The BSI first published C5 in 2016 and fundamentally revised it in 2020. C5:2020 defines 121 criteria across 17 domains – from the organisation of information security through personnel and physical security to cryptography. Basic criteria describe the mandatory minimum level and must be met in full; additional criteria address increased protection requirements. The catalogue also demands transparency: the provider's system description discloses framework parameters such as jurisdiction, processing locations and disclosure obligations towards public authorities, enabling customers to judge for themselves whether the service is suitable.
Cloud compliance with the BSI C5 criteria catalogue
What the BSI's Cloud Computing Compliance Criteria Catalogue covers, how Type 1 and Type 2 attestations work – and which obligations rest with the cloud customer itself.
121criteria across 17 domains (C5:2020)
168criteria in the revised C5:2026
100+attestations issued according to the BSI
3–12months of audit period for Type 2 (usually)
The Cloud Computing Compliance Criteria Catalogue (C5) issued by the German Federal Office for Information Security (BSI) has become the reference standard for assessing the security of cloud services in Germany since its first publication in 2016; according to the BSI, more than 100 attestations have been issued to date. Unlike a certification, C5 follows an audit-based approach: independent auditors provide attestations in accordance with international assurance standards, and the outcome is a detailed audit report rather than a seal. At the latest since § 393 SGB V tied the use of cloud services in the healthcare sector to a C5 attestation, the catalogue has been compliance-relevant far beyond the public sector. With C5:2026, a fundamentally revised version has also been available since the end of March 2026.
From SGB V deadlines to the revised catalogue
Four dates around C5 attestations and C5:2026 – tap a milestone for details.
1 July 2024
§ 393 SGB V takes effect
Healthcare providers, statutory health and long-term care insurance funds and their processors may only process health and social data in the cloud if, among other things, a current C5 attestation covering the basic criteria is in place.
1 July 2025
Type 2 becomes the rule under § 393 SGB V
§ 393 SGB V in principle only accepts Type 2 attestations. For systems first placed on the market after 30 June 2025, a Type 1 attestation suffices for the first 18 months.
End of March 2026
C5:2026 finalised
Following public consultation on the community draft, the fundamentally revised edition is final: 168 criteria in what remain 17 domains, published in machine-readable YAML format for the first time.
1 June 2027
C5:2026 becomes mandatory
C5:2026 is mandatory for attestations with reference dates or audit periods starting on or after 1 June 2027; earlier adoption is permitted.
The Essentials at a Glance
Six topic blocks — tap to expand.
Type 1 or Type 2: what the report proves
Two report types compared – select a tab.
- Confirms that the provider's controls are suitably designed and implemented as at a specific reference date – a pure design assessment.
- In practice a common intermediate step towards initial attestation, because the audit period required for Type 2 first has to elapse.
Reference dateDesign assessmentIntermediate stepInitial attestation
- Additionally examines the operating effectiveness of the controls over an audit period of usually three to twelve months.
- Only the Type 2 effectiveness assessment provides reliable statements about ongoing operations.
- Since 1 July 2025, § 393 SGB V has in principle only accepted Type 2 attestations.
Operating effectivenessAudit periodOngoing operations§ 393 SGB V
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Kriterienkatalog Cloud Computing C5:2020
The currently still authoritative version of the catalogue with 121 criteria across 17 domains, including cross-reference tables, among others to ISO/IEC 27001:2022.
Kriterienkatalog Cloud Computing C5:2026
Fundamentally revised new edition (final since the end of March 2026) with 168 criteria and new topics such as post-quantum cryptography and confidential computing; applicable to attestations from 1 June 2027.
C5 – Häufig gestellte Fragen (FAQ)
Official guidance on Type 1/Type 2 reports, assurance standards (ISAE 3000, IDW PS 860), the distinction from ISO 27001 and the transition from C5:2020 to C5:2026.
§ 393 SGB V – Cloud-Einsatz im Gesundheitswesen
Statutory anchoring of the C5 attestation for the processing of health and social data, including the Type 2 requirement from 1 July 2025 and the obligation to implement the corresponding criteria for customers.
Cloud Computing Compliance Criteria Catalog (C5) – Microsoft Compliance
Describes, from a provider's perspective, how C5 audits can be combined with SOC 2 audits and the required transparency about framework parameters in the system description.
Planning a C5 attestation or holding an audit report?
Whether you are a provider preparing a Type 2 attestation or a cloud customer required to demonstrate corresponding customer controls: in a no-obligation initial consultation we assess your starting position.