CUEDEV
← All field notes
Templates Sep 2026 8 min read

CUEC Mapping Template for SOC 1 & SOC 2 Reports

A Complementary User Entity Control (CUEC) is a control the SOC report assumes your organization runs, not the vendor. If it never got implemented on your side, the control objective can fail even with a clean SOC opinion in hand. This page gives you a free register plus the exact process for mapping them.

50
Rows ready to fill in
2
Report types covered
Free
No email required
5
FAQs answered
01

What a CUEC is, and why it is not the vendor's problem

A Complementary User Entity Control (CUEC) is a control activity a service organization's SOC report assumes you, the customer, are running. A payroll vendor's SOC 1 might state plainly that it expects you to notify it promptly when an employee leaves, so it can remove that employee's payroll access. If that notification never happens on your end, the control objective can still fail, no matter how clean the vendor's own report reads.

XLSX

CUEC Mapping Template (SOC 1 + SOC 2)

A register with status dropdowns, a worked example row, and a Summary Dashboard tab that scores coverage and gaps automatically.

Download →

Linford & Company's guide to CUECs ↗ is blunt about the risk: “if CUECs do not operate effectively at a user entity, control failures could still occur” even when the service organization's own controls are sound. A SOC report you never actually mapped is a SOC report you cannot rely on.

02

Where CUECs live in SOC 1 and SOC 2 reports

CUECs sit in both report types, and they work alongside the service organization's own controls to satisfy a control objective (SOC 1) or a Trust Services Criterion (SOC 2). Typical examples pulled straight from real SOC reports:

  • Removing a terminated employee's access to the vendor's platform promptly
  • Approving configuration or environment changes before they go live
  • Encrypting data before it is transmitted to the vendor
  • Notifying the vendor of authorized-user changes on your own systems
  • Maintaining your own contingency or backup plan, separate from the vendor's

If you have not read our comparison of the report types themselves, start with SOC 1 vs SOC 2 vs Type I vs Type II before mapping CUECs across several vendors at once.

03

How to use the template

  1. Pull every CUEC listed in Section 3 (or the equivalent) of the vendor's SOC 1 or SOC 2 report
  2. Name the internal control owner and the actual internal process that satisfies it, not just "we do this"
  3. Score the operating status: Implemented, Partially Implemented, Not Implemented, or Not Applicable
  4. Log where the evidence lives so it is a two-click pull, not a scramble, during your own audit
  5. Check the Summary Dashboard tab for your coverage rate and open-gap count
04

Where CUEC mapping usually breaks down

  • Never reading Section 3 at all . the SOC report gets filed away as proof the vendor is fine, and the CUEC list inside it never gets read
  • Assuming a CUEC without proof . "we definitely do that" is not evidence; name the actual control and where it is logged
  • No named owner . a CUEC with nobody accountable for it quietly lapses the moment the person who used to think about it changes roles
  • Treating it as a once-a-year exercise . a new SOC report can add, drop, or reword CUECs; re-map on every report refresh, not just the first time
  • One giant vendor list instead of one register . tracking CUECs per-vendor in separate documents makes it impossible to see your overall gap count
05

How CueDev's agents keep this current automatically

This template gets your CUEC register into a defensible, auditable shape by hand. What we actually build for compliance and audit teams goes a step further: an agent that reads each new SOC report as it arrives, diffs its CUEC list against your existing register, flags anything added, dropped, or reworded, and routes the gap straight to the named owner instead of waiting for the annual review to catch it.

The same evidence discipline applies to reports and extracts you rely on internally, not just vendor SOC reports. See our IPE completeness and accuracy testing template if that is the gap you are closing next, or read how we think about designing internal controls that hold up under audit.

06

FAQ

Complementary User Entity Control. It is a control the SOC report explicitly expects the customer (user entity), not the service organization, to operate.

No. CUECs appear in both SOC 1 and SOC 2 reports, and in both cases they work alongside the service organization's own controls to satisfy the report's stated control objectives or Trust Services Criteria.

The control objective it supports can fail even if the vendor's own controls are operating perfectly, because the objective was designed assuming both sides do their part.

Yes. It downloads directly with no email or signup required, and you can adapt the columns to your own control framework or your auditor's specific requests.

Every time you receive a new SOC report from that vendor. Report periods roll forward, and the CUEC list itself can change between report cycles, so a stale mapping is a common source of audit surprises.

07

Next step

If your evidence trail also includes internally-produced reports, pair this with our IPE testing template for the completeness and accuracy side of the same audit file.

Book an audit →