Frameworks · UK & Europe
BSI C5:2020
The German Federal Office for Information Security (BSI) developed the Cloud Computing Compliance Criteria Catalogue, C5:2020. It assesses the information security of cloud services against a consistent audit baseline built on internationally recognised standards such as ISO/IEC 27001. It sets minimum requirements for secure cloud computing for professional providers, their auditors and their customers. The 2020 edition adds criteria on product safety and security.
Who it applies to
It applies to cloud service providers that sell to German federal and public-sector bodies. It also applies to providers that sell to regulated German enterprises whose supervisors expect a C5 attestation.
Main requirements
Organisation & governance
This area covers the information security organisation, policies, personnel and asset management.
Operations
This area covers physical security, operations, identity and access, cryptography, communications and portability.
Product security
C5:2020 introduced criteria for secure development, product safety and product security.
Transparency
Providers supply a system description and the additional transparency information that customers rely on.
How xmodo supports it
- 1
The catalogue is set up with each of its criteria, and xmodo generates the system description from the systems and controls in scope.
- 2
Criteria map to ISO/IEC 27001, ISO/IEC 27017 and SOC 2, because C5 attestations are commonly issued alongside them.
- 3
The attestation runs as an engagement, and the auditor's evidence requests go through the portal.
Related frameworks
BSI C5:2020 shares requirements with the frameworks below. Controls you already run for any of them count towards BSI C5:2020 as well.
Frequently asked questions
Is C5 a certification?
It is an attestation by an independent auditor against the BSI catalogue, reported in a form comparable to SOC 2. xmodo runs the engagement and holds the report in the trust center under NDA.