BSI C5 Cloud Certification: A Guide for Public Authorities

Resilience, Security, Sovereignty Series 20th Feb 2026 Updated: 27th Aug 2026
BSI C5 Cloud Certification: A Guide for Public Authorities

Updated August 2026: the BSI published C5:2026 in late March 2026. It adds criteria for container management, tenant isolation, confidential computing, post-quantum cryptography and supply-chain security, and aligns the catalogue with ISO 27001:2022, NIS2 and the European EUCS scheme. Attestations with a reference date or audit period ending on or after 1 June 2027 will be measured against C5:2026 — plan the transition now.

What is BSI C5?

BSI C5 (Cloud Computing Compliance Criteria Catalogue) is the German standard for cloud security, developed by the Federal Office for Information Security (BSI). It defines minimum requirements for cloud services and is effectively mandatory for the public sector, for health data under § 393 SGB V, and increasingly for any organisation that has to evaluate cloud suppliers under NIS2.

Is cloud migration for the public sector possible without BSI C5? It’s risky. Tenders for cloud migration usually demand it, and the procurement process for cloud service providers verifies the attestation. Strictly speaking there is no “C5 certification” — C5 is attested by an auditor under IDW PS 951 / ISAE 3000. The market uses both terms; in tenders, ask for a “C5 Type 2 attestation”.

The Structure of BSI C5

BSI C5 comprises 17 requirement domains, from organisation to incident management. Each domain contains specific controls that must be demonstrated.

The 17 Domains at a Glance:

Information Security Organization, Security Policies, Human Resources, Asset Management, Physical Security, Operations Security, Identity and Access Management, Cryptography, Communication Security, Portability and Interoperability, Procurement and Development, Supplier Relationships, Security Incident Management, Compliance, Data Protection, Product Security, Interoperability.

Type 1 vs. Type 2 Attestation

BSI C5 has two attestation types, and the difference is important.

Type 1 Attestation

This assesses the appropriateness of the controls at a specific point in time.
– Are the controls designed?
– Are they implemented?

Type 2 Attestation

This assesses the effectiveness of the controls over a period of at least six months.
– Do the controls work?
– Are they being followed?

For public authorities, a Type 2 attestation is usually required. It offers more assurance and demonstrates continuous compliance.

Quick Checklist: BSI C5 Readiness

DomainCheckpointStatus
OrganizationISMS Established
PoliciesSecurity Policies Documented
PersonnelAwareness Training Conducted
AssetsInventory Complete
AccessIAM Implemented
CryptographyEncryption Active
LoggingLogging Enabled
IncidentProcess Defined

To-Do List for BSI C5 Attestation

  1. Month 1: Conduct a gap analysis.
  2. Month 2: Create an action plan.
  3. Months 3-6: Implement controls.
  4. Month 7: Perform an internal audit.
  5. Month 8: Conduct an external pre-audit.
  6. Months 9-10: Undergo the Type 1 audit.
  7. Months 11-16: Operational phase.
  8. Month 17: Undergo the Type 2 audit.

The Path to Attestation

Becoming BSI C5 compliant is a project. It requires planning, resources, and expertise.

Step 1: Gap Analysis

Where do you stand today? Which controls are missing? IT baseline protection consulting helps with the assessment. The gap analysis shows the way forward.

Step 2: Action Planning

  • What measures are necessary?
  • In what order? With what budget?
  • Who owns each measure, and when is it due?

Step 3: Implementation

  • Controls are introduced
  • Processes are established
  • Documentation is created
  • The BSI-compliant cloud security concept is developed

Step 4: Audit

An auditor conducts the review. The controls are tested. Evidence is collected. The attestation is issued. We cover this phase in detail in Preparing for a BSI C5 Audit: Practical Tips for the Public Sector.

Cloud Providers and BSI C5

Major cloud providers like Azure, GCP, and AWS hold BSI C5 attestations. But that’s not enough to claim that using them makes you compliant — quite the opposite. Because of the shared responsibility model, you still need to implement the corresponding user-side controls and operate them correctly. Only then can you be C5-compliant.

Azure migration and GCP migration must consider BSI C5. An Azure Landing Zone and a GCP Landing Zone should incorporate BSI C5 controls from day one. The Cloud Adoption Framework helps with this.

Insight42 BSI C5 Services

We guide public authorities and cloud providers to BSI C5 compliance, from gap analysis to the audit. We deliver the BSI-compliant cloud security concept and its technical implementation from a single source — with experience in BSI C5 and IT-Grundschutz projects for the public sector, and continuous-compliance managed services after the attestation.

Become BSI C5 compliant. See our BSI C5 Beratung (German) or contact us to book a C5 readiness call.