Book an Appointment

Trust Center: Self-Service Security Evidence

How to provide certificates, attestations, subprocessor lists and pentest summaries in a structured way – publicly where possible, NDA-protected where necessary.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

168criteria across 17 subject areas — the BSI's C5:2026 catalogue (April 2026)
3access tiers in the proven model — freely accessible, email-verified, NDA-protected
28Art. 28 GDPR sets the pace for the subprocessor list
2STAR levels: CAIQ self-assessment (Level 1) to audited credential (Level 2)

Security reviews have become a fixture of B2B procurement: anyone buying software or managed services demands certificates, audit reports and information about subcontractors – driven by their own obligations under the GDPR, NIS2 and DORA. Without a central point of reference, vendors answer the same questions in ever new bespoke questionnaires, and confidential documents circulate uncontrolled by email. A trust center consolidates the evidence in one well-maintained place, tiers access by confidentiality and makes the maturity of the vendor's security organization verifiable. This article shows which content belongs in it, how NDA gating works and how the portal interlocks with security questionnaires.

The Essentials at a Glance

Six topic blocks — tap to expand.

NDA gating: tiered access to evidence

The proven tiered model — tap a tier.

Tier 1 · public
  • Certificates, SOC 3, policy excerpts and the availability status are freely accessible.
  • Not every document belongs in the public domain — the principle: publicly where possible, NDA-protected where necessary.
CertificatesSOC 3Policy excerptsAvailability status

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Microsoft Learn · 2026

Get started with the Microsoft Service Trust Portal

Documentation of the reference portal: audit reports from external auditors, pentest attestations, and the sign-in and NDA requirement for compliance materials and role-restricted documents.

AICPA & CIMA · o. J.

SOC 3 – SOC for Service Organizations: Trust Services Criteria for General Use Report

Establishes SOC 3 as a freely distributable general-use report, in contrast to the more detailed SOC 2 report, which may only be shared on a restricted basis.

Cloud Security Alliance · 2026

STAR Registry (Security, Trust, Assurance and Risk)

Public registry with CAIQ self-assessments (Level 1, to be updated annually) and audited Level 2 credentials (STAR Certification/Attestation) aimed at reducing repeated vendor questionnaires.

Amtsblatt der EU / EUR-Lex · 2016

Verordnung (EU) 2016/679 (DSGVO)

Art. 28(2)–(4) governs authorization, notification of changes and the right to object regarding further processors, as well as evidence and audit obligations.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

Kriterienkatalog C5:2026

Current version of the cloud criteria catalogue (168 criteria across 17 subject areas); C5 attestations under ISAE 3000 are a common trust center credential in the German market.

Building a trust center or making yours review-ready?

We structure your evidence, define the NDA gating and connect the trust center with your questionnaire processes – happy to start with a no-obligation initial consultation.