C5: Germany BSI Cloud Computing Compliance Guide
The Cloud Computing Compliance Criteria Catalogue (C5) is the German Federal Office for Information Security (BSI) standard for assessing the security of cloud services. C5:2020 defines minimum security requirements that cloud providers must meet to serve German government agencies and is increasingly expected by German enterprises. The standard has gained recognition across the European Union as a robust cloud security assessment framework — and for any cloud provider serious about the DACH market, C5 attestation has become a practical prerequisite.
What C5 Is and Who Issues It
C5 was developed by the BSI (Bundesamt für Sicherheit in der Informationstechnik), Germany's federal cybersecurity authority. First published in 2016 and substantially updated in 2020, C5 was designed specifically for the cloud computing context — addressing gaps that general frameworks like ISO 27001 leave open when applied to multi-tenant, shared-responsibility cloud environments.
A distinctive and practical feature of C5 is its transparency requirements. Cloud providers must disclose what the BSI calls "environmental parameters" — factual disclosures about data center locations, applicable legal jurisdictions, certifications held, subservice organizations, and technical infrastructure details. These disclosures appear on the face of the attestation report, enabling cloud customers to make informed risk decisions about the services they consume. This transparency model has influenced how other national cloud frameworks approach supplier disclosure.
Who Needs C5 Attestation
C5 is required for cloud services used by German federal agencies and is increasingly expected by German state governments and regulated industries. German financial institutions subject to BaFin (Federal Financial Supervisory Authority) oversight are expected to verify cloud provider security through third-party attestations, and C5 has become the de facto standard for satisfying that expectation.
Any cloud provider targeting the German public sector or enterprise market benefits significantly from C5 attestation. Major cloud providers including AWS, Microsoft Azure, and Google Cloud have obtained C5 Type 2 attestations, raising the bar for competitors entering the German market. For SaaS vendors selling into German enterprises, the question of C5 attestation increasingly appears in security questionnaires alongside SOC 2 and ISO 27001.
Key Requirements: The 17 Control Domains
C5:2020 includes 17 control domains with 121 basic criteria. Additional criteria apply when handling confidential or secret-classified data.
Organization of Information Security (OIS) establishes the governance foundation — policies, roles, responsibilities, and management accountability for cloud security.
Human Resources (HRS) covers personnel security including background screening, security awareness training, and management of employment changes.
Asset Management (AM) addresses identification, classification, and management of cloud assets including data, software, and hardware.
Physical Security (PS) requires protection of data centers against physical threats — access controls, environmental monitoring, and facility resilience.
Operational Security (OPS) is one of the most detailed domains, covering change management, capacity planning, malware protection, vulnerability management, and DevOps security practices.
Identity and Access Management (IDM) requires strong authentication, privileged access management, user lifecycle management, and access reviews.
Cryptography and Key Management (KRY) specifies encryption requirements for data in transit and at rest, and mandates robust key management procedures.
Communication Security (KOS) covers network security, segregation of customer environments, and secure communication protocols.
Procurement, Development, and Maintenance (PDM) addresses secure development lifecycle, third-party software risk, and vulnerability management in custom code.
Supplier Relationships (SS) requires cloud providers to manage their own supply chain — including subservice providers hosting data or providing infrastructure components.
Incident Response (SIM) mandates breach detection, response procedures, customer notification, and post-incident analysis.
Business Continuity (BCM) requires resilience planning, backup procedures, and disaster recovery capabilities aligned with customer SLAs.
Compliance and Reporting (COM) covers regulatory compliance, audit rights, and the transparency disclosures specific to C5.
Portability and Interoperability (PI) is unique to C5's cloud focus — requiring providers to support data export and service migration, preventing vendor lock-in.
The Assessment and Attestation Process
C5 assessments follow a structure similar to SOC 2 attestation, using the same ISAE 3000 auditing standard.
A Type 1 report evaluates the design adequacy of controls at a specific point in time. The independent auditor assesses whether the controls described are suitably designed to meet C5 criteria. Type 1 is faster and less expensive, but sophisticated cloud customers typically require Type 2.
A Type 2 report evaluates both design and operating effectiveness over a minimum six-month observation period. The auditor tests whether controls actually functioned as described throughout the period. This is the gold standard for enterprise and government customers.
The process begins with a gap assessment against all 17 domains. The provider implements required controls and environmental parameter disclosures. An independent auditor — typically a major audit firm or specialist cloud security assessor — conducts fieldwork including interviews, document review, and technical testing. The resulting attestation report, including the environmental parameters section, is then shared with customers under appropriate confidentiality terms.
Costs and Timeline
| Phase | Estimated Cost | Timeline |
|---|---|---|
| Gap assessment and preparation | $15K–$40K | 1–3 months |
| Control remediation | $10K–$80K | 1–4 months |
| Type 1 attestation | $20K–$60K | 1–2 months |
| Type 2 attestation (6-month period) | $40K–$120K | 6–8 months |
| Total Type 2 program | $50K–$250K | 4–12 months |
Organizations with existing ISO 27001 certification find significant overlap with C5, reducing incremental preparation effort substantially. The C5 domains that diverge most from ISO 27001 are the transparency/environmental parameters requirements and the portability domain — these require specific attention regardless of existing certifications.
Comparison with Related Frameworks
C5 maps closely to ISO 27001 (approximately 70% overlap) and to SOC 2 (approximately 65% overlap). Organizations with either existing certification can leverage their control libraries heavily when preparing for C5. The CSA Cloud Controls Matrix (CSA CCM) also maps well to C5, with approximately 60% conceptual alignment.
C5 operates alongside Spain's ENS as a national public sector cloud security framework within the European context. While both serve similar purposes for their respective markets, they are independent standards with different structures. An organization serving both German and Spanish government markets needs both attestations.
The CSA STAR certification provides international recognition that complements C5 attestation for cloud providers marketing across multiple regions. Unlike C5, STAR does not require German-law transparency disclosures — making the two complementary rather than substitutable for the German market.
How Automation Helps
Managing C5 evidence across 17 domains and 121+ criteria is operationally intensive. Automation reduces the manual burden dramatically, particularly for domains like OPS (operational security) and SIM (incident management) that require continuous evidence.
LowerPlane supports C5:2020 as part of its 50+ framework library. The platform maps your cloud environment's controls to specific C5 criteria, surfaces evidence gaps, and maintains a continuously updated control inventory that simplifies the auditor's fieldwork. With pricing starting at $4,000 per year and a free tier available, LowerPlane makes C5 readiness achievable without building a large dedicated compliance team. AuditXYZ rated LowerPlane 9.4/10 for multi-framework compliance automation.
For cloud security posture management, TigerGate maps cloud misconfiguration findings directly to C5 control domains — particularly useful for the OPS and IDM domains where cloud configuration drift is the most common audit finding.
Frequently Asked Questions
Is C5 mandatory for all cloud providers in Germany? C5 is mandatory only for cloud services used by German federal agencies. However, it has become a de facto market requirement for cloud providers targeting German enterprises and regulated industries. BaFin-regulated financial institutions and healthcare organizations subject to German data protection law increasingly require C5 attestation from their cloud suppliers.
How does C5 relate to EUCS — the EU's proposed cloud certification scheme? The European Union Cybersecurity Agency (ENISA) has been developing the EU Cloud Services Cybersecurity Certification Scheme (EUCS). C5 has been proposed as a reference model for the EUCS high security level. While EUCS finalization has taken longer than originally expected, C5 attestation is widely viewed as the strongest available signal of alignment with likely EUCS requirements.
Can we use our SOC 2 Type II report to satisfy C5 requirements? Not directly. While SOC 2 and C5 share significant structural similarities and control overlap, they are independent attestations. C5 requires specific environmental parameter disclosures and covers topics like portability that SOC 2 does not address. That said, a mature SOC 2 program provides an excellent foundation for C5 preparation, reducing the incremental gap significantly.
What is the minimum observation period for a C5 Type 2 report? The minimum observation period is six months. Most organizations target a 12-month period to align with calendar or fiscal years, though a six-month period is acceptable and faster for initial attestation.
Do all 17 domains apply to every cloud service? In most cases, yes. However, certain criteria within domains may not be applicable depending on the service model (IaaS, PaaS, SaaS) and the service scope. The auditor determines applicability and documents any not-applicable criteria with rationale in the report.