BSI C5:2020 · attestation under ISAE 3000
Your provider’s C5 attestation contains a list of your tasks.
The German BSI criteria catalogue sets out what a cloud provider must deliver – and which measures explicitly remain with the customer. That is the part usually missed when the PDF gets filed.
The Cloud Computing Compliance Criteria Catalogue of the German Federal Office for Information Security is the national reference framework for cloud security. Providers have their controls examined by an audit firm; the result is an attestation under ISAE 3000, either type 1 at a point in time or type 2 across a period.
For you as a customer the report is evidence to obtain, read, assess and file with a validity date. Two parts decide its value: the environment parameters, where the provider discloses locations, jurisdictions and sub-service providers, and the complementary measures that fall to you.
What the attestation actually says
- Environment parameters: data centre locations, applicable jurisdictions, sub-service providers used.
- Deviations and limitations the auditor recorded – not every attestation is free of findings.
- The audit period: a type 1 attestation says nothing about effectiveness over time.
- Complementary customer measures, without which the audited controls achieve nothing.
- Scope: which of the provider’s services are covered – and which are not.
What the catalogue covers for the supply chain
- Provider governance
- A dedicated criteria area covers how the provider steers and monitors its own service providers and suppliers.
- Disclosure
- Sub-service providers and their role must be named – which makes the chain behind your provider visible.
- Basic and additional
- The catalogue distinguishes basic criteria and additional criteria for elevated protection needs.
- Form of evidence
- Examination by an independent body, not self-declaration.
- Currency
- Attestations cover a period and are renewed annually.
How SCRM covers it
Attestation with expiry
Type, audit period and scope as fields – not as a filename.
Complementary measures as tasks
What stays with you becomes a task with an owner instead of a footnote.
Sub-providers visible
The disclosed chain lands in the dependency graph, where it serves outage analysis.
Renewal on a cycle
The next attestation is requested before the current one lapses.
Frequently asked
Is a C5 attestation enough for ISO 27001?
It is a strong building block for controls A.5.19 to A.5.23 but does not replace your own assessment. You must show that you reviewed it and implemented the complementary measures.
What is the difference between type 1 and type 2?
Type 1 assesses the suitability of controls at a point in time; type 2 additionally their effectiveness across a period. For critical services, type 2 is the more meaningful basis.
Our provider advertises C5 – is that enough?
Advertising the acronym is not a report. Ask for the attestation and check scope, period and findings. That is precisely what the auditor will ask about.
As of July 2026. The version of the catalogue in force governs. Not legal advice.