No service controls everything end to end. A hosting platform can encrypt storage and patch hypervisors, but it cannot stop a customer from handing out admin credentials — so its report states, control by control, what user entities are expected to handle. Typical CUECs: provision and deprovision your own users promptly, enforce MFA on your accounts, configure security settings per the documentation, and review the alerts and reports the service delivers to you. They live in the system description, usually as a dedicated table near the end.
CUECs turn a vendor’s report from a verdict into a shared-responsibility contract: the auditor’s opinion holds assuming the customer side is done. A reviewer running a vendor security review reads the CUEC list as their own to-do list — if your team never enforced the MFA the report presumes, the assurance you think you bought quietly evaporates. The logic also runs both directions: your customers read your CUECs the same way, and your own auditor may sample whether you actually operate the CUECs of critical vendors like your cloud provider.
Your CUEC list is also a responsibility-scoping tool: it marks where your obligations end and the customer’s begin. Keep it short, testable, and honest — a page of vague customer duties reads as blame-shifting, and the sharp reviewers described in SOC 2 in due diligence notice.