01Structure of the catalogue: 121 criteria across 17 domains
The BSI first published C5 in 2016 and fundamentally revised it in 2020. C5:2020 defines 121 criteria across 17 domains – from the organisation of information security through personnel and physical security to cryptography. Basic criteria describe the mandatory minimum level and must be met in full; additional criteria address increased protection requirements. The catalogue also demands transparency: the provider's system description discloses framework parameters such as jurisdiction, processing locations and disclosure obligations towards public authorities, enabling customers to judge for themselves whether the service is suitable.
02Audit-based approach: attestation instead of certificate
C5 is not a certification scheme but an audit standard: independent auditors – in Germany typically public auditors (Wirtschaftsprüfer) – attest fulfilment of the criteria in accordance with the International Standard on Assurance Engagements 3000 (ISAE 3000), nationally under IDW PS 860. The result is not a binary seal but a comprehensive audit report containing the system description, the controls and the audit results. This logic, borrowed from financial statement audits, delivers considerably more detail than a certificate – but shifts the assessment effort to the reader: the report has to be evaluated in substance.
03Type 1 vs. Type 2 report
A Type 1 report confirms that the provider's controls are suitably designed and implemented as at a specific reference date – a pure design assessment. A Type 2 report additionally examines the operating effectiveness of these controls over an audit period of usually three to twelve months. Only the Type 2 effectiveness assessment provides reliable statements about ongoing operations; since 1 July 2025, § 393 SGB V has likewise in principle only accepted Type 2 attestations. In practice, a Type 1 attestation is nevertheless a common intermediate step towards initial attestation, because the audit period required for Type 2 first has to elapse.
04Who requires C5: the public sector and healthcare
C5 was developed for the secure use of cloud services by the public administration; for the federal administration it is anchored in the BSI Minimum Standard for the use of external cloud services, and it is regularly required as evidence in procurement procedures as well. Since 1 July 2024, § 393 SGB V has additionally stipulated: healthcare providers, statutory health and long-term care insurance funds and their processors may only process health and social data in the cloud if, among other things, the processing takes place in Germany, the EU or an equivalent state, the data-processing entity has an establishment in Germany and a current C5 attestation covering the basic criteria is in place. Since 1 July 2025 this must be a Type 2 attestation; for systems first placed on the market after 30 June 2025, a Type 1 attestation suffices for the first 18 months.
05Corresponding customer criteria: your own share
Cloud security is a shared responsibility: C5 audit reports contain corresponding criteria for customers – controls the user must implement itself so that the provider's attested controls can take effect, for instance in identity and access management. § 393 SGB V turns this into an explicit legal obligation: cloud use is only permissible if "the corresponding criteria for customers contained in the audit report of the attestation have been implemented". In practice this means: request and evaluate the audit report, extract the customer obligations, map them to your own controls and document their implementation verifiably. The provider's attestation alone does not make your use of the service compliant.
06ISO 27001, SOC 2 and the revised C5:2026
ISO/IEC 27001 certifies an organisation's management system, whereas C5 attests the specific cloud service – the two complement but do not replace each other; the BSI provides cross-reference tables, including to ISO/IEC 27001:2022. SOC 2 follows the same audit-based logic, and according to the BSI, C5 and SOC 2 audits can be combined so that the system description and audit results can be reused for overlapping controls. Following public consultation on the community draft, the revised C5:2026 has been final since the end of March 2026: it comprises 168 criteria in what remain 17 domains, adds topics such as container management, supply chain security, post-quantum cryptography, confidential computing and technical sovereignty, and is published in machine-readable YAML format for the first time. It is mandatory for attestations with reference dates or audit periods starting on or after 1 June 2027; earlier adoption is permitted.