A German hospital network evaluates a cloud provider for clinical data. A federal agency reviews a software vendor's hosting. A service provider wants to sell storage-as-a-service to the German public sector. In every case, the buyer asks for a C5 attestation. The Cloud Computing Compliance Criteria Catalogue, published by Germany's Federal Office for Information Security (BSI), has become the reference for cloud security in Germany and influences cloud security schemes across Europe.
This article explains what C5 is, how the new C5:2026 edition changes it, who requires it and what it means for the storage layer of a cloud service. It is part of our data sovereignty series; see also what SecNumCloud requires from storage for the French perspective.
C5 is a catalogue of security criteria for cloud service providers. Unlike a certification issued by an agency, C5 compliance is demonstrated through an attestation report produced by an independent auditor, which describes the provider's controls and, depending on the report type, whether they operated effectively over a period. Customers use these reports in their own risk assessments.
The catalogue covers areas such as organization of information security, personnel, asset management, physical security, operations, identity and access management, cryptography, communication security, development, supplier management, incident management, business continuity and compliance. It also asks providers to be transparent about surrounding conditions that customers need to assess risk, such as data location, jurisdiction and disclosure obligations to authorities.
The BSI has published C5:2026, the successor to C5:2020. According to the BSI, the revision:
Providers with C5:2020 attestations should check the BSI's transition arrangements and plan for audits against the new catalogue.
C5 applies to cloud services, not to individual products. A storage platform is not attested on its own. But when a provider builds a cloud service on a storage platform, the storage must support the controls the auditor will examine. In practice, storage design directly affects whether a provider can satisfy C5 criteria.
C5 includes criteria for encryption of data at rest and in transit and for key management. Storage should support strong encryption with keys under the provider's control, and C5:2026's attention to post-quantum cryptography means providers should track the crypto agility of their platforms.
Multi-tenant storage services must keep customers strictly separated. C5:2026 places more emphasis on how separation is implemented technically. Storage should provide separate accounts, credentials, policies and encryption per tenant, with tests that demonstrate isolation.
Administrative access to storage must be role-based, strongly authenticated and logged. Separation of duties between storage administrators and other roles supports several criteria.
Storage should produce detailed logs of administrative and data access events that feed the provider's security monitoring, with protection against tampering.
Providers must be transparent about where data is stored and processed. Storage platforms that keep data, replicas, backups, metadata and telemetry within defined locations make this straightforward.
C5:2026 adds focus on supply chain management. Providers will need to assess storage vendors, including how software is built and updated and how vendor support accesses systems.
Criteria for backup, recovery and resilience call for storage that survives hardware and site failures and supports tested recovery.
| C5 area | What to verify in the storage platform |
|---|---|
| Cryptography | Encryption at rest and in transit, provider-controlled keys, crypto agility |
| Client separation | Per-tenant accounts, policies and encryption, demonstrable isolation |
| Access management | Role-based administration, strong authentication, separation of duties |
| Logging | Complete, exportable, tamper-resistant logs |
| Location | Data, replicas, metadata and telemetry kept in defined locations |
| Supply chain | Transparent software updates, controlled vendor support |
| Continuity | Erasure coding, multi-site deployment, immutable copies, tested recovery |
Auditors will ask the provider to show how controls are designed and, for longer-period reports, how they operated over time. For the storage layer, useful preparation includes:
Storage platforms that expose configuration and logs through APIs make it easier to collect this evidence continuously rather than in a last-minute scramble.
C5 does not stand alone. Providers serving several European countries often face SecNumCloud in France, C5 in Germany, national government frameworks elsewhere and the emerging European cloud certification scheme. Mapping storage controls once, against a common set of requirements, and then showing how they satisfy each scheme saves duplicated effort. Controls for data location, tenant separation, administrator access and key management appear in almost every framework, so getting them right in the storage layer pays off across all of them.
Scality RING is software-defined object storage that runs on infrastructure chosen and operated by the provider, with no dependence on external cloud services. It supports multi-tenant S3 services with per-tenant accounts and policies, encryption, role-based administration and audit logging, along with erasure coding, multi-site deployment and compliance-mode object lock. Providers in Germany use this kind of architecture to build storage services designed to support their C5 controls, keeping data and operations within German or EU data centers. As always, the attestation applies to the provider's service as a whole.
C5 is Germany's benchmark for cloud security, and C5:2026 raises the bar on client separation, sovereignty, supply chain and cryptography. Storage is not attested on its own, but it carries many of the controls auditors examine: encryption, tenant isolation, access management, logging, data location and resilience. Choose storage that runs fully under your control and makes those controls easy to demonstrate.
C5 compliance is demonstrated through an independent auditor's attestation report rather than a certificate issued by the BSI.
The latest edition of the BSI's Cloud Computing Compliance Criteria Catalogue, adding areas such as container management, supply chain, post-quantum cryptography and confidential computing.
No. C5 applies to cloud services. The storage platform must support the provider's controls.
Federal agencies use it as a key reference, health IT providers processing health data in the cloud need an attestation and many regulated organizations require it in procurement.
Both are national schemes for trusted cloud services. SecNumCloud is a French qualification with explicit protection against non-EU law; C5 is a German criteria catalogue with auditor attestation.