← ALL FRAMEWORKS

C5

Cloud Security

Issued by Federal Office for Information Security (BSI), Germany

C5 is a catalogue of baseline security requirements for cloud service providers published by Germany's BSI, evaluated through an independent auditor's report rather than a pass/fail certification. It covers organizational and technical controls across the cloud stack, plus disclosures on data location, jurisdiction, and subcontractors. C5:2020 remains the version currently governing assessments; BSI published a substantially revised C5:2026 catalogue in April 2026, but it doesn't become binding until June 1, 2027. Cloud providers selling to German enterprises and public-sector customers are the primary audience.

Get notified the moment C5 actually changes — reviewed by a human before it ever reaches you.

Get started free

Most recent update

major

BSI announced C5:2026, a new revision replacing C5:2020, first as a public community draft and final by end of March. It aligns with EUCS Substantial, incorporates CCM v4, ISO/IEC 27001:2022, and NIS2, adds new criteria (post-quantum cryptography, confidential computing, supply chain, container management, sovereignty), introduces a subcriteria structure with 'additional sharpen'/'additional complement' classifications, and adds machine-readable YAML output.

VIEW SOURCE ↗