
Your German healthcare prospect asks where your data lives. You say “Frankfurt.” They ask which BSI C5 controls you’ve attested to. You blink - and they send a calendar invite to “revisit in Q3.” Welcome to the German cloud market, where C5 went from differentiator to default, and where July 2024 turned it into law for an entire sector.
Controls shared with ISO/IEC 27001:2022 Annex A
Mandatory controls in the BSI catalogue
Security domains they are grouped into
Type 2 operational observation period
1
Published by the Bundesamt für Sicherheit in der Informationstechnik (BSI), C5 is a cloud-specific catalogue of 121 mandatory controls across 17 security domains, layered on top of ISO/IEC 27001:2022, the Cloud Security Alliance CCM and IT-Grundschutz. The current catalogue dates from its 2020 revision.
It is an attestation, not a certificate, and comes in two flavours: Type 1, a point-in-time snapshot of control design, and Type 2, which proves operational effectiveness across a 6-month observation period - the only one regulated buyers accept. Attestations carry a three-year validity with annual re-attestation typical. Auditors must be qualified, and the audit is performed by an accredited assurance provider.
2
C5 stops being a “later” problem the moment one of these describes you.
Since 1 July 2024, §393 SGB V requires a C5 attestation - or an equivalent - for cloud providers serving the healthcare sector. There is no optional reading of this paragraph.
Banks, insurers and fintechs increasingly treat C5 as a tighter regional standard than ISO/IEC 27001:2022 alone - especially after the DORA wave.
Federal and state procurement increasingly treats C5 as baseline, with BSI’s IT-Grundschutz as the next layer up.
They all carry C5 attestations. When buyers compare side-by-side, procurement teams notice when you don’t.
Roughly 75% of C5 controls overlap with ISO/IEC 27001:2022’s Annex A - one evidence pool, two outputs.
3
We could write four paragraphs of marketing copy - instead:
Win healthcare cloud contracts. A direct unlock of §393 SGB V-regulated buyers - a market currently scrambling to find compliant suppliers.
Compete with hyperscalers on equal compliance footing. When buyers compare certifications side-by-side, you appear in the same row AWS and Azure do.
Cover ISO/IEC 27001:2022 + C5 in one audit. Our “One Audit” approach: ~75% control overlap, one evidence pool, two formal outputs, a dramatically lower combined cost.
De-risk procurement reviews. German compliance teams treat C5 as the gold standard for cloud security. Replace 30-question security follow-ups with a single attestation report.
Build the foundation for BSI IT-Grundschutz. If the German public sector is your next market, C5 is the natural bridge.
4
C5 doesn’t reinvent cloud security; it consolidates it. The catalogue sits on top of three established frameworks, which is exactly why an existing ISO/IEC 27001:2022 programme carries so much of the load.
The internationally recognised information-security management baseline C5 extends.
The Cloud Controls Matrix - cloud-native control expectations folded into the catalogue.
The German baseline-protection methodology that anchors C5 in national practice.
5
Both report against the same 121 controls. The difference is whether they capture a single moment or a stretch of real operations.
WHAT BUYERS ACCEPT
A snapshot - your controls are designed correctly as of a single specific date.
Control design
A specific date
Faster, cheaper
less convincing to a serious buyer
WHAT REGULATED BUYERS ACCEPT
Operating effectiveness of your controls, observed across a 6 month window.
Design + effectiveness
6 months
Slower, pricier
The one regulated buyers accept
6
BSI publishes the rules; the audit is performed by an accredited assurance provider whose auditors must meet real qualifications. Serious buyers - banks, hospitals, federal procurement - read the report carefully and notice the depth.
of IT audit experience at a public firm
Certified Information Systems Auditor
Certified Information Security Manager
Certified in Risk & Information Systems Control
7
Because C5 is layered directly on ISO/IEC 27001:2022, roughly 75% of its controls overlap with ISO/IEC 27001:2022’s Annex A - the same evidence, presented as a different report. Our “One Audit” approach runs them together from a single evidence pool, producing two formal outputs at a dramatically lower combined cost.
And C5 is rarely the last step. If the German public sector is your next market, BSI IT-Grundschutz is the natural bridge - and the same ISO/IEC 27001:2022 foundation feeds SOC 2, ISO/IEC 27017 and ISO/IEC 27018 for international buyers. One coordinator across the whole engagement.
ISO/IEC 27001:2022
BSI IT-Grundschutz
ISO/IEC 27017
ISO/IEC 27018
CSA CCM
SOC 2
DORA
Stop struggling with paperwork. Experience a streamlined, digital audit process that moves as fast as you do.
8