BSI C5 · READINESS

BSI C5 readiness guide

This page helps cloud providers and cloud customers self-assess against the BSI C5 criteria (Cloud Computing Compliance Controls Catalogue).

Framework scope

Relevant for German organizations operating or procuring cloud services with sensitive data, especially under KRITIS, BSI IT-Grundschutz and data processing requirements.

C5 groups requirements into areas such as information security management, operations, data protection, identity management, logging, networking and supplier management. It forms the basis for the BSI C5 attestation audit under CC5/CC6.

Orientation score

0%

0 / 100 points

Evidence examples

  • Security concept and ISMS documentation
  • Risk assessment with remediation plan
  • Access and permissions concept with review evidence
  • MFA configuration exports or screenshots
  • Logging architecture and analysis records
  • Network diagrams and hardening evidence
  • Contracts and security questionnaires for sub-service providers

Common gaps

  • C5 criteria are not fully mapped to the organization's cloud architecture
  • Missing regular access and permission reviews
  • Logging is incomplete or not analysed
  • Sub-service providers are not contractually covered
  • BC/DR plans exist but are not demonstrably tested

CloudForge workflow

CloudForge offers C5 criteria as actionable controls, collects evidence per domain, runs internal readiness assessments and prepares audit evidence for the BSI C5 attestation.

Official references

  • BSI-CS 132: C5:2020 Cloud Computing Compliance Controls Catalogue
  • BSI C5 attestation and audit criteria for cloud services (CC5/CC6)

Assessments must be validated with owners, scope and reliable evidence. This page is not a BSI C5 attestation or certification.

This guide is for orientation and preparation. It does not replace a formal BSI C5 attestation and does not automatically lead to certification or confirmation by the BSI.

CloudForge Team — Cloud, Container and AI under control