C5:2026 Attestation: A Comprehensive Guide for Cloud Service Providers
Securing cloud infrastructure remains a top priority for modern organizations, and few standards carry as much weight in the German and DACH markets as the Cloud Computing Compliance Criteria Catalogue, or C5. First introduced by Germany’s Federal Office for Information Security (BSI) in 2016, C5 has just undergone its most significant update yet: C5:2026, published in April 2026, replaces the long-standing C5:2020 version. In this post, we’ll walk through why C5 matters, what’s changed in the 2026 edition, and what cloud service providers (CSPs) need to know to prepare.
Why is C5 attestation important for CSPs?
C5 attestation gives CSPs a standardized way to demonstrate security maturity to customers, particularly those in government, banking, insurance, healthcare, and critical infrastructure sectors across Germany and the broader DACH region. Because C5 is government-backed rather than industry-developed, it carries a level of authority that has made it a de facto procurement requirement in many regulated markets — CSPs without it can find themselves excluded from consideration entirely. For customers, C5 offers a consistent framework for comparing providers’ security postures side by side, taking much of the guesswork out of vendor risk assessments.
What are the C5:2026 requirements?
C5:2026 organizes its requirements into 17 control domains, consistent with prior versions, but the catalogue itself has grown substantially, from 121 criteria in C5:2020 to 168 criteria in C5:2026. The new version also introduces a structural change: individual criteria are now broken down into distinct sub-criteria, a shift made to align C5 more closely with the European Cloud Certification Scheme (EUCS) at the Substantial assurance level. This restructuring gives both CSPs and auditors a more precise way to map requirements to internal controls.
Within the catalogue, C5:2026 continues to distinguish between two tiers of criteria:
- Basic criteria: the mandatory minimum every CSP must meet, covering cloud services that process information with standard protection needs.
- Additional criteria: required for CSPs handling sensitive business data, personal data, or critical infrastructure workloads. These are split into sharpening criteria (stricter versions of existing basic requirements) and complementing criteria (new requirements introduced beyond the basic scope).
C5:2026 also brings entirely new subject areas into scope for the first time, including container management, confidential computing, and post-quantum cryptography, along with tightened expectations around supply chain and subcontractor management and identity and access management, with an explicit nod toward zero-trust principles. CSPs already compliant with ISO/IEC 27001:2022, the CSA Cloud Controls Matrix v4, or NIS2 requirements will find meaningful overlap with the updated catalogue, since the BSI drew directly from all three when developing C5:2026.
What is the C5 examination process?
As with prior versions, C5:2026 conformity is assessed under the ISAE 3000 assurance standard, and attestation results in a report rather than a certificate. A good starting point for CSPs, especially those new to C5 or transitioning from C5:2020, is a readiness or gap assessment. This helps an organization understand where its current controls stand against the expanded C5:2026 catalogue and produces a roadmap for closing any gaps before the formal examination begins.
Type 2 reports, which test the design, implementation, and operating effectiveness of controls over a review period, remain the standard expected by most regulated buyers; a Type 1 report only attests to control design at a point in time. CSPs pursuing C5 alongside an existing SOC 2 program can often combine much of the underlying evidence collection, reducing duplicate audit effort.
What’s new in C5:2026
C5:2026 is the first full revision of the catalogue since 2020, and it reflects six years of technological and regulatory change. Key updates include:
- Alignment with EUCS and international standards: C5:2026 was built with compatibility with the EUCS Substantial assurance level in mind, and also accounts for ISO/IEC 27001:2022, the NIS2 Directive, and CSA Cloud Controls Matrix v4.
- Structural revision: As noted above, criteria are now broken into sub-criteria, improving clarity for both CSPs and auditors.
- New and tightened control areas: Container management, confidential computing, and post-quantum cryptography appear in the catalogue for the first time, while tenant separation, supply chain management, and identity and access management have all been strengthened.
- Expanded documentation expectations: CSPs should expect to produce more comprehensive process documentation, including new policies and standards that weren’t previously required.
Transitioning from C5:2020 to C5:2026
The BSI has set a clear timeline for the shift to the new standard: C5:2026 becomes mandatory for engagements with a specified date or audit period beginning on or after June 1, 2027. Until that date, C5:2020 remains valid, and CSPs can choose to continue under it for one more cycle if their timeline allows. Early adoption of C5:2026 is explicitly permitted by the BSI, and is strongly encouraged for CSPs operating in security-critical or heavily regulated markets who want to demonstrate leading-edge compliance ahead of the deadline.
One detail worth flagging: if a CSP’s audit period ends on or after February 28, 2027, the BSI requires the system description to include information about planned changes to controls addressing the new C5:2026 requirements, including implementation status and expected timing. CSPs planning their 2026–2027 audit calendar should factor this into their scoping conversations early.
Given the scope of the changes, CSPs currently certified under C5:2020 shouldn’t assume a like-for-like carryover — a gap assessment against the new criteria is the most reliable way to understand the real level of effort involved before committing to a transition timeline.
Getting started with C5:2026
Achieving C5:2026 attestation is a meaningful undertaking, but for CSPs serving customers in Germany and the DACH region, it’s quickly becoming table stakes. The expanded catalogue asks more of providers than its predecessor, but it also gives them a stronger, more current way to demonstrate security leadership, particularly around the emerging risk areas, like container security and post-quantum readiness, that competitors may not have addressed yet.
Contact A-LIGN to learn more about C5:2026 attestation and how to plan your transition.





