The SOC 2 Confidentiality category addresses whether information designated as confidential is protected as committed or agreed. Confidentiality is distinct from Privacy: it can apply to business, customer, technical, contractual, or other sensitive information whether or not it identifies a person.
Standards and scope
Confidentiality criteria extend the Security Common Criteria and focus on identifying confidential information and protecting it during collection, use, access, transmission, storage, retention, and disposal.
- The organization should define which information is confidential and what commitments govern it.
- Access, encryption, transfer, storage, and handling controls should reflect classification and risk.
- Retention and secure disposal practices should be supported by policy and operational evidence.
- Third-party handling and disclosure should align with contracts and approved processes.
- Confidentiality findings remain connected to the Common Criteria controls that support them.
Who this is for
- Students and information-governance professionals learning lifecycle-based protection.
- Security, legal, compliance, privacy, and records-management teams.
- Service organizations handling customer, commercial, regulated, or proprietary information.
- Consultants and internal reviewers preparing Confidentiality evidence and remediation.
What voiqq provides
- Canonical Confidentiality criteria beside the project's Security criteria.
- Structured records for data classes, populations, samples, evidence, tests, and exceptions.
- Assignment and remediation workflows for access, encryption, transfer, retention, and disposal gaps.
- Controlled attachments, comments, status, validation, and historical review context.
- Readiness snapshots that distinguish Confidentiality work from Privacy work.
A practical workflow
- Define confidential information, commitments, owners, systems, and third parties in scope.
- Map policies and operational controls to the applicable criteria.
- Test selected evidence and record exceptions with enough context to reproduce the review.
- Assign corrective actions and minimize sensitive content in the finding itself.
- Validate remediation and review unresolved risks before reporting.
Put the framework into practice
The Confidentiality library helps multidisciplinary teams coordinate information-protection obligations without confusing them with personal-data privacy requirements.
