Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

BSI C5 vs SOC 2 explained

BSI C5 vs SOC 2: 5 Clear Differences and the Mapping (2026)

BSI C5 vs SOC 2 is the comparison that confuses cloud providers precisely because the two look alike: both produce an auditor’s examination report rather than a certificate, both come in a type 1 (design at a point in time) and a type 2 (operating effectiveness over a period), both run under an assurance standard — ISAE 3000 (Revised) for C5, the AICPA’s attestation standards for SOC 2 — and both hand the customer a system description, a management assertion and control-by-control results. What differs is everything the report is about.

C5 is a criteria catalogue: 17 objectives, 168 criteria in the 2026 edition, split into basic and additional subcriteria, with general conditions the provider must disclose and complementary customer criteria the customer must implement. SOC 2 is a principles framework: five trust services categories, criteria written at the level of “the entity implements logical access security” that the provider’s own controls have to satisfy. This guide sets the two side by side on ten points, walks the five differences that matter to a provider deciding which to buy, shows how the criteria map, and answers the question of whether one report can be reused for the other.

BSI C5 vs SOC 2: same report shape, different content
Both: examination report, type 1 / type 2, system description, management assertion, ISAE 3000-family assurance. C5:2026: 17 objectives, 168 prescriptive criteria, basic + additional, general conditions, complementary customer criteria, German/EU market. SOC 2: five trust services categories, principles-based criteria, provider-defined controls, US-led global market.

BSI C5 vs SOC 2 at a glance

BSI C5 (C5:2026) SOC 2
Owner German Federal Office for Information Security (BSI) AICPA (American Institute of CPAs)
What it is A cloud-specific criteria catalogue and audit framework An attestation framework over the Trust Services Criteria (TSC)
Structure 17 objectives; 168 criteria; basic and additional (sharpening, complementing) subcriteria; general conditions (GC-01 to GC-06); complementary customer criteria Five trust services categories: security (required), availability, processing integrity, confidentiality, privacy; criteria plus points of focus
Prescriptiveness High — each criterion states what must be in place (e.g. OPS-27/28 patch management, CRY-05 encryption of sensitive data at rest, IAM-08 authentication) Low — criteria are principles; the provider designs the controls and the auditor tests those
Assurance standard ISAE 3000 (Revised), or IDW PS 860 or a national equivalent; ISAE 3402 / IDW PS 951 for specific questions AICPA SSAE 18 / AT-C 105 and 205; ISAE 3000 for non-US firms
Report types Type 1 (design, point in time) and type 2 (operating effectiveness, period) Type 1 and type 2, the same distinction
Auditor Certified public accountants or equivalent; BSI takes no part in selection CPA firms; the AICPA licenses the SOC 2 mark
Who asks for it German federal administration, healthcare under § 393 SGB V, regulated and public-sector buyers in Germany and the EU; increasingly EUCS-oriented buyers US enterprise customers and, through them, most SaaS supply chains worldwide
Transparency of the report Detailed; customers read control-by-control results and deviations Detailed; the same, plus tests performed and results
Alignment Built for compatibility with EUCS level Substantial; considered ISO 27001:2022, CSA CCM v4 and NIS2 Mappable to ISO 27001, NIST CSF, CCM; no regulatory scheme alignment

BSI C5 vs SOC 2: the five differences that matter

  1. Prescribed criteria versus your own controls. Under C5 the auditor tests whether the provider meets each of 168 criteria as written; under SOC 2 the auditor tests whether the provider’s own controls, described by the provider, meet principles. A C5 report is therefore comparable across providers in a way SOC 2 reports are not — which is the point of it for a public-sector buyer — and a C5 gap is a specific missing criterion rather than a judgement about sufficiency.
  2. Basic and additional. C5 defines the minimum audit scope as the basic criteria and lets the provider include additional criteria — sharpening replacements or complementing additions — for customers with higher protection needs, with the report stating which were in scope. SOC 2 has the category choice (security alone, or with availability, confidentiality, processing integrity, privacy) and nothing finer.
  3. General conditions. C5’s section 4 requires the provider to disclose facts a customer cannot verify — jurisdictions, data locations, subcontractors, investigation and disclosure obligations, certifications held — as audited criteria. SOC 2’s system description covers some of this narratively; C5 makes it testable.
  4. Complementary customer criteria. C5 states, criterion by criterion, where the customer must implement complementary controls; German healthcare law makes implementing them a legal condition of using the service. SOC 2 has complementary user entity controls in the system description, without the regulatory hook.
  5. Market. A C5 report opens the German public sector, German healthcare and EU buyers who read EUCS; a SOC 2 report opens US enterprise procurement and the global SaaS supply chain. A provider selling into both needs both, and the sections below are about doing that once.

Our guide to BSI C5 attestation covers type 1, type 2 and the report contents; SOC 2 trust services criteria covers the other side.

BSI C5 vs SOC 2 criterion by criterion: the mapping

C5:2026 objective Criteria SOC 2 trust services category / criteria area Overlap
OIS Organisation of information security; SP policies 13 CC1 control environment; CC2 communication; CC3 risk assessment; CC5 control activities High — governance, risk, policy
HR Personnel 8 CC1.4, CC1.5 competence and accountability High
AM Asset management; PS physical security 20 CC6.4 physical access; CC6.5 disposal; CC6.1 asset scope High
OPS Operations (capacity, malware, backup, logging, vulnerabilities, incidents, patching, dataset separation, confidential computing, containers) 35 CC7 system operations; A1 availability; CC6.6–6.8 High in substance; C5 far more specific — confidential computing and container criteria have no SOC 2 counterpart
IAM Identity and access; CRY cryptography 28 CC6.1–6.3 logical access; CC6.7 transmission; CC6.1 encryption High; C5’s 19 cryptography criteria including key lifecycle and customer-managed keys go beyond SOC 2
COS Communication security; PI portability and interoperability 11 CC6.6 boundaries; CC6.7; no portability equivalent Partial
DEV Procurement, development and modification; SSO service providers and suppliers 23 CC8 change management; CC9.2 vendor risk High
SIM Security incident management; BCM business continuity 10 CC7.3–7.5 incidents; A1.2–A1.3 continuity High
COM Compliance; INQ investigation requests; PSS product safety and security 20 CC1, CC2; no INQ equivalent; PSS partly in CC8 and the privacy category Partial — INQ and PSS are C5-specific

BSI publishes a cross-reference table mapping C5 criteria to other standards, and states in the catalogue that the mapping shows thematic relationship only: coverage of a C5 criterion by another audit’s results must be assessed individually, and referring to the mapping is not enough. That is the honest summary of reuse. Our guide to C5 criteria covers the 17 objectives.

BSI C5 vs SOC 2 reuse: can one report serve the other?

Not as a report; substantially, as evidence. The catalogue itself says it is more efficient to align a C5 audit with existing ISAE 3402/SOC 1 or SOC 2 audits “both in terms of organisation and timing”, so that records serve reporting to different standards simultaneously — which is what providers holding both do: one system description with two criteria mappings, one evidence period, one auditor or two coordinated ones, two reports.

What does not transfer is the C5-specific content: the general conditions, the complementary customer criteria, the additional criteria decision, and the criteria SOC 2 has no counterpart for. A provider with a clean SOC 2 type 2 typically arrives at C5 with most of OPS, IAM, CRY, DEV and SIM evidenced and with gaps in INQ, PSS, PI, the general conditions and the more specific cryptography and operations criteria. Our guide to BSI C5 vs ISO 27001 covers the certification-side comparison.

Frequently asked questions

What is the difference in BSI C5 vs SOC 2?
Both are auditor examination reports in type 1 and type 2 forms, but C5 tests the provider against a prescriptive catalogue — 17 objectives and 168 criteria in C5:2026, with basic and additional subcriteria, general conditions and complementary customer criteria — while SOC 2 tests the provider’s own controls against the AICPA’s principles-based trust services criteria. C5 serves the German and EU public and regulated market; SOC 2 serves US-led enterprise procurement.

Is C5 stricter than SOC 2?
It is more specific. Where SOC 2 asks whether encryption is used appropriately, C5 has 19 cryptography criteria covering key generation, rotation, storage, archival, compromise and customer-managed keys. Whether that is stricter depends on the controls a SOC 2 provider chose; a C5 gap is always a named criterion.

Can a SOC 2 report satisfy a C5 requirement?
No. § 393 SGB V, the federal minimum standard and public tenders ask for a C5 attestation. SOC 2 evidence shortens the C5 audit substantially — BSI recommends aligning the audits — but the C5 report is produced against the C5 criteria.

Which should a provider get first?
Whichever the target customers ask for. US enterprise and global SaaS buyers: SOC 2. German public sector, healthcare and EU regulated buyers: C5. Providers selling into both run the audits together on one evidence base.

Are the auditors the same?
Both use public accountancy firms working under assurance standards — ISAE 3000 (Revised) or IDW PS 860 for C5, SSAE 18 for SOC 2 — and BSI takes no part in selecting or approving C5 auditors. Many firms do both, which is what makes a combined engagement practical.

Where this leaves you

Treat BSI C5 vs SOC 2 as two reports from one evidence base: the same system description, the same operating period, the same auditor where possible, and two criteria mappings — SOC 2’s principles satisfied by your controls, C5’s 168 criteria met as written with the general conditions disclosed and the customer criteria stated. Buy the one your market asks for first; build so the second is an extension rather than a second programme.

References

More on BSI C5

The criteria-by-criteria control mapping for all 17 C5 objectives, the system description template, the general conditions disclosure, the complementary customer criteria statement and the evidence records an examination is built from are in the BSI C5:2026 Cloud Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.