Don’t do SECURITY. Do business SECURELY.

Germany’s BSI publishes C5:2020 cloud criteria

Germany’s BSI publishes C5:2020, updating its Cloud Computing Compliance Criteria Catalogue for cloud security attestations.

Germany’s Federal Office for Information Security (BSI) has published C5:2020, the updated Cloud Computing Compliance Criteria Catalogue, replacing the original 2016 version.

Key points

  • Criteria are revised to reflect current technical standards and experience from attestations.
  • Adds areas on product safety and security and on handling investigation requests from government agencies.
  • Includes complementary customer criteria to clarify shared responsibilities.
  • Assessed through an auditor’s attestation report under international assurance standards.
  • Widely required by German public authorities and regulated sectors.

UK cloud providers serving German public sector, healthcare or financial services clients should expect C5 attestation requests and plan for the updated criteria.

Source: C5:2020 Cloud Computing Compliance Criteria Catalogue (BSI)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights