BSI C5 — Cloud Computing Compliance Criteria Catalogue
The Cloud Computing Compliance Criteria Catalogue (C5) is the German Federal Office for Information Security (BSI) standard for assessing the security of cloud services. C5:2020 defines minimum security requirements that cloud providers must meet, organized into 17 topic areas with 121 criteria. Used by German federal agencies and widely adopted by European organizations for cloud security assurance. C5 attestation reports are issued by qualified auditors.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (2)
Cloud-Specific and Physical Security
Multi-tenancy, portability, physical infrastructure security
| Code | Title |
|---|---|
| C5-CLD-01 | Multi-Tenancy and Isolation |
| C5-CLD-02 | Portability and Interoperability |
| C5-CLD-03 | Physical Security |
| C5-CLD-04 | Incident Management |
Organization and Governance
Organizational security, policies, and compliance
| Code | Title |
|---|---|
| C5-ORG-01 | Information Security Policy |
| C5-ORG-02 | Risk Management |
| C5-ORG-03 | Personnel Security |
| C5-ORG-04 | Compliance Management |
Maps to 557 other frameworks
Frequently Asked Questions
What is BSI C5 — Cloud Computing Compliance Criteria Catalogue?
BSI C5 — Cloud Computing Compliance Criteria Catalogue is a compliance framework from Germany with 2 domains and 8 controls. The Cloud Computing Compliance Criteria Catalogue (C5) is the German Federal Office for Information Security (BSI) standard for assessing the security of cloud services. C5:2020 defines minimum security requirements that cloud providers must meet, organized into 17 topic areas with 121 criteria. Used by German federal agencies and widely adopted by European organizations for cloud security assurance. C5 attestation reports are issued by qualified auditors. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does BSI C5 — Cloud Computing Compliance Criteria Catalogue have?
BSI C5 — Cloud Computing Compliance Criteria Catalogue has 8 controls organised across 2 domains. The largest domains are Cloud-Specific and Physical Security (4 controls), Organization and Governance (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does BSI C5 — Cloud Computing Compliance Criteria Catalogue map to?
BSI C5 — Cloud Computing Compliance Criteria Catalogue maps to 557 other compliance frameworks. The top mapping partners are NIST Privacy Framework 1.0 (63% coverage), NRF Cybersecurity and Data Privacy Framework (National Retail Federation) (63% coverage), CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 (63% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with BSI C5 — Cloud Computing Compliance Criteria Catalogue compliance?
Start your BSI C5 — Cloud Computing Compliance Criteria Catalogue compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about BSI C5 — Cloud Computing Compliance Criteria Catalogue requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 8 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required