A BSI C5 attestation is not a certificate. It is an auditor’s report on a cloud provider’s internal control system, produced under an assurance standard rather than a certification scheme — which is why it comes in two types, covers a stated period, and has to be repeated to stay current.
That structure is what makes C5 useful to a customer and confusing to a provider approaching it for the first time. This guide covers the difference between a type 1 and a type 2 report, what is inside the report, the general conditions a provider has to disclose, and how often the exercise has to be repeated.

Type 1 and type 2, and why the difference matters
Both types of BSI C5 attestation are performed against the same criteria catalogue. What differs is what the auditor tests.
| Type 1 | Type 2 | |
|---|---|---|
| Question answered | Are the controls suitably designed to meet the criteria? | Were they suitably designed and did they operate effectively? |
| Time dimension | A point in time | A reporting period |
| Typical use | First examination, where there is not yet enough operating history | Ongoing assurance, and what most enterprise customers ask for |
| Evidence | Design documentation and implementation | Samples drawn across the period |
The BSI is explicit that in an initial examination there may be too little evidence to conclude on effectiveness, in which case only a type 1 report can be produced. That is the normal starting point, not a failure — but treat it as a staging post. A type 1 tells a customer what you intended; only a type 2 tells them what happened.
Which assurance standard a BSI C5 attestation runs under
This is the question that decides who you hire, and it is where a BSI C5 attestation departs from certification altogether.
C5 is not audited under a certification standard such as ISO/IEC 17021. The examination and reporting are carried out under ISAE 3000 (Revised), the international standard for assurance engagements other than audits of historical financial information. Where ISAE 3000 does not cover a point, ISAE 3402 and SOC 2 practice are applied analogously, and in Germany the national equivalents IDW PS 951 and IDW PS 860 are recognized.
The practical consequence for a provider: your auditor is a public accountancy firm operating under assurance rules, not a certification body. The engagement runs on an assertion by management, a system description, and evidence sampling — the same machinery as SOC 2, which is why organizations that hold a SOC 2 report find the process familiar even though the criteria are different.
What is inside a BSI C5 attestation report
A BSI C5 attestation report is a document set, not a certificate page:
- the independent auditor’s report, carrying the opinion;
- the provider’s own statement, in which management asserts the description is fair and the controls are suitably designed;
- the system description — the scope of the service, its boundaries, and how it works;
- the controls, the auditor’s test procedures and the results, criterion by criterion; and
- where applicable, a statement of deficiencies.
Two elements deserve particular attention from a customer reading one. Complementary customer controls are the things you must do for the provider’s controls to achieve their objective — if you do not operate them, the assurance does not extend to you. Complementary subservice organization controls are the equivalent for the provider’s own subcontractors, and they tell you where the chain of assurance passes to somebody else.
The general conditions a provider must disclose
C5’s distinguishing feature is the set of environment disclosures the provider has to make alongside the criteria — the framework conditions covering matters such as availability and troubleshooting, the sub-service providers used, the geographical location of data centers, applicable jurisdiction, existing certifications, and how the provider handles investigation requests from government agencies.
This is the part of C5 that customers in regulated sectors actually read first, because it answers questions no control test can: which law applies to your data, who else touches it, and what happens when a state authority asks for it.
How often a BSI C5 attestation has to be repeated
An attestation covers a completed period, and the BSI’s guidance contemplates reporting periods of roughly three to twelve months. To demonstrate continuous compliance, providers therefore run between one and four examinations a year depending on the period chosen. Whatever cadence you pick, plan for the gap: an annual type 2 report leaves a window between the end of the reporting period and the issue of the next report, and enterprise customers will ask you to cover it — the same problem a SOC 2 bridge letter exists to solve.
For scoping, remember that C5:2026 expanded the catalogue substantially — 168 criteria across 17 subject areas, against 121 in C5:2020 — and splits criteria into basic criteria, which must all be met, and additional criteria that either tighten or complement them. Deciding which additional criteria are in scope is a commercial decision as much as a security one, and it belongs at the start of the engagement rather than in the middle of fieldwork. What changed in the revision, and its relationship to the European cloud scheme, is covered in our guide to BSI C5:2026.
Frequently asked questions
Is a BSI C5 attestation a certification?
No. It is an assurance report issued by an independent auditor under ISAE 3000 (Revised), with ISAE 3402, SOC 2 practice and the German IDW standards applied where relevant. There is no certificate and no certification body.
Should we go for type 1 or type 2?
Type 2 if you have enough operating history to evidence effectiveness. Type 1 if you do not — the BSI expects this for initial examinations — and then move to type 2 at the next cycle.
How long is a C5 attestation valid?
It is not valid for a period; it reports on one. Customers assess how recent the reporting period is, which is why providers repeat the exercise on a fixed cadence.
Can we reuse our SOC 2 work?
Substantially, yes. The engagement machinery, the system description and much of the evidence overlap. The criteria do not — C5’s environment disclosures in particular have no SOC 2 equivalent.
Who is C5 aimed at?
Cloud providers serving the German market, their customers, and German federal authorities procuring cloud services for official data processing. Public-sector and regulated buyers are where the requirement usually originates.
Where this leaves you
Treat a BSI C5 attestation as an assurance engagement rather than a certification project. Fix the scope and the additional criteria before fieldwork starts, write the system description as the document a customer will actually read, be honest about complementary customer and subservice controls, and expect the first report to be a type 1. Then set the cadence — one to four examinations a year — so there is never an awkward gap between what the report covers and what a prospect is asking about today.
References
- BSI — C5 FAQ — audit standards, report types, complementary controls and reporting periods.
- BSI — Introduction to C5 — purpose, catalogue structure and the required framework disclosures.
More on cloud assurance
- The BSI C5 attestation — you are here
- BSI C5:2026 and what the revision changed
- SOC 2 type 1 vs type 2
- ISO 27017 cloud security controls
The system description, criteria mapping and evidence records are in the BSI C5:2026 Cloud Toolkit, or start with the free ISO templates.