BSI C5 — Cloud Computing Compliance Criteria Catalogue
What is BSI C5 — Cloud Computing Compliance Criteria Catalogue?
The Cloud Computing Compliance Criteria Catalogue (C5) is the German Federal Office for Information Security (BSI) standard for assessing the security of cloud services. C5:2020 defines minimum security requirements that cloud providers must meet, organized into 17 topic areas with 121 criteria. It comprises 8 controls organised across 2 domains, and applies in Germany.
How BSI C5 — Cloud Computing Compliance Criteria Catalogue maps to other frameworks
All 8 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 2 domains BSI C5 — Cloud Computing Compliance Criteria Catalogue groups its controls into
Where BSI C5 — Cloud Computing Compliance Criteria Catalogue overlaps with the standards you already hold
What BSI C5 — Cloud Computing Compliance Criteria Catalogue means in your sector
What BSI C5 — Cloud Computing Compliance Criteria Catalogue means for your job
Questions people ask about BSI C5 — Cloud Computing Compliance Criteria Catalogue
What is BSI C5?
How many controls does BSI C5 have?
Where does BSI C5 apply?
What frameworks does BSI C5 map to?
How do I get started with BSI C5 compliance?
Query BSI C5 — Cloud Computing Compliance Criteria Catalogue programmatically
BSI C5 — Cloud Computing Compliance Criteria Catalogue, its 8 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
BSI C5 — Cloud Computing Compliance Criteria Catalogue API reference and MCP config →What BSI C5 — Cloud Computing Compliance Criteria Catalogue requires, control by control
How much of another standard BSI C5 — Cloud Computing Compliance Criteria Catalogue already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- ACSC Essential Eight to C5 (Germany) crosswalk
- ANSSI Guide d'hygiene informatique (42 mesures, v2.0) to C5 (Germany) crosswalk
- C5 (Germany) to APEC Cross-Border Privacy Rules (CBPR) System crosswalk
- C5 (Germany) to APRA CPS 230 Operational Risk Management crosswalk
- APRA CPS 234 to C5 (Germany) crosswalk
- ASD Strategies to Mitigate Cyber Security Incidents to C5 (Germany) crosswalk
- C5 (Germany) to Australia Consumer Data Right - Banking (CDR) crosswalk
- C5 (Germany) to Australia My Health Records Act 2012 crosswalk
How ready are you for BSI C5 — Cloud Computing Compliance Criteria Catalogue?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.