Skip to main content
Informationssicherheit / NIS2

BSI C5

The Cloud Computing Compliance Criteria Catalogue (C5), issued by Germany's Federal Office for Information Security (BSI), is an audit standard that lets cloud providers have the security of their services attested by an auditor for customers and regulators.

The Cloud Computing Compliance Criteria Catalogue – C5 for short – was published in 2016 by the German Federal Office for Information Security (BSI) and substantially revised in 2020. It sets out minimum information security requirements for cloud services and addresses both providers who need to demonstrate their security posture and customers who have to assess a service before buying it. The C5:2020 edition contains around 120 basic criteria across 17 subject areas, ranging from the organisation of information security, identity and access management, cryptography and key management through to operations, logging, incident handling and the orderly termination of the contract. Additional criteria cover elevated requirements, for example for particularly sensitive data.

C5 is deliberately not a certification but an attestation: an independent auditor examines the cloud service against ISAE 3000 (Revised) or the German equivalent IDW PS 951 and issues an audit report. A Type 1 report confirms only that the controls are suitably designed at a given date, while a Type 2 report also evidences that those controls operated effectively over a review period, typically six to twelve months – in practice, only Type 2 carries real weight. A distinctive feature of C5 are the so-called environmental parameters: the provider must disclose transparently in which countries data is processed and stored, which jurisdiction and which government access powers it is subject to, and which subcontractors are involved. For assessing a service under data protection law, that disclosure is often more revealing than the controls themselves.

C5 is not legally mandatory, but it has become the de facto market standard in Germany – particularly in public sector procurement and in regulated industries, where supervisory requirements for outsourced IT services (in the financial sector, for instance, under DORA) call for solid evidence about the security of the arrangement. Its content overlaps considerably with ISO/IEC 27001 and ISO/IEC 27017; an existing ISMS certificate provides useful groundwork for a C5 attestation but does not replace it, because C5 reaches deeper into cloud operations and demands more transparency. A European cloud certification scheme (EUCS) has been under preparation for years under Regulation (EU) 2019/881 (Cybersecurity Act), but disputes over sovereignty requirements mean it has still not been adopted – so C5 remains, for now, the decisive form of evidence in the German market.

Legal Basis

BSI C5:2020 (Cloud Computing Compliance Criteria Catalogue); attestation under ISAE 3000 (Revised) or IDW PS 951 (revised); BSI mandate under the German BSI Act (BSIG); substantive links to ISO/IEC 27001 and ISO/IEC 27017

Practical Example

A mid-sized insurance broker plans to move its policy administration system to a SaaS platform. As part of supplier management, the information security officer requests the provider's C5 report and receives a Type 2 attestation covering a twelve-month review period. In reviewing it he checks three things: first, whether the scope actually covers the service being purchased and not just the underlying infrastructure; second, which deviations the auditor recorded and how the provider is remediating them; third, the environmental parameters – which reveal that a subcontractor providing 24/7 support is based in a third country and may hold administrative access to production systems. He records this as a residual risk in the risk assessment and has the data processing agreement amended to restrict remote access and to require complete logging of all administrative activity.

FAQ

No, C5 is a voluntary audit standard, not a statutory obligation. In public procurement and regulated industries, however, a C5 report is frequently required by contract because it supplies the evidence supervisors expect regarding the security of outsourced IT services. For providers it is therefore effectively a condition of market access.
Type 1 only confirms that the controls are suitably designed at a specific date. Type 2 additionally tests whether those controls actually operated effectively over a defined period, usually six to twelve months. Only Type 2 supports a reliable statement about ongoing operations; Type 1 should at most be accepted as initial evidence.
No. ISO/IEC 27001 certifies an organisation's management system, whereas C5 attests the specific security controls of a cloud service and additionally requires transparency about jurisdiction, data locations and subcontractors. An existing ISMS makes the C5 audit considerably easier but does not cover it – customers should assess both forms of evidence separately.

How preeco supports you

Learn how our software supports you with this topic.

Learn more