Book an Appointment

Cloud compliance with the BSI C5 criteria catalogue

What the BSI's Cloud Computing Compliance Criteria Catalogue covers, how Type 1 and Type 2 attestations work – and which obligations rest with the cloud customer itself.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

121criteria across 17 domains (C5:2020)
168criteria in the revised C5:2026
100+attestations issued according to the BSI
3–12months of audit period for Type 2 (usually)

The Cloud Computing Compliance Criteria Catalogue (C5) issued by the German Federal Office for Information Security (BSI) has become the reference standard for assessing the security of cloud services in Germany since its first publication in 2016; according to the BSI, more than 100 attestations have been issued to date. Unlike a certification, C5 follows an audit-based approach: independent auditors provide attestations in accordance with international assurance standards, and the outcome is a detailed audit report rather than a seal. At the latest since § 393 SGB V tied the use of cloud services in the healthcare sector to a C5 attestation, the catalogue has been compliance-relevant far beyond the public sector. With C5:2026, a fundamentally revised version has also been available since the end of March 2026.

From SGB V deadlines to the revised catalogue

Four dates around C5 attestations and C5:2026 – tap a milestone for details.

The Essentials at a Glance

Six topic blocks — tap to expand.

Type 1 or Type 2: what the report proves

Two report types compared – select a tab.

Design assessment
  • Confirms that the provider's controls are suitably designed and implemented as at a specific reference date – a pure design assessment.
  • In practice a common intermediate step towards initial attestation, because the audit period required for Type 2 first has to elapse.
Reference dateDesign assessmentIntermediate stepInitial attestation

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2020

Kriterienkatalog Cloud Computing C5:2020

The currently still authoritative version of the catalogue with 121 criteria across 17 domains, including cross-reference tables, among others to ISO/IEC 27001:2022.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

Kriterienkatalog Cloud Computing C5:2026

Fundamentally revised new edition (final since the end of March 2026) with 168 criteria and new topics such as post-quantum cryptography and confidential computing; applicable to attestations from 1 June 2027.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

C5 – Häufig gestellte Fragen (FAQ)

Official guidance on Type 1/Type 2 reports, assurance standards (ISAE 3000, IDW PS 860), the distinction from ISO 27001 and the transition from C5:2020 to C5:2026.

Bundesministerium der Justiz / gesetze-im-internet.de · 2024

§ 393 SGB V – Cloud-Einsatz im Gesundheitswesen

Statutory anchoring of the C5 attestation for the processing of health and social data, including the Type 2 requirement from 1 July 2025 and the obligation to implement the corresponding criteria for customers.

Microsoft Learn · 2025

Cloud Computing Compliance Criteria Catalog (C5) – Microsoft Compliance

Describes, from a provider's perspective, how C5 audits can be combined with SOC 2 audits and the required transparency about framework parameters in the system description.

Planning a C5 attestation or holding an audit report?

Whether you are a provider preparing a Type 2 attestation or a cloud customer required to demonstrate corresponding customer controls: in a no-obligation initial consultation we assess your starting position.