A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Complementary User Entity Controls (CUECs) are controls a service organization assumes its customers will put in place for the overall system to meet the Trust Services Criteria. They are listed in the SOC 2 report because the service provider's controls only work if the customer does its part, such as managing its own user access or reviewing configuration. They divide responsibility between provider and customer.
When assessing a vendor, treat the CUEC section as the most actionable part of their report. It tells you exactly what the provider is not doing for you, which is often where real risk sits in an otherwise clean report.
When issuing your own report, keep the CUEC list honest and specific. Vague complementary controls either confuse customers or quietly shift responsibility, and an auditor will expect each one to be genuine rather than a way to offload a gap.
traztech delivers SOC 2 readiness and audit prep for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
CUECs come up in two directions. When you read a vendor's SOC 2, the CUEC list is your to-do list: the things you must do for their controls to actually protect you. When you issue your own SOC 2, it is where you state honestly what you rely on customers to handle. Both sides are part of SOC 2 readiness and audit prep.
The quiet risk is a vendor's CUEC list that nobody on your side reads. A report can be clean and still leave you exposed if the complementary controls it assumes, like enforcing MFA on your own accounts, were never implemented.
A control the service provider expects you, the customer, to operate. Their SOC 2 only holds up if you do your part, so the list is effectively a shared-responsibility checklist.
The user entity, meaning the customer. The provider names the assumption in its report; implementing it is on you, which is why reading the list during vendor review matters.
Free PDFs, no card
SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.