Compliance – BSI C5 explained

BSI C5: finding and vetting cloud providers with a C5 attestation

There is no central register for finding a cloud provider with a BSI C5 attestation – the BSI does not maintain a public list. The reliable route: request the attestation directly from the provider and check for yourself whether the audit type, period and scope match your requirements. This page explains what the C5 criteria catalogue is, how Type 1 and Type 2 differ and which questions you should put to every provider – including the evidence centron itself provides.

What is the BSI C5 criteria catalogue?

The Cloud Computing Compliance Criteria Catalogue (C5) published by Germany's Federal Office for Information Security (BSI) is the German benchmark for cloud security. The current version, C5:2020, organises its requirements into 17 subject areas – from the organisation of information security through personnel, cryptography and operations to the handling of investigation requests by government agencies. That last area is what sets C5 apart from many international standards: the provider must disclose which jurisdiction it operates under and how it deals with disclosure requests.

C5 is not a certification but an audit-based attestation: an independent audit firm examines the provider's internal control system in accordance with the international assurance standard ISAE 3000 and confirms the result in an audit report. There is therefore no "C5 seal" and no expiry date as with ISO certificates – what counts is the current report.

Source: BSI, C5:2020 criteria catalogue (bsi.bund.de).

Type 1 or Type 2 – the difference

Type 1 Type 2
Subject of the audit Suitability of controls (design) Suitability and operating effectiveness
Time reference A single reference date An audit period (retrospective)
Statement "The controls are suitably designed as at the reference date" "The controls operated effectively throughout the period"
Typical use First attestation, new services Follow-up attestations, regulated long-term operations

A detailed step-by-step explanation is available in our tutorial Understanding the BSI C5 attestation, Type 1/Type 2.

A Type 2 report is the stronger statement, but it requires a completed audit period. An unqualified Type 1 attestation is the standard first step and sufficient for many procurements – what matters is that you know which type you are looking at.

How to read a C5 attestation

An attestation is only worth as much as its contents. Check five points:

# Check What matters
1 Auditor Independent audit firm, assurance standard ISAE 3000
2 Type and date Type 1 (reference date) or Type 2 (period)? How recent is the report?
3 Result "Unqualified" – or are there qualifications and exceptions?
4 Scope Which services are covered? An attestation for one service says nothing about the provider's other products.
5 Complementary customer controls Which obligations remain with you? Every C5 report lists them.

When do you actually need C5?

For Germany's federal administration, the BSI minimum standard for the use of external cloud services (under section 8(1) of the BSI Act) requires a C5 attestation from the provider. Beyond that, C5 has established itself as the reference wherever regulators or clients expect audited cloud security: for operators of critical infrastructure, in the financial and healthcare sectors, and in procurements by federal states and municipalities. Even without a formal obligation, the C5 report is the most thorough document you can obtain from a cloud provider about its security organisation – precisely because it comes from an independent auditor.

The evidence centron provides

Concretely and without embellishment – this evidence exists and can be viewed in the Trust Center:

Evidence Details
BSI C5:2020 Type 1 Unqualified attestation for "ccloud³ / Managed Cloud", audited by ADVANTA GmbH Wirtschaftsprüfungsgesellschaft in accordance with ISAE 3000, audit report dated 12 June 2026. A Type 2 follow-up attestation covering an audit period is not yet available.
ISO 27001 based on IT-Grundschutz German IT security certificate issued by the BSI (BSI-IGZ-0773-2026), scope "Process Hosting" of the cloud services ccloud³ and Managed Cloud at the Hallstadt, Nuremberg and Frankfurt sites, valid until 4 July 2029.
DPA & TOM Data processing agreement in accordance with Article 28 GDPR and documented technical and organisational measures, available as PDFs in the Trust Center.
Structure Owner-managed German GmbH (since 1999), its own data centre in Hallstadt near Bamberg, place of jurisdiction Germany, no parent company in a third country.

Five questions for every cloud provider

  1. Will you show me your current C5 attestation? A provider that advertises with it must hand over the report (at least under confidentiality).
  2. Type 1 or Type 2 – and from when? Reference date or period, and how long ago was the audit?
  3. Exactly which services does the scope cover? Does the attestation apply to the product you actually intend to use?
  4. Were there any qualifications or exceptions? "Unqualified" is the goal; anything else deserves follow-up questions.
  5. Which complementary customer controls does the report expect from me? Without this answer you cannot assess your own compliance.

Last reviewed: 31 August 2026 · Sources: BSI C5:2020 criteria catalogue; BSI minimum standard for the use of external cloud services (s. 8(1) BSIG); ADVANTA GmbH C5 audit report of 12 June 2026 (Trust Center); BSI certificate BSI-IGZ-0773-2026.

BSI C5 FAQ

Frequently asked questions about the BSI C5 attestation

How do I find a cloud provider with BSI C5 certification?

There is no central public register – the BSI does not maintain a list of attested providers. The reliable route: ask providers directly for their current C5 audit report and clarify four points – audit type (Type 1 or Type 2), date, result (unqualified?) and scope. Reputable providers publish their attestation in a trust centre; centron, for example, provides evidence there of an unqualified C5:2020 Type 1 attestation for ccloud³ / Managed Cloud (ADVANTA GmbH, report dated 12 June 2026).

Is BSI C5 a certification?

No. C5 is an audit-based attestation in accordance with the ISAE 3000 assurance standard: an independent audit firm confirms in a report that the provider’s internal control system meets the C5 criteria. Unlike an ISO certification there is no certificate document with an expiry date – what counts is the current audit report. Phrases such as “C5-certified” are therefore, strictly speaking, wrong.

What is the difference between C5 Type 1 and Type 2?

A Type 1 attestation confirms the suitability of the security controls as at a reference date – i.e. that they are appropriately designed. A Type 2 attestation additionally audits their operating effectiveness over a past audit period. Type 2 is the stronger statement, Type 1 the standard first step. centron currently holds an unqualified Type 1 attestation; a Type 2 follow-up attestation is not yet available.

Who is required to have a C5 attestation?

C5 is binding above all for cloud services used by Germany’s federal administration: the BSI minimum standard for the use of external cloud services (s. 8(1) BSIG) requires a corresponding attestation. Federal states, municipalities, operators of critical infrastructure, and banks and insurers increasingly use it as the benchmark in procurements and audits, even where no formal obligation exists. In practice: anyone serving public-sector or regulated clients can hardly avoid the C5 report.

Get started for free

Sign up and receive €200 credit at centron within your first 60 days.

This promotional offer applies to new accounts only. Available exclusively to businesses.