BSI · Cloud Security
C5: Cloud Computing Compliance Criteria Catalogue
BSI C5 is Germany's definitive cloud security attestation standard. With C5:2020 and its 121 criteria in 17 domains, the BSI defines binding minimum requirements for cloud providers - mandated by law in the German healthcare sector since July 2025 (§393 SGB V, DigiG). Internationally comparable to SOC 2 (USA) and ISO 27017, but with additional transparency requirements specific to European data sovereignty.
Last updated: March 2026
C5:2025 Announced: The BSI has announced a new edition of the C5 catalog for Q1/2026. Publication is still pending. This page is based on the currently valid C5:2020 and will be updated promptly after C5:2025 is released.
- C5:2020
- Current BSI Version
- 17
- Requirement Domains
- 121
- Audit Criteria
- July 2025
- DigiG Mandate (§393 SGB V)
Definition
What is C5?
The Cloud Computing Compliance Criteria Catalogue (C5) is an attestation standard for cloud services developed by Germany's Federal Office for Information Security (BSI). It defines minimum requirements for the information security of cloud providers and creates transparent, verifiable evidence of their actual security level.
The current version C5:2020 comprises 121 criteria in 17 requirement domains - from organizational security and access management to encryption and supplier relationships. Particularly important: C5 includes mandatory transparency requirements obligating providers to disclose subcontractors, data storage locations and applicable legal systems - including potential government access rights (e.g., US CLOUD Act implications for American providers).
C5 is audited and attested by independent auditing firms based on the international assurance standard ISAE 3000 (revised) or its German equivalent IDW PS 860 - the same standard underlying SOC 2 reports in the USA. The result is an attestation report that cloud customers can use as reliable evidence of cloud security.
Key Facts
Scope
Who Needs C5?
C5 concerns both cloud providers who must demonstrate an attestation, and cloud customers from regulated industries who must require an attestation from their providers.
Cloud Providers (Attestation Obligation)
- IaaS/PaaS/SaaS providers for German federal agencies
- Cloud services for healthcare (DigiG §393 SGB V)
- Cloud providers in the financial sector (BaFin BAIT/VAIT requirements)
- Cloud services for KRITIS operators
- Telematics infrastructure service providers (gematik)
- SaaS for hospitals, health insurers, medical practices
- International hyperscalers with German enterprise customers
Affected Industries (Evidence Requirement)
These organizations must require a valid C5 attestation from their cloud providers and verify its coverage for their specific use case:
- Hospitals, clinics and care facilities (DigiG)
- Statutory and private health insurers
- Physicians' associations and medical practices
- Federal agencies and subordinate authorities
- Banks, insurance companies (BaFin regulation)
- Critical infrastructure operators (KRITIS)
- State authorities and municipalities
Requirements Catalog
The 17 C5 Domains
C5:2020 organizes its 121 audit criteria into 17 requirement domains. Each domain contains specific, auditable requirements with defined evidence for the auditing firm.
01 · OIS
Organizational Security
Security organization, roles, responsibilities and management commitment to information security
02 · SP
Security Policies
Documented security policies, their approval, communication and regular review
03 · AM
Asset Management
Inventory, classification and appropriate handling of all information-processing assets
04 · PS
Physical Security
Access control to data centers, protection against environmental hazards and physical security of infrastructure
05 · OS
Operational Security
Patch management, malware protection, monitoring, logging and secure operations of the cloud environment
06 · IDM
Identity & Access Management
Authentication, authorization, privileged access management and tenant separation
07 · CRY
Encryption & Key Management
Cryptographic protections for data at rest and in transit, and secure key management
08 · CS
Communication Security
Network segmentation, secure transmission protocols and network boundary protection
09 · PI
Portability & Interoperability
Data export, migration capabilities and avoidance of vendor lock-in
10 · SOS
Availability
High availability, business continuity, disaster recovery and defined SLAs for operational continuity
11 · IR
Incident Management
Detection, reporting, handling and post-processing of security incidents including customer notification
12 · DEV
Procurement, Dev & Maintenance
Secure Development Lifecycle, code reviews, vulnerability management and secure change processes
13 · COM
Compliance & Data Privacy
Compliance with legal requirements, GDPR conformity and privacy by design
14 · CHA
Change Management
Controlled change processes for infrastructure, platform and services with impact analysis
15 · RMG
Information Security Risk Mgmt
Systematic risk identification, assessment and treatment in the cloud context
16 · AUD
Audit Management
Internal and external audits, penetration tests, vulnerability scans and tracking of findings
17 · SSO
Supplier Relationships
Security requirements for sub-service providers, their review and transparency towards cloud customers
Attestation Levels
Type 1 vs. Type 2 Attestation
C5 distinguishes two attestation types that differ significantly in depth, meaningfulness and audit effort. The choice determines which regulatory requirements are fulfilled.
01
Type 1 Attestation
Design Review - Point-in-Time
The Type 1 attestation confirms that the security controls described by the provider are appropriately designed at the point of assessment. The auditor evaluates whether the controls are fundamentally suitable to meet C5 requirements.
- Review of control design
- Point-in-time assessment
- Shorter audit period (typically 4-8 weeks)
- Lower effort and costs
- No statement on operational effectiveness
- Entry level for new providers
Suitable for: Initial C5 attestation, internal orientation, providers in build-up phase
02
Type 2 Attestation
Effectiveness Review - 6 to 12 Months
The Type 2 attestation additionally tests the operational effectiveness of security controls over a defined observation period. It is significantly more meaningful and is preferred for government and regulatory requirements.
- Review of both design AND effectiveness
- Observation period: typically 6-12 months
- Sample testing of controls in operation
- Higher audit effort and cost
- Required by German federal agencies
- Mandatory under DigiG (§393 SGB V)
- Annual renewal recommended
Suitable for: Federal agency customers, healthcare (DigiG), BaFin-regulated institutions, KRITIS operators
Roadmap
Typical Path to Type 2 Attestation
Readiness Assessment
Gap analysis against all 121 criteria, action plan
4-6 weeks
Gap Remediation
Closing identified gaps, building documentation
3-6 months
Type 1 Attestation
Auditor reviews control design, report issued
4-8 weeks
Type 2 Attestation
Observation period runs, effectiveness testing, final report
6-12 months
§393 SGB V
C5 and DigiG: Mandatory in German Healthcare
The Digital Healthcare Modernization Act (DigiG) created with §393 SGB V one of the most significant new regulations for cloud security in the German healthcare market. From July 1, 2025, social security data of statutorily insured persons may only be processed in cloud environments whose providers hold a valid C5 attestation.
The regulation affects the entire value chain of digital healthcare: hospital information systems, electronic health records, telematics infrastructure connectors, laboratory information systems, radiology PACS and all billing and administrative solutions in the cloud.
For cloud providers, this means: without a C5 attestation, they effectively lose market access in the German healthcare market. For healthcare providers - hospitals, insurers, medical practices - a documentation obligation arises: they must show that their cloud services are sourced from C5-attested providers.
Framework Relationships
C5 in Context
C5 is not an isolated standard - it builds on established frameworks and enables synergistic audit approaches that significantly reduce total effort.
ISO/IEC 27001
ISO/IEC 27001 as a Foundation
An existing ISO 27001 certificate provides the ideal foundation for C5. Many requirements overlap directly - the additional effort for C5 is substantially reduced. ISO 27001 provides the ISMS framework; C5 provides the cloud-specific requirements catalog.
- - ~60-70% overlap in requirements
- - Combined audit possible
- - ISMS documentation reusable
- - Synergies in risk analysis and audits
SOC 2
SOC 2 as International Partner
C5 and SOC 2 Type II are content-compatible. The BSI and AICPA have published an official mapping. International cloud providers are audited for both standards together - C5 for the DACH market, SOC 2 for the US market.
- - Official BSI-AICPA mapping available
- - Combined audit by auditing firm
- - Same observation period usable
- - Recommended for international providers
IT-Grundschutz
BSI IT-Grundschutz
BSI IT-Grundschutz and C5 share the same publisher (BSI) and conceptual foundations. Federal agencies that have implemented IT-Grundschutz will find many requirements already fulfilled. C5 extends IT-Grundschutz with cloud-specific aspects.
- - Same publisher (BSI)
- - Conceptual alignment
- - Government agencies benefit from IT-Grundschutz basis
- - OPS.5 Cloud Use as bridge building block
Recommended Combination Strategies
Our Services
How AWARE7 Helps with C5
We support cloud providers and cloud customers throughout the entire C5 process - from initial assessment to successful attestation.
C5 Readiness Assessment
Structured comparison of your existing security controls against all 121 C5 criteria. You receive a prioritized gap report with clear action recommendations for each domain - as a foundation for informed decisions and roadmap planning.
- Complete review of all 17 domains
- Prioritized gap report
- Effort estimate for remediation measures
- Recommendation on Type 1 vs. Type 2
Gap Analysis & Action Plan
Based on the readiness assessment, we develop a detailed, prioritized action plan. We support building missing controls, creating all required policies and procedural documentation, and the system description.
- Detailed action plan
- Policy and process documentation
- System description per C5 requirements
- Implementation support
Penetration Testing & Audit Preparation
C5 requires regular penetration tests and vulnerability assessments in the AUD domain. Our OSCP-certified penetration testers conduct the required tests and produce audit-compliant reports directly usable as C5 evidence.
- Penetration testing per C5 AUD requirements
- Vulnerability assessment
- Audit-compliant documentation
- Pre-attestation review
„C5 is not a bureaucratic audit exercise - it is an opportunity: organizations that genuinely implement all 121 criteria have cloud infrastructure that is truly secure, not just on paper. The combination of ISO 27001 methodology and cloud-specific C5 requirements is the most effective approach we know.“
Oskar Braun
ISO/IEC 27001 Lead Auditor (IRCA-certified) · AWARE7 GmbH
Why AWARE7 for C5 Compliance
What sets us apart from other providers
Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.
Research and teaching as our foundation
20 %Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.
Digital sovereignty: no compromises
100 %From first contact to final report, your data is stored on our own servers in Germany - no US cloud providers, no third-country transfers. Our AI also runs on our own hardware in Germany - with locally operated open-source models. Client and project data never reach external AI services. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.
More on digital sovereigntyFixed price within 24h: predictable project timelines
24 hWithin 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.
Your dedicated contact
1:1A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.
Peer-reviewed publications
Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations
ACM AsiaCCS 2025
Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
A Platform for Physiological and Behavioral Security
NSPW 2025
Jan Hörnemann
Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem
IEEE/IFIP DSN 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Understanding Regional Filter Lists: Efficacy and Impact
PoPETS 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Who is AWARE7 the right partner for?
Mid-sized companies with 50-2,000 employees
Companies that need real security, without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.
IT managers & CISOs
Who have to argue convincingly in-house and need a report in boardroom language for that, not just technical findings.
Regulated industries
Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA. We know the requirements and deliver evidence that auditors accept.
FAQ
Frequently Asked Questions about BSI C5
Answers to the most common questions about the Cloud Computing Compliance Criteria Catalogue and its requirements for cloud providers and cloud customers.
What is BSI C5?
What is the difference between Type 1 and Type 2 attestation?
Who is required to have a C5 attestation?
What 17 domains does C5 cover?
How does C5 relate to ISO/IEC 27001?
What are the transparency requirements in C5?
How is a C5 attestation conducted?
What is ISAE 3000 and why is it relevant for C5?
What does DigiG §393 SGB V mean for hospitals?
Can C5 and SOC 2 be combined?
What is planned for C5:2025?
How does AWARE7 help with C5 preparation?
Aus dem Blog
Weiterführende Artikel
Container-Sicherheit: Docker und Kubernetes richtig absichern
Container-Sicherheit: sichere Dockerfiles, Image-Scanning mit Trivy, Kubernetes RBAC, Pod Security Standards und Runtime Security mit Falco.
Best Websites Part 9 - Youtube & Soundcloud Download Websites!
Likes verteilen oder eine E-Mail Adresse angeben, um etwas herunterladen zu können? Diese Websites ermöglichen euch den Youtube und Soundcloud Download!
Sichere und anonyme E-Mail Anbieter vorgestellt!
Die Auswahl an E-Mail Anbietern ist groß. Doch die, die ihren Job gut machen ist klein. Wir stellen kostenfreie, sichere und anonyme E-Mail Anbieter vor!
DigiG Deadline Approaching - Check Your C5 Readiness Now
We analyze whether your cloud environment or your providers' services meet C5 requirements - with a clear result and a prioritized action plan on a fixed-price basis.
Free · 30 minutes · No obligation