Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

BSI C5:2026 transition infographic

BSI C5:2026 Transition: The Essential Guide for Cloud Service Providers

The BSI C5:2026 transition is the next big compliance project for cloud providers that sell to German public sector and regulated customers. The Federal Office for Information Security has revised the Cloud Computing Compliance Criteria Catalogue for the first time since 2020, and providers who hold a C5 attestation now need to understand what changes and when.

This guide summarizes the reported changes, explains the new structure of basic and additional criteria, describes the audit approach and gives a practical gap-analysis and timeline plan. It is based on the BSI page and on published assessor summaries, which do not agree in every detail. Confirm the final criteria text and the transition rules with BSI and your auditor before you commit dates or budgets.

Free gap assessment

Are you ready for C5:2026?

Score all 17 domains of the 2026 catalogue, free, including container management, confidential computing and the customer responsibility boundary.

Run the free BSI C5 gap assessment →  or  View premium report sample

What the BSI C5:2026 transition means

BSI C5 is a catalogue of minimum security requirements for cloud services. Providers demonstrate conformity through an attestation report issued by an independent auditor, not through a certificate. C5:2026 is the new edition. According to the BSI page, it builds on the 2020 edition and incorporates six years of developments, including requirements drawn from the European cloud certification scheme, the Cloud Controls Matrix version 4, ISO/IEC 27001:2022 and the NIS2 directive.

For the BSI C5:2026 transition, that means providers with a current C5:2020 report must plan a move to the new catalogue, while providers new to C5 will be assessed against the new edition. Our overview of BSI C5 and the page on C5 criteria give the background.

What changed in C5:2026

Published summaries highlight several changes. First, the catalogue was restructured. Criteria are broken into distinct sub-criteria, which clarifies what an auditor must test. One assessor reports that the number grew from 121 to 168 criteria. Second, criteria are now tiered. Basic criteria are the mandatory minimum, while additional criteria apply where the provider handles sensitive data or infrastructure. BSI describes two kinds of additional criteria: those that sharpen basic criteria with stricter requirements and those that complement them with new requirements.

Third, new topics were added, including container management, confidential computing and post-quantum cryptography, along with stronger supply chain management, identity and access management, client separation and data sovereignty. Fourth, the catalogue is now also published in machine-readable YAML, in addition to PDF and Excel, to support automation.

Deadline and timeline for the BSI C5:2026 transition

One assessor summary reports that C5:2026 becomes mandatory for engagements beginning on or after 1 June 2027, that C5:2020 remains valid until then and that earlier adoption is permitted. Treat that as a reported date and confirm it with BSI and your auditor, since summaries and transition notices can differ.

Work backward from your next attestation. A typical plan allows a few months for the gap analysis, several months for implementation of new controls and time before the audit period starts so that operating evidence exists. If your reporting period begins on the new catalogue, controls must operate for the whole period, so late changes create a risk of exceptions. Choosing an early adoption date in a period with fewer competing priorities may be the smoother path.

TopicC5:2020C5:2026 (as reported)
Criteria121 criteriaExpanded to 168, with sub-criteria
StructureSingle criteria listBasic criteria plus additional criteria for sensitive data
Criteria typesNot applicableAdditional sharpen and additional complement
New topicsNot coveredContainers, confidential computing, post-quantum cryptography
Strengthened areasSupply chain, identitySupply chain, identity and access management, data sovereignty
FormatsPDF and ExcelPDF, Excel and machine-readable YAML
AttestationType 1 and Type 2Type 1 and Type 2, with Type 2 the usual expectation

Basic versus additional criteria: what applies to you

The tiering is the most important planning decision. Every provider needs the basic criteria. Additional criteria apply for sensitive data and infrastructure, which typically means public sector customers, critical infrastructure and regulated industries. Ask your key customers which level they expect, and scope the attestation accordingly. Our page on who needs BSI C5 can help you decide whether the work is even necessary for your market.

Document your reasoning. If you decide that some additional criteria are out of scope, the system description and the discussion with your auditor should make that clear, so that customers reading the report can see what is covered.

Running a gap analysis against C5:2026

Start with the catalogue itself. Map each criterion to your current controls, evidence and policies. Mark each as met, partially met or new. For new topics, such as container management, ask the engineering teams how workloads are built, deployed and isolated, and what evidence is available.

Pay extra attention to supply chain, identity, cryptography and data location. These are areas where the expectations rose and where cloud providers often rely on third parties. Also check your complementary customer controls, the responsibilities left to your customers; see complementary customer controls, because the boundaries may shift with the new criteria.

Audit approach and report type

C5 attestation is performed under an international assurance standard by a qualified auditor, and the output is a report. Reports can describe design and implementation at a point in time, often called Type 1, or also test operating effectiveness over a period, called Type 2. Customers typically prefer Type 2 because it shows controls working over time. See BSI C5 attestation for the process and BSI C5 report review for what customers look for when they read your report.

If you also hold SOC 2 or ISO 27001, much evidence overlaps. Compare approaches in BSI C5 vs SOC 2 and BSI C5 vs ISO 27001 to reuse your audits.

Budget and planning

The main cost drivers are the gap analysis, engineering work for new controls, the audit fee and internal time. See BSI C5 attestation cost for typical ranges. The transition will often cost more than a simple renewal because the criteria expanded, though the increase depends on your current maturity. Ask your auditor for a quote that separates transition effort from the ordinary renewal.

Templates for the BSI C5:2026 transition

Policy, procedure and evidence templates save time when criteria multiply. The BSI C5 2026 Cloud Toolkit covers the 17 domains of the catalogue, so you can update your documentation set to the new edition instead of starting again. Templates must still match your real practice, so review each one with the control owner.

For the source document and the latest announcements, see the BSI page on the C5:2026 criteria catalogue.

Building a transition plan for the BSI C5:2026 transition

Assign an owner and a sponsor, then break the work into workstreams: governance and policy, identity and access, cryptography and key management, container and workload security, supply chain and subservice providers, data location and sovereignty, and logging and monitoring. Each workstream lead reviews the relevant criteria, lists the changes needed and estimates effort. Consolidate the lists into one plan with dates, and review progress every two weeks. A single tracker showing each criterion, its status, its owner and the evidence location helps the auditor too, because the same sheet can drive the walkthroughs.

Brief your auditor early. Ask how it will treat criteria that are new in C5:2026, what evidence it expects for operating effectiveness and how it will handle the period in which your controls were changing. Agree on the reporting period, the scope and the list of subservice organizations in writing, so that surprises do not appear after fieldwork starts.

Explaining the change to customers

Customers who rely on your C5 report will ask whether it will continue. Prepare a short customer note that says which edition your current report covers, when you expect to move to the new edition, which additional criteria you plan to include and when the next report will be available. Share the note through your trust center and account managers, and update it each time the plan changes. Clear communication keeps procurement reviews moving and reduces repeated questionnaires.

Evidence to collect for new C5:2026 topics

New topics need new evidence. For container management, collect image build and scanning records, registry access controls, cluster hardening baselines and runtime isolation settings. For cryptography, collect your algorithm inventory, key management procedures and any roadmap for post-quantum migration. For data sovereignty, collect documentation of where data is stored and processed and the controls that prevent unauthorized movement. Keep each item dated so the auditor can match it to the reporting period.

Common mistakes in the BSI C5:2026 transition

Providers often assume their old report carries over unchanged. They ignore the additional criteria and discover late that a customer expects them. They underestimate new technical topics such as container and cryptography controls. Another mistake is waiting until the audit period begins, which leaves no time to generate operating evidence. Start early and keep a change log of every control you add or modify.

BSI C5:2026 Transition FAQ

What is C5:2026?

It is the revised Cloud Computing Compliance Criteria Catalogue from the German Federal Office for Information Security, replacing the 2020 edition.

When is the transition deadline?

One assessor reports that C5:2026 is mandatory for engagements starting on or after 1 June 2027. Confirm the date with BSI and your auditor.

Is C5 a certificate?

No. Conformity is shown by an attestation report issued by an independent auditor.

Do I need the additional criteria?

Only if you handle sensitive data or infrastructure or your customers require it. Agree the scope with your auditor and customers.

Type 1 or Type 2?

Type 1 covers design and implementation at a point in time; Type 2 also tests operating effectiveness over a period. Customers usually prefer Type 2.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.