Learn about the carve-out method & the inclusive method for sub-processors in SOC 2, & evaluating a vendor’s sub-processor carve-out decisions, and more through the Frequently Asked Questions (FAQs) below. Please schedule a consultation if you are looking for a SOC 2 Readiness Partner or would like to discuss a customized solution for your organization.
Table of Contents
What is the carve-out method for sub-processors in SOC 2?
The carve-out method excludes a sub-processor’s controls from the SOC 2 examination scope, with the vendor’s report identifying the sub-processor and directing readers to obtain the sub-processor’s own SOC 2 Report for assurance over that layer.
The carve-out method is the more common approach and keeps examination scope manageable. It is the standard treatment for major cloud providers, AWS, Azure, and Google Cloud, all of which maintain their own SOC 2 Type 2 Reports that customers can independently review.
What is the inclusive method for sub-processors in SOC 2?
The inclusive method incorporates a sub-processor’s controls directly into the SOC 2 examination, meaning the auditor tests those controls as part of the engagement. This provides consolidated assurance, readers do not need to obtain a separate sub-processor report, but requires the sub-processor’s active cooperation and increases scope, cost, and complexity. The inclusive method is used selectively, typically when the sub-processor relationship is central to the service and the carve-out approach would leave a meaningful assurance gap that customers cannot otherwise fill.
How should a customer evaluate a vendor’s sub-processor carve-out decisions?
When a vendor uses the carve-out method for a sub-processor handling a customer’s data, the customer must independently obtain and review the sub-processor’s own SOC 2 Report, the vendor’s report does not provide that assurance. Evaluating carve-out decisions requires confirming that carve-out sub-processors are identified in Section 3 of the vendor’s report, independently obtaining and reviewing each sub-processor’s current SOC 2 Report to verify it covers the relevant Trust Services Criteria with a current unqualified opinion, and verifying that the sub-processor’s report covers the specific services the vendor is using, not just the sub-processor’s infrastructure generally. A vendor’s SOC 2 Report is only as comprehensive as the sum of the vendor’s own report plus the sub-processor reports for any carve-out parties whose controls are material to the service.
Explore Blogs, Webinars and other Resources
Trusted by Reputed Companies
What Our Clients Say
We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center
Our Growing List of Credentials
0
+
Assessments
0
+
Clients
0
+
Assessment Libraries
0
+
Years of Experience
0
+
No. of Staff Trained
0
+
HIPAA
0
+
SOC 2 Readiness
0
+
Pen Testing
0
+
ISO 27001 Certifications
0
+
Dollars Saved in Compliance Penalties