BSI C5 attestation for cloud providers: What it does, when it is mandatory
The BSI's C5 certificate is the standard for the security of cloud services in the German market. This article explains the structure, type 1 and type 2 testing, relationship to ISO 27001 and operational preparation as a provider and as a customer.
TheCloud Computing Compliance Criteria Catalog(C5) from the Federal Office for Information Security (BSI) has been the German reference work for security testing of cloud services since 2016 and was most recently fundamentally revised in 2020 (C5:2020). It contains 121basic criteriaand 17additional criteriain 17 areas, from information security organisation to personnel security, asset management, cryptography, operations, identity and authorisation management to compliance, data protection and emergency management. Providers prove that they meet the criteria with acertificatefrom an auditing company in accordance with ISAE 3000 (revised) or IDW PS 951.
This article is aimed at two target groups. Firstly, to cloud providers who require a C5 certificate as a marketing and award requirement, for example for public clients, banks according to BAIT or insurers according to VAIT. Secondly, to cloud customers who want to use a C5 attestation as part of their outsourcing control, their ISMS according to ISO/IEC 27001:2022 or their NIS 2 supply chain audit. We classify the types of exams, compare C5 with ISO 27001 and SOC 2, and show what thorough preparation of outsourcing documentation looks like.
The reading is designed as a practical guide, not as a legal opinion. Each statement is supported by reference to C5:2020 criteria, ISO standards or relevant regulatory circulars, so that you can understand and use the content in your own discussions with auditing, supervision and sales.
Key Takeaways
- The C5 certificate documents the effectiveness of a cloud provider's security measures, audited by an auditing firm in accordance with ISAE 3000.
- Type 1 checks the deadline, type 2 checks the effectiveness over a period of usually six to twelve months, which is mandatory for many supervisory authorities.
- C5 does not replace an ISO/IEC 27001:2022 certificate, but it complements it in a useful way, especially for public clients and KRITIS sectors.
Structure of the C5: 17 areas, 121 basic and 17 additional criteria
The C5:2020 is divided into 17 areas with a total of 121 basic criteria and 17 additional criteria. The areas largely correspond to the structure of an ISMS according to ISO/IEC 27001:2022 and cover organisation of information security (OIS), security policies and procedures (SP), personnel security (HR), asset management (AM), physical security (PS), operational security (OPS), identity and authorisation management (IDM), cryptography and key management (CRY), communications security (COS), portability and interoperability (PI), procurement, development and change of information systems (DEV), Control and monitoring of service providers and suppliers (SSO), security incident management (SIM), business continuity management (BCM), compliance (COM), data protection (DAT) and security requirements for mobile devices (MOB).
Each criterion consists of a requirement, a explanation and a reference to additions. The additional criteria cover special requirements, for example for government or particularly sensitive data. Complete coverage of all criteria is not mandatory; rather, the certificate documents which criteria were implemented and with what findings.
In terms of content, the C5 is based on international standards such as ISO/IEC 27001:2022, ISO/IEC 27017:2015 for cloud security, ISO/IEC 27018:2019 for cloud data protection, NIST SP 800-53 and ENISA Cloud Security Recommendations. Anyone who already operates an ISMS according to ISO/IEC 27001:2022 with the 93 controls from Appendix A structurally covers most of the C5. The BSI provides a direct mapping table in the appendix to C5:2020.
For preparation purposes, it is worth taking a well-founded inventory of the existing measures along the 17 areas, supplemented by a gap analysis with defined owners, deadlines and audit evidence. If you maintain this in a platform with a versioned list of measures, you avoid redundant Excel maintenance and can start audit communication in hours instead of weeks.
Type 1 and Type 2 testing: cut-off date versus effective period
The C5 attestation has two types of examinations that are taken from the world of auditing. Type 1 confirms on a deadline that the measures described are designed appropriately to achieve the control objectives. It is a design review. Type 2 also confirms that the measures were implemented effectively over a defined period of time, usually six to twelve months. To do this, the auditing company takes samples from the ongoing operation.
In practice, this means: A type 1 certificate is often used as an entry point for young cloud providers or new products in order to create a marketing basis. A type 2 certificate is regularly the minimum requirement for awarding contracts by public clients, for outsourcing management according to BAIT or VAIT, and for industries with high availability and confidentiality requirements. The extension takes place annually; a gap in the attestation period regularly leads to discussions with supervisors and clients.
The audit itself is divided into preparation (risk and materiality analysis, scoping, definition of the system description), design test, effectiveness test, report and attestation. The effectiveness test is carried out through walkthroughs, observations, surveys and samples from the IT and organisational processes. Those who document their processes clearly and file evidence in an audit-proof manner will go through the audit much more quickly. The auditor calls, the evidence is ready. An overview of ISO/IEC 27001:2022 as a basis can be found at civac.de/news/iso-27001-2022-übergang-oktober-2026.
It is important for practice to deal with adjustments during the examination period. Anyone who only tightens up measures two weeks before the deadline has no effective period, which produces findings and reservations. Thorough preparation plans changes to measures at least six months before the attestation period.
C5, ISO/IEC 27001, SOC 2: Which standard applies when
A common misconception: C5 is a competitor to ISO/IEC 27001:2022. In fact, both standards are complementary. ISO/IEC 27001:2022 certifies the management system (ISMS) as a framework that includes risk management, statement of applicability (SoA), 93 controls from Annex A and continuous improvement. The C5 attestation, on the other hand, confirms the implementation of specific measures in a cloud service on a specific date or over a period of time, audited by an auditing firm.
SOC 2 (System and Organisation Controls) is the US counterpart according to AICPA standards, is based on the Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy) and follows a similar logic with Type 1 and Type 2 reports. In practice, many global providers comply with SOC 2 and C5 in parallel, as both standards are expected by different customer groups. For German public clients and KRITIS sectors, C5 is typically the relevant certificate.
In practice, it is worth having an integrated measures matrix that contains the ISMS controls from ISO/IEC 27001:2022 Annex A, C5 criteria, SOC 2 Trust Services Criteria and sectoral requirements (BAIT, VAIT, KRITIS obligations, NIS-2) in one list merges. If you maintain the sources and audit evidence centrally for each control, you can significantly reduce the amount of work you do. The CIVAC platform with 490 ready-to-use audit templates supports exactly this mapping and makes audit communication reproducible.
For operational implementation, a statement of applicability (SoA) is recommended, which maps each control to C5 criteria, SOC 2 trust criteria and sectoral obligations. This file is maintained once and read by different audits in different perspectives, which significantly reduces the effort for the audit.
It should also be noted the role of the BSI IT-Grundschutz, which can be binding for federal and state authorities and whose components should be included in the C5 mapping matrix when addressing public clients.
When do you as a cloud provider need a C5 certificate?
A C5 certificate is not generally required by law, but is in fact a requirement for many market segments. Public clients regularly require it in tenders for IT procurement, often as a minimum requirement in conjunction with German data residency and a certified ISMS. BAIT (banking supervisory requirements for IT) and VAIT (insurance supervisory requirements for IT) require appropriate outsourcing control, which in practice is only served with a current C5 type 2 certificate or equivalent proof.
NIS-2 further exacerbates the situation. The NIS-2 Directive (Directive (EU) 2022/2555) obliges essential and important institutions to manage supply chain security, including cloud service providers (Art. 21 Para. 2 lit. d NIS-2). Cloud providers without a demonstrable level of security effectively lose access to these customers. The approximately 29,500 companies in Germany affected by NIS 2 will systematically go through their outsourcing documentation over the next few years and demand evidence.
For the cost side: An initial C5 test typically costs between 80,000 and 350,000 euros, depending on the size and complexity of the cloud service, and the annual extension slightly less. There are also internal expenses for preparation, hardening of measures, documentation and monitoring of the test. The CIVAC platform reduces internal effort because audit templates, action lists and reporting lines are already standardised.
In addition, DORA (Regulation (EU) 2022/2554) specifies requirements for the resilience of ICT third-party providers in the financial sector, which will apply from January 2025. Cloud providers who serve financial customers combine C5 with DORA-compliant contractual and reporting obligations in order to do justice to both worlds.
In practice, providers should maintain a compliance heatmap document that clearly presents market requirements per segment (public sector, banks, insurers, industry, healthcare) and the required attestations. This makes it possible to understand from a sales perspective which effort opens up which market access.
Preparation as a provider: system description, measures, samples
Preparation as a cloud provider follows a clear path. Step one is the System Description: a detailed description of the cloud service, its components, interfaces, person roles, locations and data flows. It is created by the provider and checked by the auditing company for consistency with the 17 areas. Step two is the risk and materiality analysis, which identifies the relevant risk and the assigned controls for each criterion.
Step three is the hardening of measures. Here, gaps to the C5 requirement are closed, configurations are adjusted, authorizations are revised and emergency plans are supplemented. Step four is the evidence collection: logs, tickets, training records, tests, reviews. A versioned file with a time stamp and person responsible is mandatory. Step five is accompanying the effectiveness test with walkthroughs, samples and surveys.
We see four stumbling blocks most often in practice: firstly, unclear escalation and reporting lines between cloud operations, information security and data protection, secondly, missing or incomplete order processing contracts with sub-service providers, thirdly, incomplete personnel security (HR onboarding, background checks, training), fourthly, weak emergency and BCM tests without documented effectiveness. Anyone who has these four building blocks in the workspace, with owner, deadline and proof, will be much more relaxed in effectiveness tests. Audit-proof, documented, C5-proof.
Experienced providers maintain the system description as a versioned document with clear boundaries between platform, service and sub-service providers. An unclear demarcation creates additional effort in the audit because controls have to be assigned multiple times or it remains unclear who is responsible for which measure.
Successful audit runs work with an internal Audit Committee that reviews open measures on a weekly basis, addresses owners and manages escalations. Experience has shown that without this cadence there is a loss of efficiency because measures are only processed shortly before the deadline.
Outsourcing control as a customer: How to read and use a C5 certificate
As a cloud customer, you use the provider's C5 certificate as part of your own outsourcing control. Three evaluation steps are important. Firstly, the Scope: Which cloud services, which locations, which interfaces are included in the system description? An attestation for a storage service does not automatically apply to adjacent identity services. Secondly, the reporting period and the audit type: type 1 or type 2, which months are covered, are there gaps to the current date?
Thirdly, the exceptions and reservations: A C5 certificate can show criteria as not implemented or as an exception, for example because they are not applicable from the provider's perspective. You must evaluate these exceptions as part of your risk and outsourcing management. If a criterion is critical for your use case, you must implement compensating controls or persuade the provider to implement them.
Operationally, cloud customers should maintain an outsourcing file per provider, with a contract, AVV, C5 certificate (current version in each case), risk and materiality analysis, emergency and exit plan, measures for residual risks and an annual effectiveness assessment. CIVAC provides the swap file as a module in the workspace, with reminders for annual updates and an audit-proof storage of the C5 versions. An overview of the role of the Information Security Officer can be found on the role pages.
Anyone who maintains an outsourcing register according to BAIT 8.1 or VAIT links the provider's C5 certificate with their own materiality assessment, the contract documentation, the emergency and exit plans as well as the ongoing risk assessment. This link is the most desired view in the supervisory audit.
A customer who negotiates with the provider about a right-to-audit ideally defines the scope, frequency, people and confidentiality in advance. A law that is formulated too openly creates discussions, a law that is formulated too narrowly creates compliance gaps in your own outsourcing management.
C5 and NIS-2: Supply chain security as a new driver
The NIS 2 Directive (Directive (EU) 2022/2555) and its implementation into German law via the NIS2UmsuCG require that essential and important institutions have documented risk management that explicitly includes supply chain security (Art. 21 Para. 2 lit. d). Cloud providers that provide services for such institutions must have demonstrably implemented their security measures and work in a compatible manner with the NIS 2 reporting channels in the event of an incident.
In practical terms, this means: A C5 Type 2 attestation is an established method of demonstrating supplier security to an institution subject to NIS 2. It does not replace your own risk assessment, but provides an audit-proof basis. In addition, there is 24-hour early warning and 72-hour follow-up notification in the event of significant security incidents according to BSIG. Cloud providers must be able to inform their customers within this period, with template texts, contact points and registration certificates.
CIVAC integrates the NIS 2 reporting paths as a guided workflow that runs parallel to the GDPR reporting obligation according to Art. 33. Deadline begins as soon as we become aware of it. Anyone who manages both paths in one platform avoids double reporting and gaps in supervisory communication. You can find out more about the context at civac.de/news/nis-2-umstellung-deutschland-2026.
The interface to the GDPR is also important. A cloud provider must be able to transparently present data transfers in the event of an incident, including third country references, sub-service providers and data categories. Anyone who only delivers PDFs here is losing valuable time. Machine-readable data transfer in order processing is best practice.
For KRITIS sectors, there are additional BSIG obligations, which, depending on the sector, place special requirements on availability and incident management. The integration with the C5 certificate should be explicitly stated in the system description.
For incident communication, it is worthwhile to have a jointly coordinated Crisis Playbook that contains language regulations, escalation paths and template texts. Anyone who writes this playbook only after the incident loses the first few hours that are crucial for supervisory communication.
Avoid practical errors: Typical findings in C5 exams
Five topics that recur in C5 exams are striking and which providers can easily avoid with thorough preparation. Firstly,identity and authorisation management: missing joiner-mover-leaver processes, unused service accounts, missing periodic authorisation reviews. Secondly,cryptography and key management: key rotations without proof of effectiveness, long certificate lifetimes, missing hardware security modules for high-security services.
Thirdly,vulnerability and patch management: Incomplete inventory, lack of risk prioritization of vulnerabilities, slow patch cycles without documented justification. Fourth,sub-service providers: order processing contracts without a TOM appendix, lack of background checks on sub-providers, unclear responsibility matrix in multi-cloud constellations. Fifth,Business Continuity: BCM tests without proof of effectiveness, lack of restart sequence, emergency roles not updated after reorganizations.
Pragmatic preparation includes a mock exam with real samples six to nine months before the first type 2 attestation. Anyone who goes through this mock test with a documented list of measures typically concludes 80 percent of the later findings in advance. The effort is worth it because a certificate that is not issued is relevant to reputation and sales. CIVAC offers the audit templates for exactly this mock run, including effectiveness testing workflow and reporting function to management.
There are also organisational issues such as delineation of roles and responsibilities in multi-cloud constellations, maintaining current data flow diagrams and the management of exception approvals. Anyone who makes exceptions without a time limit and effectiveness assessment creates the impression of uncontrolled drift in the audit, which leads to reactions in the report notes.
In the report notes, auditing firms also regularly address topics such as the depth of training of employees, the maturity of threat modelling and the effectiveness of penetration tests. Anyone who reduces this to annual compulsory tests risks reservations. A continuous effectiveness view shows providers and assessors in a more mature light.
Afindings tracking dashboardhelps in practice, which displays all findings from internal audits, penetration tests and external tests with status and effectiveness assessment.
From the audit run to the verifiable certificate: How CIVAC supports
A C5 attestation is not created in the week of the exam, but in the twelve months beforehand. CIVAC sees itself as a compliance platform and officer-as-a-service and provides the operational layer that is necessary for sound exam preparation. The workspace contains action lists, audit templates, training certificates, reporting paths and reporting lines, so that you can access the current status of each C5 criterion in minutes. The data resides in Germany, authentication takes place via SSO or SAML.
Others run compliance like a filing cabinet. We run it like software. Licence the workspace for your internal representatives, or have our representatives order it. The dual approach is deliberately kept open because cloud providers of different sizes require different depths, from start-ups with their first Type 1 certificate to established providers with an annual Type 2 run for several services. The platform's SLA is two business days, measured from receipt of the request.
Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de. We schedule a 30-minute initial consultation in which we reflect your level of maturity against the 17 C5 areas, discuss the materiality analysis and suggest three next steps. You will receive a written proposal with a task list, timeline and transparent prices, in German and with EU data residency, no later than the next working day.
Beyond the pure platform, we provide methodology. You will receive a mapping matrix C5-ISO-SOC-2-BAIT-VAIT, a prepared system description template, a SoA template and training modules for the operational teams. This shortens the time-to-audit from quarters to weeks.
Proven providers know that the second and third wave of audits will be easier as soon as the mapping matrix is in place and the effectiveness period runs smoothly. This is exactly what our templates, workflows and reporting lines are aimed at.
FAQ
What differentiates the C5 certificate from an ISO/IEC 27001:2022 certification?
ISO/IEC 27001:2022 certifies the management system (ISMS) as a framework with risk management, declaration of applicability and 93 controls from Annex A. The BSI's C5 certificate confirms the implementation of specific measures in a cloud service, audited by an auditing company according to ISAE 3000 or IDW PS 951. Both standards are complementary. For German public clients and KRITIS sectors, the C5 certificate is typically the relevant document.
What is the difference between a Type 1 and a Type 2 attestation?
Type 1 checks on a specific date whether the controls are appropriately designed. Type 2 additionally checks whether the controls were operated effectively over a period of typically six to twelve months. Type 2 is standard for regulated sectors such as banks according to BAIT, insurers according to VAIT and for many public clients. Type 1 is often used as an entry point, for example for young cloud services.
How many criteria does the C5:2020 include?
The C5:2020 contains 121 basic criteria and 17 additional criteria in 17 areas. The areas range from organisation of information security to personnel security, identity and authorisation management, cryptography, operations, compliance and data protection to security on mobile devices. The additional criteria cover special requirements for sensitive data categories and are not relevant for every cloud service, but must be documented in the scope.
Is a SOC 2 Type 2 report sufficient for German customers?
A SOC 2 Type 2 report according to AICPA standards is accepted by many international customers, but does not fully cover the C5 scope. German public clients, institutions subject to KRITIS and banks according to BAIT regularly expect an additional C5 certificate or require a mapping declaration. In practice, many global providers meet both standards in parallel because the cost difference is small compared to the loss in sales.
How much does a C5 certificate cost?
The costs depend on the size and complexity of the cloud service. An initial type 2 test typically costs between 80,000 and 350,000 euros, the annual extension slightly less. There are also internal expenses for preparation, hardening of measures and support. A well-founded mock test six to nine months before the race significantly reduces later findings and is a sensible investment. Platform-supported preparation reduces these internal costs.
How does a C5 attestation help with NIS 2 supply chain management?
NIS-2 obliges essential and important institutions to carry out risk management that explicitly includes supply chain security (Art. 21 Para. 2 lit. d). A C5 Type 2 attestation provides a verified basis to provide verifiable evidence of the security of a cloud provider. It does not replace the NIS 2 person's own risk assessment, but it significantly reduces the burden of justification to supervisory authorities and internal stakeholders.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.