We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

SOC 2 Trust Services Criteria · Optional category

SOC 2 Confidentiality (C1)

Two criteria, deceptively simple: identify and protect confidential information, then dispose of it provably. Scoped in when contracts carry confidentiality commitments — which is most B2B paper. The work is classification discipline and deletion evidence.

Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the TSC series · SOC 2 reports are issued by licensed CPA firms; we prepare you and coordinate the audit

The criteria that decide your examination

C1.1
Identify and protect confidential information

Confidential information identified (classification) and protected through its lifecycle — access limits, encryption, handling rules tied to the classification.

C1.2
Disposal

Confidential information disposed of when retention ends — executed deletion with records, including at contract termination when customers ask for it.

Criteria reference the AICPA 2017 Trust Services Criteria (revised points of focus, 2022).

Where examinations produce exceptions

Classification policy without labels in practice

C1.1 fails when sampled repositories show no evidence anyone applies the classification — the policy exists, the discipline does not.

Contract-exit deletion promised, never evidenced

Customer offboarding that contractually promises deletion needs execution records per tenant — the C1.2 sample auditors now routinely take.

Confidential data sprawling into analytics and tickets

Copies in BI tools, support tickets and spreadsheets escape the protection the primary store has — discovery before the auditor’s walkthrough finds it for you.

Evidence auditors sample

  • Classification scheme and sampled evidence of its application (C1.1)
  • Access and encryption controls mapped to classification levels
  • Retention schedule for confidential information
  • Deletion execution records, including customer-offboarding samples (C1.2)

Confidentiality FAQ

How does Confidentiality differ from Privacy in SOC 2?

Confidentiality covers any information designated confidential (customer business data, IP); Privacy applies specifically to personal information and carries the full P1–P8 criteria set.

Do NDAs satisfy the Confidentiality category?

NDAs are one control; C1 requires lifecycle protection — identification, access restriction, and provable disposal — beyond the contractual promise.

What disposal evidence do auditors accept?

Executed deletion logs or destruction certificates tied to the retention schedule — and for customer exits, per-customer deletion confirmation where committed.

Processing Integrity (PI1)Privacy (P1–P8)

Confidentiality in your SOC 2 scope

We run readiness, close the gaps, build the evidence and coordinate the examination with the CPA firm — with the programme kept audit-ready on SigmaTrust between reports.