Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

Germany BSI C5 — Cloud Computing Compliance Criteria Catalogue (C5:2026)

The Cloud Computing Compliance Criteria Catalogue (C5) is the German federal cloud assurance standard issued by the Federal Office for Information…

What Germany BSI C5 — Cloud Computing Compliance Criteria Catalogue (C5:2026) requires

The Cloud Computing Compliance Criteria Catalogue (C5) is the German federal cloud assurance standard issued by the Federal Office for Information Security (Bundesamt fuer Sicherheit in der Informationstechnik / BSI). The current revision C5:2026 was completed in 2025/26 to incorporate post-quantum cryptography migration considerations, AI workload security, supply-chain risk under EU NIS2 and the EU AI Act, and updated DORA third-party ICT risk alignment. C5 audits are conducted by qualified independent auditors (Wirtschaftspruefer or comparable) using an examination report aligned to the International Standard on Assurance Engagements ISAE 3402 and the German IDW Pruefungsstandard PS 951. C5 differentiates Basis Criteria (mandatory baseline for any C5-certified cloud service) and Additional Criteria (elective extensions including data residency in Germany / EU, high availability, and high confidentiality categories). The C5 control areas span the full information security and operations lifecycle including Organisation of Information Security (OIS), Security Policies and Procedures (COS), Human Resources Security (HR), Asset Management (AM), Physical Security (PS), Operations Security (RB), Communications Security (KOS), Identity and Access Management (IDM), Cryptography (CRY), System Acquisition Development and Maintenance (DEV), Supplier Relationships (PSS), Business Continuity Management (BCM), Compliance (COM), Incident Management (BEI), Privacy and Data Protection (PI), Customer Inquiries (BEI), and Cloud-Specific Architecture (KOS). C5 is mandatory or strongly preferred for German federal public-sector cloud procurements, KRITIS critical infrastructure operators under IT-SiG 2.0, and many BaFin-supervised financial institutions consuming third-party cloud services under DORA. C5 attestation reports are reusable across customers under a Type 1 (design) and Type 2 (operating effectiveness over period) framework, materially reducing repeat-audit burden for hyperscale CSPs and enterprise consumers. C5 also intersects with the European Cybersecurity Certification Scheme for Cloud Services (EUCS) as Germany's national basis for the harmonised EU-level scheme expected to enter force from 2025 onward.

Pillar: Cloud & SaaS · Authority: Bundesamt fuer Sicherheit in der Informationstechnik (BSI / Federal Office for Information Security), Germany · Version: 1.0.0 · Last updated:

Primary source: https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Empfehlungen-nach-Angriffszielen/Cloud-Computing/Kriterienkatalog-C5/kriterienkatalog-c5_node.html

SHA-256 integrity: 449b22d43d9d6ba782bb976e2b205ba758999e6fe685de919c6817e20729ca42

Primary Citations — 10 traced to source

  • Bundesamt fuer Sicherheit in der Informationstechnik (BSI) Cloud Computing Compliance Criteria Catalogue (C5:2026) - German federal cloud assurance standard
  • ISAE 3402 (International Standard on Assurance Engagements) - international audit framework underpinning C5 attestation reports

+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.