Most English-speaking companies meet C5 the same way: a German customer, or a German subsidiary's procurement team, asks whether the cloud service in question has "a C5". Some ask for a certificate. There is no such thing, and knowing why is the fastest way to have a useful conversation instead of an awkward one.
What C5 is, and who issues it
The Bundesamt für Sicherheit in der Informationstechnik (BSI), Germany's Federal Office for Information Security, publishes C5, the Cloud Computing Compliance Criteria Catalogue. It is Germany's answer to a question every cloud purchase raises: against what, exactly, do I measure a provider's security, and whose word do I take for the result. The BSI first published the catalogue in 2016 and revised it fundamentally in 2025 and 2026.
C5 is a catalogue of criteria, not a management system standard. It describes what a cloud service should satisfy, not how an organisation builds its security management. That distinction is the cleanest way to place it next to the frameworks an English-speaking reader already knows: it sits where SOC 2 sits, not where ISO/IEC 27001 sits.
Who actually has to care
C5 is not binding of itself. It becomes binding through other rules, and through the market:
- German federal bodies. The BSI's Mindeststandard on the use of external cloud services (a minimum standard binding on federal public bodies in Germany, not on private companies) requires them to obtain C5 evidence when procuring cloud services for official data processing.
- Regulated sectors. Individual sectors require an attestation through their own rules. For healthcare the BSI notes that § 393 of the German Social Code Book V (Sozialgesetzbuch V) remains unaffected alongside C5.
- German enterprise buyers. For companies C5 is not a legal duty, but it is a broadly recognised benchmark in Germany and slots neatly into a supplier assessment.
- Providers selling into Germany. If your customers are German, the question will arrive whether or not you have prepared for it.
The catalogue addresses three groups at once: cloud providers as a yardstick of requirements, auditors as a basis for their engagement, and cloud customers as an aid to assessment. The BSI stresses that each of these parties carries its own duty to contribute to information security.
Structure and scope
The C5:2020 edition consisted of 121 criteria. The current C5:2026 edition contains 168 criteria organised into 17 subject areas, running from the organisation of information security through personnel, regular operations and cryptography to product security. Newly added topics include container management, post-quantum cryptography and confidential computing; existing topics such as tenant separation and supply chain security are addressed more specifically. Structurally, C5:2026 is modelled on EUCS: criteria now consist of clearly delimited sub-criteria, which makes it easier to map them onto a provider's controls and to work through a report. Alongside PDF and Excel, the catalogue appears in machine-readable YAML for the first time.
Alongside the basic criteria stand additional criteria, and C5:2026 makes explicit a distinction that used to be implicit: a sharpening additional criterion replaces the basic sub-criterion it belongs to, while a complementing one is tested in addition to it. That leaves the customer with a decision of their own: whether the minimum criteria have to be supplemented by further criteria for the specific use case.
Which edition applies when
The BSI published C5:2026 on 7 April 2026. The catalogue carries a semantic version number, most recently 1.1.0 of 11 August 2026, so a report is worth reading for the version it was issued against. The transition rules are set out in the catalogue itself.
| Engagement | Edition to apply |
|---|---|
| Type 1 report, reference date on or after 1 June 2027 | C5:2026 |
| Type 2 report, period beginning on or after 1 June 2027 | C5:2026 |
| Type 2 period beginning before that date and ending after it | C5:2020 only, no mixing |
| Earlier engagements | C5:2020; applying C5:2026 sooner is permitted |
Where the audit period ends on or after 28 February 2027, the provider has to record planned control changes in the system description, each with the criterion, the nature of the change, its implementation status and its date. The auditor examines that presentation but does not yet assess whether those changes are effective.
Attestation, not certification
The point that matters most: no certification procedure exists for C5, and consequently there are no C5 certificates. Conformity is demonstrated by an attestation. The overarching framework for the audit methodology is the International Standard on Assurance Engagements 3000, ISAE 3000 for short. As national counterparts to it the BSI names SOC 2 in the United States and, in Germany, IDW PS 860, an auditing standard issued by the Institut der Wirtschaftsprüfer, the Institute of Public Auditors in Germany.
The difference is more than formal. A certification is a procedure with three parties: the audited organisation, a certification body and an accreditation body. An attestation is an assurance engagement between two: the audited company and its auditor. What a C5 attestation and an ISO 27001 certificate each prove, and what stays with the customer either way, is compared in BSI C5 vs ISO 27001.
Type 1 and Type 2
| Type | What it says |
|---|---|
| Type 1 | The design of the internal measures is such that the criteria of the catalogue are met. |
| Type 2 | In addition, the operating effectiveness of the implemented measures is assessed over the reporting period. |
The BSI emphasises that the effectiveness assessment in a Type 2 attestation is a material difference from many other IT security certifications. For assessing a provider, only a Type 2 attestation is therefore usually meaningful.
Two details decide how much any attestation is worth. First, what is audited is always a cloud service, never a company: a provider as such cannot hold a C5 attestation, only its individual services can. The question is therefore never "does the provider have C5" but "is this particular service inside the scope of this report". Second, an audit opinion can be qualified, and whether deviations lead to a qualification is at the auditor's discretion. An attestation is not a yes-or-no signal; it is a document that has to be read.
The reporting period, and what follows from it
C5 attestations always relate to a period that has already ended. An attestation therefore says nothing about today's state, only about the state during the period audited. Anyone who needs coverage as close to continuous as possible asks the provider for consecutive attestations and pays attention to the gap between the end of the last reporting period and the present day. The BSI recommends that customers request and evaluate the audit report initially and then annually. It also states that it is itself involved neither in the choice of auditor nor in the audit, and that it does not evaluate the reports. Reading them is the customer's job.
If you are the provider being asked
The useful reply to "do you have C5" is rarely yes or no. It is: which criteria, over which period, covering which services and which regions, in which type. If you hold no attestation, the catalogue is still usable; it gives a structured basis for answering questionnaires and makes your answers comparable with those of other providers, which is what the customer is actually trying to achieve.
If you are the buyer
In procurement the catalogue earns its keep less as an audit standard than as a question set. Three steps do most of the work. First, decide before selecting a provider which criteria beyond the basic ones your intended use case requires. Nobody can take that decision off your hands. Second, request the report and read it, rather than relying on the statement that an attestation exists. Third, carry the report's statements into your own documentation, so that they can serve later as evidence of supplier assessment.
The licence question, if you want to reuse the criteria
If you intend to lift C5 criteria into your own questionnaires or tooling, check the licence before you start, because the BSI's own statements are not consistent. The download pages for both editions, and the C5:2026 catalogue itself, name the Creative Commons Attribution-NoDerivatives 4.0 International licence (CC BY-ND 4.0); the NoDerivatives clause forbids distributing an adapted version. The BSI's C5 FAQ, by contrast, names CC BY 4.0, without that clause. For passing the catalogue on unchanged the difference is immaterial. For restructuring, abridging or rebuilding the criteria into a catalogue of your own it is decisive, and what governs is the licence notice in the document you are actually using.
What a C5 attestation means for your own responsibility
A provider's attestation does not relieve you of your own duties. The split follows the shared responsibility model: configuration, permissions, data classification and log review regularly stay with the customer. Check in the report which services and locations are actually covered, and which assumptions the provider makes about measures on your side. The catalogue and the accompanying guidance are available from the BSI.