SCRM Supplier Compliance & Risk Management

Home

BSI C5:2020 · attestation under ISAE 3000

Your provider’s C5 attestation contains a list of your tasks.

The German BSI criteria catalogue sets out what a cloud provider must deliver – and which measures explicitly remain with the customer. That is the part usually missed when the PDF gets filed.

The Cloud Computing Compliance Criteria Catalogue of the German Federal Office for Information Security is the national reference framework for cloud security. Providers have their controls examined by an audit firm; the result is an attestation under ISAE 3000, either type 1 at a point in time or type 2 across a period.

For you as a customer the report is evidence to obtain, read, assess and file with a validity date. Two parts decide its value: the environment parameters, where the provider discloses locations, jurisdictions and sub-service providers, and the complementary measures that fall to you.

What the attestation actually says

  • Environment parameters: data centre locations, applicable jurisdictions, sub-service providers used.
  • Deviations and limitations the auditor recorded – not every attestation is free of findings.
  • The audit period: a type 1 attestation says nothing about effectiveness over time.
  • Complementary customer measures, without which the audited controls achieve nothing.
  • Scope: which of the provider’s services are covered – and which are not.

What the catalogue covers for the supply chain

Provider governance
A dedicated criteria area covers how the provider steers and monitors its own service providers and suppliers.
Disclosure
Sub-service providers and their role must be named – which makes the chain behind your provider visible.
Basic and additional
The catalogue distinguishes basic criteria and additional criteria for elevated protection needs.
Form of evidence
Examination by an independent body, not self-declaration.
Currency
Attestations cover a period and are renewed annually.

How SCRM covers it

Attestation with expiry

Type, audit period and scope as fields – not as a filename.

Complementary measures as tasks

What stays with you becomes a task with an owner instead of a footnote.

Sub-providers visible

The disclosed chain lands in the dependency graph, where it serves outage analysis.

Renewal on a cycle

The next attestation is requested before the current one lapses.

Frequently asked

Is a C5 attestation enough for ISO 27001?

It is a strong building block for controls A.5.19 to A.5.23 but does not replace your own assessment. You must show that you reviewed it and implemented the complementary measures.

What is the difference between type 1 and type 2?

Type 1 assesses the suitability of controls at a point in time; type 2 additionally their effectiveness across a period. For critical services, type 2 is the more meaningful basis.

Our provider advertises C5 – is that enough?

Advertising the acronym is not a report. Ask for the attestation and check scope, period and findings. That is precisely what the auditor will ask about.

As of July 2026. The version of the catalogue in force governs. Not legal advice.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required