Short answer: yes, in US practice an NDA and a confidentiality agreement are the same instrument. The risk lives in the clauses, not the caption on the cover.
A vendor sends over a two-page document titled "Confidentiality Agreement." Your own template is called an "NDA." Before you spend a minute worrying about the mismatch, know this: in United States practice, the two names describe the same instrument. A contract that legally binds someone to keep specified information secret and use it only for a stated purpose. The word on the cover page is not where the risk lives.
The risk lives inside the document. Whether it runs one way or both ways, how it defines confidential information, how long the duty survives, what state law does to enforceability, and whether the remedies survive an unrelated liability cap. This guide covers where the two terms are genuinely interchangeable, the handful of places the naming convention shifts by context, and, in more depth than a definitional overview, the legal mechanics an in-house team should read before signing either one. For the ground-level definition, see what an NDA is; this post is the comparison and the review.

TL;DR
- NDA and confidentiality agreement are the same contract. The names are interchangeable in the US, and nothing legal turns on which word is on the cover.
- One-way vs mutual is the first real split. A unilateral version protects one side's information; a mutual version protects both. Match it to who is actually disclosing.
- The definition of "confidential information" is where deals go wrong. Too broad and it is unworkable or gets narrowed; too narrow and your real secrets fall out of scope.
- A contractual confidentiality duty is not a trade-secret claim. The contract gives you breach remedies against the signer. Trade-secret law (the federal DTSA and state UTSA) gives you a separate claim against misappropriation, with its own requirements. You often want both.
- Enforceability turns on reasonableness and consideration, and both are state-law questions. A perpetual duty on everything, or an employee NDA signed with no fresh consideration in the wrong state, is a red flag, not a strength.
- A non-compete is not an NDA. A duty to keep secrets is not a restriction on where someone can work, and the two face very different state-law treatment.
In US practice, is an NDA the same as a confidentiality agreement?
Are they the same? Yes, with one caveat
A non-disclosure agreement and a confidentiality agreement do the same legal job. Both are contracts where one or more parties promise to protect information the agreement defines as confidential and to use it only for a stated purpose.
Lawyers, contract templates, and courts use the two names for the same document, and a court enforcing one asks the same questions it asks of the other: what did the parties define as confidential, what did they promise, and what remedy did they agree to. You will also see "confidential disclosure agreement" (CDA), "secrecy agreement," and "proprietary information agreement" for the same instrument. None of these labels changes the analysis. Cornell's Legal Information Institute describes an NDA as a contract that protects confidential information shared between parties, with no separate legal category for the "confidentiality agreement" label.
The one caveat is habit, not law. In some contexts one name is simply more common, which is why people assume a difference exists. That convention is worth knowing so you are not thrown when a counterparty uses the "other" word.
NDA vs confidentiality agreement: the distinctions that actually matter
Skip the title. These are the variables that change your risk.
One-way (unilateral) vs mutual. A unilateral version protects a single disclosing party. Use it when only you are handing over sensitive information, for example when you send data to a vendor. A mutual (bilateral) version protects both sides and fits two companies exploring a deal, a partnership, or a merger where each will see the other's secrets. Signing a one-way agreement as the receiving party when you are also disclosing is a common, avoidable mistake.
Definition of confidential information. This clause decides what the whole contract actually covers. A workable definition names the categories (business plans, financials, customer lists, source code, pricing, roadmaps) and pairs them with the standard exclusions: information that is already public, independently developed, rightfully received from a third party, or already known to the recipient. A definition with no exclusions is not pro-you. It is a fight waiting to happen, because it sweeps in information you cannot actually keep the other side from using.
Term and survival. Two clocks run here: how long the agreement itself lasts, and how long the confidentiality duty survives after it ends. Ordinary confidential information commonly carries a 2 to 5 year duty. Trade secrets are the exception, and the reason is covered in the next section.
Remedies. Money often cannot fix a leak, so most agreements let the disclosing party ask a court for injunctive relief (an order to stop the disclosure). The clause preserves the right to ask; it does not remove the equitable standards a court applies, so you may still have to show irreparable harm and no adequate remedy at law. Two things to check: an acknowledgment that a breach may cause irreparable harm (helpful, not dispositive), and whether a liability cap somewhere else in the deal quietly swallows breach-of-confidentiality damages. More on that cap below.
Permitted disclosures and the standard of care. Two clauses do quiet work that people skip. First, the standard of care: many agreements require the recipient to guard your information with "the same degree of care it uses for its own confidential information," which is only as good as that recipient's own habits. A "reasonable degree of care" floor is safer for the discloser. Second, the permitted-disclosure carve-outs. A recipient legitimately needs to share your information with its own employees, lawyers, accountants, and advisors (usually called "Representatives") on a need-to-know basis, and the clause should make the recipient liable for any Representative who leaks. Separately, a compelled-disclosure carve-out lets the recipient comply with a subpoena or court order without breaching, and a well-drafted one requires prompt notice to you (where legally allowed) plus cooperation so you can seek a protective order first. Read both: an uncapped "Representatives" definition or a compelled-disclosure clause with no notice duty is where your information walks out under cover of the fine print.
The contractual duty is not the trade-secret claim
This is the distinction most "they are the same" explanations skip, and it changes how you draft the survival term.
When someone breaches an NDA, you have a contract claim. The measure is the deal you struck: whatever duties, term, and remedies the document sets, enforceable against the party who signed it. Straightforward, but limited to the four corners of the agreement and to the people bound by it.
Separately, if the leaked information qualifies as a trade secret, you may also have a trade-secret misappropriation claim. That claim comes from statute, not from your contract. Federally, the Defend Trade Secrets Act (DTSA, 18 U.S.C. Section 1836) gives the owner of a misappropriated trade secret a civil cause of action, with remedies including an injunction, damages, and in some cases a reasonable royalty. At the state level, nearly every state (all but New York and North Carolina) has adopted a version of the Uniform Trade Secrets Act (UTSA), which runs in parallel. The DTSA and most UTSA states share the same core requirement: the information must derive value from being secret, and the owner must have taken reasonable measures to keep it secret (the federal definition is at 18 U.S.C. Section 1839).
Two practical consequences follow.
First, a well-drafted NDA is itself evidence of a "reasonable measure." Requiring recipients to sign confidentiality terms is one of the standard facts courts look at when deciding whether an owner protected its secrets. So the NDA does double duty: it is a contract, and it is part of your trade-secret hygiene.
Second, and this is the accuracy point the pillar summary does not have room for: a fixed expiration date does not, by itself, forfeit trade-secret status. What a hard expiry actually does is end the contractual confidentiality duty on that date and create an evidentiary problem. If your own agreement says the recipient is free to use the information after, say, three years, a defendant will argue you stopped treating it as secret, which undercuts the "reasonable measures" element of a trade-secret claim. But trade-secret protection under the DTSA or your state's UTSA can still exist independently, for as long as the information stays secret and you kept protecting it. The fix is not to panic about forfeiture. It is to draft the survival term so trade secrets are carved out and protected for as long as they remain secret, while ordinary confidential information carries its 2 to 5 year clock.
There is one more DTSA wrinkle that catches employers. The Act includes a whistleblower immunity: an individual cannot be held liable under trade-secret law for confidentially disclosing a trade secret to a government official or attorney solely to report or investigate a suspected legal violation, or in a sealed court filing (18 U.S.C. Section 1833(b)). The teeth are in the notice rule: an employer must include notice of that immunity in "any contract or agreement with an employee that governs the use of a trade secret or other confidential information." Miss it, and you lose the right to recover exemplary damages and attorney fees against that employee in a later DTSA action. An NDA that binds contractors and staff to secrecy but omits the immunity notice is a common, quietly expensive gap.
How state law changes the answer
"Are NDAs enforceable?" has no single national answer, because the two enforceability levers are governed by state law.
Reasonableness. Courts will narrow or refuse to enforce a confidentiality duty that is overbroad in scope or effectively perpetual on ordinary business information. How aggressively a court does that varies. Some jurisdictions blue-pencil an overbroad term down to something reasonable; others are more willing to strike it. A definition that covers "all information disclosed" with no exclusions and no time limit is the classic candidate for that treatment.
Consideration. An NDA needs consideration like any contract. For a standalone NDA signed at the start of a relationship, the disclosure itself or entering the deal usually supplies it. The harder case is the employee NDA presented to someone who already works for you. States split. In Illinois, the line of cases from Fifield v. Premier Dealer Services (2013 IL App (1st) 120327) treats at least two years of continued employment as the benchmark for adequate consideration behind a restrictive covenant, later codified in the state's Freedom to Work Act, though that Act expressly excludes pure confidentiality provisions from its definition of a covenant not to compete. Texas courts, by contrast, generally accept continued at-will employment tied to access to confidential information as sufficient. If you roll out a new confidentiality agreement to existing staff, whether you owe them a raise, a bonus, or some other benefit is a state-by-state question worth checking before you send it.
Employee mobility and public policy. Confidentiality obligations that reach too far can collide with an employee's right to use general skills and knowledge, and with state public-policy limits on restraining mobility. California is the sharp edge. Business and Professions Code Section 16600 voids most post-employment restraints, and courts now read it to reach confidentiality clauses that function as de facto non-competes. In Brown v. TGS Management Co. (2020), a California appellate court struck down a confidentiality provision so broad (it swept in "any information usable in the entire securities industry") that it effectively barred the employee from working in the field. A clause that specific to real categories would likely have survived. This is also why the residuals clause (which lets a recipient use what its people remember without reference to your documents) is negotiated so hard in employee and vendor NDAs. The confidentiality clause breakdown covers that residuals trap in detail.
Two guardrails keep these from becoming abstract. Keep the definition tied to real categories with real exclusions, and keep the survival term proportionate to the information. Those two moves are what make a confidentiality duty read as reasonable rather than as a restraint a court wants to cut down.
Where the naming convention shifts by context
The document is the same, but which word people reach for tends to track the situation.
| You will usually hear... | In this context |
|---|---|
| NDA | Startups, investors, pitches, product and tech discussions, vendor onboarding |
| Confidentiality agreement | Employment and HR, M&A and due diligence, settlements, board and professional-services work |
| Confidentiality clause | A section inside a larger contract (MSA, employment agreement, SOW), not a standalone document |
| CDA (confidential disclosure agreement) | Life sciences, pharma, and clinical research |
None of this is a legal rule. It is vocabulary. One context-specific difference is real, though: an M&A confidentiality agreement (often the "CDA" in a diligence process) frequently carries terms an ordinary vendor NDA never sees, such as a standstill, a non-solicit of employees, and clean-team provisions that wall off competitively sensitive data. That is not the label doing the work. It is the deal type pulling in extra clauses.
If your MSA already carries a confidentiality clause covering the same information, parties, and purpose, a separate standalone NDA is often redundant, and stacking both can create conflicting terms you now have to reconcile under the order-of-precedence clause.
A vendor NDA review, redline by redline
Here is what a real first pass looks like on an inbound agreement, so the clauses above stop being abstract. The reviewer's order rarely changes: read the caption, then the named parties, then the operative verbs (who owes what to whom), then any incorporated MSA, then the cap and its carve-outs, then survival, then hunt for the residuals sentence.

A SaaS vendor sends a two-page document titled "Mutual Confidentiality Agreement." The title says mutual. The body does not. Four problems, in the order they cost you:
-
It is actually one-way. Every operative sentence binds "the Recipient." Your company is the only party that receives anything under it, so despite the title, only you carry the duty, and your data going into their platform is unprotected. Redline: convert the obligations to genuinely mutual, or add reciprocal duties covering the information you disclose.
-
No residuals carve-out, or a bad one. Read for a "residuals" sentence letting them use anything their personnel "retain in memory" or use "without reference to" your materials. If it is there and broad, it can hollow out the whole agreement. Redline: strike it, or at minimum exclude trade secrets and anything reduced to writing from its reach.
-
A 12-month survival period on everything. The confidentiality duty ends 12 months after termination, with no separate treatment for trade secrets. Once that clock runs out, they are contractually free to use information that is still a live trade secret for you, and, worse, the short cutoff is the kind of fact a defendant later points to when arguing you stopped treating it as secret. Redline: split the survival clause. Ordinary confidential information gets its fixed term (say, 2 or 3 years); trade secrets are protected for as long as they remain secret.
-
An MSA liability cap that swallows the remedy. The NDA looks fine on remedies, but the master services agreement it references caps all liability at fees paid in the prior 12 months, with no carve-out for confidentiality breaches. So the strongest confidentiality language in the NDA is capped at a number that makes breach cheap. Redline: carve confidentiality (and IP) breaches out of the liability cap in the MSA, and align the two documents so the NDA's remedies are not quietly overridden.
None of those four is exotic. They are the routine places a fast "just sign the NDA" costs you later, which is exactly why inbound confidentiality agreements deserve a real read against your own standard positions.
That first-pass triage is work AI is genuinely good at: classify an inbound NDA as one-way or mutual, test the definition and survival term against an AI-enforced NDA playbook template, and flag the missing exclusions, the residuals clause, or the cap conflict before it reaches a lawyer. In Vaquill AI, that runs as a structured NDA triage pass against your own positions, so the routine ones clear in minutes and only the real deviations get partner time.

FAQ
Is a confidentiality agreement the same as an NDA? Yes. In US practice the two terms are interchangeable and describe the same contract: a binding promise to protect information the agreement defines as confidential. Courts do not treat them differently based on the title. For the fuller definition, see what an NDA is.
Is an NDA a contract? Yes. An NDA is a legally binding contract once it has offer, acceptance, and consideration (something of value exchanged, often the disclosure of the information itself or entering the business relationship). A signed NDA is enforceable like any other contract, subject to state-law rules on reasonableness.
What is the difference between a one-way and a mutual NDA? A one-way (unilateral) NDA protects only the disclosing party's information, which fits sending data to a vendor. A mutual (bilateral) NDA protects both parties and fits two companies that will each share secrets, such as in a partnership or acquisition talk.
Does an NDA protect a trade secret, or do I need trade-secret law too? Both, and they are separate. The NDA gives you a contract claim against the party who signed it. If the information qualifies as a trade secret, the federal DTSA and your state's UTSA give you an additional misappropriation claim, provided you took reasonable measures to keep it secret. A signed NDA is one of those reasonable measures, so the contract and the statute reinforce each other.
Does a fixed expiration date destroy trade-secret protection? No, not by itself. A hard expiry ends the contractual confidentiality duty on that date and can create an evidentiary problem, because a defendant may argue you stopped treating the information as secret. Trade-secret protection under the DTSA or state UTSA can still exist if the information stays secret and you kept protecting it. The safer draft carves trade secrets out of the fixed term and protects them for as long as they remain secret.
Is a non-compete the same as an NDA? No. An NDA protects confidential information. A non-compete restricts where and for whom a person can work after leaving. They serve different purposes and follow different enforceability rules, and non-competes face far more state-law restriction. See non-compete enforceability by state.
How long does an NDA last? It depends on the term clause. A common range is 2 to 5 years for ordinary confidential information. Trade secrets are usually protected for as long as they stay secret, so a well-drafted agreement carves them out rather than putting a hard expiry on trade-secret protection.
Are NDAs enforceable? Generally yes, if the scope and duration are reasonable and the agreement is supported by consideration. Overbroad definitions or an indefinite duty on ordinary information can be narrowed or struck down, and the specifics (including what consideration an employee NDA needs) vary by state. See NDA enforceability by state.
Can an NDA stop someone from reporting to a regulator or blowing the whistle? No. Federal law overrides that. Under the Defend Trade Secrets Act (18 U.S.C. Section 1833(b)), an individual has immunity for confidentially disclosing a trade secret to a government official or attorney to report a suspected legal violation, or in a sealed court filing, and the SEC has penalized employers whose NDAs tried to restrict reporting. An NDA cannot lawfully gag that conduct, and if the agreement governs trade secrets with an employee or contractor, it must actually include a notice of that immunity or you lose exemplary damages and fees in a later suit.
Do I need both an NDA and a confidentiality clause? Usually not at the same time. A standalone NDA is for pre-contract discussions. Once a larger contract with its own confidentiality clause is in place, a separate NDA is often redundant and can conflict under the order-of-precedence clause, so check the main agreement first.
For more, see what NDA triage is and how it works, the confidentiality clause breakdown, and the in-house contract review playbook.
New legal AI guides, weekly.
Further Reading
Contract Review Checklist for In-House Counsel (2026)
Read postHow to Review a SaaS Agreement: An In-House Playbook
Read postNDA vs Non-Compete vs Non-Solicit: Which Restrictive Covenant Do You Need?
Read postWhat Is an NDA? A Plain-English Guide to Non-Disclosure Agreements
Read postThe In-House Contract Review Playbook for 2026
Read postNDA Enforceability by State: A 2026 Reference for Corporate Counsel
Read post
Co-Founder & CEO · Attorney
Arshita leads product and strategy at Vaquill, building the legal AI suite that solo, small-firm, and in-house US lawyers use to run a matter end to end.