SOC 2 Confidentiality (C1)
Two criteria, deceptively simple: identify and protect confidential information, then dispose of it provably. Scoped in when contracts carry confidentiality commitments — which is most B2B paper. The work is classification discipline and deletion evidence.
Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the TSC series · SOC 2 reports are issued by licensed CPA firms; we prepare you and coordinate the audit
The criteria that decide your examination
Criteria reference the AICPA 2017 Trust Services Criteria (revised points of focus, 2022).
Where examinations produce exceptions
C1.1 fails when sampled repositories show no evidence anyone applies the classification — the policy exists, the discipline does not.
Customer offboarding that contractually promises deletion needs execution records per tenant — the C1.2 sample auditors now routinely take.
Copies in BI tools, support tickets and spreadsheets escape the protection the primary store has — discovery before the auditor’s walkthrough finds it for you.
Evidence auditors sample
- Classification scheme and sampled evidence of its application (C1.1)
- Access and encryption controls mapped to classification levels
- Retention schedule for confidential information
- Deletion execution records, including customer-offboarding samples (C1.2)
Confidentiality FAQ
How does Confidentiality differ from Privacy in SOC 2?
Confidentiality covers any information designated confidential (customer business data, IP); Privacy applies specifically to personal information and carries the full P1–P8 criteria set.
Do NDAs satisfy the Confidentiality category?
NDAs are one control; C1 requires lifecycle protection — identification, access restriction, and provable disposal — beyond the contractual promise.
What disposal evidence do auditors accept?
Executed deletion logs or destruction certificates tied to the retention schedule — and for customer exits, per-customer deletion confirmation where committed.
Confidentiality in your SOC 2 scope
We run readiness, close the gaps, build the evidence and coordinate the examination with the CPA firm — with the programme kept audit-ready on SigmaTrust between reports.
