Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

BSI C5 compared with ISO 27001

BSI C5 vs ISO 27001: A Clear Guide to the 4 Differences

BSI C5 vs ISO 27001 is a choice German cloud buyers make for you. One is an international certification of a management system; the other is a German attestation about a specific cloud service, reported by an auditor who tested your controls and wrote up what they found. They overlap heavily in content and not at all in what the customer receives.

This guide covers the four differences that matter commercially, how much of an ISO 27001 ISMS carries over, and when you need both.

BSI C5 vs ISO 27001: certification against attestation
Same control ground, entirely different deliverable.

BSI C5 vs ISO 27001 at a glance

  BSI C5 ISO 27001
Deliverable An auditor’s attestation report, with findings and exceptions A certificate, plus a scope statement
Subject A specific cloud service and its controls An information security management system
What the reader sees Control-by-control detail, including what failed A pass, with the detail staying between you and the auditor
Time dimension Type 1 at a point in time; type 2 over a period Three-year cycle with annual surveillance
Audience German public sector and regulated buyers, principally Global, across every sector

The four differences that actually matter

1. A report versus a certificate. This is the whole of BSI C5 vs ISO 27001 in one line. A certificate says an accredited body concluded your ISMS conforms. A C5 attestation hands the customer the auditor’s own account of each control, including deviations, so their risk team can read your weaknesses directly. Providers used to certification find that uncomfortable the first time.

2. Scope is the service, not the organization. In BSI C5 vs ISO 27001 terms, the ISO 27001 scope is whatever you define it to be, and a narrow scope is a legitimate choice. C5 is written around a cloud service, so the boundary is set by what you actually operate for that service.

3. Basic and additional criteria. C5 separates the criteria every provider must meet from the additional ones a buyer may require, and the report says which were in scope. There is no equivalent tiering in ISO 27001, where applicability is decided by your Statement of Applicability.

4. Transparency obligations. C5 asks providers to state environmental facts a customer cannot verify alone — jurisdictions, data locations, subcontractors, investigation and disclosure obligations. That reporting has no counterpart in a certificate.

BSI C5 vs ISO 27001: how much carries over

Most of the substance. The control ground is close enough that an operating ISMS gets you a long way into a C5 readiness assessment: policies, risk management, access control, cryptography, operations security, supplier management, incident response and continuity are all common territory, and Annex A evidence generally satisfies the equivalent C5 criteria with rework rather than rebuilding.

What does not carry over is the evidence discipline. An attestation — particularly a type 2 covering a period — needs evidence that the control operated throughout, sampled across the window. Certification audits sample far more lightly. Providers moving from ISO 27001 to C5 usually discover their evidence exists at points in time and not continuously. Our guides to what BSI C5:2026 changed and type 1 versus type 2 cover that in detail.

Which to do first

If you are selling into Germany’s public sector or its regulated industries, C5 is often the requirement in the tender and ISO 27001 is the thing you already have. If you sell internationally, ISO 27001 is the baseline everybody recognises. Doing ISO 27001 first and C5 second is the cheaper order in practice, because the management system gives the attestation something to test.

BSI C5 vs ISO 27001: when you need both

  • You hold ISO 27001 and a German customer’s procurement now names C5 — common, and the reason most providers end up with both.
  • Your customers span the EU and expect one recognised certificate plus regional assurance detail.
  • You are watching the European cybersecurity certification scheme for cloud services, where C5 work is a reasonable hedge and ISO 27001 remains the international baseline.
  • A financial-sector customer needs the control-level detail an attestation gives to satisfy its own outsourcing supervision.

Frequently asked questions

Is BSI C5 a certification?
No. It is an attestation: an audit report issued under an assurance standard, not a certificate issued by an accredited certification body. That is the core of BSI C5 vs ISO 27001.

Does C5 replace ISO 27001?
Not outside Germany, and rarely inside it. They answer different questions and most providers that need C5 hold ISO 27001 as well.

Can the same auditor do both?
Not usually in one engagement — certification bodies and audit firms operate under different accreditation regimes. Some groups offer both through separate entities.

How long does C5 take if we hold ISO 27001?
The readiness work is measured in months rather than years, but a type 2 attestation also needs an observation period, so the report lands well after the controls do.

Which is more expensive?
C5 usually, because the testing is deeper and the report is written for external readers. The gap narrows if your ISO 27001 evidence is already continuous.

Where this leaves you

Read BSI C5 vs ISO 27001 as report versus certificate, service versus organization. If you already hold ISO 27001, the control content is largely done and the real work is evidence that runs continuously across an observation period. If you hold neither and sell into Germany, build the management system first — it is what makes the attestation testable — then scope C5 around the service the customer is actually buying.

References

More on cloud assurance

Criteria mappings, policies and the evidence set are in the BSI C5:2026 Cloud Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.