Is an employer of record a subservice organization for SOC 2?
The provider employs the contractor, but you grant the access. That split decides which controls you still own.
Is an employer of record a subservice organization? For the system a SOC 2 report describes, no. The provider handles payroll, tax and local employment paperwork. It does none of the work your customers are paying for.
That makes it a supplier under your vendor management. Screening, security terms, training, access and offboarding remain your controls. What the provider gives you is evidence for those controls, never a substitute for them.
The one question that settles it
A subservice organization performs part of the service you deliver to your customers.1 Your cloud host fits that. So does a model provider in your request path. A payroll intermediary does not, and there is a quick way to see why.
Imagine the vendor stops working tomorrow. Would your customers notice through your product, or would you notice through your bank account? Infrastructure fails the first way. Employment administration fails the second way.
The contractor, meanwhile, is fully yours in every way that matters to an auditor. They sign in through your identity provider, read your customer data and merge to your main branch. You grant their access, review it and revoke it, so those controls are yours to run and yours to evidence.2
One exception. If you resell the provider’s service under your own brand, their processing becomes part of what your customers buy, and the carve-out decision applies.3 Our page on complementary user entity controls covers that mechanism.
Get this backwards and the damage is concrete. A description that carves out a payroll vendor also seems to hand off personnel controls you are still the only one running. The auditor then finds the same people with the same access and nothing testable behind it.
Who does what for a contractor on an EOR
Two sets of criteria apply to the same worker at once. The hiring and competence criteria expect a record for each person with access.2 The vendor criterion expects you to have assessed the supplier. This table is the split an auditor can actually test, row by row.
| Activity | Done by | Evidence source | What the auditor checks |
|---|---|---|---|
| Screening, CC1.4 | The provider at onboarding, or a screening vendor you hire | Their record, your vendor report, or your written risk acceptance | Something existed before access was granted, per sampled person |
| Confidentiality and security terms | The provider drafts, you set the required clauses | The signed worker agreement, or a pass-through clause in your contract | The duties reach the individual, not just the provider entity |
| Security training, CC1.4 | You | Your completion record in your own system | Same module and same yearly cadence as staff |
| Access provisioning, CC6.1 | You | Your identity provider and the approved request | Approval came before access |
| Access review, CC6.2 | You | Your review record per system | Contractors are in the population, not only payroll staff |
| Device requirements, CC6.7 | You set them, the worker follows them | The agreement clause and whatever enforces it technically | Something beyond the clause does the enforcing |
| Offboarding, CC6.5 | You revoke, the provider ends the engagement | Revocation timestamps from your systems and their end date | Access ended on or before the last working day |
| Payroll, tax, benefits | The provider | Their own records | Nothing. Outside your system boundary |
| The provider itself, CC9.2 | You | Your vendor assessment and their report, with a dated read note | You chose them on purpose and noticed when their report lapsed |
Watch two rows closely. Access review is where contractors drop out, because the list is often built from a payroll system that never held them. Offboarding is where both sides need matching dates. Our access review template and offboarding checklist produce those two records.
Evidence to request from the provider
Provider support teams answer specific requests and deflect vague ones. Name the worker, the date and the artifact. Below is a request you can paste into a ticket as written, changing only the names.
We are the client for the workers named below. Our SOC 2 examination covers personnel security for everyone with access to our systems, and our auditor samples people by name. For each worker, please attach the items below instead of describing them.
- Screening before the engagement began: which checks, the completion date of each, the country of the record, and who ran it.
- The screening record. If you cannot release it, the issuing body, a reference number and a statement of the result.
- The signed worker agreement, or its clauses on confidentiality, intellectual property, acceptable use, device security and return of data.
- Any security training the worker completed through you, with the date. If none, please say so.
- Your current SOC 2 or ISO report, its period, and its complementary user entity controls.
- What you disable, and how fast, when we end an engagement, and who confirms it to us.
Some items will come back refused. That is still useful. A refusal tells you which control you now run yourself, and it is far better to learn that before the period opens than during fieldwork. If the training item comes back empty, the training record simply has to be yours.
File the reply with the vendor assessment, not in someone’s inbox. Our vendor assessment template has a row for it, and a dated note saying who read the provider’s report is itself CC9.2 evidence.
Screening records country by country
The screening control does not require a particular document. It asks that people were screened before they got access, so the evidence takes whatever form the worker’s country issues. Several national registers release an extract only to the individual. What you receive is a certificate the worker got and handed over, and that still works as evidence.
| Country | Record available | What you can receive | Source, checked 1 August 2026 |
|---|---|---|---|
| United Kingdom | Basic Disclosure and Barring Service check, for applicants 16 or older | A paper certificate mailed to the applicant. The published fee is £21.50, and processing usually takes up to 3 days | gov.uk |
| Germany | Führungszeugnis from the Federal Central Criminal Register | A certificate the person requests, online with an electronic ID card or residence permit and its PIN | fuehrungszeugnis.bund.de |
| Poland | National Criminal Register certificate, which anyone may request | A signed XML file, 20 zloty online or 30 in person, with up to 20 calendar days for the online route | gov.pl |
| Brazil | Federal Police certidão de antecedentes criminais | A free online certificate valid for 90 days, with an official page to validate a copy you were sent | gov.br |
| Philippines | National Bureau of Investigation clearance | A clearance collected in person after biometric capture, even if registration and payment were online. Published fees are 115, 165 and 415 pesos | nbi.gov.ph |
| India | Police Clearance Certificate, for passport holders seeking residence, work abroad, a long term visa or immigration | Often nothing through this route, since a contractor staying in India is not emigrating. A commercial report covering court records and employment checks is the normal substitute | mea.gov.in |
Each row describes a record that exists and the form an auditor can receive. None of it says you may ask for it. Whether you can request a check, keep the result or act on it is employment and data protection law in the worker’s country, and that belongs with local counsel. We are not lawyers and this is not legal advice.
Plan for two practical issues. Lead times differ by weeks, so a certificate requested in the last fortnight may arrive after your period closes. And a certificate the worker obtains needs a chain of custody: who received it, when, and where it is stored. Record that. An auditor can test it without reading the certificate.
Controls for a laptop you do not manage
Contractors bring their own hardware, and you cannot push device management onto a machine you do not own. NIST calls these third party controlled devices and states the limit plainly: agreements requiring such devices to be secured generally cannot be automatically enforced, so compromised devices may end up connected to sensitive resources. That is Special Publication 800-46 Revision 2, from July 2016, which we read on 1 August 2026.
A contract clause is a promise. A control works whether or not the promise is kept. So shift the control off the endpoint and onto systems you do own.
| What you cannot do | What replaces it | Evidence |
|---|---|---|
| Enroll the device | Browser only access or a hosted desktop, so customer data never lands on the disk. NIST also recommends moving high risk resources to servers that take on their protection | The access configuration and a data flow showing no local copy |
| Confirm disk encryption | Access tiers by device type. The NIST example tier table gives contractor, partner and vendor devices their own columns, apart from company hardware | Your tier definition and the conditional access rule that applies it |
| Check patch levels | Short sessions and reauthentication, so a lost laptop loses access on your schedule | The session lifetime setting and one timestamped revocation |
| Wipe the machine | An isolated work container that can be removed on its own | The container policy and a removal record from a real departure |
| Close the gap entirely | A dated risk acceptance naming the person, device, exposure and approving owner | The signed acceptance, in the risk register, reviewed on a schedule |
Each row is ordinary engineering, and none needs the contractor to install anything. The final row is the honest fallback when the others fall short. Our risk register template shows what a defensible acceptance must include.
Picture a policy that says every endpoint runs managed antivirus and full disk encryption, while four of nine engineers use machines nobody has seen. The auditor tests you against your own written procedure, so that sentence manufactures the exception. Write the contractor case into the policy, name the compensating controls, and the same test passes.
Cost: what this takes to do yourself
Contractors do not add a new control. They change where the evidence for existing controls comes from, and they add one vendor to assess. A consultant would bill hours to sort that out. Here is one published estimate of the consultant route for full SOC 2 preparation.
- Comp AI states that a vCISO or compliance consultant might charge $150 to $400 an hour, which can total $20,000 to $50,000 for a full SOC 2 prep engagement. Source, checked 2026-07-30.
You can do nearly all of this page in-house. The provider request is a ticket. The country certificates cost the small government fees listed above, and the laptop controls are settings in tools you already run. What you cannot do yourself is the examination. cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Our questionnaire and policy set are built around everyone who holds access, contractors included, so the personnel rows are filled in before an auditor asks. The software is $199 a month, cancel any time. Audits go through our preferred pricing program, and we negotiate the fee on your behalf, and you see the price in your account before you book. For the wider picture at low headcount, see SOC 2 for a small team.
Where to start
Begin with the population. List everyone with access, note who employs each person, and send the six item request for everyone not on your own payroll. Then check what each control must produce on the SOC 2 evidence checklist. To see your gaps across the whole program, take the free readiness assessment, or compare plans first.
Questions
Does an employer of record count as a subservice organization in SOC 2?
Do EOR contractors need background checks for SOC 2?
What should I request from an employer of record for SOC 2?
How do I screen a contractor who lives in another country?
How do I handle a contractor laptop I cannot enroll in device management?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.