BSI C5 · Cloud Compliance

BSI C5 Consulting: Gap Analysis, Readiness and Attestation Preparation

Insight42 prepares cloud providers for the C5 attestation and helps cloud customers — public authorities, KRITIS operators, regulated companies — implement the customer-side C5 criteria in their architecture in a verifiable way. Including the transition from C5:2020 to C5:2026.

Book a BSI C5 readiness call

C5:2026 is here — and the transition period is running

The BSI Cloud Computing Compliance Criteria Catalogue (C5) is the benchmark for the security of cloud services in Germany: in public-sector tenders, for health insurers and health data (Section 393 SGB V), for KRITIS operators and increasingly for every company that has to assess cloud suppliers. At the end of March 2026 the BSI published C5:2026: new criteria on container management, tenant separation, confidential computing, post-quantum cryptography and the supply chain, structurally aligned with ISO 27001:2022, NIS2 and the European EUCS scheme.

For providers this means: anyone attested against C5:2020 today must move their internal control system to C5:2026 in good time before the cut-off date (1 June 2027). For customers it means: the corresponding criteria — what you must deliver on your side of the shared responsibility model — become more concrete and more auditable.

We support both sides. Pragmatic, technically grounded and with the goal that your attestation or your evidence holds up with the auditor, the assessor and in procurement.

Two perspectives, two offerings

For cloud providers & SaaS companies

You need a C5 attestation (Type 1 or Type 2) because customers, tenders or supervisors require it — or you need to migrate from C5:2020 to C5:2026.

We deliver: Gap analysis, readiness program, setup and documentation of the internal control system, system description, environment information, pre-audit, support during the audit.

For cloud customers: public authorities, KRITIS, regulated companies

You use Azure, AWS, Google Cloud or a sovereign platform and must prove that your usage is C5-compliant — to internal audit, data protection, supervisors or the procurement office.

We deliver: Assessment of your providers’ C5 reports, implementation of the corresponding criteria in your landing zone and operations, control evidence, requirements catalogue for procurement.

Our BSI C5 services in detail

1. C5 gap analysis (2–3 weeks)

Comparison of your existing controls, processes and documentation with the 17 criteria areas of C5 — against C5:2020, C5:2026 or as a delta analysis for the transition. We assess the design and effectiveness of each control, not just its existence.

Result: Gap report per criterion with maturity level, risk assessment, effort estimate and prioritized action plan; decision paper for a Type 1 vs. Type 2 attestation and timeline.

2. C5 readiness program (3–9 months)

Closing the gaps: building or hardening the ISMS and the internal control system, technical implementation (identity & access, cryptography and key management, logging/monitoring, tenant separation, backup, incident processes, supplier management), policies, system description and environment information in the form the auditor expects.

Result: Audit-ready control system with evidence, control owners and RACI; automated evidence collection wherever possible.

3. Pre-audit & attestation support

Internal pre-audit following audit logic (IDW PS 951 / ISAE 3000), preparation of interviewees, preparation of evidence, support during the audit and follow-up on findings.

Result: Fewer findings, fewer re-audits, an attestation that customers and supervisors accept.

4. C5 for cloud customers: corresponding criteria

We read your providers’ C5 reports, identify the controls that sit with you (configuration, identities, keys, logging, data classification, business continuity) and implement them as code in your Azure, AWS, GCP or sovereign landing zone — verifiable and repeatable.

Result: C5 customer concept, implemented controls, evidence documentation for internal audit and supervisors. Closely linked to our sovereign cloud consulting.

5. Continuous compliance & managed services

After the attestation is before the attestation: policy-as-code, continuous compliance monitoring, drift detection, annual re-assessments — optionally as a managed service, so that the Type 2 audit period brings no surprises.

C5 together with ISO 27001, IT-Grundschutz and NIS2

Hardly any organization has only C5 on its plate. We build your control system so that one piece of evidence serves several requirements at once:

  • ISO 27001:2022 — C5:2026 is structurally aligned; an existing ISMS is the best starting point for the C5 readiness program.
  • IT-Grundschutz — for public authorities and public IT service providers we map C5 criteria to IT-Grundschutz modules (in particular OPS.2.2 Cloud Usage), see our article on ISO 27001 based on IT-Grundschutz.
  • NIS2 / NIS2UmsuCG — the risk management measures under Section 30 BSIG and the supply chain obligations can largely be evidenced with C5 controls; more in our NIS2 consulting.
  • GDPR — C5 covers data protection as a separate criteria area; we build the data protection impact assessment for cloud projects directly on it.

How a C5 project with us works

  1. Kick-off & scoping: Scope of the audit (services, locations, tenants), target version (C5:2020/C5:2026), attestation type, timeline, choice of auditor.
  2. Gap analysis: Interviews, document review, technical sampling; gap report and action plan.
  3. Implementation: Technical and organizational measures, documentation, evidence automation — in sprints, with visible progress per criteria area.
  4. Pre-audit: Internal review following auditor logic, interview training, remediation.
  5. Attestation & operations: Support during the audit; afterwards continuous compliance for the Type 2 period.

Why Insight42 for BSI C5

  • Technology and compliance from one source. We don’t just write policies — we configure identity, encryption, logging and landing zones so that each control actually works and evidence is created automatically.
  • Experience with BSI C5 and IT-Grundschutz in public-sector projects; familiar with procurement requirements, the DVC context and auditors’ expectations.
  • Independent of the auditor. We do not issue attestations ourselves and therefore have no interest in a “mild” pre-audit — we prepare you for the strict case.
  • German company, based in Ingolstadt. Documentation in German or English, German contract basis, European standards.

Frequently asked questions about BSI C5

C5 certification or C5 attestation — which is correct?

Formally there is no “C5 certification”. C5 is attested by an auditor through an audit under IDW PS 951 or ISAE 3000. The market uses both terms synonymously; in tenders you should require a “C5 attestation Type 2”.

Type 1 or Type 2?

Type 1 confirms the appropriateness of the controls at a reference date, Type 2 their effectiveness over a period (usually at least six months). Public authorities and KRITIS operators almost always require Type 2; Type 1 is a sensible intermediate step.

How long does it take to get a C5 attestation?

With an existing ISMS typically 6–12 months to Type 1, followed by the Type 2 audit period. Without an ISMS correspondingly longer. The gap analysis delivers a reliable timeline within 2–3 weeks.

What changes for us with C5:2026?

New or tightened criteria on container orchestration, tenant separation, confidential computing, cryptography (incl. post-quantum readiness) and the supply chain, as well as closer alignment with ISO 27001:2022 and NIS2. For audit periods ending on or after 1 June 2027, C5:2026 is the benchmark recommended by the BSI — the internal control system should be switched well before that. We deliver a C5:2020 → C5:2026 delta analysis for this.

We only use Azure/AWS — does that make us automatically C5-compliant?

No. The hyperscaler’s attestation covers its own area of responsibility. Configuration, identities, keys, logging and data classification are your responsibility and must be evidenced separately.

Where are you on the way to a C5 attestation?

In a 30-minute readiness call we clarify the scope of the audit, the target version and a realistic timeline — and whether a gap analysis is the right next step.

Book a BSI C5 readiness call

Why Insight42

  • Regulated-market focus: we work with enterprises and public-sector organizations in Germany and Europe, and design architectures aligned with BSI C5, NIS2 and GDPR.
  • End-to-end delivery: assessment, architecture, implementation and operations from one team — founded and led by Martin-Peter Lambert in Ingolstadt.
  • Engineers who ship: we build and operate our own products — Secretary42, Unimatrix-OI and InheritanceVault — and bring the same production discipline to client work.
  • Sovereignty by design: data residency, key custody (BYOK/HYOK) and a documented exit strategy are design inputs from day one.

About Insight42 · Growth & strategy hub · Talk to us