C5 Pre-Assessment for Cloud Providers Serving German Entities

Understanding the Role of Independent Evaluation in Germany’s Cloud Assurance Environment

Why More EU Customers Are Referencing C5 in Cloud Vendor Evaluations Image

Introduction

Cloud providers entering the German market often encounter assurance expectations that differ from those applied elsewhere in Europe.

One of the most prominent is the Cloud Computing Compliance Criteria Catalogue, commonly known as C5. Developed by Germany’s Federal Office for Information Security, or BSI, C5 provides criteria for assessing the information security of cloud services. It is designed for professional cloud service providers, their auditors, and the organizations purchasing or using those services. (BSI)

C5 is sometimes discussed as though it were a general requirement for every cloud provider operating within the European Union. That framing is too broad.

C5 is primarily connected to the German market. An organization may encounter it when supplying cloud services to:

  • German public authorities
  • German healthcare entities
  • German regulated organizations
  • Private German enterprises
  • International customers that explicitly incorporate C5 into vendor requirements

 

Cloud providers elsewhere in the EU may also adopt C5 voluntarily. However, it should not be presented as a universal EU requirement. Outside Germany, its relevance is generally determined by a customer request, procurement condition, contractual obligation, or defined sector-specific expectation.

This distinction is important for B2B SaaS companies and other cloud providers evaluating whether C5 is relevant to a particular customer relationship.

C5 Is a German Cloud Assurance Framework

C5 was established by the BSI to provide a consistent basis for examining the information security controls of cloud services.

The framework defines criteria against which the cloud provider’s internal control environment can be evaluated. It also places considerable emphasis on transparency, including information that customers need when assessing the allocation of responsibilities between the provider and the cloud user.

The BSI describes C5 as applicable to professional cloud service providers, auditors, and customers. It also provides materials for customers evaluating C5 reports, including consideration of the provider’s security measures, the related audit results, and the user controls assigned to the cloud customer. (BSI)

This customer-facing dimension is particularly relevant. C5 is not limited to determining whether technical safeguards exist. It also examines whether the service description, control environment, responsibilities, and transparency information provide an adequate basis for independent assurance.

C5 Is Not a General EU Requirement

C5 has influenced cloud security discussions beyond Germany, and the BSI has described it as a catalogue implemented both nationally and internationally. Elements of C5 have also contributed to wider European cloud security initiatives. (BSI)

However, international recognition does not mean that C5 applies automatically to every cloud service offered in the EU.

For organizations outside Germany, the key question is not simply:

“Do we have EU customers?”

The more relevant questions are:

  • Does the cloud service supply a German entity?
  • Has a German customer referenced C5 in procurement documentation?
  • Does a contract require evaluation against C5 criteria?
  • Is the service being considered by a German public authority or regulated organization?
  • Has a specific customer requested independent C5 assurance?

A cloud provider serving customers in France, Spain, Italy, or another EU jurisdiction may not encounter C5 at all. Another provider based outside Europe may receive a direct C5 requirement because it supplies a German customer.

The determining factor is therefore often the German customer relationship or the explicit assurance requirement, rather than the provider’s headquarters.

Why German Entities Reference C5

German customers may use C5 to establish a structured basis for evaluating cloud service providers.

Instead of relying entirely on questionnaires, policy statements, or broad claims about security, the customer can examine evidence against defined criteria. This creates a more consistent basis for understanding the cloud service and the provider’s control environment.

C5 may appear during:

  • Cloud vendor selection
  • Enterprise procurement
  • Third-party risk evaluation
  • Contract renewal
  • Public-sector acquisition
  • Customer due diligence
  • Regulatory or internal governance review

 

For German public administration, the BSI also maintains a minimum standard for the use of external cloud services. The BSI notes that a C5 attestation may be considered within procurement and assessment activities, while also clarifying that a C5 attestation alone is not necessarily sufficient to satisfy every requirement of that minimum standard. (BSI)

This is an important distinction. C5 may form part of a wider evaluation, but it should not automatically be represented as satisfying every German legal, procurement, or sectoral obligation.

The precise requirement depends on the organization, service, contract, sector, and defined scope.

What C5 Evaluates

C5 focuses on the information security of cloud services and the controls surrounding their delivery.

Depending on the applicable criteria and defined assessment scope, the evaluation may address areas such as:

  • Security governance and organizational responsibilities
  • Security policies and control documentation
  • Personnel-related security measures
  • Asset management
  • Physical security
  • Operational security
  • Identity and access management
  • Cryptographic mechanisms
  • Communication security
  • Vulnerability and configuration management
  • Incident detection and handling
  • Business continuity arrangements
  • Supplier and subcontractor relationships
  • Compliance-related controls
  • Product security
  • Transparency information provided to customers
  • Responsibilities assigned to the cloud provider and cloud user

 

C5:2020 expanded the framework to address developments in cloud delivery, including product security, government investigation requests, shared responsibilities, and criteria relevant to continuous auditing. (BSI)

The applicable assessment scope must still be defined for the specific cloud service. A provider may operate several products, environments, geographic regions, or deployment models. A C5 evaluation should therefore identify which service, infrastructure, locations, systems, processes, and organizational units fall within the assessment boundary.

What Is a C5 Pre-Assessment?

A C5 Pre-Assessment is an independent, point-in-time evaluation of a defined cloud service against applicable C5 criteria before formal C5 attestation.

It examines the control environment and evidence available at the time of the engagement.

The assessment may consider:

  • The defined cloud service and assessment boundary
  • The provider’s description of the service
  • Applicable C5 criteria
  • Documented policies and procedures
  • Technical and organizational controls
  • Evidence demonstrating control operation
  • Transparency disclosures
  • Customer and provider responsibilities
  • Dependencies on subcontractors and external service providers
  • Conditions observed during the assessment

The outcome is a structured record of the criteria evaluated and the conditions observed.

A C5 Pre-Assessment does not result in formal C5 attestation. It does not replace the formal examination, and it does not determine or guarantee the outcome of a later attestation engagement.

Why Scope Definition Matters

Cloud services frequently rely on complex technical and organizational environments.

A SaaS platform may operate across multiple cloud accounts, regions, development environments, identity systems, data stores, and external providers. The organization may also offer different products or service tiers under the same corporate name.

A meaningful C5 Pre-Assessment therefore requires a clearly defined boundary.

The scope may include:

  • The specific cloud service being evaluated
  • Production infrastructure used to deliver the service
  • Supporting systems that affect service security
  • Personnel and organizational functions within the control environment
  • Data processing and storage locations
  • Identity and privileged access mechanisms
  • External providers and subcontractors
  • Customer-facing transparency information
  • The assessment period or point in time
  • Applicable C5 criteria

Without a clearly stated scope, stakeholders may incorrectly assume that an evaluation covers the provider’s entire organization or every service it offers.

The assessment documentation should identify what was included and any relevant boundaries or exclusions.

What Evidence May Be Examined

A C5 Pre-Assessment is evidence-based.

The existence of a policy alone may not demonstrate that a control is operating. Depending on the criterion, the evaluation may examine documentation, technical records, system configurations, operational records, or other evidence associated with the defined control.

Examples may include:

  • Information security policies
  • Organizational responsibility records
  • Access control procedures
  • User access and privileged-access records
  • Authentication configurations
  • Change-management records
  • Vulnerability-management records
  • Security-event records
  • Incident records
  • Backup and recovery evidence
  • Business continuity documentation
  • Encryption configurations
  • Supplier oversight records
  • Data-location information
  • Service descriptions
  • Customer responsibility statements
  • Subcontractor disclosures

The evidence selected depends on the criterion, assessment scope, service architecture, and nature of the control.

The purpose is to determine what the available evidence demonstrates against the applicable C5 criteria.

C5 Pre-Assessment and Formal Attestation Are Different Activities

The distinction between a pre-assessment and formal attestation must remain clear.

C5 Pre-Assessment

A pre-assessment:

  • Occurs before formal attestation
  • Evaluates a defined service against applicable C5 criteria
  • Is based on the agreed scope and evidence examined
  • Produces documented assessment findings
  • Does not issue a formal C5 attestation report
  • Does not guarantee a later attestation outcome

Formal C5 Attestation

Formal C5 attestation:

  • Is conducted under defined assurance and reporting requirements
  • Involves a formal examination of the cloud service provider’s control environment
  • Results in an assurance report
  • Includes a formal conclusion issued under the applicable professional requirements

The BSI describes C5 evidence through an assurance report based on established professional examination standards. It also makes clear that C5 is not a certification issued by the BSI. (BSI)

Accordingly, marketing language should not describe an organization as “C5 certified.” The accurate terms are C5 attestation, C5 examination, or C5 report, depending on the specific context.

Why Independent Evaluation Matters

C5 is intended to provide credible information about a cloud provider’s security controls and transparency statements.

That credibility depends on a clear separation between control ownership and independent evaluation.

The cloud provider remains responsible for:

  • Defining its control environment
  • Operating its cloud service
  • Maintaining its documentation
  • Producing the evidence associated with its controls
  • Establishing its customer and provider responsibilities

The independent assessment body evaluates the defined criteria and available evidence. It does not design or implement the provider’s controls.

Consilium Labs performs C5 Pre-Assessments as an independent conformity assessment body. The engagement is limited to objective, evidence-based evaluation against the defined C5 criteria and the documentation of assessment findings.

This preserves the separation required for credible independent assurance.

When a C5 Pre-Assessment May Be Relevant

A C5 Pre-Assessment may be considered when an organization has a defined reason to examine its cloud service against C5.

Examples include the following.

A German Enterprise Includes C5 in Vendor Evaluation

A B2B SaaS provider supplies a cloud-based platform to a German enterprise. During procurement, the customer requests independent evidence against defined C5 criteria.

The pre-assessment examines the specified service, applicable controls, and available evidence within the agreed boundary.

A cloud provider headquartered outside Germany begins supplying services to German customers.

The provider encounters C5 references in procurement questionnaires and contractual documentation. A pre-assessment provides an independent evaluation of the defined service before a separate formal attestation engagement is considered.

A healthcare technology provider supplies a cloud service to a German healthcare entity.

The customer includes C5 criteria in its third-party evaluation. The assessment scope may include the service environment, access controls, operational security, incident processes, data handling, and relevant external providers.

The presence of a German healthcare customer does not automatically create the same C5 requirement in every engagement. The applicable requirement must be established from the customer’s documentation, contract, procurement criteria, or other relevant source.

A provider seeks to supply an external cloud service to a German public authority.

C5 may be referenced as part of the authority’s evaluation of the service. Other public-sector requirements may also apply, and a C5 report should not be represented as automatically satisfying all of them. (BSI)

A German customer specifies C5 within its vendor assurance requirements, even where no general statutory obligation has been established for that particular service.

In this situation, C5 becomes relevant because of the contractual relationship and the customer’s defined evaluation criteria.

An EU-based cloud provider without a current German customer may still choose to evaluate a service against C5.

This is a voluntary use of the framework. It should not be described as an EU-wide requirement unless a specific legal, regulatory, contractual, or procurement basis has been identified.

Questions to Clarify When C5 Is Requested

When a customer references C5, the requirement should be examined carefully.

Important questions include:

  • Which customer or contracting entity is requesting C5?
  • Is the request connected to a German organization?
  • Is C5 stated in a contract, procurement questionnaire, or vendor policy?
  • Is the customer requesting a pre-assessment, formal attestation, or an existing C5 report?
  • Which cloud service must be included?
  • Which locations, systems, and external providers fall within the expected scope?
  • Is a Type 1 or Type 2 attestation ultimately being requested?
  • Are additional German sectoral or public-sector requirements involved?
  • Is the request mandatory for the transaction, or is C5 being considered voluntarily?

 

These questions prevent a broad C5 reference from being interpreted incorrectly.

They also establish whether the customer expects independent assessment documentation, a formal attestation report, or another form of assurance.

C5 Alongside Other Frameworks

Cloud providers may already hold an ISO/IEC 27001 certification or have completed another independent assurance engagement.

These outcomes may provide relevant evidence, but they should not be treated as interchangeable with C5.

The BSI publishes a cross-reference between C5:2020 and ISO/IEC 27001:2022, reflecting areas of relationship between the frameworks. A cross-reference can identify related requirements, but it does not turn one outcome into the other. (BSI)

Each framework retains:

  • Its own criteria
  • Its own defined scope
  • Its own evidence requirements
  • Its own examination methodology
  • Its own reporting outcome

An organization with existing assurance documentation may present that evidence during a C5 evaluation where relevant. The assessor must still determine what that evidence demonstrates against the applicable C5 criteria.

Why Accurate Geographic Positioning Matters

Describing C5 as a general EU requirement creates several problems.

It may:

  • Overstate the framework’s applicability
  • Create unnecessary concern among cloud providers with no German market connection
  • Blur the distinction between German and EU-level requirements
  • Misrepresent voluntary adoption as mandatory
  • Weaken credibility with informed procurement and compliance stakeholders

The more accurate position is:

C5 is a German cloud assurance framework that is particularly relevant to providers serving German entities. Organizations elsewhere may adopt it voluntarily or encounter it through customer-specific, procurement, contractual, or sectoral requirements.

This framing recognizes C5’s international relevance without presenting it as universally required across the European Union.

Frequently Asked Questions

Is C5 required for every cloud provider operating in the EU?

No. C5 should not be presented as a universal EU requirement.

It is primarily associated with the German market. An organization outside Germany may encounter C5 when supplying services to a German entity, responding to a customer requirement, participating in procurement, or adopting the framework voluntarily.

C5 may be referenced by German public authorities, healthcare entities, regulated organizations, private enterprises, and other customers that use the framework within cloud vendor evaluations.

The exact requirement should be confirmed from the relevant procurement, contractual, customer, or sector-specific documentation.

Yes.

The location of the provider does not prevent evaluation against C5. International and EU-based cloud providers may undergo assessment when serving German entities or when C5 has otherwise been specified for the service.

A C5 Pre-Assessment is an independent, evidence-based evaluation of a defined cloud service against applicable C5 criteria before formal attestation.

It produces documented assessment findings but does not result in a formal C5 attestation report.

No.

A pre-assessment is a separate engagement and does not determine the outcome of a subsequent formal examination.

No.

C5 is associated with an assurance examination and report. The BSI does not issue a C5 certification. (BSI)

No.

The frameworks contain related areas, but each retains separate criteria, scope, evidence requirements, and outcomes. The existence of an ISO/IEC 27001 certificate does not automatically establish conformity with all applicable C5 criteria. (BSI)

Relevance should be established from the organization’s market, customer relationships, procurement documentation, contracts, sector, service scope, and stated assurance requirements.

For many providers, the clearest indicator is a direct request from a German customer or another entity that has explicitly incorporated C5 into its evaluation criteria.

Independent C5 Pre-Assessment by Consilium Labs

Consilium Labs performs independent C5 Pre-Assessments for cloud providers serving German entities or responding to defined C5 requirements.

Each engagement is based on an agreed scope, applicable C5 criteria, and evidence available during the assessment. The resulting documentation records the criteria evaluated and the findings identified through the independent examination

Related Articles

Let's get in touch

Start your audit now. Achieving cybersecurity audit can be complex. We have made it our mission to simplify the process, giving you access to the professional expertise you need to prepare your company for the future. Get in touch with us today!

Please enable JavaScript in your browser to complete this form.
Please enable JavaScript in your browser to complete this form.

GET YOUR QUOTE NOW