Cloud & Certification

BSI C5

Cloud Computing Compliance Criteria Catalogue

Formal standard EU / Germany BSI (Germany) Since 2016

A criteria catalogue for cloud service security, assessed by an auditor and reported as an attestation rather than a certificate, so the customer receives a full report, including the auditor's findings, not just a pass mark.

The transparency criteria are the distinctive part: providers must disclose jurisdiction, data location, and the legal environment they operate under, which is exactly what a European data sovereignty review needs to see.

At a glance

Category
Cloud & Certification
Jurisdiction
EU / Germany
Governance
BSI (Germany)
Status
C5:2020: 121 criteria in 17 areas; attested under ISAE 3000
First released
2016

Links

Related frameworks

Other entries under Cloud & Certification.

See BSI C5 in context

Open the interactive Data Landscape for Regulation to compare BSI C5 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.