Back to Cybersecurity

BSI C5 compliance checklist: how SaaS and cloud providers prepare for a C5 attestation

BSI C5 compliance checklist illustration: a red shield with a check mark over a gold circle, labelled C5:2026

Short answer: BSI C5 compliance means an independent auditor has tested your cloud service against the Cloud Computing Compliance Criteria Catalogue published by Germany's Federal Office for Information Security (BSI). To prepare, scope your service, map existing ISO 27001 or SOC 2 controls to the C5 criteria, close gaps, write the required disclosures, then choose a Type 1 or Type 2 attestation.

Related guides:

Key takeaways

  • C5 is not a certificate. It is an attestation report issued by an auditor under ISAE 3000, and German buyers read it much like a SOC 2 report.
  • A Type 2 attestation, which tests operating effectiveness over a period, is what most regulated German buyers expect. A Type 1 is a useful first step.
  • Beyond controls, C5 asks you to disclose facts about your environment, such as where data is processed and which jurisdictions apply, and to state which controls your customers must run themselves.
  • If you already hold ISO 27001 or a SOC 2 report, much of the control and evidence work carries over. The gaps tend to sit in transparency, government access requests, product security and portability.
  • Plan for a readiness phase before the audit window opens. Most delays come from unclear scope and missing evidence, not from the audit itself.

What is BSI C5, and who asks for it?

C5 (Cloud Computing Compliance Criteria Catalogue) is a set of security criteria for cloud services published by the BSI, Germany's Federal Office for Information Security, and it has become the reference baseline German public sector and regulated buyers use to judge cloud providers.

The catalogue defines what a secure cloud service should look like and how an auditor should test it. It covers familiar ground such as personnel, asset management, physical security, operations, identity and access management, cryptography, secure development, supplier management, incident management and business continuity. It also goes further than many frameworks on topics that matter to German and European buyers, including how a provider handles investigation requests from government agencies and how it supports customers with product security information.

The BSI revises C5 periodically. In 2026 the BSI published C5:2026 as the successor to C5:2020, which many existing attestations still use. Before you start, confirm with your auditor which edition your attestation will use, because criteria wording and scope can change between versions.

Who asks for it? In practice you will see C5 requests from:

  • German federal, state and municipal public sector bodies procuring cloud services
  • Healthcare organizations, insurers and HealthTech buyers in Germany. Since 1 July 2024, § 393 SGB V requires healthcare providers and statutory health insurers to process health and social data in the cloud only with a current C5 attestation (or an equivalent certification) from the cloud provider, so HealthTech vendors should expect the question.
  • Banks, insurers and other regulated enterprises that use C5 as evidence in their own outsourcing and vendor risk reviews
  • Large German enterprises that prefer a domestic, BSI-backed benchmark

For an SMB SaaS vendor, the trigger is usually a single deal where a procurement questionnaire asks for a current C5 report.

C5 Type 1 vs Type 2: which attestation do you need?

Most buyers ultimately want a Type 2 attestation, but a Type 1 is a sensible first milestone when a deal cannot wait for a full observation period.

C5 attestations are performed by independent auditors, typically audit firms experienced in assurance engagements, under the international assurance standard ISAE 3000 (Revised). The structure will feel familiar if you know SOC reporting.

C5 Type 1 C5 Type 2
What the auditor tests Whether controls are suitably designed and implemented Whether controls are designed and operated effectively
Point in time or period A specific date An observation period
Evidence depth Policies, configurations, walkthroughs Samples across the period, such as tickets, logs, reviews and approvals
Buyer perception Shows intent and design maturity Shows controls actually work over time
Typical use First report, fast answer for procurement Ongoing, renewed report that satisfies regulated buyers

Auditors can also combine C5 with a SOC 2 engagement so the same testing supports both. If you already run SOC 2, ask your auditor early whether a combined approach is available. Our explainer on what a SOC report is covers the Type 1 and Type 2 logic in more depth.

Basic criteria, additional criteria and what you must disclose

C5 separates a mandatory baseline from optional higher requirements, and it expects you to be transparent about your environment and the controls your customers own.

Basic criteria are the baseline every attested cloud service must meet. An attestation against the basic criteria is what most buyers mean when they say "we need C5."

Additional criteria describe a higher level of security for services with elevated protection needs. You can choose to include them in scope. Doing so strengthens your position with buyers who handle especially sensitive data, but it adds testing effort, so decide based on who you sell to.

Complementary customer criteria (sometimes referred to as corresponding criteria) describe controls your customers must operate for the overall system to be secure. Examples include managing their own user accounts, configuring multi-factor authentication for their tenants, and protecting API keys issued to them. Documenting them shows where your responsibility ends. If shared responsibility is new to your team, our guide to ISO 27017 cloud security controls explains it well.

Environment and system description disclosures. C5 requires a description of the cloud service and information about its surrounding conditions. Expect to document items such as:

  • the locations where customer data is stored and processed, including subservice providers like your hosting platform
  • the jurisdictions and applicable law that govern the service
  • how you respond to disclosure requests from government authorities
  • existing certifications and attestations
  • availability commitments and how the service is delivered

Public sector buyers often read these disclosures first, so write them precisely and keep them current.

Can you reuse ISO 27001 and SOC 2 work for C5?

Yes. A large share of C5 criteria overlap with ISO 27001 Annex A controls and the SOC 2 Trust Services Criteria, so an existing program gives you a strong head start.

Area ISO 27001 SOC 2 C5 focus to check
Governance and risk ISMS, risk assessment, Statement of Applicability Control environment, risk assessment Largely reusable
Access control Annex A access controls Logical access criteria Reusable, confirm privileged access evidence
Operations and logging Operations security controls Monitoring and system operations Reusable, check log retention and review records
Supplier management Supplier relationship controls Vendor management Add subservice provider disclosures
Transparency Limited System description Environment parameters and data location detail
Government access requests Not a specific focus Not a specific focus Usually a new policy and procedure
Product security and portability Partly covered Partly covered Often needs new documentation for customers

Build one control library and map each control to every framework it satisfies, so a single access review or vulnerability scan counts as evidence for ISO 27001, SOC 2 and C5 at once. For a deeper view of how the two most common frameworks relate, see SOC 2 vs ISO 27001, and if you are starting from zero, the ultimate ISO 27001 guide walks through building the ISMS foundation that C5 expects.

The C5 readiness checklist

Work through this checklist in order. Each item should end with a named owner and stored evidence.

1. Scope and commitments

  • Identify the services in scope and the buyers driving the request
  • Confirm which C5 edition your auditor will use
  • Decide on basic criteria only, or basic plus additional criteria
  • Decide on Type 1 first, Type 2 directly, or a combined C5 and SOC 2 engagement
  • Select an auditor experienced with C5 and agree on the timeline

2. System description and disclosures

  • Write the service description: components, infrastructure, data flows and interfaces
  • List all subservice providers and state whether each is included in scope or carved out
  • Document data storage and processing locations
  • Document jurisdiction and applicable law
  • Describe your process for handling government disclosure requests
  • List current certifications and attestations

3. Gap assessment

  • Map existing controls from ISO 27001, SOC 2 or internal policies to each C5 criterion
  • Mark each criterion as met, partially met or missing
  • Prioritize gaps and assign remediation owners and deadlines

4. Policies and procedures

  • Information security policies reviewed and approved
  • Procedure for investigation and disclosure requests from authorities
  • Secure development and change management procedures
  • Incident management, including customer notification
  • Business continuity and disaster recovery plans, with test records
  • Customer-facing documentation for product security, data portability and exit

5. Technical controls and evidence

  • Identity and access management, including MFA and periodic access reviews
  • Encryption in transit and at rest, with documented key management
  • Logging, monitoring and alerting with defined retention
  • Vulnerability management and penetration testing
  • Backup and restore testing
  • Hardened configurations for your cloud environment (see our overview of cloud security controls)

6. People and suppliers

  • Security awareness training completed and tracked
  • Background checks and onboarding or offboarding records, where lawful
  • Supplier risk assessments and contracts for subservice providers
  • Review of your hosting provider's own C5 or equivalent reports

7. Complementary customer criteria

  • List the controls customers must operate
  • Publish them in customer documentation and onboarding materials

8. Audit readiness

  • Run an internal pre-audit or readiness review against the full criteria set
  • Organize evidence by criterion so the auditor can request samples easily
  • For Type 2, confirm controls have operated consistently before the observation period starts

How long does a C5 attestation take?

It depends mainly on your starting point: a team with a mature ISO 27001 or SOC 2 program can move far faster than one building controls from scratch.

The main timeline factors are:

  1. Existing framework coverage. Reusing an ISMS or SOC 2 control set shortens gap assessment and remediation.
  2. Scope size. More services, regions and subservice providers mean more description work and testing.
  3. Basic vs additional criteria. Additional criteria increase remediation and fieldwork.
  4. Type 1 vs Type 2. A Type 2 adds an observation period on top of readiness work.
  5. Auditor availability. Experienced C5 auditors book up, so engage early.
  6. Evidence maturity. Scattered screenshots and spreadsheets slow everything down. Continuous, organized evidence speeds up readiness and fieldwork.

A common path for SMB vendors is to complete readiness, issue a Type 1 to unblock active deals, then move into a Type 2 observation period and renew annually after that.

How SecureSlate helps

SecureSlate gives you a single control library mapped across frameworks such as ISO 27001, SOC 2 and HIPAA, so you can map and track the C5 criteria alongside the controls you already run instead of starting a separate program. Automated evidence collection from your cloud and SaaS stack keeps access reviews, configurations and logs current, and audit-ready exports make it easier to hand your auditor organized evidence.

Policy templates help you close documentation gaps, while the risk register and vendor risk management tools cover supplier and subservice provider oversight. A trust center lets you share your security posture and reports with German buyers once your attestation is complete.

Start your free SecureSlate trial

FAQ

Is C5 a certification?

No. C5 results in an attestation report from an independent auditor, not a certificate. Buyers review it much as they would a SOC 2 report.

Is BSI C5 mandatory?

It depends on who you sell to. Many German public sector and regulated buyers require or strongly prefer it in procurement, and § 393 SGB V requires it, or an equivalent certification, for cloud processing of health data by German healthcare providers and statutory health insurers. For other buyers it is a competitive advantage rather than a legal requirement.

Do I need ISO 27001 before C5?

No, it is not a formal prerequisite. However, an established ISMS covers much of the governance, risk and control foundation C5 expects, so ISO 27001 or SOC 2 makes C5 readiness considerably faster.

Can non-German companies get a C5 attestation?

Yes. C5 applies to cloud services regardless of where the provider is based. Non-German providers must be especially clear in their disclosures about data location, jurisdiction and how they handle requests from government authorities.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

4.9(409 reviews)

Keep reading

Sep 30, 2026 · Cybersecurity

AWS Foundational Technical Review: FTR Checklist and Prep Guide for SaaS Teams

Sep 30, 2026 · Cybersecurity

Cyber Essentials vs Essential Eight: UK and Australian Cyber Baselines Compared

Sep 29, 2026 · Cybersecurity

AI-Generated Code Security: How to Keep AI-Assisted Development Safe and Audit-Ready

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?