C1 Confidentiality · 2 criteria

SOC 2 C1 — Confidentiality

The Confidentiality category applies when you commit to protecting information designated as confidential beyond the baseline Security criteria. It is narrow — two criteria covering identification and disposal — but it depends on classification actually existing, so organisations without a working data classification scheme struggle to evidence it.

All 2 C1 criteria

C1.1 Identification and protection of confidential information
Confidential information is identified and maintained to meet the entity's confidentiality objectives.
C1.2 Disposal of confidential information
Confidential information is disposed of to meet the entity's confidentiality objectives.

Other criteria series

CC1 CC2 CC3 CC4 CC5 CC6 CC7 CC8 CC9 A1 PI1 P
Crosswalk to ISO 27001 & NIST CSF →
Map these criteria across frameworks in the Control Mapper.
Search all 61 criteria →
Filter the Trust Services Criteria by keyword or series.

Frequently asked questions

How many criteria are in SOC 2 C1?

C1 Confidentiality contains 2 criteria. The Trust Services Criteria define 61 in total: 33 Common Criteria across CC1–CC9 plus the criteria for the Availability, Confidentiality, Processing Integrity and Privacy categories.

Is C1 required in every SOC 2 report?

No. C1 is only tested when you elect to include the Confidentiality category in the engagement. The Common Criteria (CC1–CC9) are mandatory; the rest are scoped based on what you commit to customers.

What is the difference between a Type 1 and Type 2 report for C1?

A Type 1 assesses whether the controls are suitably designed at a point in time. A Type 2 also tests whether they operated effectively across a review period, typically 3 to 12 months, by sampling evidence from throughout that window. Most customers asking for a SOC 2 mean Type 2.