C5 Attestation – Standards and Implementation Guidelines for Secure Cloud Services
The Cloud Computing Compliance Criteria Catalogue (C5) is an audit catalog developed by the Federal Office for Information Security (BSI) for cloud services. It defines minimum requirements for secure cloud systems and is aimed at professional cloud providers, their auditors, and customers.
Why is C5 relevant?
Section titled “Why is C5 relevant?”- First published in 2016, major revision in 2019
- Broad acceptance among large and small providers
- Guidance for risk management for cloud customers
- Legal obligation in the healthcare sector since 2024 (§ 393 SGB V)
Important for healthcare: Until June 30, 2025, a C5 Type 1 Attestation is sufficient. From July 1, 2025, a C5 Type 2 Attestation or equivalent standard will be mandatory.
The 17 Requirement Areas of the C5 Catalogue
Section titled “The 17 Requirement Areas of the C5 Catalogue”The current C5:2020 Catalogue is based on ISO 27001 and covers the following core areas:
Organizational Requirements
Section titled “Organizational Requirements”-
Information Security Organization
Planning, implementation, and continuous improvement of an information security framework -
Security Policies & Work Instructions
Clear guidelines and instructions to support the security framework -
Personnel
Ensuring employees understand their security-related responsibilities and protecting assets during role changes -
Asset Management
Identification and adequate protection of assets throughout their lifecycle
Technical Security Requirements
Section titled “Technical Security Requirements”-
Physical Security
Protection against unauthorized access and physical damage -
Operations
Secure operations including capacity planning, malware protection, logging, vulnerability management, and incident handling -
Identity & Access Management
Safeguarding authorization and authentication of privileged users -
Cryptography & Key Management
Effective use of encryption to ensure confidentiality, integrity, and authenticity -
Communication Security
Protection of information in networks and systems
Cloud-Specific Requirements
Section titled “Cloud-Specific Requirements”-
Portability & Interoperability
Ensuring data can be exported at contract termination and deleted by the provider -
Product Security
Secure configurations, vulnerability information, error handling mechanisms, and customer authentication/authorization
Process Requirements
Section titled “Process Requirements”-
Development & Change of Information Systems
Integration of information security into development and change processes -
Supplier & Subservice Provider Management
Secure information processing by subcontractors and monitoring compliance with agreed requirements -
Incident Management
Consistent procedures for capturing, evaluating, and handling incidents -
Business Continuity & Disaster Recovery
Planning and testing of business continuity and disaster recovery measures
Compliance and Governance
Section titled “Compliance and Governance”-
Compliance
Meeting legal, regulatory, and contractual information security requirements -
Handling Government Investigations
Appropriate treatment of governmental investigation requests
Types of C5 Attestations in Detail
Section titled “Types of C5 Attestations in Detail”Type 1 Attestation
Section titled “Type 1 Attestation”Characteristics:
- Reviews the design of internal controls at a specific point in time
- Does not assess the effectiveness of controls
- Suitable for initial audits or when operational data is not yet available
- Can serve as a transitional solution
Use Cases:
- New cloud services without operational history
- Transitional phase in healthcare (until June 30, 2025)
- Preparation for Type 2 certification
Type 2 Attestation
Section titled “Type 2 Attestation”Characteristics:
- Assesses design AND effectiveness of controls
- Examination over a defined period (typically 6–12 months)
- Requires proof of effective operation
- Considered the standard for C5
Use Cases:
- Regular operations of established cloud services
- Mandatory in healthcare from July 1, 2025
- Strong basis for risk management
Audit Process and Reporting Standards
Section titled “Audit Process and Reporting Standards”ISAE 3000 (Revised) as Foundation
Section titled “ISAE 3000 (Revised) as Foundation”C5 audits follow the internationally recognized assurance standard:
- Audit Standard: ISAE 3000 (Revised)
- Reporting Format: SOC 2 report with C5-specific additions
- Additional Standards: ISAE 3402, SOC 2 applied analogously
Quality Criteria for C5 Attestations
Section titled “Quality Criteria for C5 Attestations”Cloud customers should review the following when evaluating a C5 attestation:
-
Auditor Qualification
- Conducted in accordance with ISAE 3000
- Information about the entire audit team included
-
Reporting Principles
- Relevance
- Completeness
- Reliability
- Neutrality
- Understandability
-
Type of Opinion
- Unqualified: Full compliance with all criteria
- Qualified: Deviations present, must be assessed
-
Timeliness
- Attestation should be current (usually renewed annually)
- Audited period must be clearly specified
C5:2025 – The Next Generation
Section titled “C5:2025 – The Next Generation”The BSI working group is currently developing C5:2025 with key updates:
International Harmonization
Section titled “International Harmonization”- EUCS Integration: Assurance level “Substantial” of the European Cloud Certification Scheme
- ISO/IEC 27001:2022: Alignment with the latest version
- NIS2 Directive: Incorporation of EU requirements
- CSA Cloud Controls Matrix v4: Compatibility with international standards
New Technical Topics
Section titled “New Technical Topics”- Container Management
- Supply Chain Security
- Post-Quantum Cryptography
- Confidential Computing
- Stricter Tenant Separation
- Digital Sovereignty
Structural Improvements
Section titled “Structural Improvements”- Subcriteria for better auditability
- New criteria categories:
- “Additional Sharpen” (stricter)
- “Additional Complement” (supplementary)
Relations to Other Standards
Section titled “Relations to Other Standards”ISO 27001 / ISO 27017
Section titled “ISO 27001 / ISO 27017”- Many C5 criteria derived from ISO 27001 Annex A
- Existing ISO 27001 ISMS serves as a solid foundation
- Statement of Applicability (SoA) enables mapping to C5
SOC 2 / ISAE 3000
Section titled “SOC 2 / ISAE 3000”- C5 audit reports issued as SOC 2 reports
- SOC 2 covers Trust Service Principles
- C5 adds cloud-specific requirements:
- Transparency
- Tenant separation
- Government investigations
C5 Equivalence Regulation
Section titled “C5 Equivalence Regulation”During the transition period, the following may serve as temporary replacements:
- ISO 27001:2022
- BSI IT-Grundschutz
- CSA CCM v4
Conditions:
- Additional measures to close gaps required
- Maximum 18-month transition period
- Especially for small providers
Implementation Aids and Best Practices
Section titled “Implementation Aids and Best Practices”Phase 1: Risk-Based Planning and Preparation
Section titled “Phase 1: Risk-Based Planning and Preparation”Secure Management Commitment
Section titled “Secure Management Commitment”- Anchor relevance of C5 at executive level
- Provide sufficient resources
- Clearly define responsibilities
Define Scope
Section titled “Define Scope”- Identify affected cloud services
- Define regions and customer data
- Consider legal requirements (e.g., SGB V)
- Document scope decisions
Establish Risk Management
Section titled “Establish Risk Management”- Build asset inventory
- Analyze threats and vulnerabilities
- Assess likelihoods
- Use established ISO 27005 methods
Conduct Readiness Assessment
Section titled “Conduct Readiness Assessment”- Pre-audit (e.g., SOC 2 + C5 readiness)
- Identify gaps in existing controls
- Develop an implementation roadmap
Phase 2: Implementing C5 Controls
Section titled “Phase 2: Implementing C5 Controls”Select and Adapt Controls
Section titled “Select and Adapt Controls”- Identify relevant C5 criteria
- Leverage overlap with ISO 27001 (e.g., access control, incident response)
- Implement cloud-specific controls (tenant isolation, portability, investigations)
Documentation and Evidence
Section titled “Documentation and Evidence”- Create policies and processes
- Collect evidence for all controls
- For Type 2: provide operational evidence (logs, change management, audit trails)
Involve Subservice Providers
Section titled “Involve Subservice Providers”- Ensure subcontractor C5 compliance
- Accept equivalent certificates where applicable
- Integrate evidence into own audit
Continuous Monitoring
Section titled “Continuous Monitoring”- Conduct regular internal audits
- Perform management reviews
- Test control effectiveness
- Implement ongoing monitoring
Practical Tips for Implementation
Section titled “Practical Tips for Implementation”Tip 1: Use Transition Rules
Small providers can use the C5 Equivalence Regulation for up to 18 months. An ISO 27001:2022 or IT-Grundschutz certificate serves as a temporary replacement for a C5 Type 1 Attestation. A plan for closing remaining gaps is required. Use this period to prepare for full Type 2 certification.
Tip 2: Implement Tenant Separation Precisely
A focus of C5:2025 is strict tenant isolation. Ensure your cloud platform technically separates tenant data. Document mechanisms such as tenant isolation and per-tenant encryption clearly.
Tip 3: Strengthen Supply Chain Security
New requirements call for tighter supplier and subcontractor controls. Integrate third-party risk management into your ISMS. Review SLAs and require security evidence from all partners.
Tip 4: Prepare for Post-Quantum Cryptography
C5:2025 includes post-quantum cryptography. Start evaluating algorithms resistant to quantum attacks, especially for long-term sensitive data.
How the fuentis Suite Supports You
Section titled “How the fuentis Suite Supports You”The fuentis Suite offers full support for implementing and operating a C5-compliant ISMS:
Risk Management Module
Section titled “Risk Management Module”- Structured ISO 27005 risk assessment
- Central risk register with asset mapping
- Support for C5-specific risks (tenant separation, supply chain)
- Action tracking and effectiveness evaluation
Asset Management
Section titled “Asset Management”- Detailed asset inventory with classification
- Ownership and responsibility mapping
- Fulfillment of C5 asset requirements
- Lifecycle management from acquisition to disposal
Compliance Management
Section titled “Compliance Management”- Templates for ISO 27001 and ISO 27017
- Customizable C5 criteria catalogues
- Integration of C5 controls into existing structures
- SoA generation
- Implementation tracking
Audit & Review Modules
Section titled “Audit & Review Modules”- Internal audit support
- Management review processes
- Nonconformity tracking
- Evidence collection for Type 2 attestations
- Mapping evidence to controls
Document Management (DMS)
Section titled “Document Management (DMS)”- Versioned storage of policies and processes
- Centralized storage of attestation reports
- Approval workflows
- Full audit trail
- Automated document distribution
Online Assessment
Section titled “Online Assessment”- Web-based self-assessment questionnaires
- Automatic compliance status evaluation
- Gap analysis for C5 readiness
- Action plan generation
Key Takeaways at a Glance
Section titled “Key Takeaways at a Glance”✅ C5 defines minimum requirements for secure cloud services across 17 areas based on ISO 27001 with cloud-specific additions.
✅ Type 2 Attestations prove control effectiveness over time and will be mandatory in healthcare from July 1, 2025; Type 1 Attestations serve only as a transitional solution.
✅ C5 audits are based on ISAE 3000/SOC 2 – customers should demand unqualified, up-to-date reports and review subcontractor involvement.
✅ C5:2025 introduces key updates including container management, supply chain security, post-quantum cryptography, and alignment with EUCS, ISO 27001:2022, and NIS2.
✅ Structured implementation with proper tools like the fuentis Suite enables efficient management of risks, assets, compliance, and audits for practical C5 adoption.