Dark Rock Cybersecurity

BSI C5 Cloud Security Attestation for the German Market

BSI C5 (Cloud Computing Compliance Criteria Catalogue) is Germany's authoritative cloud security attestation - increasingly required by German and EU public sector organizations and regulated industries.

Why BSI C5 Is Essential for German and EU Cloud Providers

The Cloud Computing Compliance Criteria Catalogue (C5), developed by Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik - BSI), defines minimum security requirements for cloud services used by German government agencies, critical infrastructure operators, and regulated industries. First published in 2016 and updated in 2020, C5 has become the de facto cloud security standard for the German market and is gaining recognition across the broader EU.

C5 attestation is structured as a type 1 (design effectiveness) or type 2 (operational effectiveness over a minimum 12-month period) assessment conducted by an independent, qualified auditor. The 2020 update expanded C5 from 114 to 128 criteria across 17 domains, aligned C5 to ISO 27001 and SOC 2 Trust Services Criteria, and introduced Basic Criteria that all cloud providers must meet plus Special Criteria applicable to specific use cases.

German public authorities are increasingly mandating C5 attestations in cloud procurement contracts - particularly for systems processing personal data or handling sensitive government information. German and European enterprises in financial services, healthcare, and critical infrastructure use C5 as a vendor assessment tool. Cloud providers targeting German enterprise or public sector customers are finding C5 attestation a requirement rather than a differentiator.

Our Approach

Scope & Applicability Analysis

We define the C5 system scope (the cloud service subject to attestation), determine applicable criteria (Basic vs. Special), analyze existing certifications for harmonization opportunities (C5 maps closely to ISO 27001 and SOC 2), and engage a qualified BSI-approved auditor for the formal attestation.

Gap Assessment

We assess your cloud service against all applicable C5 criteria across the 17 domains - from Organization of Information Security and Physical Security through to Supply Chain Management and Incident Management. You receive a gap report with prioritized remediation items and estimated effort.

Remediation & Documentation

We implement controls to close C5 gaps and build the required documentation: policies, procedures, evidence libraries, and technical specifications mapped to each criterion. For Type 2 attestations, we ensure controls are operational and evidenced across the full observation period.

Attestation & Market Access

We coordinate the formal C5 attestation with your auditor, manage evidence submissions, and facilitate the Assurance Report preparation. The resulting C5 Attestation Report is the deliverable your German and EU customers need - we also prepare the System Description and Transparency Document required for public disclosure.

What You Get

  • C5 system scope definition and applicability analysis
  • Gap assessment against all 128 C5 criteria
  • Remediation plan with effort estimates and priority ranking
  • Policy and procedure documentation aligned to C5 domains
  • Evidence library organized by C5 criterion
  • Control implementation support across all 17 C5 domains
  • Auditor coordination and evidence submission management
  • C5 Attestation Report (Type 1 or Type 2) preparation support
  • System Description and C5 Transparency Document

0

C5 criteria across 17 security domains - the comprehensive standard for cloud security in the German and EU market.

Related Frameworks

Frequently Asked Questions