←  Zurück
Lexikon

C5

BSI auditing standard for the security of cloud services.

Definition

The C5 issued by the German Federal Office for Information Security (BSI) establishes security requirements for cloud services and is aligned with established standards such as ISO 27001. An auditor certifies compliance on the basis of the C5, typically within the framework of an audit conducted under ISAE 3402 or IDW PS 951. The result is a C5 attestation, issued either as Type 1 (point in time) or Type 2 (period of time). In Germany, the C5 is a widely recognised form of evidence, particularly in the public sector and among regulated clients.

was für Dienstleister bedeutet

For cloud providers with German or public sector clients, a C5 attestation is often the key requirement for entry. As with other forms of evidence, the attestation alone is rarely sufficient: clients use it as a basis for detailed follow-up questions on individual criteria. These questions overlap significantly with ISO 27001, SOC 2, and security questionnaires. Those who keep their attestation and the corresponding answers readily at hand will pass audits with German clients more quickly.

Wie kann tendry helfen

With Tendry, you keep your C5 attestation and the associated evidence centrally accessible and answer the detailed questions behind it from a verified source. This allows you to handle cloud security inquiries from German clients quickly and consistently.

Was andere leser auch interessiert
No items found.