BSI C5: cloud security attestation for banks
BSI C5, the Cloud Computing Compliance Criteria Catalogue, is a catalog of cloud security requirements published by Germany's Federal Office for Information Security (BSI), first in 2016. A cloud provider has an auditor test its service against the criteria and receives an attestation report that customers can read, as the BSI page on C5 explains.
German banks meet C5 when they outsource to the cloud. BaFin names C5 among the third-party reports that a bank's internal audit may use, and it also says where that use ends.
What a C5 attestation contains
The catalog has basic criteria that every attested provider meets and additional criteria for higher protection needs. The provider writes a description of its system, and a public auditor tests it under the assurance standard ISAE 3000 (Revised). A Type 1 report confirms that the controls are suitably designed at a point in time. A Type 2 report also tests whether they worked over a period.
The attestation has spread beyond finance. According to Rödl & Partner, German healthcare law has required a C5 Type 2 attestation for cloud services that process health data since July 1, 2025.
How BaFin and the ECB treat C5 reports
The BaFin notice on cloud outsourcing of February 2024 (in German) lets internal audit draw on certificates and audit reports from third parties, naming ISO 27001, BSI C5, SOC 2 and the CSA Cloud Controls Matrix. For material outsourcing, internal audit may not rely on them alone. It reads the full report, not only the certificate, and checks that the scope covers the services the bank actually uses.
The ECB's guide on cloud outsourcing takes the same line for the banks it supervises: internal audit cannot rely solely on certifications. A C5 report therefore shortens a bank's own audit work and does not replace it.
What C5:2026 adds
The BSI has revised the catalog as C5:2026. According to IT Finanzmagazin (in German), the new version covers container management, post-quantum cryptography and confidential computing for the first time, and it is mapped to the European cloud scheme EUCS, the CSA Cloud Controls Matrix v4, ISO 27001:2022 and NIS2. For banks, the cryptography criteria connect to their own migration plans, see post-quantum cryptography in finance.
Upcoming events on digital infrastructure
Is BSI C5 a certification?
No. The BSI publishes the criteria and does not certify providers. A public auditor tests the provider and issues an attestation report, so the correct term is attestation, not certificate. Customers then read the report to see which criteria were tested and with what result.
What is the difference between BSI C5 and ISO 27001?
ISO 27001 certifies an information security management system of any organization. C5 is written for cloud services, sets detailed criteria for them, and its Type 2 report describes each test and its result. A bank gets more detail from a C5 report than from an ISO certificate, and the large cloud providers hold both.
Which country is BSI C5 for?
C5 comes from Germany and is published by the German federal agency for IT security. Providers from other countries use it to sell to German customers in finance and the public sector, and Amazon Web Services and Microsoft Azure publish C5 reports for their services.
BSI C5 and Finance Loop
Finance Loop brings the internal auditors and outsourcing managers of German banks together with the cloud providers whose C5 reports they read, in its Digital Infrastructure & Sovereignty track. Finance Loop offers an audit firm or provider a sponsored webinar to walk banks through what changed in C5:2026.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.