Is an employer of record a subservice organization for SOC 2?

The provider employs the contractor, but you grant the access. That split decides which controls you still own.

Is an employer of record a subservice organization? For the system a SOC 2 report describes, no. The provider handles payroll, tax and local employment paperwork. It does none of the work your customers are paying for.

That makes it a supplier under your vendor management. Screening, security terms, training, access and offboarding remain your controls. What the provider gives you is evidence for those controls, never a substitute for them.

The one question that settles it

A subservice organization performs part of the service you deliver to your customers.1 Your cloud host fits that. So does a model provider in your request path. A payroll intermediary does not, and there is a quick way to see why.

Imagine the vendor stops working tomorrow. Would your customers notice through your product, or would you notice through your bank account? Infrastructure fails the first way. Employment administration fails the second way.

The contractor, meanwhile, is fully yours in every way that matters to an auditor. They sign in through your identity provider, read your customer data and merge to your main branch. You grant their access, review it and revoke it, so those controls are yours to run and yours to evidence.2

One exception. If you resell the provider’s service under your own brand, their processing becomes part of what your customers buy, and the carve-out decision applies.3 Our page on complementary user entity controls covers that mechanism.

Get this backwards and the damage is concrete. A description that carves out a payroll vendor also seems to hand off personnel controls you are still the only one running. The auditor then finds the same people with the same access and nothing testable behind it.

Who does what for a contractor on an EOR

Two sets of criteria apply to the same worker at once. The hiring and competence criteria expect a record for each person with access.2 The vendor criterion expects you to have assessed the supplier. This table is the split an auditor can actually test, row by row.

ActivityDone byEvidence sourceWhat the auditor checks
Screening, CC1.4The provider at onboarding, or a screening vendor you hireTheir record, your vendor report, or your written risk acceptanceSomething existed before access was granted, per sampled person
Confidentiality and security termsThe provider drafts, you set the required clausesThe signed worker agreement, or a pass-through clause in your contractThe duties reach the individual, not just the provider entity
Security training, CC1.4YouYour completion record in your own systemSame module and same yearly cadence as staff
Access provisioning, CC6.1YouYour identity provider and the approved requestApproval came before access
Access review, CC6.2YouYour review record per systemContractors are in the population, not only payroll staff
Device requirements, CC6.7You set them, the worker follows themThe agreement clause and whatever enforces it technicallySomething beyond the clause does the enforcing
Offboarding, CC6.5You revoke, the provider ends the engagementRevocation timestamps from your systems and their end dateAccess ended on or before the last working day
Payroll, tax, benefitsThe providerTheir own recordsNothing. Outside your system boundary
The provider itself, CC9.2YouYour vendor assessment and their report, with a dated read noteYou chose them on purpose and noticed when their report lapsed

Watch two rows closely. Access review is where contractors drop out, because the list is often built from a payroll system that never held them. Offboarding is where both sides need matching dates. Our access review template and offboarding checklist produce those two records.

Evidence to request from the provider

Provider support teams answer specific requests and deflect vague ones. Name the worker, the date and the artifact. Below is a request you can paste into a ticket as written, changing only the names.

Personnel evidence request

We are the client for the workers named below. Our SOC 2 examination covers personnel security for everyone with access to our systems, and our auditor samples people by name. For each worker, please attach the items below instead of describing them.

  1. Screening before the engagement began: which checks, the completion date of each, the country of the record, and who ran it.
  2. The screening record. If you cannot release it, the issuing body, a reference number and a statement of the result.
  3. The signed worker agreement, or its clauses on confidentiality, intellectual property, acceptable use, device security and return of data.
  4. Any security training the worker completed through you, with the date. If none, please say so.
  5. Your current SOC 2 or ISO report, its period, and its complementary user entity controls.
  6. What you disable, and how fast, when we end an engagement, and who confirms it to us.

Some items will come back refused. That is still useful. A refusal tells you which control you now run yourself, and it is far better to learn that before the period opens than during fieldwork. If the training item comes back empty, the training record simply has to be yours.

File the reply with the vendor assessment, not in someone’s inbox. Our vendor assessment template has a row for it, and a dated note saying who read the provider’s report is itself CC9.2 evidence.

Screening records country by country

The screening control does not require a particular document. It asks that people were screened before they got access, so the evidence takes whatever form the worker’s country issues. Several national registers release an extract only to the individual. What you receive is a certificate the worker got and handed over, and that still works as evidence.

CountryRecord availableWhat you can receiveSource, checked 1 August 2026
United KingdomBasic Disclosure and Barring Service check, for applicants 16 or olderA paper certificate mailed to the applicant. The published fee is £21.50, and processing usually takes up to 3 daysgov.uk
GermanyFührungszeugnis from the Federal Central Criminal RegisterA certificate the person requests, online with an electronic ID card or residence permit and its PINfuehrungszeugnis.bund.de
PolandNational Criminal Register certificate, which anyone may requestA signed XML file, 20 zloty online or 30 in person, with up to 20 calendar days for the online routegov.pl
BrazilFederal Police certidão de antecedentes criminaisA free online certificate valid for 90 days, with an official page to validate a copy you were sentgov.br
PhilippinesNational Bureau of Investigation clearanceA clearance collected in person after biometric capture, even if registration and payment were online. Published fees are 115, 165 and 415 pesosnbi.gov.ph
IndiaPolice Clearance Certificate, for passport holders seeking residence, work abroad, a long term visa or immigrationOften nothing through this route, since a contractor staying in India is not emigrating. A commercial report covering court records and employment checks is the normal substitutemea.gov.in
Evidence, not legal permission

Each row describes a record that exists and the form an auditor can receive. None of it says you may ask for it. Whether you can request a check, keep the result or act on it is employment and data protection law in the worker’s country, and that belongs with local counsel. We are not lawyers and this is not legal advice.

Plan for two practical issues. Lead times differ by weeks, so a certificate requested in the last fortnight may arrive after your period closes. And a certificate the worker obtains needs a chain of custody: who received it, when, and where it is stored. Record that. An auditor can test it without reading the certificate.

Controls for a laptop you do not manage

Contractors bring their own hardware, and you cannot push device management onto a machine you do not own. NIST calls these third party controlled devices and states the limit plainly: agreements requiring such devices to be secured generally cannot be automatically enforced, so compromised devices may end up connected to sensitive resources. That is Special Publication 800-46 Revision 2, from July 2016, which we read on 1 August 2026.

A contract clause is a promise. A control works whether or not the promise is kept. So shift the control off the endpoint and onto systems you do own.

What you cannot doWhat replaces itEvidence
Enroll the deviceBrowser only access or a hosted desktop, so customer data never lands on the disk. NIST also recommends moving high risk resources to servers that take on their protectionThe access configuration and a data flow showing no local copy
Confirm disk encryptionAccess tiers by device type. The NIST example tier table gives contractor, partner and vendor devices their own columns, apart from company hardwareYour tier definition and the conditional access rule that applies it
Check patch levelsShort sessions and reauthentication, so a lost laptop loses access on your scheduleThe session lifetime setting and one timestamped revocation
Wipe the machineAn isolated work container that can be removed on its ownThe container policy and a removal record from a real departure
Close the gap entirelyA dated risk acceptance naming the person, device, exposure and approving ownerThe signed acceptance, in the risk register, reviewed on a schedule

Each row is ordinary engineering, and none needs the contractor to install anything. The final row is the honest fallback when the others fall short. Our risk register template shows what a defensible acceptance must include.

A policy that creates its own exception

Picture a policy that says every endpoint runs managed antivirus and full disk encryption, while four of nine engineers use machines nobody has seen. The auditor tests you against your own written procedure, so that sentence manufactures the exception. Write the contractor case into the policy, name the compensating controls, and the same test passes.

Cost: what this takes to do yourself

Contractors do not add a new control. They change where the evidence for existing controls comes from, and they add one vendor to assess. A consultant would bill hours to sort that out. Here is one published estimate of the consultant route for full SOC 2 preparation.

  • Comp AI states that a vCISO or compliance consultant might charge $150 to $400 an hour, which can total $20,000 to $50,000 for a full SOC 2 prep engagement. Source, checked 2026-07-30.

You can do nearly all of this page in-house. The provider request is a ticket. The country certificates cost the small government fees listed above, and the laptop controls are settings in tools you already run. What you cannot do yourself is the examination. cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Our questionnaire and policy set are built around everyone who holds access, contractors included, so the personnel rows are filled in before an auditor asks. The software is $199 a month, cancel any time. Audits go through our preferred pricing program, and we negotiate the fee on your behalf, and you see the price in your account before you book. For the wider picture at low headcount, see SOC 2 for a small team.

Where to start

Begin with the population. List everyone with access, note who employs each person, and send the six item request for everyone not on your own payroll. Then check what each control must produce on the SOC 2 evidence checklist. To see your gaps across the whole program, take the free readiness assessment, or compare plans first.

Questions

Does an employer of record count as a subservice organization in SOC 2?
Normally not. A subservice organization performs part of the service your customers receive. An employer of record handles payroll, tax, benefits and local employment paperwork for you, none of which sits inside the system your report describes. Treat it as a supplier under vendor management instead of carving it out in the system description.
Do EOR contractors need background checks for SOC 2?
Anyone with access to in-scope systems falls under your screening control, whoever employs them. The record can come from the provider onboarding check, from a screening vendor you hire, or you can write a dated risk acceptance naming the person and the reason. Having nothing at all is what produces a finding.
What should I request from an employer of record for SOC 2?
For each named worker: the screening checks run and their dates, the record or a reference to it, the signed agreement with confidentiality and security terms, any security training completed through them, their own current SOC 2 or ISO report, and what they switch off when an engagement ends. Ask for attachments, not descriptions.
How do I screen a contractor who lives in another country?
Use the record that country issues. Several registers release an extract only to the individual, so the evidence is a certificate the worker obtains and hands to you. Where no general employment channel exists, a commercial report covering court records and employment history is the usual substitute. Whether you may request or keep it is a question for local counsel.
How do I handle a contractor laptop I cannot enroll in device management?
Move the control away from the device. Browser only access or a hosted desktop keeps data off the disk, device based access tiers limit what an unmanaged machine can reach, and short sessions limit how long a lost laptop stays useful. Record what is left as a dated risk acceptance with a named owner.

Sources

  1. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  2. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  3. SOC 2: Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy AICPA. The implementation guide practitioners work from, including sampling and the assertion. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.