BSI C5
The Cloud Computing Compliance Criteria Catalogue (C5), issued by Germany's Federal Office for Information Security (BSI), is an audit standard that lets cloud providers have the security of their services attested by an auditor for customers and regulators.
The Cloud Computing Compliance Criteria Catalogue – C5 for short – was published in 2016 by the German Federal Office for Information Security (BSI) and substantially revised in 2020. It sets out minimum information security requirements for cloud services and addresses both providers who need to demonstrate their security posture and customers who have to assess a service before buying it. The C5:2020 edition contains around 120 basic criteria across 17 subject areas, ranging from the organisation of information security, identity and access management, cryptography and key management through to operations, logging, incident handling and the orderly termination of the contract. Additional criteria cover elevated requirements, for example for particularly sensitive data.
C5 is deliberately not a certification but an attestation: an independent auditor examines the cloud service against ISAE 3000 (Revised) or the German equivalent IDW PS 951 and issues an audit report. A Type 1 report confirms only that the controls are suitably designed at a given date, while a Type 2 report also evidences that those controls operated effectively over a review period, typically six to twelve months – in practice, only Type 2 carries real weight. A distinctive feature of C5 are the so-called environmental parameters: the provider must disclose transparently in which countries data is processed and stored, which jurisdiction and which government access powers it is subject to, and which subcontractors are involved. For assessing a service under data protection law, that disclosure is often more revealing than the controls themselves.
C5 is not legally mandatory, but it has become the de facto market standard in Germany – particularly in public sector procurement and in regulated industries, where supervisory requirements for outsourced IT services (in the financial sector, for instance, under DORA) call for solid evidence about the security of the arrangement. Its content overlaps considerably with ISO/IEC 27001 and ISO/IEC 27017; an existing ISMS certificate provides useful groundwork for a C5 attestation but does not replace it, because C5 reaches deeper into cloud operations and demands more transparency. A European cloud certification scheme (EUCS) has been under preparation for years under Regulation (EU) 2019/881 (Cybersecurity Act), but disputes over sovereignty requirements mean it has still not been adopted – so C5 remains, for now, the decisive form of evidence in the German market.
Legal Basis
BSI C5:2020 (Cloud Computing Compliance Criteria Catalogue); attestation under ISAE 3000 (Revised) or IDW PS 951 (revised); BSI mandate under the German BSI Act (BSIG); substantive links to ISO/IEC 27001 and ISO/IEC 27017
Practical Example
A mid-sized insurance broker plans to move its policy administration system to a SaaS platform. As part of supplier management, the information security officer requests the provider's C5 report and receives a Type 2 attestation covering a twelve-month review period. In reviewing it he checks three things: first, whether the scope actually covers the service being purchased and not just the underlying infrastructure; second, which deviations the auditor recorded and how the provider is remediating them; third, the environmental parameters – which reveal that a subcontractor providing 24/7 support is based in a third country and may hold administrative access to production systems. He records this as a residual risk in the risk assessment and has the data processing agreement amended to restrict remote access and to require complete logging of all administrative activity.