Framework National Cyber & Cloud Schemes
BSI C5
The Cloud Computing Compliance Criteria Catalogue (C5) is the German Federal Office for Information Security's (BSI) standard for demonstrating the information security of cloud services.
The current edition, C5:2020, contains 121 criteria in 17 domains (organization of information security, personnel, asset management, physical security, operations, identity and access, cryptography, communications security, portability and interoperability, procurement and development, supplier management, incident management, business continuity, compliance, dealing with investigation requests, and product safety and security), split into basic criteria and optional additional criteria for higher assurance.
It also requires the provider to publish system description information about jurisdiction, data location, subcontractors, and government access so that customers can judge the environment.
C5 is widely required in German public sector procurement and, since a 2024 legal change, is referenced for cloud services processing health data under SGB V (verify the current statutory wording).
C5 is an attestation, not a certificate. An independent auditor examines the provider's controls against the criteria under the ISAE 3000 assurance standard (or the equivalent German IDW PS 860) and issues a Type 1 report (design at a point in time) or Type 2 report (design and operating effectiveness over a period, usually six to twelve months).
In writing, the provider needs a system description, a control matrix mapping each C5 criterion to its controls and owners, policies and procedures for each domain, the environmental disclosures required by the catalog, and operating evidence for the period. Many providers combine the C5 examination with SOC 2 in a single audit.
help
Who has to comply
Voluntary in general; effectively required for cloud providers selling to German federal agencies and many state and municipal bodies, for providers of health data processing under German social law, and increasingly requested by German enterprise customers, banks (alongside BaFin expectations), and insurers.
What the assessor asks to see
System description including the environmental disclosures on jurisdiction, data location, subcontractors, and disclosure obligations; control matrix per criterion; policies and procedures for all 17 domains; organization chart and role assignments; risk assessment; access reviews, change tickets, incident records, backup and continuity tests, vulnerability scans, supplier assessments, and training records as samples for the period; management assertion letter; prior reports and remediation of exceptions.
Assessors
Who assesses BSI C5
Independent auditors qualified to issue ISAE 3000 or IDW PS 860 assurance reports, which in Germany means Wirtschaftsprüfer (public auditors) and their firms; auditors from other jurisdictions may report under ISAE 3000 where they meet the catalog's independence and competence requirements. BSI itself does not audit or certify.
German public auditors are licensed and supervised by the Wirtschaftsprüferkammer and the Abschlussprüferaufsichtsstelle; the audit follows IDW and IAASB standards.
No firm has claimed a BSI C5 assessor listing yet. Claim yours →
Consultants
Who helps with BSI C5
German and international audit-readiness consultancies help providers build the control matrix and system description, often aligning C5 with SOC 2 and ISO/IEC 27001. Readiness takes three to nine months before a first Type 1 report.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a BSI C5 consultant listing yet. Claim yours →
Software
Tools for BSI C5
Tools that name this framework in their own material.
No firm has claimed a BSI C5 tool listing yet. Claim yours →
Related reading
- Cloud Computing Compliance Criteria Catalogue (C5)Explains that C5 is delivered as an attestation report by an audit firm, not a certificate, and what the report contains.Amazon Web Services
- Cloud Computing Compliance Criteria Catalog (C5)Covers the basic and additional criteria, the ISAE 3000 audit basis and how customers use the resulting report.Microsoft
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for BSI C5
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with BSI C5
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.