Skip to main content
Category: Trust Services Criteria

Confidentiality Criteria (C1)

Also known as: C1, Confidentiality Category, Confidentiality Trust Services Criteria, C1 Criteria
Simply put

The Confidentiality criteria (C1) are one of the optional categories within the SOC 2 Trust Services Criteria, focusing on how an organization identifies, classifies, and protects information it has designated as confidential. Unlike the required Security category, Confidentiality is selected only when it is relevant to a service organization's scope. Including these criteria in a SOC 2 examination means an auditor evaluates whether confidential information is handled and safeguarded in line with the entity's stated commitments, but it does not guarantee that no unauthorized disclosure will ever occur.

Formal definition

Within the SOC 2 framework, the Confidentiality category (the C1.x criteria) is one of the four optional Trust Services Criteria categories that a service organization may include alongside the required Security (Common Criteria) category, depending on scoping decisions and the commitments made to user entities. The category addresses the identification, classification, maintenance, and protection of information designated as confidential in order to meet the entity's confidentiality-related objectives, and typically includes criteria such as C1.1, which requires the entity to identify and maintain confidential information to meet its objectives (with additional criteria addressing the protection and disposal of that information). In a SOC 2 examination, a licensed CPA firm evaluates the suitability of design of the associated controls (Type I) and, over a defined review period, their operating effectiveness (Type II). These criteria are distinct from ISO/IEC 27001 Annex A reference controls and from other SOC 2 categories such as Privacy, and a resulting SOC 2 report attests only to the controls and period covered rather than certifying the absence of confidentiality breaches.

Why it matters

Confidential information, such as contractual data, intellectual property, business plans, and non-public financial details, often sits at the heart of the relationships a service organization maintains with its user entities. When a customer entrusts sensitive material to a vendor, they frequently expect assurance that the vendor has procedures to identify what is confidential and to protect it accordingly. Including the Confidentiality criteria (C1) in a SOC 2 examination allows a licensed CPA firm to evaluate whether an organization handles this designated information in line with its stated confidentiality commitments, giving customers an independent basis for trust rather than relying on self-assertion.

Because Confidentiality is an optional category, its inclusion signals that a service organization has scoped its examination to cover commitments that go beyond baseline security. This matters most in engagements where the primary value the organization delivers involves holding or processing sensitive customer data. Without these criteria in scope, a SOC 2 report addresses the required Security (Common Criteria) category but does not speak to how confidential information specifically is classified, maintained, protected, and disposed of.

It is important to recognize the limits of what these criteria provide. A SOC 2 report that includes C1 attests only to the controls and the period covered by the examination; it does not certify that unauthorized disclosure will never occur, nor does it guarantee freedom from breaches. Stakeholders should read the report to understand the defined scope and the auditor's conclusions rather than treating inclusion of Confidentiality as an absolute warranty against data loss.

Who it's relevant to

Service organizations handling sensitive customer data
Organizations that receive, store, or process information their customers designate as confidential, such as business plans, contractual terms, or intellectual property, may choose to include C1 in their SOC 2 scope to demonstrate that they identify, classify, and protect that information in line with their commitments. Whether to include the category depends on scoping decisions and the assurances customers expect.
Compliance managers and GRC professionals
Those responsible for scoping a SOC 2 examination need to decide whether Confidentiality is relevant to the organization's commitments, since it is optional rather than required. They also design and maintain the procedures for identifying, classifying, protecting, and disposing of confidential information that an auditor will evaluate.
Auditors and CPA firms
Licensed CPA firms performing a SOC 2 examination evaluate the design and, in a Type II engagement, the operating effectiveness over a defined review period of the controls supporting the C1.x criteria, forming conclusions that address only the controls and period covered rather than certifying the absence of confidentiality breaches.
Customers and user entities reviewing SOC 2 reports
Organizations evaluating a vendor can use the inclusion of Confidentiality criteria to understand whether the report addresses how the vendor protects designated confidential information. Readers should review the defined scope and the auditor's conclusions and recognize that these criteria are distinct from ISO 27001 controls and from the SOC 2 Privacy category.

Inside C1

Optional Trust Services Category
Confidentiality (C1) is one of the four optional Trust Services Criteria categories that may be added to a SOC 2 examination scope, alongside Availability, Processing Integrity, and Privacy. It is only included when scoping decisions call for it, unlike the Security category (Common Criteria), which is always required.
Scope of Protected Information
The Confidentiality criteria address information designated as confidential by the service organization or its clients, such as contractual data, business plans, or intellectual property. This is distinct from the Privacy category, which specifically concerns personal information.
Lifecycle Coverage
The criteria typically address how confidential information is identified, protected, retained, and disposed of throughout its lifecycle, depending on how the controls are designed and scoped for the engagement.
Relationship to the Common Criteria
Confidentiality is evaluated in addition to, not in place of, the Security (Common Criteria) category. The Common Criteria remain the foundation, and C1 supplements them with confidentiality-specific control objectives.
Assessment Basis (Type I vs. Type II)
In a Type I examination, the confidentiality controls are assessed for suitability of design at a point in time; in a Type II examination, they are assessed for both design and operating effectiveness over a defined review period whose length is set by scoping decisions.

Common questions

Answers to the questions practitioners most commonly ask about C1.

Is the Confidentiality category required for every SOC 2 report?
No. Security (the Common Criteria) is the only required Trust Services Criteria category in a SOC 2 examination. Confidentiality, along with Availability, Processing Integrity, and Privacy, is optional and included only when scoping decisions call for it. A SOC 2 report can be issued covering Security alone, so the presence of the Confidentiality criteria depends on the scope agreed for the engagement.
Is the Confidentiality category the same as the Privacy category?
No. They are distinct optional categories with different focuses. The Confidentiality criteria address information designated as confidential (which may include business information, not just personal data), while the Privacy category addresses personal information and its collection, use, retention, disclosure, and disposal. An organization may select one, both, or neither depending on scope, and selecting Confidentiality does not automatically bring Privacy into scope.
How do we decide what information falls under the Confidentiality criteria?
In most engagements this begins with identifying and classifying information the organization or its customers have designated as confidential, often informed by contractual commitments and internal policies. The specific scope depends on the service being examined and the commitments made to users, so classification decisions are typically documented and agreed during scoping rather than fixed by a universal rule.
What kinds of controls typically support the Confidentiality criteria?
Depending on scope, organizations commonly implement controls addressing the identification and classification of confidential information, restrictions on access, protection during storage and transmission (such as encryption where appropriate), and disposal of confidential information when no longer needed. The exact controls, and how the auditor evaluates them, vary by engagement, the CPA firm, and the commitments in scope.
How does the Confidentiality category interact with the review period in a Type II report?
In a SOC 2 Type II examination, controls supporting the selected Confidentiality criteria are assessed for both suitability of design and operating effectiveness over the defined review period. The length of that period is set by scoping decisions and varies between engagements, so the Confidentiality controls are evaluated across whatever period the report covers rather than at a single point in time as in a Type I.
Does including the Confidentiality criteria in our SOC 2 report satisfy ISO 27001 confidentiality requirements?
Not automatically. SOC 2 and ISO 27001 are different in nature, SOC 2 is an attestation examination resulting in a report, while ISO 27001 is a certification against a management system standard. Mapping between the Confidentiality criteria and relevant ISO 27001 requirements or Annex A reference controls is possible but partial, and satisfying one framework does not by itself demonstrate conformance with the other. Each covers only its defined scope.

Common misconceptions

The Confidentiality category is a mandatory part of every SOC 2 report.
Only the Security category (Common Criteria) is required in a SOC 2 examination. Confidentiality is one of four optional categories, included only when scoping decisions call for it.
Confidentiality and Privacy cover the same thing.
They are distinct categories. Confidentiality addresses information designated as confidential more broadly, while the Privacy category specifically concerns the handling of personal information. Selecting one does not imply the other.
Meeting the Confidentiality criteria is equivalent to satisfying the corresponding ISO 27001 controls.
The Trust Services Criteria are not the same as ISO 27001 Annex A reference controls. Mapping between the two frameworks is possible but partial, and addressing C1 in a SOC 2 examination does not automatically satisfy ISO 27001 requirements.

Best practices

Confirm early in scoping whether Confidentiality (C1) should be included, since it is optional and adds specific control objectives beyond the required Security Common Criteria.
Clearly define and document what information is designated as confidential, and keep this distinct from personal information governed by the Privacy category.
Address the full information lifecycle, identification, protection, retention, and disposal, when designing controls, so that confidentiality obligations are covered end to end.
Align the scope of confidentiality controls with the type of examination sought, recognizing that a Type II engagement will assess operating effectiveness over a defined review period, not just design at a point in time.
If pursuing both SOC 2 and ISO 27001, map controls deliberately but treat the mapping as partial, and do not assume that satisfying C1 fulfills ISO 27001 requirements.
Communicate to stakeholders that a SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches of confidential information.