German Cloud Computing Compliance Criteria Catalogue
BSI C5 (Germany)
The German Federal Office for Information Security (BSI) Cloud Computing Compliance Criteria Catalogue (C5) defines a baseline of security requirements that cloud service providers must meet. It covers organization of information security, physical security, identity and access management, cryptography, operations, and portability, and is commonly attested via an audit report.
For providers and customers operating on AWS, Azure, GCP, or OCI, BSI C5 sets clear expectations for security operations, access management, and cryptography. Cloudanix continuously validates the cloud controls behind a C5 attestation and maintains the supporting evidence.