Who needs BSI C5 is answered by law in one sector, by the federal government’s own rules in another, and by procurement in the rest. The Cloud Computing Compliance Criteria Catalogue is not a general legal obligation; a cloud provider is not fined for lacking a C5 attestation. It becomes mandatory when a customer cannot lawfully or contractually use the service without it — and in Germany that now includes every provider whose cloud service processes health or social data for healthcare providers and insurers, because § 393 SGB V makes a current C5 attestation a condition of the processing, and every provider whose customer is a federal agency bound by the BSI’s minimum standard for external cloud services.
Beyond those, regulated financial and insurance buyers, critical-infrastructure operators, public bodies at state and municipal level, and enterprise procurement in Germany and increasingly the EU ask for it as the evidence of choice. This guide sets out the five groups of customers whose demands make C5 necessary, the legal texts behind the two hard cases, what each group actually requires — type, criteria, currency — and how a provider decides whether to invest.

Who needs BSI C5: the five groups
| Customer group | Basis | What is required | How hard |
|---|---|---|---|
| 1. Healthcare: statutory health and care insurers, healthcare providers, and their processors, processing social or health data in the cloud | § 393 SGB V (Digital Act, in force since 2024) | A current C5 attestation on the basic criteria for the cloud systems and technology used; type 1 accepted until 30 June 2025, type 2 from 1 July 2025 (new systems: type 1 for the first 18 months, type 2 from month 19); the complementary customer criteria in the report implemented; processing in Germany, the EU, an equivalent state or an adequacy country, with an establishment in Germany | Legal condition of the processing |
| 2. Federal administration | BSI minimum standard for the use of external cloud services under § 8(1) BSIG, binding on federal agencies | Proof of the service’s security through suitable audits — the standard’s requirements point at a C5 attestation — plus transparency about the service’s provision | Binding on the agency, hence on its suppliers |
| 3. Regulated financial services and insurance | Supervisory expectations on outsourcing and ICT risk (BaFin’s outsourcing guidance; DORA for ICT third-party risk since January 2025) | Evidence of the provider’s control effectiveness; a C5 type 2 is the German-market answer alongside SOC 2 and ISO 27001 | Expected, not named in law |
| 4. KRITIS operators and state and municipal public bodies | BSIG obligations for critical infrastructure; state procurement rules and IT security guidelines | Cloud providers to critical-infrastructure operators and public bodies are asked for C5 as the recognised German baseline | Procurement condition |
| 5. Enterprise and EU procurement; EUCS-oriented buyers | Supplier due diligence; C5:2026’s compatibility with EUCS level Substantial | A C5 report as comparable, criteria-level evidence; increasingly requested by EU buyers preparing for EUCS | Commercial |
Who needs BSI C5 by law: healthcare under § 393 SGB V
The provision is specific enough to quote in substance. Healthcare providers, health and care insurers and their processors may process social and health data by cloud computing only if: the processing takes place in Germany, an EU member state, an equivalent state or an adequacy-decision third country, and the processing entity has an establishment in Germany; state-of-the-art technical and organisational measures are in place; a current C5 attestation of the processing entity exists with regard to the C5 basic criteria for the cloud systems and technology used; and the complementary criteria for customers contained in the attestation report are implemented.
Until 30 June 2025 a type 1 counted as current; from 1 July 2025 a current type 2 is required; a system first placed on the market after 30 June 2025 may rely on a type 1 for its first 18 months and needs a type 2 from month 19.
The Federal Ministry of Health may, by ordinance with the BSI, recognise other standards of comparable or higher security, and attested systems are listed by the interoperability competence centre. Two consequences follow for providers: the attestation has to be current, which means an annual type 2, and the customer’s obligation to implement the complementary criteria makes the provider’s statement of them a legal document. Our guide to complementary customer controls covers that statement.
Who needs BSI C5 in government: the federal minimum standard
Under § 8(1) of the BSI Act the BSI sets minimum standards for federal agencies, and the minimum standard for the use of external cloud services covers, in BSI’s description, information security, transparency of cloud service provision and proof of these aspects by means of suitable audits.
A federal agency deciding to buy a cloud service is the client and must apply the standard; the provider therefore has to supply the audit evidence the standard specifies, which is where the C5 attestation sits. A separate minimum standard covers shared use — where agency staff use a cloud service without a contract between the agency and the provider — with lighter requirements. Our guide to BSI C5 covers the catalogue the attestation is issued against.
What each group actually requires
| Group | Type | Criteria | Currency | Also |
|---|---|---|---|---|
| Healthcare (§ 393 SGB V) | Type 2 (type 1 only for new systems’ first 18 months) | Basic criteria as a minimum | Current — annually in practice | Complementary customer criteria implemented by the customer; location and establishment conditions |
| Federal administration | Type 2 expected | Basic; additional where the agency’s protection need requires | Current | Transparency on service provision; integration into the agency’s IT-Grundschutz management |
| Financial and insurance | Type 2 | Basic plus additional criteria relevant to the data | Annual, aligned to the supervisory review cycle | Often alongside SOC 2 and ISO 27001; DORA register entries |
| KRITIS and public bodies | Type 2 preferred | Basic, with additional criteria for higher protection needs | Annual | Tender-specific conditions |
| Enterprise and EU | Type 2 | Basic; additional criteria as a differentiator | Annual | Comparison against EUCS Substantial expectations |
Deciding who needs BSI C5 in your own pipeline
- List the customers by group. One hospital, insurer or federal agency in the pipeline makes the decision; the attestation is a condition of their contract, not a preference.
- Check what you already hold. OIS-01.01B requires an ISO 27001-compliant ISMS; a SOC 2 type 2 evidences most operational criteria. Both shorten the path. Our guides to BSI C5 vs ISO 27001 and BSI C5 vs SOC 2 cover what transfers.
- Plan for type 2. Every group above expects it; the type 1 is a staging post, and for healthcare a new system’s 18-month allowance is the only exception.
- Decide the additional criteria by customer. Basic satisfies the law; higher protection needs in finance, KRITIS and federal use may require sharpening or complementing subcriteria.
- Price it honestly. Our guide to BSI C5 attestation cost gives the estimate by profile.
- Treat it as annual. A current attestation is a repeating obligation for the healthcare and federal groups, and the report’s period has to cover the customer’s use.
Who does not need BSI C5
- Providers with no German or EU public, healthcare, regulated or enterprise customers — SOC 2 and ISO 27001 serve the rest of the world.
- Customers, as such. C5 attests the provider; the customer’s obligation is to obtain and read the report, implement the complementary customer criteria, and repeat the review — annually, in BSI’s recommendation.
- On-premise software vendors — C5 is a cloud service catalogue; software the customer runs itself is outside it.
- Providers whose customers accept an equivalent — § 393 SGB V allows an ordinance to recognise standards of comparable or higher security; none replaces C5 for healthcare until it is issued.
Frequently asked questions
Who needs BSI C5 as a requirement?
No one by general law, but cloud providers to two groups in effect: healthcare providers, insurers and their processors under § 393 SGB V, which makes a current C5 attestation (type 2 since 1 July 2025) a condition of processing health and social data in the cloud; and federal agencies bound by the BSI minimum standard for external cloud services. Regulated financial buyers, KRITIS operators, public bodies and enterprise procurement require it commercially.
Does a hospital need its own C5 attestation?
No. C5 attests the cloud provider. The hospital’s obligations under § 393 SGB V are to use a provider with a current attestation, to implement the complementary customer criteria in the provider’s report, and to meet the location and establishment conditions.
Is type 1 enough?
For healthcare, only for a system first placed on the market after 30 June 2025, and only for its first 18 months; otherwise a current type 2 is required since 1 July 2025. Federal, financial and enterprise buyers expect type 2 as well.
Does C5 apply outside Germany?
The law does not, but C5:2026 was built for compatibility with EUCS level Substantial, and EU buyers preparing for EUCS increasingly accept or request it. Outside the EU, SOC 2 and ISO 27001 remain the currency.
Can another standard substitute for C5 in healthcare?
Only if the Federal Ministry of Health, by ordinance with the BSI, recognises it as providing comparable or higher security under § 393(4) SGB V. Until such an ordinance names a standard, C5 is the requirement.
Where this leaves you
Decide who needs BSI C5 by customer, not by preference: a healthcare or federal customer makes it a condition, a regulated or public-sector customer makes it the expected evidence, and an enterprise or EU buyer makes it a differentiator. If any of the first two are in your pipeline, plan the type 1 now and the type 2 within the year — and state the complementary customer criteria carefully, because in healthcare the customer’s compliance depends on them.
References
- § 393 SGB V — Cloud-Einsatz im Gesundheitswesen; Verordnungsermächtigung (gesetze-im-internet.de) — The healthcare requirement: current C5 attestation on the basic criteria, type 2 from 1 July 2025, complementary customer criteria, location and establishment.
- BSI — Minimum standards for the use and shared use of external cloud services — The federal administration’s binding minimum standard under § 8(1) BSIG.
- BSI — Cloud Computing Compliance Criteria Catalogue (C5) — The catalogue, its users, and BSI’s recommendation that customers review reports annually.
More on BSI C5
- Who needs BSI C5 — you are here
- BSI C5: the complete guide
- BSI C5 attestation: type 1 and type 2
- Complementary customer controls in C5
- BSI C5 attestation cost
- C5 criteria: the 17 objectives
The system description template, the general conditions disclosure, the complementary customer criteria statement that healthcare customers depend on, and the control documents for all 17 objectives are in the BSI C5:2026 Cloud Toolkit, or start with the free templates.