Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

Complementary User Entity Controls (CUEC)

Complementary User Entity Controls (CUECs) are controls a service organization assumes its customers will put in place for the overall system to meet the Trust Services Criteria. They are listed in the SOC 2 report because the service provider's controls only work if the customer does its part, such as managing its own user access or reviewing configuration. They divide responsibility between provider and customer.

In practice

When assessing a vendor, treat the CUEC section as the most actionable part of their report. It tells you exactly what the provider is not doing for you, which is often where real risk sits in an otherwise clean report.

When issuing your own report, keep the CUEC list honest and specific. Vague complementary controls either confuse customers or quietly shift responsibility, and an auditor will expect each one to be genuine rather than a way to offload a gap.

// how traztech helps

traztech delivers SOC 2 readiness and audit prep for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

CUECs come up in two directions. When you read a vendor's SOC 2, the CUEC list is your to-do list: the things you must do for their controls to actually protect you. When you issue your own SOC 2, it is where you state honestly what you rely on customers to handle. Both sides are part of SOC 2 readiness and audit prep.

The quiet risk is a vendor's CUEC list that nobody on your side reads. A report can be clean and still leave you exposed if the complementary controls it assumes, like enforcing MFA on your own accounts, were never implemented.

Complementary User Entity Controls (CUEC): common questions

What is a CUEC in plain terms?

A control the service provider expects you, the customer, to operate. Their SOC 2 only holds up if you do your part, so the list is effectively a shared-responsibility checklist.

Who is responsible for CUECs?

The user entity, meaning the customer. The provider names the assumption in its report; implementing it is on you, which is why reading the list during vendor review matters.

Free PDFs, no card

Get the checklists that go with this

SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.