responsibility model.


4. Implement Strong Access Controls

  • Enforce MFA
  • Use least privilege
  • Review access regularly

5. Enable Logging and Monitoring

  • Track user activity
  • Monitor changes
  • Set alerts for suspicious behavior

6. Document Everything

If it’s not documented, it doesn’t exist in an audit.


Why This Matters for Your Business

This is not just about passing SOC 2.

It directly impacts:

Security

Misconfigurations are one of the top causes of breaches.


Customer Trust

Clients want to know you understand your security responsibilities.


Sales and Deals

Security questionnaires often go deep into cloud and vendor controls.


Final Thoughts

Cloud platforms like AWS and Google Cloud are powerful.

But they are not a shortcut to compliance.

SOC 2 expects you to understand your environment, your risks, and your responsibilities.

Subservice providers are part of your system, not a replacement for it.

If you rely on them without proper controls, you are building on a false sense of security.

The companies that succeed in SOC 2 are not the ones with the biggest providers.

They are the ones who own their responsibilities completely.

Facebook
Twitter
Email
Print

Leave a Reply

Your email address will not be published. Required fields are marked *