A common assumption shows up in almost every SOC 2 journey:
“We’re hosted on AWS or Google Cloud, so most of our security is already covered.”
It sounds reasonable. These platforms are secure, globally trusted, and heavily audited.
But here’s the reality.
Relying on cloud providers without understanding your responsibilities is one of the fastest ways to fail a SOC 2 audit.
Let’s break this down in simple terms.
What Are Subservice Providers in SOC 2?
In SOC 2, a subservice provider is any third party that performs part of your system operations.
This includes platforms like:
- Amazon Web Services (AWS)
- Google Cloud Platform (GCP)
- Payment processors
- Email service providers
- CRM systems
These providers are critical to how your service works.
But they are not a replacement for your own controls.
The Biggest Misconception
Many companies believe:
“AWS is SOC 2 compliant, so we’re covered.”
That’s not how SOC 2 works.
SOC 2, defined by the AICPA, evaluates your controls, not just your vendors.
Even if your cloud provider is fully compliant, auditors will still ask:
- How do you configure your infrastructure?
- Who has access to your systems?
- How do you monitor and respond to incidents?
In short, you are still accountable.
Understanding the Shared Responsibility Model
Cloud providers operate on a shared responsibility model.
What the Cloud Provider Handles
- Physical data center security
- Hardware and infrastructure
- Core networking
What You Are Responsible For
- User access management (IAM)
- Data protection and encryption
- Application security
- Monitoring and logging
- Configuration of cloud services
This is where most SOC 2 gaps happen.
How Subservice Providers Are Treated in SOC 2
There are two main approaches:
1. Inclusive Method
You include the controls of the subservice provider in your SOC 2 scope.
This is rare and complex.
2. Carve-Out Method (Most Common)
You exclude the provider’s controls but must:
- Identify all subservice providers
- Describe their role in your system
- Define Complementary User Entity Controls (CUECs)
CUECs are critical.
They outline what you must do to ensure the provider’s controls remain effective.
What Are CUECs (And Why They Matter)
CUECs are often misunderstood or ignored.
They typically include things like:
- Enforcing MFA for cloud access
- Restricting admin privileges
- Monitoring logs and alerts
- Managing encryption keys
- Performing regular access reviews
If you don’t implement these, your auditor will flag gaps.
Real-World SOC 2 Failures (Common Scenarios)
1. Misconfigured Cloud Storage
A company uses AWS but leaves an S3 bucket public.
AWS is secure. The configuration is not.
2. Weak Access Controls
Too many users have admin access.
No regular reviews are performed.
3. No Logging or Monitoring
Cloud logs exist but are not actively monitored.
No alerts. No response plan.
4. Missing Vendor Documentation
The company cannot clearly explain:
- Which subservice providers are used
- What they are responsible for
- How risks are managed
What Auditors Actually Expect
Auditors are not just checking if you use AWS or GCP.
They want to see:
✔ Clear Identification of Subservice Providers
Document all third-party dependencies.
✔ Defined Responsibilities
Who handles what? Be specific.
✔ Implemented CUECs
Not just documented, but actively enforced.
✔ Evidence of Monitoring
Logs, alerts, reviews, and incident response.
✔ Vendor Risk Management
You should assess and review your providers regularly.
How to Get This Right (Practical Steps)
Here’s how to avoid surprises during your SOC 2 audit:
1. List All Subservice Providers
Include cloud, SaaS tools, APIs, and integrations.
2. Review Their SOC Reports
Ask for SOC 2 reports from your vendors.
Understand their control scope.
3. Map Responsibilities Clearly
Align your controls with the shared responsibility model.
4. Implement Strong Access Controls
- Enforce MFA
- Use least privilege
- Review access regularly
5. Enable Logging and Monitoring
- Track user activity
- Monitor changes
- Set alerts for suspicious behavior
6. Document Everything
If it’s not documented, it doesn’t exist in an audit.
Why This Matters for Your Business
This is not just about passing SOC 2.
It directly impacts:
Security
Misconfigurations are one of the top causes of breaches.
Customer Trust
Clients want to know you understand your security responsibilities.
Sales and Deals
Security questionnaires often go deep into cloud and vendor controls.
Final Thoughts
Cloud platforms like AWS and Google Cloud are powerful.
But they are not a shortcut to compliance.
SOC 2 expects you to understand your environment, your risks, and your responsibilities.
Subservice providers are part of your system, not a replacement for it.
If you rely on them without proper controls, you are building on a false sense of security.
The companies that succeed in SOC 2 are not the ones with the biggest providers.
They are the ones who own their responsibilities completely.




















