BSI C5:2026: What the New Cloud Security Standard Changes—and Why Companies Should Take a Closer Look Now

BSI C5:2026 Cloud Security Standard

With the C5:2026, the Federal Office for Information Security (BSI) has fundamentally revised its authoritative set of criteria for secure cloud computing. For companies, government agencies, and other organizations that select, evaluate, or provide cloud services themselves, this new version is more than just a routine update. It marks a significant advancement in Germany’s cloud security standards and responds to new technologies, evolving threat landscapes, and heightened regulatory expectations. Precisely because cloud services today often involve critical business processes, sensitive data, and complex supply chains, it is worth taking a closer look at the new version.

To provide some context, it is important to note that C5 stands for “Cloud Computing Compliance Criteria Catalog.” It is not a traditional BSI certification process, but rather a catalog of criteria, compliance with which is verified through audits conducted by independent auditors. The BSI itself is not involved in selecting the auditors, conducting the audits, or preparing the reports. For consumers of cloud services, C5 is therefore primarily a tool for better assessing the security level, transparency, and comparability of cloud offerings.

Why the C5:2026 Became Necessary in the First Place

From the BSI’s perspective, the revision was long overdue. Since the release of version C5:2020, cloud architectures, threat scenarios, and regulatory requirements have evolved significantly. The BSI therefore comprehensively revised the catalog in 2025/26, taking into account, among other things, the current versions of ISO/IEC 27001:2022, the CSA Cloud Controls Matrix Version 4, and the European NIS 2 Directive. In addition, the new C5 was closely aligned with the planned European cloud certification scheme EUCS, particularly the “Substantial” level. This demonstrates that C5:2026 is not only a German update but also a step toward greater European interoperability.

Greater scope, greater precision, greater verifiability

A key difference from the previous version lies in its scope. While C5:2020 consisted of 121 criteria, C5:2026 now includes 168 criteria across 17 subject areas. These figures alone show that the BSI has significantly expanded the assessment framework. In terms of content, the catalog continues to range from organizational and personnel requirements to physical security, access control, encryption, and communication security, all the way to cloud-specific technical and procedural measures. For companies, this means that the assessment of cloud security is becoming broader, deeper, and more granular.

In addition, there is a structural change that is highly relevant in practice: The requirements have been more clearly broken down into subcriteria. This increases verifiability, but also raises expectations for a clear mapping of measures, controls, and supporting documentation. Whereas work used to be conducted primarily at a higher-level criteria level, the new structure requires more precise documentation and more robust evidence. This not only makes the catalog easier to understand but also, in many areas, more stringent, as it leaves less room for interpretation.

Also particularly noteworthy is the new distinction regarding additional criteria. C5:2026 now explicitly distinguishes between “additional sharpen” and “additional complement.” “Additional sharpen” tightens existing basic criteria by replacing them with stricter requirements. “Additional complement” supplements base criteria with additional requirements. This classification makes it clearer than before where a higher level of protection is not only recommended but also specified in concrete terms. For organizations with increased protection needs, this is an important step forward because more demanding security levels are presented more transparently. At the same time, the pressure on providers increases to systematically and verifiably implement not only minimum requirements but also stricter variants.

Where the new standard has become noticeably stricter

The C5:2026 is stricter than the previous version, particularly in areas where the BSI responds directly to recent risk developments. These include new basic criteria for incident and system failure management, as well as vulnerability management. This places greater emphasis on operational security practices. It is therefore even less sufficient than before to merely define security measures in general terms; what matters most is how disruptions, security-related events, and vulnerabilities are detected, addressed, documented, and mitigated during ongoing operations. This is a logical step, particularly in dynamic cloud environments, where risks often arise not from static configurations but from ongoing changes, dependencies, and operational events.

According to the published descriptions, existing requirements for tenant isolation and supply chain management have also been significantly tightened. Both are classic vulnerabilities in modern cloud models. Tenant isolation is essential because cloud services typically provide shared infrastructure, and flaws in isolation mechanisms can have serious implications for confidentiality and integrity. Supply chain management is gaining importance because cloud providers, in turn, often rely on subcontractors, platform services, data center operators, and external components. The new C5 addresses these dependencies in greater detail and calls for greater transparency regarding responsibilities, data flows, and the effectiveness of outsourced controls. This is precisely why the standard is more stringent in these areas: it addresses the risks that are particularly critical to security in real-world cloud environments today.

In the area of Identity and Access Management as well, the new standard has become more rigorous and up-to-date. C5:2026 explicitly incorporates modern security models such as Zero Trust. This is not merely a conceptual update, but an indication that access, permissions, and trust assumptions in cloud architectures will be viewed even more critically in the future. Whereas earlier models relied more heavily on network boundaries and blanket trust in systems, the focus is now shifting toward the need to continuously verify and secure identities, sessions, permissions, and technical access paths. In practice, the new standard therefore appears stricter because it is more closely aligned with current attack patterns and modern cloud operating models.

Another new development is that, for the first time, technological topics that were not addressed in this form in C5:2020 have been specifically and systematically included. These include container management, post-quantum cryptography, and confidential computing. These three topics in particular demonstrate just how strongly C5:2026 is focused on future-readiness. Containers are central to modern cloud platforms and carry their own risks related to images, orchestration, runtime environments, and tenant isolation. Post-quantum cryptography addresses the question of how cryptographic protection mechanisms can be safeguarded against new computing paradigms in the long term. Confidential computing, in turn, aims to protect data during processing—that is, to provide a level of protection that goes beyond traditional security measures for data “at rest” and “in transit.” The fact that the new C5 explicitly includes these areas makes it more up-to-date from a technical standpoint and, as a result, more rigorous, because it requires additional evidence in areas that were previously often outside the scope of traditional audit logic.

Why the changes are also relevant in practice

This increased rigor stems not only from the content but also from the new format in which it is made available. For the first time, C5:2026 is also being provided in a machine-readable format. While this may seem like a purely technical detail at first glance, it has significant practical implications. This is because machine-readable requirements can be more easily integrated into governance, risk, and compliance processes, control libraries, and automated testing and verification procedures. The more requirements can be operationalized and systematically reconciled, the less room there is for vague interpretations or informal case-by-case solutions. This, too, is one reason why the new version has a more disciplining effect in practice than its predecessor.

For cloud providers, the C5:2026 therefore means one thing above all else: more effort required for implementation, stricter documentation requirements, and greater accountability. In the future, it will be even less sufficient to describe security measures merely in conceptual terms. What will be expected are clearly defined responsibilities, robust policies, documented procedures, technical implementation, and convincing evidence in the context of audits. For cloud customers and procurement agencies, however, this is precisely an advantage. They gain a better foundation for comparing providers, assessing residual risks, and more clearly defining requirements for critical or particularly sensitive workloads. The new standard thus strengthens both sides of the market: reliability on the provider side and verifiability on the customer side.

What Companies Should Keep in Mind During the Transition

It is also important to consider the transition period. The criteria of C5:2026 are to be applied to audits with a reference date for Type 1 reports on or after June 1, 2027, and to audit periods for Type 2 reports beginning on or after June 1, 2027; earlier application is permitted. Furthermore, according to the published guidelines, there are no provisions for a mixed application of C5:2020 and C5:2026 within the same relevant audit period. For service providers and their clients, this means that anyone currently relying on C5:2020 should not delay the transition. The time until mid-2027 may seem long, but it will pass quickly when conducting gap analyses, planning actions, gathering evidence, and preparing for audits.

Conclusion: C5:2026 as the New Benchmark for Cloud Security

Taken as a whole, C5:2026 is therefore not simply “more of the same.” The new version expands the scope of criteria, refines existing requirements, addresses new technology risks, reduces room for interpretation, and enhances alignment with European and international reference frameworks. This is precisely what makes the standard stricter than the previous version: not only because more points are assessed, but because cloud-specific risks are addressed more precisely, operationally, and with a forward-looking perspective. Anyone who takes cloud security seriously in 2026 will have no choice but to adopt this new version.

To facilitate practical implementation in companies, the GRC Suite HITGuard will offer a questionnaire for the BSI C5:2026 standard. This will enable companies to assess and present their implementation status in a structured, efficient, and traceable manner. For companies, this provides a solid foundation for transparently evaluating their maturity level, areas requiring action, and progress toward compliance with the new standard, as well as for clearly communicating this information both internally and externally.


Sources:

Do you have any questions on this topic?

Our experts will be happy to advise you. Please contact us for a free consultation.

Contents

TOP