The Confidentiality category applies when you commit to protecting information designated as confidential beyond the baseline Security criteria. It is narrow — two criteria covering identification and disposal — but it depends on classification actually existing, so organisations without a working data classification scheme struggle to evidence it.
C1 Confidentiality contains 2 criteria. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.
No. C1 is only tested when you elect to include the Confidentiality category in the engagement. The Common Criteria (CC1–CC9) are mandatory; the rest are scoped based on what you commit to customers.
A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.