Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

Subservice Organization

A subservice organization is a vendor whose own controls are relevant to the services covered by a company's SOC 2 report, such as the cloud provider that hosts the audited system. The report handles it one of two ways: the carve-out method excludes the subservice organization's controls and names the customer's reliance on them, while the inclusive method folds them in. Most SOC 2 reports use the carve-out method.

In practice

When a report carves out a subservice organization, the assurance stops at that boundary. The practical response is to collect the carved-out vendor's own SOC 2 and read its complementary controls, rather than assuming the provider's opinion covered them.

On your own report, the choice is almost always carve-out, because your infrastructure providers already produce their own attestations. Your job is to track those attestations and implement the complementary controls they assume.

// how traztech helps

traztech delivers third-party risk management for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

The term matters when you read a SOC 2 and see a subservice organization carved out, because it changes what the report actually covers. The provider's clean opinion does not extend to the carved-out vendor, so you are expected to review that vendor's own report separately. Tracking those reports is part of third-party risk management.

When you issue your own report, your major infrastructure providers are usually subservice organizations handled by carve-out. The report then leans on complementary controls at those vendors, which is why their current attestations belong in your own vendor file.

Subservice Organization: common questions

What is the difference between the carve-out and inclusive methods?

Carve-out excludes the subservice organization's controls from your report and discloses the reliance; inclusive brings their controls into the examination. Carve-out is far more common because it is simpler and most providers already have their own SOC 2.

Is a subservice organization the same as a subprocessor?

Related but not identical. Subservice organization is a SOC 2 reporting concept about controls; subprocessor is a privacy-law concept about processing personal data. A cloud host is usually both, but the labels answer different questions.

Free PDFs, no card

Get the checklists that go with this

SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.