EVEN MORE SECURITY FOR YOUR CLOUD CUSTOMERS THROUGH BSI C5 TESTING!

We support you in making your cloud service even more secure by setting up an internal control system and BSI C5 audit!

Free consultation or send us an E-Mail

Advantages of a BSI C5 Audit

Build trust, minimize risks and secure competitive advantages with a BSI C5 audit

Building trust with clients and partners

A C5 certificate signals that your cloud services meet the highest security standards – this strengthens the trust of clients and business partners.

Meeting regulatory requirements

The BSI C5 audit helps fulfill legal and industry-specific requirements regarding information security – an important step towards compliance. Especially when processing social or health data.

Transparency and traceability

The BSI C5 criteria catalog creates uniform requirements – your clients receive clear, traceable statements on the security of your cloud services.

Competitive advantage through BSI C5 audit

A successful BSI C5 certificate can serve as a differentiating feature in the market – especially compared to providers without BSI C5 certification.

Preparation for international standards

The BSI C5 criteria catalog is compatible with other standards such as ISO 27001 or SOC 2 – the BSI C5 audit is an ideal entry point for globally oriented compliance strategies.

Pass the BSI C5 exam in 4 steps!

Step 1
GAP Analysis & Status Check

We analyze the current state of your information security level in relation to your cloud service and identify gaps with regard to the requirements of BSI C5.

🕒 Duration: 1-2 days
Step 2
Development of tailored controls

Based on the analysis, you develop an internal control system tailored to your cloud service – we accompany you throughout the entire development as part of our audit-related consulting.

🕒 Duration: 4-6 weeks
Step 3
Audit of the control system

Our independent auditors assess the appropriateness and implementation (Type 1) and, if applicable, the effectiveness (Type 2) of your implemented controls and their alignment with the BSI C5 criteria catalog.

🕒 Duration: 4-6 weeks
Step 4
Issuance of the certificate

After a successful BSI C5 audit, we issue the certificate regarding your internal control system according to BSI C5 (including audit report) – as proof of a verified security level of your cloud service.

🕒 Duration: 2 weeks
Free consultation or send us an

BSI C5, ISO 27001, NIS 2, DORA

Criterion
BSI C5
ISO 27001
NIS 2
DORA
Specific reference to cloud services
Legally mandatory implementation
Specification of concrete security requirements
Implementation of a service-related ICS necessary/possible
Adaptability to company specifications
BSI C5
Specific reference to cloud services
Legally mandatory implementation
Specification of concrete security requirements
Implementation of a service-related ICS necessary/possible
Adaptability to company specifications
ISO 27001
Specific reference to cloud services
Legally mandatory implementation
Specification of concrete security requirements
Implementation of a service-related ICS necessary/possible
Adaptability to company specifications
NIS 2
Specific reference to cloud services
Legally mandatory implementation
Specification of concrete security requirements
Implementation of a service-related ICS necessary/possible
Adaptability to company specifications
DORA
Specific reference to cloud services
Legally mandatory implementation
Specification of concrete security requirements
Implementation of a service-related ICS necessary/possible
Adaptability to company specifications

FAQ

What is C5? +
The BSI C5 Criteria Catalogue contains minimum requirements for secure cloud computing, which have been specified by the BSI. From the BSI's perspective, it summarizes criteria that cloud providers should meet regardless of the application context to ensure a minimum level of security for their cloud services towards their customers.

After successful examination of all criteria by auditors, the cloud provider is issued a C5 attestation for the audited cloud services.
What is audited during a C5 examination? +
During a C5 examination, one or more cloud services of a cloud provider are audited for defined regions. A C5 attestation is therefore not issued for a cloud provider as a whole, but always only for the audited cloud services in the defined geographical regions of the cloud provider.
What is a C5 attestation? +
A C5 attestation is a confirmation statement in the form of an audit report, following an examination of one or more cloud services, in which at least all basic criteria of the C5 criteria catalogue have been audited.

This examination is carried out according to the international standard ISAE 3000 or its national equivalents. According to this standard, only certified auditors may conduct audits and only they may issue corresponding attestations.
What is the difference between an attestation and a certificate? +
With a certificate, there are three different parties: auditee, auditor, and certification body. The audit report from the auditor accredited by the certification body is sent to the certification body for review. If it complies with the certification regulations, the certification body issues a corresponding certificate. The involvement of these three parties is intended to ensure the quality and comparability of certificates. Furthermore, such a procedure prevents or makes "favor certificates" more difficult. With attestation, there are only two parties: the auditee and the auditor.

The auditor is commissioned by the auditee and paid by them. This creates a dependency of the auditor on the auditee, which can lead to an impairment of the quality of the attestation. To counteract this, a procedure was chosen for C5 in which the auditor is generally liable for their audit services. Following an examination of the C5 criteria, an attestation is issued.
Who is authorized to issue a C5 attestation? +
According to current regulations, only certified auditors can issue a C5 attestation. ADVANTA is a recognized auditing firm - contact us now.
What happens when an attestation and certification are conducted simultaneously? +
Simultaneous execution of attestation and certification has the following major advantage: Since all requirements of ISO/IEC 27001 are also listed in C5, the principle of "audit once – certify many" can be applied when conducting attestation and certification simultaneously. This means that the result of the audit can be used for different audits, e.g., for C5 and for an ISO/IEC 27001 certificate. This significantly reduces the effort required to conduct the audit.
Is a valid ISO 27001 certification required for a C5 attestation? +
No, an ISO 27001 certification is not a prerequisite for a C5 attestation. However, many requirements of C5 are based on ISO/IEC 27001. An existing certification can therefore be helpful and facilitate the audit, but it is not mandatory. Learn more about ISO 27001 certification now.
Does a C5 attestation refer to the entire organization or only the cloud service? +
A C5 attestation refers exclusively to the audited cloud service, not to the entire organization. The respective service is specifically assessed, including its processes, security measures, and infrastructure as they were operated during the audit period.
What is meant by a service-related internal control system (ICS)? +
A service-related internal control system (ICS) encompasses all organizational measures and controls that a cloud service provider implements to ensure security, proper operation, and regulatory compliance when operating their services. It forms the basis for the C5 audit, as it documents and safeguards the implementation of requirements.
Free consultation or send us an

THESE ARE YOUR CONTACTS

Lorem Ipsum

Justus Franke

Managing Director,
Certified Auditor


Justus Franke is Managing Partner at ADVANTA. As a certified auditor and consultant, he supports companies in establishing, implementing, and auditing management and control systems – with a particular focus on process-oriented governance, risk management, and compliance.

Etiam Luctus

Lena Franke

Managing Director, Certified Auditor


Lena Franke is Managing Partner at ADVANTA. She advises companies on establishing, developing, and auditing management systems – with particular focus on quality management as well as energy and environmental management. Her emphasis is on practical implementation of regulatory requirements and continuous improvement of operational processes.

Consectetur Elit

Nils Lingthaler

Manager,
ISO 27001 Auditor


Nils Lingthaler is Manager at ADVANTA. As an industrial engineer and certified ISO 27001 auditor, he advises companies on IT compliance, information security, and management and control systems. His focus is on implementing and developing management systems as well as practical implementation of regulatory requirements.

Free consultation or send us an

References

Dr. Leif-Nissen Lundbæk

CEO & Co-Founder of Noxtua AG

Noxtua AG

"Thanks to the competent and goal-oriented approach of the ADVANTA team, we were able to successfully complete the BSI C5 Type 1 audit on schedule. We were particularly impressed by the systematic working method and the targeted preparation for all coordination meetings, which made the entire audit process efficient and transparent."

Mathias Schmon

Managing Director nubedian GmbH

nubedian GmbH

"Thanks to the professional and efficient support from ADVANTA, we were able to successfully complete the BSI C5 Type 1 audit within the planned timeframe. The structured approach and the constructive, well-prepared coordination meetings made the entire audit process smooth and transparent. We value the excellent collaboration and especially the ability of the ADVANTA team to familiarize themselves with corporate structures and business models."
DE