BSI C5 - CLOUD COMPUTING - ATTESTATION

The German trust mark every serious cloud will eventually need

Proks Certification compliant C5 badge with a checkmark and yellow border.

Your German healthcare prospect asks where your data lives. You say “Frankfurt.” They ask which BSI C5 controls you’ve attested to. You blink - and they send a calendar invite to “revisit in Q3.” Welcome to the German cloud market, where C5 went from differentiator to default, and where July 2024 turned it into law for an entire sector.

Proks Certification compliant C5 badge with a checkmark and yellow border.
75%

Controls shared with ISO/IEC 27001:2022 Annex A

121

Mandatory controls in the BSI catalogue

17

Security domains they are grouped into

6 mo

Type 2 operational observation period

1

THE CATALoGUE

What BSI C5 actually is

A cloud-specific compliance
catalogue. An attestation,
not a certificate.

In the German cloud market, C5 went from differentiator to default - and the signature on the cover matters as much as the controls inside it.

Published by the Bundesamt für Sicherheit in der Informationstechnik (BSI), C5 is a cloud-specific catalogue of 121 mandatory controls across 17 security domains, layered on top of ISO/IEC 27001:2022, the Cloud Security Alliance CCM and IT-Grundschutz. The current catalogue dates from its 2020 revision.

It is an attestation, not a certificate, and comes in two flavours: Type 1, a point-in-time snapshot of control design, and Type 2, which proves operational effectiveness across a 6-month observation period - the only one regulated buyers accept. Attestations carry a three-year validity with annual re-attestation typical. Auditors must be qualified, and the audit is performed by an accredited assurance provider.

2

THE FIT

Who actually needs this

C5 stops being a “later” problem the moment one of these describes you.

01
You sell cloud services to German healthcare.

Since 1 July 2024, §393 SGB V requires a C5 attestation - or an equivalent - for cloud providers serving the healthcare sector. There is no optional reading of this paragraph.

02
You are a cloud provider selling to BaFin-regulated buyers.

Banks, insurers and fintechs increasingly treat C5 as a tighter regional standard than ISO/IEC 27001:2022 alone - especially after the DORA wave.

03
You sell cloud to the German public sector.

Federal and state procurement increasingly treats C5 as baseline, with BSI’s IT-Grundschutz as the next layer up.

04
You compete with AWS, Azure, IBM and Google in Germany.

They all carry C5 attestations. When buyers compare side-by-side, procurement teams notice when you don’t.

05
You already have ISO/IEC 27001:2022 and want to lock the German market.

Roughly 75% of C5 controls overlap with ISO/IEC 27001:2022’s Annex A - one evidence pool, two outputs.

If none of these describe you - wait. If even one does - yesterday was the best time to start.

3

THE PAYOFF

What you actually get from an attestation

We could write four paragraphs of marketing copy - instead:

I.

Win healthcare cloud contracts. A direct unlock of §393 SGB V-regulated buyers - a market currently scrambling to find compliant suppliers.

II.

Compete with hyperscalers on equal compliance footing. When buyers compare certifications side-by-side, you appear in the same row AWS and Azure do.

III.

Cover ISO/IEC 27001:2022 + C5 in one audit. Our “One Audit” approach: ~75% control overlap, one evidence pool, two formal outputs, a dramatically lower combined cost.

IV.

De-risk procurement reviews. German compliance teams treat C5 as the gold standard for cloud security. Replace 30-question security follow-ups with a single attestation report.

V.

Build the foundation for BSI IT-Grundschutz. If the German public sector is your next market, C5 is the natural bridge.

4

THE STRUCTURE

121 controls, 17 domains - layered on three frameworks

C5 doesn’t reinvent cloud security; it consolidates it. The catalogue sits on top of three established frameworks, which is exactly why an existing ISO/IEC 27001:2022 programme carries so much of the load.

C5 IS LAYERED ON TOP OF:

01
ISO/IEC 27001:2022

The internationally recognised information-security management baseline C5 extends.

02
Cloud Security Alliance CCM

The Cloud Controls Matrix - cloud-native control expectations folded into the catalogue.

03
BSI IT-Grundschutz

The German baseline-protection methodology that anchors C5 in national practice.

5

TYPE I & TYPE II

Two flavours - and only one convinces a regulated buyer

Both report against the same 121 controls. The difference is whether they capture a single moment or a stretch of real operations.

Type I

WHAT BUYERS ACCEPT

A snapshot - your controls are designed correctly as of a single specific date.

WHAT IT TESTS

Control design

PERIOD

A specific date

TRADE-OFF

Faster, cheaper

BUYER VIEW

less convincing to a serious buyer

Type II

WHAT REGULATED BUYERS ACCEPT

Operating effectiveness of your controls, observed across a 6 month window.

WHAT IT TESTS

Design + effectiveness

PERIOD

6 months

TRADE-OFF

Slower, pricier

BUYER VIEW

The one regulated buyers accept

6

WHO CAN ATTEST IT

Not every signature carries the same weight

BSI publishes the rules; the audit is performed by an accredited assurance provider whose auditors must meet real qualifications. Serious buyers - banks, hospitals, federal procurement - read the report carefully and notice the depth.

EXPERIENCE
3+ years

of IT audit experience at a public firm

OR CREDENTIAL
CISA

Certified Information Systems Auditor

OR CREDENTIAL
CISM

Certified Information Security Manager

OR CREDENTIAL
CRISC

Certified in Risk & Information Systems Control

7

ONE AUDIT - TWO OUTPUTS

Stack it with ISO/IEC 27001:2022 and assemble the evidence once

Because C5 is layered directly on ISO/IEC 27001:2022, roughly 75% of its controls overlap with ISO/IEC 27001:2022’s Annex A - the same evidence, presented as a different report. Our “One Audit” approach runs them together from a single evidence pool, producing two formal outputs at a dramatically lower combined cost.

And C5 is rarely the last step. If the German public sector is your next market, BSI IT-Grundschutz is the natural bridge - and the same ISO/IEC 27001:2022 foundation feeds SOC 2, ISO/IEC 27017 and ISO/IEC 27018 for international buyers. One coordinator across the whole engagement.

WHAT ONE EVIDENCE POOL CAN FEED

ISO/IEC 27001:2022

BSI IT-Grundschutz

ISO/IEC 27017

ISO/IEC 27018

CSA CCM

SOC 2

DORA

GET IN TOUCH

Start your application process
now

Stop struggling with paperwork. Experience a streamlined, digital audit process that moves as fast as you do.

8

FAQs

Clear answers, the same way we run an audit

Is C5 a certificate?

We already hold ISO/IEC 27001:2022 - does that help?

Who is allowed to perform the attestation?

Type I or Type II - which do we need?

Do we legally need C5?

How long does a C5 report stay valid?