BSI C5: Germany’s Cloud Security Standard Explained
C5 — the Cloud Computing Compliance Criteria Catalogue — is the German Federal Office for Information Security (BSI)’s benchmark for cloud-service security. If you sell cloud services into Germany, especially to the public sector, regulated industries or large enterprises, C5 is the assurance your buyers increasingly expect to see.
What C5 actually is
C5 is a catalogue of security requirements for cloud providers, structured around 17 objective areas — from organisation of information security and physical security through to identity & access management, cryptography, operations, and portability. Crucially, it’s not a self-declared badge: C5 is demonstrated through an attestation by an independent auditor, performed under the same professional standards (ISAE 3000 / 3402) used for SOC 2, so the output is a report, not a certificate.
The distinctive parts
- Basic vs additional criteria: a baseline set every provider meets, plus additional criteria for higher-assurance needs.
- Type 1 and Type 2 reports — like SOC 2, Type 1 tests design at a point in time; Type 2 tests operating effectiveness over a period.
- Mandatory “surrounding parameters”: providers must disclose jurisdiction, data location, certifications and investigation-support arrangements — transparency that buyers use for risk decisions.
- A strong emphasis on portability and interoperability, so customers aren’t locked in.
How it relates to SOC 2 and ISO 27001
| BSI C5 | SOC 2 / ISO 27001 | |
|---|---|---|
| Origin | German government (BSI) | US (AICPA) / international (ISO) |
| Output | Auditor attestation report | SOC 2 report / ISO certificate |
| Assurance basis | ISAE 3000/3402 | ISAE/SSAE / ISO audit |
| Distinctive | Mandatory transparency on jurisdiction & data location | Trust Services Criteria / Annex A controls |
The good news for providers who already hold SOC 2 or ISO 27001: the control overlap is substantial. Most C5 criteria map to controls you already operate; the work is closing the C5-specific deltas (transparency parameters, portability) and adding the German audit.
Why buyers ask for it
German enterprises and public bodies use C5 as a shortcut for cloud due diligence — it standardises the questions they’d otherwise ask in a long questionnaire, and it carries the weight of the national security authority. Having a C5 attestation can be the difference between clearing procurement and being asked for months of bespoke evidence.
Getting there
- Start from your existing control library (ISO 27001 SoA / SOC 2) and map C5’s 17 areas onto it — most is already covered.
- Fill the C5-specific gaps: documented surrounding parameters, portability/interoperability, and investigation support.
- Choose Type 1 first to prove design, then Type 2 once controls have operated over a period.
- Engage an auditor experienced with C5/ISAE 3000 and keep evidence continuous, not point-in-time.
The bottom line
C5 is Germany’s cloud-assurance lingua franca — an auditor-attested, transparency-heavy overlay on the control set you likely already run for SOC 2 or ISO 27001. If Germany is a market, it converts “trust us” into the report procurement teams expect.
Map C5 onto controls you already have
Cyber Horizon cross-maps BSI C5 with ISO 27001, SOC 2 and 70+ other frameworks — so the German attestation is additional coverage over one control library, not a separate programme.
Book a Demo