Attestation · Last verified
Cloud Computing Compliance Criteria Catalogue
C5 is the BSI's cloud security criteria catalogue for Germany — auditors examine against it and the output is an attestation (Testat), not a certificate. Under § 393 SGB V, a current C5 Type 2 attestation is one of the statutory conditions for cloud use in German health care from 1 July 2025.
- Class
- Attestation
- Owner
- Bundesamt für Sicherheit in der Informationstechnik (BSI)
- Last verified
What it is
C5 is a criteria catalogue published by Germany's federal information security authority, the BSI. In the BSI's words, "The C5 (Cloud Computing Compliance Criteria Catalogue) criteria catalogue specifies minimum requirements for secure cloud computing." It is not a certificate: cloud providers commission auditors — the BSI refers to "certified public accountants or other auditors" — to produce an examination report, and the output is an attestation (Testat).
Who owns it
The catalogue is published by the Bundesamt für Sicherheit in der Informationstechnik (BSI), Germany's federal information security authority.
Who assesses it
Cloud providers commission auditors — the BSI refers to "certified public accountants or other auditors" — to examine against the catalogue under international auditing standards; the BSI states that "over a hundred attestations have already been granted" (as stated by the BSI, 28 August 2026 — the count is the BSI's own statement, not our measurement).
Attestation types
- Typ 1 —
"Bis zum 30. Juni 2025 gilt als aktuelles C5-Testat im Sinne des Absatzes 3 Nummer 2 ein C5-Typ1-Testat." (§ 393 SGB V)
- Typ 2 —
"Ab dem 1. Juli 2025 gilt als aktuelles C5-Testat im Sinne des Absatzes 3 Nummer 2 ein aktuelles C5-Typ2-Testat." (§ 393 SGB V)
Who asks for it
Statutory (scoped). Statutory in one defined scope: cloud use in German health care under § 393 SGB V. Outside that scope this record documents no verified demand driver.
In Germany a current C5 attestation carries statutory weight in one defined scope: § 393 SGB V ("Cloud-Einsatz im Gesundheitswesen") makes a current C5 attestation one of the conditions under which health care providers, health and care insurance funds and their processors may process social and health data in the cloud, and the statute states that from 1 July 2025 a current C5 Type 2 attestation is required ("Ab dem 1. Juli 2025 gilt als aktuelles C5-Testat … ein aktuelles C5-Typ2-Testat"). Outside that scope, no obligation was identified in the sources reviewed as of 28 August 2026 — confirm against BSI and the relevant procurement authority.
Sources
- BSI — C5 criteria catalogue (scheme owner) ↗ — accessed
- § 393 SGB V — Cloud-Einsatz im Gesundheitswesen ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.