Confidentiality Criteria (C1)
The Confidentiality criteria (C1) are one of the optional categories within the SOC 2 Trust Services Criteria, focusing on how an organization identifies, classifies, and protects information it has designated as confidential. Unlike the required Security category, Confidentiality is selected only when it is relevant to a service organization's scope. Including these criteria in a SOC 2 examination means an auditor evaluates whether confidential information is handled and safeguarded in line with the entity's stated commitments, but it does not guarantee that no unauthorized disclosure will ever occur.
Within the SOC 2 framework, the Confidentiality category (the C1.x criteria) is one of the four optional Trust Services Criteria categories that a service organization may include alongside the required Security (Common Criteria) category, depending on scoping decisions and the commitments made to user entities. The category addresses the identification, classification, maintenance, and protection of information designated as confidential in order to meet the entity's confidentiality-related objectives, and typically includes criteria such as C1.1, which requires the entity to identify and maintain confidential information to meet its objectives (with additional criteria addressing the protection and disposal of that information). In a SOC 2 examination, a licensed CPA firm evaluates the suitability of design of the associated controls (Type I) and, over a defined review period, their operating effectiveness (Type II). These criteria are distinct from ISO/IEC 27001 Annex A reference controls and from other SOC 2 categories such as Privacy, and a resulting SOC 2 report attests only to the controls and period covered rather than certifying the absence of confidentiality breaches.
Why it matters
Confidential information, such as contractual data, intellectual property, business plans, and non-public financial details, often sits at the heart of the relationships a service organization maintains with its user entities. When a customer entrusts sensitive material to a vendor, they frequently expect assurance that the vendor has procedures to identify what is confidential and to protect it accordingly. Including the Confidentiality criteria (C1) in a SOC 2 examination allows a licensed CPA firm to evaluate whether an organization handles this designated information in line with its stated confidentiality commitments, giving customers an independent basis for trust rather than relying on self-assertion.
Because Confidentiality is an optional category, its inclusion signals that a service organization has scoped its examination to cover commitments that go beyond baseline security. This matters most in engagements where the primary value the organization delivers involves holding or processing sensitive customer data. Without these criteria in scope, a SOC 2 report addresses the required Security (Common Criteria) category but does not speak to how confidential information specifically is classified, maintained, protected, and disposed of.
It is important to recognize the limits of what these criteria provide. A SOC 2 report that includes C1 attests only to the controls and the period covered by the examination; it does not certify that unauthorized disclosure will never occur, nor does it guarantee freedom from breaches. Stakeholders should read the report to understand the defined scope and the auditor's conclusions rather than treating inclusion of Confidentiality as an absolute warranty against data loss.
Who it's relevant to
Inside C1
Common questions
Answers to the questions practitioners most commonly ask about C1.