C5 went from 121 criteria to 168, and the switchover is 1 June 2027. C5:2026 was published on 7 April 2026 and applies to type 1 engagements with specified dates after 1 June 2027, and type 2 engagements for periods beginning on or after it. Today you are still being attested against C5:2020.

This assessment scores 73 questions across all 17 domains of C5:2026, including the container management, confidential computing and dataset separation criteria that are new in this edition, plus the system description and customer responsibility boundary where C5 engagements most often come unstuck. It is free, it saves as you go, and you can stop and come back to it.

What this is

The domain count did not change but two abbreviations did: IDM became IAM, and INV became INQ. The bigger structural change is that criteria are now decomposed into subcriteria, and additional criteria are split into sharpening ones that replace a basic subcriterion with something stricter, and complementing ones that add a requirement the basic criteria do not cover. BSI restructured it this way for compatibility with the EUCS Substantial level.

The background is elsewhere — what C5 is, the criteria, how attestation works, what it costs, who needs it, against ISO 27001 and against SOC 2. Come here when you want a score.

What it covers

73 questions, about 45 minutes.

SectionQuestions
Governance, policy and people12
Assets and physical security7
Operations13
Identity and cryptography10
Communications, portability and suppliers8
Development5
Incidents, continuity, compliance and investigations8
Product security and the attestation10

How the scoring works

StatusWeightMeans
Not started0%No policy, process or activity exists
Planned25%Agreed and scheduled, nothing in place yet
Partially implemented50%In place for part of the scope, or applied inconsistently
Implemented, not evidenced75%Operating as intended, but you could not prove it today
Implemented and evidenced100%Operating as intended, with records someone could sample
Not applicable—A justified exclusion, removed from the score

C5 is an attestation engagement under ISAE 3000, not a certification, and only an audit firm can issue one. BSI publishes the catalogue and nothing else — it does not accredit auditors, approve reports or keep a register of attested providers.

Free score, or the full report

The assessment and your overall score are free. The full report is a one-off $39 and gives you every question with your status and notes, the score broken down by section, a prioritised gap list, and the documents from the BSI C5:2026 Cloud Toolkit that close each gap — as a PDF and a working Excel file.

How long does it take?

About 45 minutes. Operations and cryptography carry the most weight — between them they are 54 of the 168 criteria, and key lifecycle management is where the 2026 edition grew most.

What to do with your score

Below 40% — start with the system description. You write it, not the auditor, and the auditor opines on it. Everything else in a C5 engagement is read against that document.

40–70% — the usual shape for a provider with an ISO 27001 certificate. BSI states the C5 basic criteria include all of the ISO 27001 criteria, so the gap is almost always in the C5-specific domains: portability, investigation requests, product security and the new 2026 subject matter.

Above 70% — pin down the complementary customer controls. The auditor assesses whether your assumptions about what the customer does are fairly presented, but never tests whether customers actually do it. Undocumented assumptions are the quiet failure.

Frequently asked questions

Is this assessment really free?

Yes. All 73 questions, the breakdown by domain and your overall score cost nothing. The $39 report is optional.

Should I assess against C5:2020 or C5:2026?

This assessment is written to C5:2026. If your next engagement covers a period ending before 1 June 2027 you will still be attested against C5:2020, so treat the result as readiness for the switchover rather than as a finding against your current attestation.

Does a C5 attestation expire?

Not formally — it reports on a period that has already ended. But BSI notes that an attestation several years old is of little use, and customers expect annual, gap-free coverage.

Do I need a type 2 report?

BSI’s position is that a type 2 carries the real information value, because it covers operating effectiveness across a period. Type 1 is essentially for a first engagement where period evidence does not exist yet.

Can I use this for a client?

Yes. Run one assessment per client organisation.

What happens to my answers?

They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.