SOC 2 Trust Services Criteria

SOC 2 Confidentiality Criterion

Confidentiality covers the protection of designated confidential information. It matters when you handle client data, trade secrets, or any information marked as confidential.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILSOC 2 Confidentiality EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Common control areas

Confidential information identification and labelling

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Encryption of confidential data

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Access restrictions on confidential data

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Data retention and disposal

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

NDA and confidentiality agreements

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Information flow controls

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Evidence to keep

  • Control owner and review cadence
  • Policy or procedure approved by management
  • System export, ticket, report, or log sample
  • Exception record and remediation evidence

Confidentiality policy templates

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map

Back to all SOC 2 criteria, or open the SOC 2 template pack.