BSI C5: finding and vetting cloud providers with a C5 attestation
There is no central register for finding a cloud provider with a BSI C5 attestation – the BSI does not maintain a public list. The reliable route: request the attestation directly from the provider and check for yourself whether the audit type, period and scope match your requirements. This page explains what the C5 criteria catalogue is, how Type 1 and Type 2 differ and which questions you should put to every provider – including the evidence centron itself provides.
What is the BSI C5 criteria catalogue?
The Cloud Computing Compliance Criteria Catalogue (C5) published by Germany's Federal Office for Information Security (BSI) is the German benchmark for cloud security. The current version, C5:2020, organises its requirements into 17 subject areas – from the organisation of information security through personnel, cryptography and operations to the handling of investigation requests by government agencies. That last area is what sets C5 apart from many international standards: the provider must disclose which jurisdiction it operates under and how it deals with disclosure requests.
C5 is not a certification but an audit-based attestation: an independent audit firm examines the provider's internal control system in accordance with the international assurance standard ISAE 3000 and confirms the result in an audit report. There is therefore no "C5 seal" and no expiry date as with ISO certificates – what counts is the current report.
Source: BSI, C5:2020 criteria catalogue (bsi.bund.de).
Type 1 or Type 2 – the difference
| Type 1 | Type 2 | |
|---|---|---|
| Subject of the audit | Suitability of controls (design) | Suitability and operating effectiveness |
| Time reference | A single reference date | An audit period (retrospective) |
| Statement | "The controls are suitably designed as at the reference date" | "The controls operated effectively throughout the period" |
| Typical use | First attestation, new services | Follow-up attestations, regulated long-term operations |
A detailed step-by-step explanation is available in our tutorial Understanding the BSI C5 attestation, Type 1/Type 2.
A Type 2 report is the stronger statement, but it requires a completed audit period. An unqualified Type 1 attestation is the standard first step and sufficient for many procurements – what matters is that you know which type you are looking at.
How to read a C5 attestation
An attestation is only worth as much as its contents. Check five points:
| # | Check | What matters |
|---|---|---|
| 1 | Auditor | Independent audit firm, assurance standard ISAE 3000 |
| 2 | Type and date | Type 1 (reference date) or Type 2 (period)? How recent is the report? |
| 3 | Result | "Unqualified" – or are there qualifications and exceptions? |
| 4 | Scope | Which services are covered? An attestation for one service says nothing about the provider's other products. |
| 5 | Complementary customer controls | Which obligations remain with you? Every C5 report lists them. |
When do you actually need C5?
For Germany's federal administration, the BSI minimum standard for the use of external cloud services (under section 8(1) of the BSI Act) requires a C5 attestation from the provider. Beyond that, C5 has established itself as the reference wherever regulators or clients expect audited cloud security: for operators of critical infrastructure, in the financial and healthcare sectors, and in procurements by federal states and municipalities. Even without a formal obligation, the C5 report is the most thorough document you can obtain from a cloud provider about its security organisation – precisely because it comes from an independent auditor.
The evidence centron provides
Concretely and without embellishment – this evidence exists and can be viewed in the Trust Center:
| Evidence | Details |
|---|---|
| BSI C5:2020 Type 1 | Unqualified attestation for "ccloud³ / Managed Cloud", audited by ADVANTA GmbH Wirtschaftsprüfungsgesellschaft in accordance with ISAE 3000, audit report dated 12 June 2026. A Type 2 follow-up attestation covering an audit period is not yet available. |
| ISO 27001 based on IT-Grundschutz | German IT security certificate issued by the BSI (BSI-IGZ-0773-2026), scope "Process Hosting" of the cloud services ccloud³ and Managed Cloud at the Hallstadt, Nuremberg and Frankfurt sites, valid until 4 July 2029. |
| DPA & TOM | Data processing agreement in accordance with Article 28 GDPR and documented technical and organisational measures, available as PDFs in the Trust Center. |
| Structure | Owner-managed German GmbH (since 1999), its own data centre in Hallstadt near Bamberg, place of jurisdiction Germany, no parent company in a third country. |
Five questions for every cloud provider
- Will you show me your current C5 attestation? A provider that advertises with it must hand over the report (at least under confidentiality).
- Type 1 or Type 2 – and from when? Reference date or period, and how long ago was the audit?
- Exactly which services does the scope cover? Does the attestation apply to the product you actually intend to use?
- Were there any qualifications or exceptions? "Unqualified" is the goal; anything else deserves follow-up questions.
- Which complementary customer controls does the report expect from me? Without this answer you cannot assess your own compliance.
Last reviewed: 31 August 2026 · Sources: BSI C5:2020 criteria catalogue; BSI minimum standard for the use of external cloud services (s. 8(1) BSIG); ADVANTA GmbH C5 audit report of 12 June 2026 (Trust Center); BSI certificate BSI-IGZ-0773-2026.
Frequently asked questions about the BSI C5 attestation
How do I find a cloud provider with BSI C5 certification?
Is BSI C5 a certification?
What is the difference between C5 Type 1 and Type 2?
Who is required to have a C5 attestation?
Get started for free
Sign up and receive €200 credit at centron within your first 60 days.
This promotional offer applies to new accounts only. Available exclusively to businesses.