Skip to content
SecuriFii

Certification

Writing the user entity controls in your own SOC 2

Every SOC 2 report names controls the customer has to operate for the whole to work. Most service organisations write that section last and thinly, which is the wrong way round — it is the clause that defines where your assurance stops.

Facts checked2026-09-11

What goes in the user entity controls?

The test is simple: what must your customer do, that you cannot do for them, without which your controls do not achieve the criteria? Managing their own users and offboarding promptly. Configuring roles rather than accepting defaults. Enabling the options that make your assurances true — enforcing multi-factor authentication, setting session limits, turning on the audit log. Reviewing the logs you expose to them.

Be specific enough to be actionable. "Customers are responsible for appropriate use of the service" is not a control, and it does not move any responsibility anywhere — a reader cannot act on it, and an auditor is unlikely to accept it as delineating your boundary.

The consequence of under-specifying is that the gap stays yours. If your controls only achieve the criteria when the customer does something, and you never said so, you have asserted more than you can deliver — and the place that surfaces is an incident, not an audit.

The bottom line

Write this section early and specifically, then read it as though you were the customer. If an item does not tell them what to actually do, it is not yet a control and it has not moved any responsibility.

  • SOC 2 Type 2 Readiness

    Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.

Related insights