C5 went from 121 criteria to 168, and the switchover is 1 June 2027. C5:2026 was published on 7 April 2026 and applies to type 1 engagements with specified dates after 1 June 2027, and type 2 engagements for periods beginning on or after it. Today you are still being attested against C5:2020.
This assessment scores 73 questions across all 17 domains of C5:2026, including the container management, confidential computing and dataset separation criteria that are new in this edition, plus the system description and customer responsibility boundary where C5 engagements most often come unstuck. It is free, it saves as you go, and you can stop and come back to it.
What this is
The domain count did not change but two abbreviations did: IDM became IAM, and INV became INQ. The bigger structural change is that criteria are now decomposed into subcriteria, and additional criteria are split into sharpening ones that replace a basic subcriterion with something stricter, and complementing ones that add a requirement the basic criteria do not cover. BSI restructured it this way for compatibility with the EUCS Substantial level.
The background is elsewhere — what C5 is, the criteria, how attestation works, what it costs, who needs it, against ISO 27001 and against SOC 2. Come here when you want a score.
What it covers
73 questions, about 45 minutes.
| Section | Questions |
|---|---|
| Governance, policy and people | 12 |
| Assets and physical security | 7 |
| Operations | 13 |
| Identity and cryptography | 10 |
| Communications, portability and suppliers | 8 |
| Development | 5 |
| Incidents, continuity, compliance and investigations | 8 |
| Product security and the attestation | 10 |
How the scoring works
| Status | Weight | Means |
|---|---|---|
| Not started | 0% | No policy, process or activity exists |
| Planned | 25% | Agreed and scheduled, nothing in place yet |
| Partially implemented | 50% | In place for part of the scope, or applied inconsistently |
| Implemented, not evidenced | 75% | Operating as intended, but you could not prove it today |
| Implemented and evidenced | 100% | Operating as intended, with records someone could sample |
| Not applicable | — | A justified exclusion, removed from the score |
C5 is an attestation engagement under ISAE 3000, not a certification, and only an audit firm can issue one. BSI publishes the catalogue and nothing else — it does not accredit auditors, approve reports or keep a register of attested providers.
Free score, or the full report
The assessment and your overall score are free. The full report is a one-off $39 and gives you every question with your status and notes, the score broken down by section, a prioritised gap list, and the documents from the BSI C5:2026 Cloud Toolkit that close each gap — as a PDF and a working Excel file.
How long does it take?
About 45 minutes. Operations and cryptography carry the most weight — between them they are 54 of the 168 criteria, and key lifecycle management is where the 2026 edition grew most.
What to do with your score
Below 40% — start with the system description. You write it, not the auditor, and the auditor opines on it. Everything else in a C5 engagement is read against that document.
40–70% — the usual shape for a provider with an ISO 27001 certificate. BSI states the C5 basic criteria include all of the ISO 27001 criteria, so the gap is almost always in the C5-specific domains: portability, investigation requests, product security and the new 2026 subject matter.
Above 70% — pin down the complementary customer controls. The auditor assesses whether your assumptions about what the customer does are fairly presented, but never tests whether customers actually do it. Undocumented assumptions are the quiet failure.
Frequently asked questions
Is this assessment really free?
Yes. All 73 questions, the breakdown by domain and your overall score cost nothing. The $39 report is optional.
Should I assess against C5:2020 or C5:2026?
This assessment is written to C5:2026. If your next engagement covers a period ending before 1 June 2027 you will still be attested against C5:2020, so treat the result as readiness for the switchover rather than as a finding against your current attestation.
Does a C5 attestation expire?
Not formally — it reports on a period that has already ended. But BSI notes that an attestation several years old is of little use, and customers expect annual, gap-free coverage.
Do I need a type 2 report?
BSI’s position is that a type 2 carries the real information value, because it covers operating effectiveness across a period. Type 1 is essentially for a first engagement where period evidence does not exist yet.
Can I use this for a client?
Yes. Run one assessment per client organisation.
What happens to my answers?
They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.