Cloud & Certification
BSI C5
Cloud Computing Compliance Criteria Catalogue
A criteria catalogue for cloud service security, assessed by an auditor and reported as an attestation rather than a certificate, so the customer receives a full report, including the auditor's findings, not just a pass mark.
The transparency criteria are the distinctive part: providers must disclose jurisdiction, data location, and the legal environment they operate under, which is exactly what a European data sovereignty review needs to see.
At a glance
- Category
- Cloud & Certification
- Jurisdiction
- EU / Germany
- Governance
- BSI (Germany)
- Status
- C5:2020: 121 criteria in 17 areas; attested under ISAE 3000
- First released
- 2016
Links
Related frameworks
Other entries under Cloud & Certification.
- CSA CCM: Cloud Controls Matrix
- ISO/IEC 27017: Cloud Security Controls
- EU Cloud CoC: EU Cloud Code of Conduct
See BSI C5 in context
Open the interactive Data Landscape for Regulation to compare BSI C5 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.