Skip to main content Skip to search Skip to main navigation
Menu
Important Standards & legislation Score: 7/10

C5:2026 – New BSI Standard for Secure Cloud Services

The BSI has published C5:2026: the revised criteria catalogue for cloud computing takes account of current threats and technological developments such as post-quantum cryptography.

C5:2026: The Federal Office for Information Security updates its cloud computing standard

The German Federal Office for Information Security (BSI) has published the new version of the Cloud Computing Compliance Criteria Catalogue (C5). The revised C5:2026 standard is intended to help companies, public authorities and organisations use and select cloud services more securely. Since 2016, C5 has been regarded as Germany's most important security standard for cloud providers and users.

What is C5 and what purpose does it serve?

The C5 catalogue translates complex security requirements for future-proof cloud services into auditable criteria. This means that abstract requirements are made concrete and can be verified by auditors. Following a successful audit, auditors certify that the cloud provider meets the security criteria set out in the standard.

Its practical relevance lies in the fact that C5 does not only provide companies and public authorities with reliable information for their own risk management. The standard also creates market-wide transparency and guidance when selecting cloud providers. Security promises thus become easier to compare.

Key facts about the new C5:2026 version

The revised version of the standard takes account of current technological developments and the present threat situation. The following topics are addressed in C5:2026 for the first time, or more specifically than before:

  • Container management: Administration and security of container technologies
  • Post-quantum cryptography: Cryptographic methods designed to be resistant to quantum computers as well
  • Confidential computing: Processing sensitive data in protected environments
  • Tenant separation: Addressed even more specifically than in earlier versions
  • Supply chain management: Targeted coverage of supply chain security

Structural and technical improvements

BSI Vice President Thomas Caspers emphasises that C5:2026 not only brings additional security, but also improves usability. The revised structure with sub-criteria and supplementary additional criteria provides greater clarity in auditing, mapping and evaluation.

One special feature: in future the catalogue will be available not only in English and, shortly, in German, but for the first time also in a machine-readable format. This considerably simplifies integration into governance, risk and compliance processes (GRC processes), as it creates a standardised, reliable descriptive language for cloud security.

Harmonisation with other standards and directives

In terms of both content and structure, C5:2026 is closely aligned with the European certification scheme EUCS. Other relevant requirement documents were also taken into account during its development:

  • CSA Cloud Controls Matrix Version 4
  • ISO/IEC 27001:2022
  • NIS 2 Directive (European Network and Information Security Directive)

This alignment ensures that C5:2026 harmonises with international and European security standards rather than standing in isolation.

Incorporating practical experience

In developing C5:2026, the BSI carried out a community draft. As a result, practical experience from cloud providers, cloud auditors and cloud consultants fed directly into the new edition. This ensures that the standard is not only theoretically sound, but also applicable in practice.

Why is C5:2026 relevant for the security industry?

Cloud computing is indispensable for modern organisations, but it also carries considerable security risks. A reliable standard such as C5:2026 enables companies and public authorities to make well-founded decisions when using cloud services. As a security manager, it allows you to:

  • Assess and compare cloud providers on a standardised basis
  • Conduct contract negotiations with clear, auditable criteria
  • Demonstrate compliance requirements
  • Identify and assess risks systematically

BSI President Claudia Plattner emphasises that C5:2026 sets a "contemporary, practical benchmark" for everyone who uses, audits, offers or procures cloud services. The standard thus underlines the aim of viewing cybersecurity and digitalisation as a single whole.

Outlook: Sovereignty criteria to follow

In addition to the security criteria for cloud services described in C5:2026, the BSI will shortly publish general sovereignty criteria for cloud computing solutions. These are likely to be particularly relevant for organisations that regard data sovereignty and control over their infrastructure as critical.

With the publication of C5:2026 and the announced sovereignty criteria, the BSI demonstrates its continuous commitment to secure and trustworthy cloud services in Germany. The international response to the standard shows that this approach also carries significance beyond Germany's borders.