A German hospital network evaluates a cloud provider for clinical data. A federal agency reviews a software vendor's hosting. A service provider wants to sell storage-as-a-service to the German public sector. In every case, the buyer asks for a C5 attestation. The Cloud Computing Compliance Criteria Catalogue, published by Germany's Federal Office for Information Security (BSI), has become the reference for cloud security in Germany and influences cloud security schemes across Europe.
This article explains what C5 is, how the new C5:2026 edition changes it, who requires it and what it means for the storage layer of a cloud service. It is part of our data sovereignty series; see also what SecNumCloud requires from storage for the French perspective.
What C5 is
C5 is a catalogue of security criteria for cloud service providers. Unlike a certification issued by an agency, C5 compliance is demonstrated through an attestation report produced by an independent auditor, which describes the provider's controls and, depending on the report type, whether they operated effectively over a period. Customers use these reports in their own risk assessments.
The catalogue covers areas such as organization of information security, personnel, asset management, physical security, operations, identity and access management, cryptography, communication security, development, supplier management, incident management, business continuity and compliance. It also asks providers to be transparent about surrounding conditions that customers need to assess risk, such as data location, jurisdiction and disclosure obligations to authorities.
What is new in C5:2026
The BSI has published C5:2026, the successor to C5:2020. According to the BSI, the revision:
- Builds on experience from C5:2020, which also served as a basis for work on the European cybersecurity certification scheme for cloud services.
- Adds technical focus areas including container management, supply chain management, post-quantum cryptography and confidential computing.
- Clarifies requirements for client separation and the technical implementation of sovereignty.
- Introduces a clearer hierarchy of criteria: basic criteria, additional criteria that sharpen basic requirements and additional criteria that complement them.
- Is published for the first time in machine-readable form alongside the usual document formats.
Providers with C5:2020 attestations should check the BSI's transition arrangements and plan for audits against the new catalogue.
Who requires C5
- German federal administration: federal agencies use C5 as a key reference when assessing external cloud services.
- Healthcare: German health legislation now requires a C5 attestation for cloud processing of health and social data, which has made C5 a requirement for many health IT providers.
- Regulated industries: banks, insurers and critical infrastructure operators often request C5 reports in procurement.
- Enterprises: many German companies use C5 as a benchmark when selecting cloud providers.
Does storage need to meet C5?
C5 applies to cloud services, not to individual products. A storage platform is not attested on its own. But when a provider builds a cloud service on a storage platform, the storage must support the controls the auditor will examine. In practice, storage design directly affects whether a provider can satisfy C5 criteria.
What C5 means for the storage layer
Cryptography and key management
C5 includes criteria for encryption of data at rest and in transit and for key management. Storage should support strong encryption with keys under the provider's control, and C5:2026's attention to post-quantum cryptography means providers should track the crypto agility of their platforms.
Client separation
Multi-tenant storage services must keep customers strictly separated. C5:2026 places more emphasis on how separation is implemented technically. Storage should provide separate accounts, credentials, policies and encryption per tenant, with tests that demonstrate isolation.
Identity and access management
Administrative access to storage must be role-based, strongly authenticated and logged. Separation of duties between storage administrators and other roles supports several criteria.
Logging and monitoring
Storage should produce detailed logs of administrative and data access events that feed the provider's security monitoring, with protection against tampering.
Data location and transparency
Providers must be transparent about where data is stored and processed. Storage platforms that keep data, replicas, backups, metadata and telemetry within defined locations make this straightforward.
Supplier management and supply chain
C5:2026 adds focus on supply chain management. Providers will need to assess storage vendors, including how software is built and updated and how vendor support accesses systems.
Business continuity
Criteria for backup, recovery and resilience call for storage that survives hardware and site failures and supports tested recovery.
A storage checklist for C5-ready services
| C5 area | What to verify in the storage platform |
|---|---|
| Cryptography | Encryption at rest and in transit, provider-controlled keys, crypto agility |
| Client separation | Per-tenant accounts, policies and encryption, demonstrable isolation |
| Access management | Role-based administration, strong authentication, separation of duties |
| Logging | Complete, exportable, tamper-resistant logs |
| Location | Data, replicas, metadata and telemetry kept in defined locations |
| Supply chain | Transparent software updates, controlled vendor support |
| Continuity | Erasure coding, multi-site deployment, immutable copies, tested recovery |
Preparing for a C5 audit: the storage team's part
Auditors will ask the provider to show how controls are designed and, for longer-period reports, how they operated over time. For the storage layer, useful preparation includes:
- Architecture documentation showing sites, data flows, tenant separation and management interfaces.
- Access reviews listing who has administrative access to storage and why, with evidence of periodic review.
- Configuration evidence for encryption, key management, object lock and replication.
- Log samples and retention settings demonstrating that administrative and access events are captured and protected.
- Change records for upgrades and configuration changes, linked to the provider's change management process.
- Recovery test results showing that data can be restored after failures.
- Vendor management records covering the storage vendor's support model and update process.
Storage platforms that expose configuration and logs through APIs make it easier to collect this evidence continuously rather than in a last-minute scramble.
C5 in a European context
C5 does not stand alone. Providers serving several European countries often face SecNumCloud in France, C5 in Germany, national government frameworks elsewhere and the emerging European cloud certification scheme. Mapping storage controls once, against a common set of requirements, and then showing how they satisfy each scheme saves duplicated effort. Controls for data location, tenant separation, administrator access and key management appear in almost every framework, so getting them right in the storage layer pays off across all of them.
Common gaps
- Shared administrator accounts that make it impossible to show who did what.
- Incomplete logs missing administrative actions or data access events.
- Telemetry or support channels that leave the declared data locations.
- Tenant isolation that relies only on application logic without storage-level separation.
- Recovery procedures that exist on paper but have not been tested.
How Scality fits
Scality RING is software-defined object storage that runs on infrastructure chosen and operated by the provider, with no dependence on external cloud services. It supports multi-tenant S3 services with per-tenant accounts and policies, encryption, role-based administration and audit logging, along with erasure coding, multi-site deployment and compliance-mode object lock. Providers in Germany use this kind of architecture to build storage services designed to support their C5 controls, keeping data and operations within German or EU data centers. As always, the attestation applies to the provider's service as a whole.
Questions to ask a storage vendor
- Can the platform run fully on our infrastructure with no mandatory external services?
- How are tenants separated technically, and how can we demonstrate it?
- What encryption algorithms and key management options are supported, and what is the roadmap for post-quantum cryptography?
- How is support delivered, and how is vendor access controlled and logged?
- Which logs are available, and how are they exported?
Putting it together
C5 is Germany's benchmark for cloud security, and C5:2026 raises the bar on client separation, sovereignty, supply chain and cryptography. Storage is not attested on its own, but it carries many of the controls auditors examine: encryption, tenant isolation, access management, logging, data location and resilience. Choose storage that runs fully under your control and makes those controls easy to demonstrate.
Frequently asked questions
Is C5 a certification?
C5 compliance is demonstrated through an independent auditor's attestation report rather than a certificate issued by the BSI.
What is C5:2026?
The latest edition of the BSI's Cloud Computing Compliance Criteria Catalogue, adding areas such as container management, supply chain, post-quantum cryptography and confidential computing.
Does a storage product need a C5 attestation?
No. C5 applies to cloud services. The storage platform must support the provider's controls.
Who needs C5 in Germany?
Federal agencies use it as a key reference, health IT providers processing health data in the cloud need an attestation and many regulated organizations require it in procurement.
How does C5 relate to SecNumCloud?
Both are national schemes for trusted cloud services. SecNumCloud is a French qualification with explicit protection against non-EU law; C5 is a German criteria catalogue with auditor attestation.














