C1.1 C1 · Confidentiality · Confidentiality

C1.1 — Identification and protection of confidential information

Confidential information is identified and maintained to meet the entity's confidentiality objectives.

Also written as C 1.1, TSC C1.1, SOC2 C1.1, SOC 2 Type 2 C1.1.

What SOC 2 C1.1 requires

Identification and protection of confidential information is one of 2 criteria in the Confidentiality (C1) series of the Confidentiality category. Confidential information is identified and maintained to meet the entity's confidentiality objectives. Because this sits outside the Common Criteria, it is only tested when Confidentiality is in the scope of your engagement — check your report scope before building evidence for it.

Audit evidence assessors look for

When preparing for a SOC 2 audit against C1.1, gather artefacts such as:

  • Data classification policy identifying confidential data
  • Inventory of confidential information and locations
  • Access restrictions and encryption for confidential data
  • NDAs with employees and third parties

ISO 27001 mapping

C1.1 corresponds to the following ISO 27001:2022 Annex A control(s): A.5.12, A.5.13, A.5.14, A.5.33, A.6.6, A.7.7, A.8.3, A.8.11, A.8.12, A.8.33. If you already run an ISO 27001 ISMS, map your existing evidence for these controls to C1.1 rather than duplicating work.

Map C1.1 to ISO 27001 & NIST CSF →
Crosswalk this criterion in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against C1.1 in the Risk Register.

Other Confidentiality criteria

C1.2 Disposal of confidential information

All C1 Confidentiality criteria →

Frequently asked questions

Is C1.1 required for a SOC 2 report?

Only if the Confidentiality category is in scope. The Common Criteria (CC1–CC9) are mandatory for every SOC 2, but C1 criteria are tested only when you elect to include Confidentiality in the engagement. Scope is your choice, usually driven by customer contracts.

How does an auditor test C1.1?

In a Type 1 report the auditor assesses design only — does a control exist at a point in time that would meet C1.1 if it operated. In a Type 2 report they also test operating effectiveness by sampling evidence from across the review period, typically 3 to 12 months. That difference is why Type 2 evidence has to be continuous rather than assembled the week before fieldwork.

What happens if C1.1 fails testing?

A control that fails becomes an exception, which the auditor describes in the report along with management's response. Exceptions do not automatically make a report "failed" — a SOC 2 report is an opinion, not a pass/fail certificate — but a qualified opinion is what customers notice, so remediate and re-test before fieldwork closes where you can.

Does SOC 2 C1.1 map to ISO 27001?

Yes — C1.1 aligns with ISO 27001:2022 Annex A control(s) A.5.12, A.5.13, A.5.14, A.5.33, A.6.6, A.7.7, A.8.3, A.8.11, A.8.12, A.8.33. If you already run a certified ISMS, re-point that evidence rather than building a parallel set; the underlying control is the same and only the reporting format differs.