BSI C5 Standard for Cloud Services

What is the BSI C5 Standard?

The BSI C5 (Cloud Computing Compliance Criteria Catalogue) is a framework established by the German Federal Office for Information Security (BSI). It sets the baseline security standard for cloud services storing sensitive data or serving German public sector and healthcare organizations.

Requirements & Implementation

C5 Control Domain BSI C5 Legal & Security Requirement Technical & Operational Implementation
Identity & Access Management (IAM) Strict access controls, separation of administrative privileges, and enforced multi-factor authentication (MFA). Deploy zero-trust identity governance, cryptographic key-based access, and granular role-based permissions (RBAC).
Cryptographic Controls Mandatory strong encryption for sensitive data at rest and in transit using BSI-compliant algorithms. Implement AES-256 persistent database encryption and TLS 1.3 protocol channels across all cloud microservices.
Audit Logging & Operations Comprehensive operational logging, system monitoring, and tamper-proof retention of administrative activities. Establish immutable, real-time logging APIs that capture all read/write data events for independent auditor verification.
Subprocessor Oversight Formal risk assessment and contractual compliance management for third-party supply chain and cloud infrastructure providers. Maintain automated vendor risk tracking, subprocessor Data Processing Agreements (DPAs), and continuous posture monitoring.
Business Continuity & Resilience Documented disaster recovery protocols, incident response plans, and redundancy testing to guarantee high availability. Configure multi-region automated backups, rapid failover architectures, and routine stress-testing schedules.

Key domains of BSI C5

Meeting the German BSI C5 standard requires cloud providers to prove robust safeguards across four primary pillars: Organization & Operational Security, Identity & Access Management (IAM), Cryptographic Controls, and Resilience & Incident Management. Achieving attestation means enforcing strict access policies, privileged user controls, BSI-approved encryption for data at rest and in transit, and 24/7 logging alongside tested disaster recovery plans.

  • Organization & Operational Security: Formal security policies, asset management, and physical access controls.
  • Identity & Access Management (IAM): Multi-factor authentication, privileged access separation, and identity governance.
  • Cryptographic Controls: Mandatory encryption of data at rest and in transit using BSI-approved algorithms.
  • Resilience & Incident Management: Documented disaster recovery plans, backup redundancy, and 24/7 security logging.