SOC 2 Confidentiality criteria explained
Confidentiality is two criteria about protecting and then destroying information you agreed to keep confidential. It is the cheapest optional category and the most misunderstood.
The Confidentiality category adds two criteria, C1.1 and C1.2. C1.1 asks whether you identify and protect information designated as confidential. C1.2 asks whether you dispose of it when the retention period ends. That second one is where companies fail. Deleting data on schedule is harder than encrypting it. Adding the category adds 10 to 20 percent to a Canadian audit fee.
Confidentiality is not Security, and not Privacy
Security protects the system against unauthorized access of any kind. Confidentiality is about a commitment you made about specific information: your customer said this material is confidential and you agreed to treat it that way. Privacy is about personal information and the promises in your privacy notice.
- Security
- Nobody gets in who should not.
- Confidentiality
- The material a customer designated as confidential is protected and then destroyed as agreed, whether or not it is personal information.
- Privacy
- Personal information is collected, used, retained, disclosed and disposed of in line with the notice you published.
When to add it
Add Confidentiality when customers put their own commercially sensitive material into your product and your contract says something specific about it. Legal technology, data rooms, contract management, financial modelling, source code tooling and anything handling deal documents are the obvious cases. If the only sensitive thing you hold is your customers' end user personal data, Privacy or nothing is the better question, and for most Canadian SaaS companies the answer is still Security only.
The argument against it: Confidentiality commits you to a data classification scheme and a retention and disposal process you then have to evidence every year. A company with one database, one retention setting and no classification scheme will spend readiness effort building a program to satisfy a category nobody asked for. Ask the customer first.
What satisfies each criterion
| Criterion | What it asks | Evidence |
|---|---|---|
| C1.1 | Confidential information is identified and maintained to meet your commitments | Data classification policy, an inventory showing where confidential data lives, access restrictions tied to classification, encryption settings, NDA and contract terms that define what confidential means |
| C1.2 | Confidential information is disposed of to meet your commitments | Retention schedule by data type, evidence deletion actually ran, customer offboarding and data return or destruction records, backup expiry settings, certificates of destruction for physical media |
Disposal is the hard half
Most companies can show that confidential data is protected. Far fewer can show it was destroyed. Backups are the usual problem: production deletion works, and the record persists in snapshots for another 35 days, or forever in an archive nobody set an expiry on. Auditors ask about backups specifically.
- Write a retention schedule that names data types and periods you can actually enforce, not aspirational ones.
- Set expiry on every backup, snapshot and archive tier so deletion propagates without anyone remembering.
- Make customer offboarding produce a record: what was deleted, when, and who confirmed it.
- Run a spot check inside the observation window and keep the output. That single artifact answers C1.2.
Contract language becomes audit scope
Your commitments are set by what you signed. A contract promising deletion within 30 days of termination makes 30 days the standard you are tested against. Sales teams agree to shorter windows to close deals, and nobody tells the person who will have to evidence it. Read your own master agreement before you add this category.
The Canadian overlay
Confidential and personal are different words with different consequences here. Personal information carries statutory duties under PIPEDA, and under Quebec's Law 25 and Ontario's PHIPA depending on where you operate and what you hold. A Confidentiality opinion says nothing about those duties. The PIPEDA page covers what the audit does not discharge, and the Privacy criteria page covers the category that comes closest without replacing the law.
Get the category priced
Ask Canadian firms what Confidentiality adds to your fee and to your evidence load before you commit to it.
Get matchedCommon questions
How many Confidentiality criteria are there in SOC 2?
Two: C1.1 on identifying and protecting confidential information, and C1.2 on disposing of it when retention ends. They are added to the 33 common criteria that every report contains.
Do we need Confidentiality if we already have Security?
Only if you make specific commitments about specific confidential information. Security already covers protecting the system from unauthorized access. Confidentiality adds classification, retention and destruction against promises you made in contracts, which is a different obligation.
Is customer personal data confidential information?
It can be both, and the categories still differ. Personal data handled under a privacy notice belongs to the Privacy category and to Canadian privacy statutes. The same data can also be covered by a confidentiality commitment in a contract. Which categories to include depends on which promises your buyer wants tested.
What is the most common Confidentiality exception?
Failure to evidence disposal. Data was deleted from production but persisted in backups past the stated retention period, or a customer offboarded and nobody recorded what was destroyed. Setting expiry on backups and producing a deletion record at offboarding removes most of it.