77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
BSI C5: What the criteria catalogue for cloud compliance requires
IT Security & NIS-2

BSI C5: What the criteria catalogue for cloud compliance requires

9 August 202613 min readBy Lena Vogt
CIVAC

The BSI C5 is the German de facto standard for cloud compliance. This article describes the structure, criteria structure, the relationship to ISO/IEC 27001:2022 and how CIVAC halves the mapping effort between ISMS, C5 and client requirements.

The BSI Cloud Computing Compliance Criteria Catalog, or BSI C5 for short, was published for the first time by the Federal Office for Information Security in 2016 and converted to the currently relevant status C5:2020 in 2020. With the increasing cloud migration of public administration, KRITIS operators and financial supervision, it has developed from a voluntary standard to a de facto requirement specification. In tenders, federal authorities, social security institutions and increasingly large private customers require a C5 attestation from the cloud provider, often in the Type 2 variant with an operational effectiveness test over a period of at least six months.

This article describes the structure of the catalogue (basic and additional criteria), the relationship to ISO/IEC 27001:2022 with its 93 controls, the difference between Type 1 and Type 2 attestation as well as the Mapping effort that arises in practice between the cloud provider, customer and auditor. You will also learn how the CIVAC compliance platform and Officer-as-a-Service constellation as an ISMS backbone reduces the burden of providing cloud evidence by maintaining ISO 27001 controls, C5 criteria and customer audit obligations in a single versioned reporting line. With this structure, the follow-up costs decrease significantly from the second certificate onwards because existing evidence continues to be used and does not have to be collected again every year. Licence the workspace for your internal representatives, or have our representatives order it. In the background, 490 audit templates, EU data residency and the CIVAC SLA of two working days instead of the classic two to six weeks run. The auditor calls, the evidence is ready.

Key Takeaways

  • C5 is not a law, but is actually mandatory for federal authorities, KRITIS operators and social security providers in cloud tenders.
  • A C5 attestation is carried out by an auditor according to ISAE 3000/3402 logic; Type 2 covers operational effectiveness for at least six months.
  • C5 and ISO/IEC 27001:2022 overlap by around 70 to 80 percent, the rest are C5 additional criteria for transparency and data sovereignty.

What the BSI C5 regulates and to whom it applies

The BSI C5 is aimed at providers of cloud services and their customers. It specifies information security requirements for IaaS, PaaS and SaaS deployments and is methodologically based on ISAE 3000 and ISAE 3402, so that a cloud provider presents an audit result (certificate) from an auditor that evaluates the structure and effectiveness of the controls over a defined period of time. This means that C5 differs structurally from an ISO 27001 certification, which is a system certification by an accredited certification body.

The addressees in public administration are in particular federal and state authorities that use the Online Access Act or the EVB-IT Cloud. In the KRITIS environment, the supervisory authorities in energy, water, health, finance and telecommunications regularly require a C5 certificate as proof of the technical and organisational measures required by BSI Act § 8a. The BaFin circulars on outsourcing (BAIT, KAIT, VAIT, ZAIT) also indirectly refer to cloud-specific audits for which C5 is accepted as a form of proof.

For the cloud customer, C5 is evidence as part of their own supplier monitoring. Anyone who includes cloud services within the scope of their own ISMS or an NIS 2 obligation must be able to document the provider's control environment. The C5 attestation is a recognised component of this evidence. CIVAC carries out the role of the information security officer as a central interface for such supplier audits and files certificates in a structured manner in the reporting line. Audit-proof, documented, § 8a-proof. In addition: The C5 creates comparability between providers. Anyone who works without an attestation has to answer each of the customer's individual audit questions individually, which can include several hundred questions for large customers and cannot be accomplished in a reasonable amount of time without a structured reporting line. It is precisely this efficiency effect that makes the C5 equally valuable for providers and customers.

Structure of the criteria catalogue: basic, additional and environmental criteria

The C5:2020 catalogue contains over 120 requirements divided into 17 subject areas. Topic areas range from information security organisation, human resources management, asset management, physical security, operations, procurement, development and maintenance, security incident management, business continuity to data protection, mobile computing and cross-cutting aspects. Each subject area includes basic criteria and some additional criteria that address increased protection needs.

The basic criteria form the minimum standard. They must be addressed in a certificate and cover the typical topics that are also contained in ISO/IEC 27001:2022 (access control, encryption, backup, incident management, supplier management). The additional criteria go beyond this and address topics that are specifically relevant to highly sensitive data or particularly critical applications. They are optional, but often required in public tenders.

A special feature of the C5 are the environmental parameters (complementary requirements for the cloud customer). C5 recognises that information security in the cloud only works if the customer also assumes certain responsibilities (e.g. identity and access management at the client level, patching of own applications, key management). The provider is obliged to describe these complementary obligations transparently; the customer is obliged to fulfil them and prove them internally. CIVAC maps this shared responsibility using structured templates. The 490 audit templates contain their own C5 mapping. Others run compliance like a filing cabinet. We run it like software. Each complementary requirement is linked to a specific measure in the workspace, with the person responsible, due date and field of evidence, so that during the next supplier audit the customer does not argue with references to the provider, but rather presents their own evidence. Audit-proof, documented, § 8a-proof. The templates are available in German and English versions and explicitly depict the client configuration and client separation.

Relation to ISO/IEC 27001:2022: Overlap and gaps

Anyone who already operates a certified ISMS according to ISO/IEC 27001:2022 has done a large part of the preparatory work for a C5 attestation. The 93 controls of ISO 27001:2022 (in the four domains Organizational, People, Physical, Technological) cover between 70 and 80 percent of the C5 criteria. Topic areas such as asset management, access control, cryptography, physical security, operational security and relationships with suppliers are almost identical.

The typical gaps lie, firstly, in the transparency requirement. The C5 requires detailed information about the cloud service, sub-processing, data residency and investigation behaviour in the event of a crisis, which ISO 27001 does not explicitly require in this form. Secondly, with regard to data sovereignty and sovereignty: C5 contains specific requirements for responding to orders from foreign authorities (US CLOUD Act, FISA 702), which ISO 27001 leaves to the ISMS. Thirdly, with investigation support: The obligation to support forensic investigations is explicitly anchored in C5.

Anyone who operates ISO 27001:2022 and aims for C5 should therefore specifically close these three gap areas instead of rebuilding the ISMS. The ISO 27001:2022 transition period expired in October 2025, so companies tackling C5 now are usually already up to speed on the new standard. CIVAC maintains a cross-reference table between the 93 ISO controls, the C5 basic criteria, the C5 additional criteria and customer audit questionnaires, so that each measure is only documented once and referenced multiple times. The auditor calls, the evidence is ready. The cross-reference also takes into account frequent customer audit forms (VSA, CAIQ, large clients' own corporate forms), so that answers are not compiled manually each time, but come from one source and are issued in consistent wording.

Attestation type 1 and type 2: What the examiner really does

A C5 certificate is not issued by the BSI itself, but by an auditor or an auditing firm according to the standards of the Institute of Auditors (IDW PS 860 and IDW PH 9.860.2). Methodologically, the procedure is based on ISAE 3000 and ISAE 3402. The auditor documents his results in a structured report with five sections: description of the cloud provider, description of the control environment, assessment of the set-up effectiveness, if necessary, assessment of the operational effectiveness and attachments.

In the type 1 attestation, the auditor confirms the set-up effectiveness of the controls as of a key date. Methodologically, this is the first step after introducing new controls. In the type 2 attest, the auditor also checks the operational effectiveness over a period of at least six months. In practice, demanding public and private clients require the Type 2 certificate because this is the only way to make a statement about the actual function of the controls over time.

For the cloud provider, this means: The lead time to the first Type 2 certificate is usually 12 to 18 months, including a six-month effectiveness window, three to six months of preparation and three to six months of testing. For the cloud customer, this means that the Type 2 requirement must appear explicitly in the negotiation sheet because a Type 1 attestation only provides point-in-time evidence. CIVAC bundles all audit-relevant evidence (guidelines, training, incidents, reviews) for the cloud provider in the reporting line. The appointment certificate, signed, filed, verifiable. Licence the workspace for your internal representatives, or have our representatives order it. The clock starts on awareness.

C5 in relation to NIS-2, DORA and KRITIS

The C5 has its greatest impact in conjunction with other regulations. Within the scope of NIS-2 (implemented in Germany by the NIS2UmsuCG), around 29,500 affected companies must implement appropriate and proportionate technical, operational and organisational measures, including security in the supply chain in accordance with Article 21 Paragraph 2 Letter d. C5 certificates from a cloud provider are a recognised component of this evidence because they document the controls in the cloud area in a structured manner.

The Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) has also applied to financial service providers since January 17, 2025. DORA requires contracts with ICT third parties with extensive minimum clauses, a register of all ICT third party agreements and a risk assessment of critical third parties. C5 certificates from a cloud provider help to document the due diligence requirements required by DORA Art. 28 ff. without each financial service provider having to carry out an on-site inspection at the cloud provider individually.

In the KRITIS area, Section 8a of the BSI Act requires the implementation of the state of the art. Cloud providers that act as KRITIS service providers or are used by KRITIS operators regularly demonstrate the state of the art via the C5 certificate. The BSIG also contains sanction options for violations, which, in combination with NIS-2 according to the NIS2UmsuCG draft, range up to 10 million euros or 2 percent of group sales for essential facilities. CIVAC maps the evidence between C5, NIS-2, DORA and KRITIS in a single NIS-2-compliant reporting line, thereby reducing multiple surveys for the same information. Anyone who addresses several supervisory regimes at the same time saves a significant amount of follow-up effort through mapping because the auditor can rely on existing evidence and does not have to initiate a separate survey for each regime. This applies in particular to the DORA third-party registers.

Typical weaknesses in C5 audits and how they arise

Recurring weaknesses can be derived from the practice of the initial C5 tests. Weakness one: The control environment is described but not proven. The auditor finds a process in the guideline, but sees no consistent evidence that the process is being implemented. The result is findings that delay the transition from type 1 to type 2. Weakness two: The complementary requirements for the customer are unclearly formulated or are completely missing. The customer does not understand what he has to do himself, the provider argues with the customer's lack of contribution.

Weakness three: sub-processors and sub-sub-processors are not consistently documented. C5 requires a description of the sub-processing chain, which in practice includes many layers in large hyperscalers. Without proper documentation, findings arise that do not make the certificate unconditional. Weakness four: Investigation support and inquiries from authorities are neither reflected in the standard processes nor in the contract templates. C5 calls for explicit regulations regarding response time, escalation path and transparency report.

Weakness five: The training situation is not differentiated according to roles. Those who handle security incidents need different content than those who are responsible for identity offerings. Without role-specific training, operational effectiveness is implausible. Weakness Six: Audit findings from previous audits were not systematically closed or accepted as risk without documented approval. CIVAC addresses all six weaknesses via the reporting line with mandatory fields for evidence, responsible person, deadline and status, linked to the ISB appointment certificate and to the supplier auditor role. Audit-proof, documented, § 8a-proof. Findings from preliminary examinations are automatically kept as a resubmission so that the provider does not have to address the same point again in the following year, but can specifically document the remaining measures that are still open.

C5 for cloud customers: How to use attestations sensibly

Anyone who requests C5 certificates as a cloud customer should not be reassured by the mere existence of the document. The attestation is a necessary, but not sufficient, condition. In practice, three steps are required. First, read the attestation section for the control environment and description of the system. This determines which services and which regions are covered by the certificate. Often the service used is outside the scope.

Second: Check the complementary requirements. It states what you as a customer must do for the provider's controls to work. Anyone who does not transfer this list to their own ISMS will not have the benefit of the certificate in their own audit inventory. Specific examples include multi-factor authentication of administrators, patch management of your own applications, encryption with customer-held keys and configuration-controlled client separation.

Third: Read the findings in the certificate. A type 2 certificate also usually contains complaints that are identified as insignificant or essential findings. Significant findings often have a concrete impact on the customer and must be taken into account in your own risk analysis. CIVAC provides cloud customers with a checklist in the audit templates, which evaluates each new attestation in a structured manner in 30 to 60 minutes and transfers it to its own reporting line. Licence the workspace for your internal representatives, or have our representatives order it. CIVAC-SLA: two working days instead of the classic two to six weeks. In multi-cloud strategies, certificates from different providers are compared in a common evaluation matrix, so that operationally comparable statements are possible for the board of directors and supervisory board and concentration risks according to DORA Art. 29 become visible before they become a supervisory finding.

Effort, costs and realistic benchmarks

How much does a C5 certificate cost? The range is wide because it depends on the scope of cloud services, the number of regions, the complexity of the controls and the auditor. For a medium-sized SaaS provider with a clearly defined service, the external audit costs are typically between 60,000 and 180,000 euros for a type 2 attestation. Experience has shown that the internal expenses in the areas of information security, legal, IT operations and compliance are around twice the external costs in the first year.

For a follow-up attestation, the external costs usually fall by 20 to 40 percent because descriptions, mappings and evidence can be reused. A prerequisite is clean versioning. Anyone who builds an isolated solution per criterion in the first year will pay almost the full price again in the second year. Anyone who operates an integrated ISMS platform in which C5 mapping, ISO 27001 controls, incidents, training and suppliers are in one data structure halves the follow-up costs.

CIVAC provides this integrated platform. In the workspace model, all evidence flows into a single reporting line, with templates for describing the control environment, for complementary requirements and for mapping between 93 ISO controls and C5 criteria. In the Officer-as-a-Service model, the order from the external ISB is also taken over and shown in the certificate. Licence the workspace for your internal representatives, or have our representatives order it. EU data residency, 490 audit templates, versioned reporting line are included. The workspace scales from a single SaaS service to a multi-region platform without the need to replace the underlying data structure as the scope of the attestation grows. The later inclusion of further regulations such as DORA or new KRITIS sectors is also possible without a structural break.

From reading to implementation: setting up a C5 strategy

A C5 strategy begins with three questions: What cloud services do you use or offer? Which clients or supervisory regimes require the certificate or comparable evidence? What level of maturity does your ISMS have today, measured against ISO/IEC 27001:2022 with 93 controls? The sequence follows from the answers: gap analysis, gap closure, internal test attestation, auditor selection, type 1, six-month effectiveness window, type 2.

In the second step, the attestation process is integrated into the existing compliance landscape. C5 criteria are mapped to ISO controls, complementary customer requirements are transferred to contract templates, and audit trail obligations are included in the reporting line. In the third step, the effectiveness is documented for at least six months and checked by the auditor. Findings are stored with measures, responsibility and deadline and closed until the follow-up certificate.

CIVAC provides ready-made building blocks for each of these three steps: ISO/C5 cross-reference tables, template texts for complementary requirements, evidence templates for effectiveness testing. The platform works in two modes: licence the workspace for your internal representatives, or have our officers appointed it. In both models, the CIVAC SLA of two business days applies to the initial setup. EU data residency is a prerequisite so that the verification data does not trigger additional C5 requirements.

Turn reading into a mandate. Write to the central mailbox info@civac.de or use the contact form on civac.de/faq. We will send a concrete roadmap for your C5 project within two working days, tailored to your ISMS maturity level, your service model and your client expectations, including a comparison between existing ISO 27001:2022 documentation and the C5-specific additional criteria as well as a suggestion for a sensible time window for the first type 2 effectiveness interval and a recommendation for auditor selection.

FAQ

Is a BSI C5 certificate required by law?

No, the C5 itself is not a law. It is a catalogue of criteria published by the BSI. In fact, federal authorities, KRITIS operators and increasingly financial service providers require a C5 certificate as proof of cloud security in tenders, so that the effect corresponds to an obligation. NIS-2, DORA and Section 8a of the BSI Act indirectly refer to such structured evidence. Anyone who offers without a certificate is effectively excluding themselves from relevant client groups.

What is the difference between a C5 Type 1 and a Type 2 attestation?

Type 1 confirms the effectiveness of the controls as of a specific date, i.e. that the control system is designed appropriately. Type 2 also tests the operational effectiveness over at least six months. Type 2 is usually required in public tenders because only this allows a reliable statement about the actual function of the controls over time.

How does BSI C5 relate to ISO/IEC 27001:2022?

ISO/IEC 27001:2022 with its 93 controls and the C5 overlap by around 70 to 80 percent. Gaps typically exist in transparency obligations, data sovereignty, investigation support and response to requests from foreign authorities. Anyone who is already certified has done the main work and should specifically address the C5-specific additional criteria instead of rebuilding the ISMS.

Who is allowed to issue a C5 certificate?

C5 certificates are not issued by the BSI, but by auditors or auditing firms in accordance with the standards of the Institute of Auditors (IDW PS 860, IDW PH 9.860.2). Methodologically, the procedure is based on ISAE 3000 and ISAE 3402. The auditor qualification is a prerequisite; a pure ISO certification body is not authorised. In practice, two audit teams make sense: an ISO 27001 audit team and an auditor.

What are complementary requirements in C5?

Complementary requirements are obligations that the cloud customer must assume in order for the provider's controls to be effective. Examples: multi-factor authentication of administrative accounts, patch management of your own applications, tenant configuration, key management for customer-held keys and secure configuration of identity connections. The provider must describe them transparently, the customer must perceive them and document them in their own ISMS, otherwise the attestation will no longer be effective.

How long is a C5 certificate valid?

C5 certificates are usually renewed annually, with an examination period of 6 to 12 months. A certificate does not have a fixed period of validity, but in practice clients expect that the current certificate is not older than 12 to 15 months. Without a complete follow-up certificate, there will be a breach in evidence that is relevant in tenders and supplier monitoring.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles