BSI C5 is Germany’s cloud security criteria catalogue, and in 2026 it stopped being a purely German document. The revised C5:2026 was deliberately built to be compatible with the European Union Cybersecurity Certification Scheme for Cloud Services at level Substantial.
That makes this the most consequential C5 release since the catalogue first appeared in 2016 — not because the criteria changed most, but because of what they are now aligned to.
What BSI C5 is
The Cloud Computing Compliance Criteria Catalogue sets a baseline security level for cloud services. It is published by the Federal Office for Information Security and used by three groups at once: providers implementing it, auditors examining it, and customers reading the resulting reports.
The mechanism is unusual and worth understanding, because it is not a certification.
A provider engages auditors — certified public accountants or equivalent — who examine whether the criteria are met, and depending on the engagement type whether they were met over a past period. The output is a detailed examination report to international standards, including a system description. BSI states plainly that it is not involved in selecting auditors and does not check the reports.
So the assurance model puts the work on the customer. You request the report, you analyse it, you decide whether the baseline is sufficient for your use case, and you carry the residual risk. BSI recommends repeating that annually. Over a hundred attestations have been granted to date, across global, European and smaller providers.
What changed in BSI C5:2026

C5:2026 was released first as a community draft for public comment, with the final version published by the end of March. It builds on C5:2020 — many tried-and-tested criteria are preserved — and adds to reflect six years of change.
The EUCS loop, and why it matters
This is the part of the BSI C5 story that most summaries miss.
The relationship between BSI C5 and the European scheme runs in a circle, and it is the single most useful thing to understand about this release.
C5:2020, as a widely used international cloud security standard, served as the basis for developing the planned EUCS level Substantial. Those requirements were handed to CEN/CENELEC to produce a Technical Specification. That work — improved along the way — then came back as a major ingredient of C5:2026, with compatibility to EUCS Substantial deliberately ensured.
The practical consequence for a provider: work done for C5:2026 is not stranded German-market effort. It is aligned with where European cloud certification is heading, which is a different investment case from where C5 stood five years ago.
Three other frameworks were also folded in: the CSA Cloud Controls Matrix v4, ISO/IEC 27001:2022, and the NIS2 Directive.
The BSI C5 structural change auditors will notice first
C5:2026 was restructured in line with EUCS, and it changes how you document compliance.
Criteria now consist of subcriteria that are distinct from one another in content. This makes it materially easier to map C5 onto the controls in your internal control system, easier to audit, and clearer when someone is evaluating the resulting report.
Additional criteria are now explicitly classified. There are two kinds, and they behave differently:
- Additional sharpen — stricter versions of a basic subcriterion. Where applied, they replace the basic subcriterion.
- Additional complement — genuinely new requirements that sit alongside the basic criteria and must also be checked in the audit.
BSI describes this as making an already implicit distinction explicit, and it is the sharpest edge in the new BSI C5 text. If you have run a C5 audit before, this is the change most likely to alter your scoping conversation, because which additional criteria apply is specified in the report itself.
New technical ground in BSI C5
The revision added criteria in areas that barely featured in 2020:
- Container management and supply chain management.
- Post-quantum cryptography — its appearance in a national baseline catalogue is a signal about direction of travel.
- Confidential computing.
- Client separation and the technical implementation of sovereignty, which is where the European policy debate has concentrated.
- Sharper applicability to different data types, following common feedback that C5:2020 was ambiguous here.
One quiet but significant addition: C5:2026 is published in machine-readable YAML for the first time, alongside PDF and Excel. If you run a GRC platform, that is the difference between typing criteria in and importing them.
How BSI C5 relates to what you may already hold
| Standard | Relationship |
|---|---|
| ISO 27001 | The 2022 edition was considered in the revision. ISO 27001 is a certifiable management system; C5 produces an examination report. They answer different questions and most German-market providers hold both |
| CSA STAR | CCM v4 fed into C5:2026. If you have completed a CAIQ, a substantial part of the control thinking transfers |
| NIS2 | Also considered in the revision. C5 is a defensible way of evidencing cloud security measures where NIS2 obligations apply |
| SOC 2 | Structurally the closest analogue — an examination report by an accountant rather than a certificate. The criteria differ; the reporting model does not |
Where to start
- Read the changelog before anything else. BSI publishes one specifically so you can see what moved from C5:2020.
- Take the YAML. Import the criteria rather than rekeying them.
- Decide which additional criteria apply, and be clear which are sharpen and which are complement — it changes what gets audited.
- Map subcriteria to your existing controls. This is what the new structure was designed to make possible.
- Engage the auditor early, since BSI takes no part in selecting them and the engagement type determines whether past periods are covered.
- If EUCS matters to your market, say so in scoping — the alignment is the point of this release.
This guide reflects bsi.bund.de at 15 August 2026. The cross-reference table mapping C5:2026 to international standards was still scheduled for publication at that date — worth watching if you are planning an integrated audit.
The BSI C5:2026 Cloud Toolkit provides 107 editable compliance templates covering the criteria mapping, the system description, the control implementation records and the evidence an examination report is built from.