Book an Appointment

Cloud compliance with the BSI C5 criteria catalogue

What the BSI's Cloud Computing Compliance Criteria Catalogue covers, how Type 1 and Type 2 attestations work – and which obligations rest with the cloud customer itself.

The Cloud Computing Compliance Criteria Catalogue (C5) issued by the German Federal Office for Information Security (BSI) has become the reference standard for assessing the security of cloud services in Germany since its first publication in 2016; according to the BSI, more than 100 attestations have been issued to date. Unlike a certification, C5 follows an audit-based approach: independent auditors provide attestations in accordance with international assurance standards, and the outcome is a detailed audit report rather than a seal. At the latest since § 393 SGB V tied the use of cloud services in the healthcare sector to a C5 attestation, the catalogue has been compliance-relevant far beyond the public sector. With C5:2026, a fundamentally revised version has also been available since the end of March 2026.

The Essentials at a Glance

01

Structure of the catalogue: 121 criteria across 17 domains

The BSI first published C5 in 2016 and fundamentally revised it in 2020. C5:2020 defines 121 criteria across 17 domains – from the organisation of information security through personnel and physical security to cryptography. Basic criteria describe the mandatory minimum level and must be met in full; additional criteria address increased protection requirements. The catalogue also demands transparency: the provider's system description discloses framework parameters such as jurisdiction, processing locations and disclosure obligations towards public authorities, enabling customers to judge for themselves whether the service is suitable.

02

Audit-based approach: attestation instead of certificate

C5 is not a certification scheme but an audit standard: independent auditors – in Germany typically public auditors (Wirtschaftsprüfer) – attest fulfilment of the criteria in accordance with the International Standard on Assurance Engagements 3000 (ISAE 3000), nationally under IDW PS 860. The result is not a binary seal but a comprehensive audit report containing the system description, the controls and the audit results. This logic, borrowed from financial statement audits, delivers considerably more detail than a certificate – but shifts the assessment effort to the reader: the report has to be evaluated in substance.

03

Type 1 vs. Type 2 report

A Type 1 report confirms that the provider's controls are suitably designed and implemented as at a specific reference date – a pure design assessment. A Type 2 report additionally examines the operating effectiveness of these controls over an audit period of usually three to twelve months. Only the Type 2 effectiveness assessment provides reliable statements about ongoing operations; since 1 July 2025, § 393 SGB V has likewise in principle only accepted Type 2 attestations. In practice, a Type 1 attestation is nevertheless a common intermediate step towards initial attestation, because the audit period required for Type 2 first has to elapse.

04

Who requires C5: the public sector and healthcare

C5 was developed for the secure use of cloud services by the public administration; for the federal administration it is anchored in the BSI Minimum Standard for the use of external cloud services, and it is regularly required as evidence in procurement procedures as well. Since 1 July 2024, § 393 SGB V has additionally stipulated: healthcare providers, statutory health and long-term care insurance funds and their processors may only process health and social data in the cloud if, among other things, the processing takes place in Germany, the EU or an equivalent state, the data-processing entity has an establishment in Germany and a current C5 attestation covering the basic criteria is in place. Since 1 July 2025 this must be a Type 2 attestation; for systems first placed on the market after 30 June 2025, a Type 1 attestation suffices for the first 18 months.

05

Corresponding customer criteria: your own share

Cloud security is a shared responsibility: C5 audit reports contain corresponding criteria for customers – controls the user must implement itself so that the provider's attested controls can take effect, for instance in identity and access management. § 393 SGB V turns this into an explicit legal obligation: cloud use is only permissible if "the corresponding criteria for customers contained in the audit report of the attestation have been implemented". In practice this means: request and evaluate the audit report, extract the customer obligations, map them to your own controls and document their implementation verifiably. The provider's attestation alone does not make your use of the service compliant.

06

ISO 27001, SOC 2 and the revised C5:2026

ISO/IEC 27001 certifies an organisation's management system, whereas C5 attests the specific cloud service – the two complement but do not replace each other; the BSI provides cross-reference tables, including to ISO/IEC 27001:2022. SOC 2 follows the same audit-based logic, and according to the BSI, C5 and SOC 2 audits can be combined so that the system description and audit results can be reused for overlapping controls. Following public consultation on the community draft, the revised C5:2026 has been final since the end of March 2026: it comprises 168 criteria in what remain 17 domains, adds topics such as container management, supply chain security, post-quantum cryptography, confidential computing and technical sovereignty, and is published in machine-readable YAML format for the first time. It is mandatory for attestations with reference dates or audit periods starting on or after 1 June 2027; earlier adoption is permitted.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2020

Kriterienkatalog Cloud Computing C5:2020

The currently still authoritative version of the catalogue with 121 criteria across 17 domains, including cross-reference tables, among others to ISO/IEC 27001:2022.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

Kriterienkatalog Cloud Computing C5:2026

Fundamentally revised new edition (final since the end of March 2026) with 168 criteria and new topics such as post-quantum cryptography and confidential computing; applicable to attestations from 1 June 2027.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

C5 – Häufig gestellte Fragen (FAQ)

Official guidance on Type 1/Type 2 reports, assurance standards (ISAE 3000, IDW PS 860), the distinction from ISO 27001 and the transition from C5:2020 to C5:2026.

Bundesministerium der Justiz / gesetze-im-internet.de · 2024

§ 393 SGB V – Cloud-Einsatz im Gesundheitswesen

Statutory anchoring of the C5 attestation for the processing of health and social data, including the Type 2 requirement from 1 July 2025 and the obligation to implement the corresponding criteria for customers.

Microsoft Learn · 2025

Cloud Computing Compliance Criteria Catalog (C5) – Microsoft Compliance

Describes, from a provider's perspective, how C5 audits can be combined with SOC 2 audits and the required transparency about framework parameters in the system description.

Planning a C5 attestation or holding an audit report?

Whether you are a provider preparing a Type 2 attestation or a cloud customer required to demonstrate corresponding customer controls: in a no-obligation initial consultation we assess your starting position.