Attestation · Last verified

Cloud Computing Compliance Criteria Catalogue

C5 is the BSI's cloud security criteria catalogue for Germany — auditors examine against it and the output is an attestation (Testat), not a certificate. Under § 393 SGB V, a current C5 Type 2 attestation is one of the statutory conditions for cloud use in German health care from 1 July 2025.

Class
Attestation
Owner
Bundesamt für Sicherheit in der Informationstechnik (BSI)
Last verified

What it is

C5 is a criteria catalogue published by Germany's federal information security authority, the BSI. In the BSI's words, "The C5 (Cloud Computing Compliance Criteria Catalogue) criteria catalogue specifies minimum requirements for secure cloud computing." It is not a certificate: cloud providers commission auditors — the BSI refers to "certified public accountants or other auditors" — to produce an examination report, and the output is an attestation (Testat).

Who owns it

The catalogue is published by the Bundesamt für Sicherheit in der Informationstechnik (BSI), Germany's federal information security authority.

Who assesses it

Cloud providers commission auditors — the BSI refers to "certified public accountants or other auditors" — to examine against the catalogue under international auditing standards; the BSI states that "over a hundred attestations have already been granted" (as stated by the BSI, 28 August 2026 — the count is the BSI's own statement, not our measurement).

Attestation types

  • Typ 1 — "Bis zum 30. Juni 2025 gilt als aktuelles C5-Testat im Sinne des Absatzes 3 Nummer 2 ein C5-Typ1-Testat." (§ 393 SGB V)
  • Typ 2 — "Ab dem 1. Juli 2025 gilt als aktuelles C5-Testat im Sinne des Absatzes 3 Nummer 2 ein aktuelles C5-Typ2-Testat." (§ 393 SGB V)

Who asks for it

Statutory (scoped). Statutory in one defined scope: cloud use in German health care under § 393 SGB V. Outside that scope this record documents no verified demand driver.

In Germany a current C5 attestation carries statutory weight in one defined scope: § 393 SGB V ("Cloud-Einsatz im Gesundheitswesen") makes a current C5 attestation one of the conditions under which health care providers, health and care insurance funds and their processors may process social and health data in the cloud, and the statute states that from 1 July 2025 a current C5 Type 2 attestation is required ("Ab dem 1. Juli 2025 gilt als aktuelles C5-Testat … ein aktuelles C5-Typ2-Testat"). Outside that scope, no obligation was identified in the sources reviewed as of 28 August 2026 — confirm against BSI and the relevant procurement authority.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Cloud Computing Compliance Criteria Catalogue." Certifidex, FutureTechnologies. Last verified 28 August 2026. https://certifidex.com/frameworks/bsi-c5

All frameworks & audits →