CUECs, complementary user entity controls, are the controls a service organisation assumes its customers have in place. A SOC 1 or SOC 2 report lists them in the description of the system, because some of the provider's controls only achieve their objective if the customer does its part. The auditor's opinion depends on them: it says the controls were effective provided user entities applied the complementary controls assumed in the design.
What a CUEC looks like
They cover the part of the service the customer controls. Typical examples: the customer approves and removes its own users' access, reviews that access periodically, keeps its credentials secret and turns on multi-factor authentication where the service offers it, reports suspected incidents to the provider, and checks that the data it sends is complete and correct.
What to do with them
Read the CUEC section before relying on a supplier's SOC 2 report, and map each item to a control in your own environment. A supplier's report is evidence only for the controls it covers; when your own auditor asks how you rely on suppliers, the CUECs are the part you are expected to show you have covered.
CUECs are not the same as CSOCs, complementary subservice organisation controls. Those are expected of the provider's own subcontractors, such as the cloud platform it runs on, rather than of its customers.