HomeFrameworksNational Cyber & Cloud SchemesBSI C5

Framework  National Cyber & Cloud Schemes

BSI C5

The Cloud Computing Compliance Criteria Catalogue (C5) is the German Federal Office for Information Security's (BSI) standard for demonstrating the information security of cloud services.

The current edition, C5:2020, contains 121 criteria in 17 domains (organization of information security, personnel, asset management, physical security, operations, identity and access, cryptography, communications security, portability and interoperability, procurement and development, supplier management, incident management, business continuity, compliance, dealing with investigation requests, and product safety and security), split into basic criteria and optional additional criteria for higher assurance.

It also requires the provider to publish system description information about jurisdiction, data location, subcontractors, and government access so that customers can judge the environment.

C5 is widely required in German public sector procurement and, since a 2024 legal change, is referenced for cloud services processing health data under SGB V (verify the current statutory wording).

C5 is an attestation, not a certificate. An independent auditor examines the provider's controls against the criteria under the ISAE 3000 assurance standard (or the equivalent German IDW PS 860) and issues a Type 1 report (design at a point in time) or Type 2 report (design and operating effectiveness over a period, usually six to twelve months).

In writing, the provider needs a system description, a control matrix mapping each C5 criterion to its controls and owners, policies and procedures for each domain, the environmental disclosures required by the catalog, and operating evidence for the period. Many providers combine the C5 examination with SOC 2 in a single audit.

AI-compiled
Share
Sponsored
BSI
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with BSI C5
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Voluntary in general; effectively required for cloud providers selling to German federal agencies and many state and municipal bodies, for providers of health data processing under German social law, and increasingly requested by German enterprise customers, banks (alongside BaFin expectations), and insurers.

What the assessor asks to see

System description including the environmental disclosures on jurisdiction, data location, subcontractors, and disclosure obligations; control matrix per criterion; policies and procedures for all 17 domains; organization chart and role assignments; risk assessment; access reviews, change tickets, incident records, backup and continuity tests, vulnerability scans, supplier assessments, and training records as samples for the period; management assertion letter; prior reports and remediation of exceptions.

Assessors

Who assesses BSI C5

Independent auditors qualified to issue ISAE 3000 or IDW PS 860 assurance reports, which in Germany means Wirtschaftsprüfer (public auditors) and their firms; auditors from other jurisdictions may report under ISAE 3000 where they meet the catalog's independence and competence requirements. BSI itself does not audit or certify.

German public auditors are licensed and supervised by the Wirtschaftsprüferkammer and the Abschlussprüferaufsichtsstelle; the audit follows IDW and IAASB standards.

No firm has claimed a BSI C5 assessor listing yet. Claim yours →

Consultants

Who helps with BSI C5

German and international audit-readiness consultancies help providers build the control matrix and system description, often aligning C5 with SOC 2 and ISO/IEC 27001. Readiness takes three to nine months before a first Type 1 report.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a BSI C5 consultant listing yet. Claim yours →

Software

Tools for BSI C5

Tools that name this framework in their own material.

No firm has claimed a BSI C5 tool listing yet. Claim yours →

Related reading

  1. Cloud Computing Compliance Criteria Catalogue (C5)Explains that C5 is delivered as an attestation report by an audit firm, not a certificate, and what the report contains.Amazon Web Services
  2. Cloud Computing Compliance Criteria Catalog (C5)Covers the basic and additional criteria, the ISAE 3000 audit basis and how customers use the resulting report.Microsoft

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for BSI C5

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with BSI C5

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.