C5 (Germany)NIST SP 800-218

C5 (Germany) covers 61.9% of NIST SP 800-218

26 of the 42 controls in NIST SP 800-218 are already satisfied by evidence you collected for C5 (Germany). 16 are genuine gaps. Every claim below was judged against both control sets and then argued against; the ones that did not survive are published further down with the reason each failed.

61.9%
of the target already covered
26
controls evidenced
16
genuine gaps
0
claims rejected in review

This number is directional. It says how much of NIST SP 800-218 your C5 (Germany) evidence satisfies. The reverse pair is a different number, often very different, because a security standard has enormous depth for access control and almost none for lawful basis or data subject rights.

73 candidate mappings were examined and 0 were removed. Signed off 2026-08-19, review level machine verified. Mappings were judged by Claude Code rather than read line by line by a practitioner. Every claim shows its reasoning so you can check it. Ask and a practitioner will review this pair.

Where the gaps are

Coverage is never evenly spread. A source standard usually satisfies one part of a target almost completely and barely touches another, and which part is which is the thing worth knowing before you plan the work.

NIST SP 800-218: Access Control4 of 5 evidenced, 1 to do
Prepare the Organization6 of 8 evidenced, 2 to do
NIST SP 800-218: Cryptography3 of 4 evidenced, 1 to do
Respond to Vulnerabilities2 of 3 evidenced, 1 to do
NIST SP 800-218: Information Security Policies3 of 5 evidenced, 2 to do
Produce Well Secured Software4 of 8 evidenced, 4 to do
Protect the Software2 of 4 evidenced, 2 to do
NIST SP 800-218: Asset Management2 of 5 evidenced, 3 to do

Theme level, not control level, deliberately. The per-control list of what is evidenced and what is a gap is the report itself, so publishing it here would be publishing the thing being sold.

Claims that held

A sample. Each one names the control whose evidence does the work, the control it satisfies, and why.

C5-DEV-01SP800-218-PO.1.1argued against and upheld
Define Security Requirements for Software Development

Issued secure development policies grounded in standards, covering requirements, design, implementation and verification.

C5-DEV-07SP800-218-PO.1.2argued against and upheld
Implement Security Requirements in the Toolchain

Source code management and deployment tooling placed under the role and rights concept with enforced authorisation.

C5-DEV-02SP800-218-PO.1.3argued against and upheld
Communicate Requirements to Third-Party Providers

Outsourced development contractually bound to recognised secure engineering practice and acceptance testing.

C5-OIS-04SP800-218-PO.2.1argued against and upheld
Roles and Responsibilities for Secure Development

Duties separated across change development, testing, release and system operation on documented risk assessment.

C5-DEV-04SP800-218-PO.2.2argued against and upheld
Training and Skills Maintenance

Recurring audience specific training on secure software development and delivery, refreshed as tooling changes.

C5-OIS-02SP800-218-PO.2.3argued against and upheld
Obtain Management Commitment to Secure Development

Top management adopts the security policy and issues it to internal and external personnel.

C5-DEV-07SP800-218-PO.3.3argued against and upheld
Toolchain Generates Security Artifacts

Tooling configured so every production change is logged and traceable to the executing person or component.

C5-DEV-09SP800-218-PO.4.1argued against and upheld
Criteria for Software Security

Release into production requires defined criteria such as test results and prior sign-offs.

Claims that did not hold

Nothing proposed for this pair was rejected in review. That is unusual and worth knowing rather than hiding: it means the candidate set was small and every candidate held.

The full report

Everything above is a sample. The report is every evidenced control and every gap, with the reasoning and the source document behind each one, in a form you can hand to an assessor. $299, emailed immediately.

Buy this crosswalk