Cyber Horizon
Back to Blog
BSI C5CloudGermany

BSI C5: Germany’s Cloud Security Standard Explained

31 July 2026·7 min read·Cyber Horizon Team

C5 — the Cloud Computing Compliance Criteria Catalogue — is the German Federal Office for Information Security (BSI)’s benchmark for cloud-service security. If you sell cloud services into Germany, especially to the public sector, regulated industries or large enterprises, C5 is the assurance your buyers increasingly expect to see.

What C5 actually is

C5 is a catalogue of security requirements for cloud providers, structured around 17 objective areas — from organisation of information security and physical security through to identity & access management, cryptography, operations, and portability. Crucially, it’s not a self-declared badge: C5 is demonstrated through an attestation by an independent auditor, performed under the same professional standards (ISAE 3000 / 3402) used for SOC 2, so the output is a report, not a certificate.

The distinctive parts

  • Basic vs additional criteria: a baseline set every provider meets, plus additional criteria for higher-assurance needs.
  • Type 1 and Type 2 reports — like SOC 2, Type 1 tests design at a point in time; Type 2 tests operating effectiveness over a period.
  • Mandatory “surrounding parameters”: providers must disclose jurisdiction, data location, certifications and investigation-support arrangements — transparency that buyers use for risk decisions.
  • A strong emphasis on portability and interoperability, so customers aren’t locked in.

How it relates to SOC 2 and ISO 27001

BSI C5SOC 2 / ISO 27001
OriginGerman government (BSI)US (AICPA) / international (ISO)
OutputAuditor attestation reportSOC 2 report / ISO certificate
Assurance basisISAE 3000/3402ISAE/SSAE / ISO audit
DistinctiveMandatory transparency on jurisdiction & data locationTrust Services Criteria / Annex A controls

The good news for providers who already hold SOC 2 or ISO 27001: the control overlap is substantial. Most C5 criteria map to controls you already operate; the work is closing the C5-specific deltas (transparency parameters, portability) and adding the German audit.

Why buyers ask for it

German enterprises and public bodies use C5 as a shortcut for cloud due diligence — it standardises the questions they’d otherwise ask in a long questionnaire, and it carries the weight of the national security authority. Having a C5 attestation can be the difference between clearing procurement and being asked for months of bespoke evidence.

Getting there

  • Start from your existing control library (ISO 27001 SoA / SOC 2) and map C5’s 17 areas onto it — most is already covered.
  • Fill the C5-specific gaps: documented surrounding parameters, portability/interoperability, and investigation support.
  • Choose Type 1 first to prove design, then Type 2 once controls have operated over a period.
  • Engage an auditor experienced with C5/ISAE 3000 and keep evidence continuous, not point-in-time.

The bottom line

C5 is Germany’s cloud-assurance lingua franca — an auditor-attested, transparency-heavy overlay on the control set you likely already run for SOC 2 or ISO 27001. If Germany is a market, it converts “trust us” into the report procurement teams expect.

Map C5 onto controls you already have

Cyber Horizon cross-maps BSI C5 with ISO 27001, SOC 2 and 70+ other frameworks — so the German attestation is additional coverage over one control library, not a separate programme.

Book a Demo