Certification
Writing the user entity controls in your own SOC 2
Every SOC 2 report names controls the customer has to operate for the whole to work. Most service organisations write that section last and thinly, which is the wrong way round — it is the clause that defines where your assurance stops.
Facts checked — 2026-09-11
What goes in the user entity controls?
The test is simple: what must your customer do, that you cannot do for them, without which your controls do not achieve the criteria? Managing their own users and offboarding promptly. Configuring roles rather than accepting defaults. Enabling the options that make your assurances true — enforcing multi-factor authentication, setting session limits, turning on the audit log. Reviewing the logs you expose to them.
Be specific enough to be actionable. "Customers are responsible for appropriate use of the service" is not a control, and it does not move any responsibility anywhere — a reader cannot act on it, and an auditor is unlikely to accept it as delineating your boundary.
The consequence of under-specifying is that the gap stays yours. If your controls only achieve the criteria when the customer does something, and you never said so, you have asserted more than you can deliver — and the place that surfaces is an incident, not an audit.
The bottom line
Write this section early and specifically, then read it as though you were the customer. If an item does not tell them what to actually do, it is not yet a control and it has not moved any responsibility.
Related services
SOC 2 Type 2 Readiness
Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.
Related insights
Certification
The Statement of Applicability, and why an auditor opens it first
The document that shows whether your management system has reasoning behind it — and the one most organisations build backwards.
Certification
Stage 1 and Stage 2: what each audit tests, and why Stage 1 is not a rehearsal
One checks that you are ready to be audited. The other is the audit. Both feed the certification decision.
Certification
ISO 27001:2013 certificates have expired — including the ones with later dates on them
The window closed on 31 October 2025. A lapsed holder is treated as a new client — which is the part most summaries leave out.