Skip to content

SOC 2 Confidentiality Library

Manage confidential-information commitments, lifecycle controls, evidence, exceptions, remediation, and validation for SOC 2 readiness.

The SOC 2 Confidentiality category addresses whether information designated as confidential is protected as committed or agreed. Confidentiality is distinct from Privacy: it can apply to business, customer, technical, contractual, or other sensitive information whether or not it identifies a person.

Standards and scope

Confidentiality criteria extend the Security Common Criteria and focus on identifying confidential information and protecting it during collection, use, access, transmission, storage, retention, and disposal.

  • The organization should define which information is confidential and what commitments govern it.
  • Access, encryption, transfer, storage, and handling controls should reflect classification and risk.
  • Retention and secure disposal practices should be supported by policy and operational evidence.
  • Third-party handling and disclosure should align with contracts and approved processes.
  • Confidentiality findings remain connected to the Common Criteria controls that support them.

Who this is for

  • Students and information-governance professionals learning lifecycle-based protection.
  • Security, legal, compliance, privacy, and records-management teams.
  • Service organizations handling customer, commercial, regulated, or proprietary information.
  • Consultants and internal reviewers preparing Confidentiality evidence and remediation.

What voiqq provides

  • Canonical Confidentiality criteria beside the project's Security criteria.
  • Structured records for data classes, populations, samples, evidence, tests, and exceptions.
  • Assignment and remediation workflows for access, encryption, transfer, retention, and disposal gaps.
  • Controlled attachments, comments, status, validation, and historical review context.
  • Readiness snapshots that distinguish Confidentiality work from Privacy work.

A practical workflow

  1. Define confidential information, commitments, owners, systems, and third parties in scope.
  2. Map policies and operational controls to the applicable criteria.
  3. Test selected evidence and record exceptions with enough context to reproduce the review.
  4. Assign corrective actions and minimize sensitive content in the finding itself.
  5. Validate remediation and review unresolved risks before reporting.

Put the framework into practice

The Confidentiality library helps multidisciplinary teams coordinate information-protection obligations without confusing them with personal-data privacy requirements.

Start free

Review the SOC 2 Program