Cloud Computing Compliance Controls Catalogue
C5
German cloud security certification establishing minimum security requirements for cloud providers.
Purpose
Creates transparency and comparability for cloud service security assessments in Germany.
Requirements Overview
114 security requirements across 17 domains; Organization of information security; Compliance; Human resources; Asset management; Access control; Cryptography; Physical security; Operations; Communications; System development; Supplier relationships; Incident management
Overview
The Cloud Computing Compliance Controls Catalogue (C5) emerged in 2016 as a critical response to the growing complexity of cloud security in the German digital landscape. Developed by the German Federal Office for Information Security (BSI), the standard was created to establish a comprehensive and standardized framework for evaluating cloud service providers operating within German jurisdictional boundaries. Prior to C5, cloud security assessments were fragmented and inconsistent, leaving organizations vulnerable to potential security gaps. The standard represents a significant evolution in cloud governance, specifically addressing the unique challenges of cloud-native infrastructure and emerging digital threats. Unlike broader international frameworks, C5 provides a targeted approach that reflects the precise security requirements of German enterprises and government agencies. The standard comprises 114 specific security requirements distributed across 17 specialized domains, offering a detailed blueprint for secure cloud infrastructure design, operation, and monitoring. Its unique strength lies in its prescriptive yet flexible methodology, allowing certified providers to demonstrate compliance through multiple approaches while maintaining rigorous security standards. For data center operators, C5 certification has become a critical market differentiator. The standard goes beyond traditional security frameworks by emphasizing transparency, continuous monitoring, and robust incident response capabilities. It effectively sets a new benchmark for cloud security, particularly for organizations processing sensitive data within German territory.
Key Requirements
Organization of Information Security
Data centers must establish documented information security management systems (ISMS) with defined governance structures, including a Chief Information Security Officer (CISO) role or equivalent, security committees, and documented security policies specific to cloud operations.
Organizations must maintain evidence of security strategy documentation, incident response plans specific to cloud infrastructure, and regular security training programs for all personnel with access to customer data or infrastructure management functions.
This requirement mandates quarterly security reviews and annual risk assessments specifically addressing cloud-specific threat vectors, multi-tenant isolation risks, and hypervisor vulnerabilities.
Access Control and Authentication
Data centers must implement multi-factor authentication (MFA) for all administrative access to cloud infrastructure management systems, with mandatory hardware security keys or certificate-based authentication for privileged accounts.
Role-based access control (RBAC) must enforce the principle of least privilege with segregation between network administrators, storage administrators, and security personnel; access logs must be retained for minimum two years with tamper-evident protection and real-time alerting for privilege escalation attempts.
C5 explicitly requires that administrative access from outside German territory be logged, justified, and subject to additional approval workflows, addressing data sovereignty concerns specific to German regulatory expectations.
Cryptography and Key Management
All data in transit must be encrypted using TLS 1.2 or higher (or equivalent approved algorithms), while data at rest must employ AES-256 or higher encryption for customer data, with encryption keys managed through Hardware Security Modules (HSMs) or certified key management services.
Data centers must maintain documented cryptographic key lifecycle procedures including generation, rotation (minimum annually), storage in geographically segregated locations, and secure destruction protocols; customers must have the ability to bring their own keys (BYOK) or have keys encrypted such that the cloud provider cannot access plaintext customer data.
The standard requires cryptographic algorithm choices to be compliant with German BSI technical guidelines (TR-02102), explicitly excluding algorithms flagged as deprecated by BSI.
Physical Security and Data Center Infrastructure
C5 mandates that physical data centers housing German customer data must be located within German territory (with limited exceptions for redundancy in Austria, Switzerland, and Liechtenstein), with access controlled through multi-factor biometric systems or equivalent controls, surveillance by CCTV with minimum 90-day retention, and environmental monitoring with automated alerts for temperature, humidity, and water detection anomalies.
Facilities must maintain documented visitor logs, implement cages or separate physical zones for customer equipment where applicable, and conduct quarterly security penetration tests of physical access controls; power distribution and network interconnects must have redundancy rated to handle single component failures without customer data exposure.
Operations and Incident Management
Data centers must maintain 24/7 monitoring of cloud infrastructure with documented incident response procedures that achieve notification to affected customers within 24 hours of incident discovery, with detailed incident reports provided within 72 hours.
Organizations must conduct annual disaster recovery drills with documented results, maintain Recovery Time Objective (RTO) of maximum 4 hours and Recovery Point Objective (RPO) of maximum 1 hour for critical customer systems, and provide customers with transparent access to audit logs of all operations affecting their infrastructure.
C5 requires that data center staff involved in incident response receive annual specialized training and that post-incident reviews be documented with evidence of corrective actions implemented.
Supplier and Subcontractor Management
Data centers must maintain detailed inventories of all subcontractors and third-party service providers with contractual obligations requiring equivalent C5-level security controls; any subcontracting relationships must be disclosed to customers and subject to customer approval before implementation.
Organizations must conduct annual security audits of critical suppliers, maintain documented evidence of supplier compliance assessments, and establish contractual clauses requiring immediate notification of security incidents, audit results, and any changes to data handling practices.
The requirement explicitly mandates that data centers cannot subcontract core security functions without explicit C5 compliance from the subcontractor.
Communications Security and Network Architecture
Data centers must implement network segmentation using documented network architecture diagrams with segregation of customer environments, administrative networks, and security monitoring infrastructure; customer data networks must be isolated from data center operational networks using firewalls with documented egress filtering rules.
All inter-data-center communications and backups must transit encrypted tunnels (IPsec or equivalent) with cryptographic authentication; the standard requires documented network change control procedures with mandatory testing in isolated environments before production deployment.
DDoS protection mechanisms must be documented with specific thresholds and mitigation strategies, and customers must have visibility into network security controls affecting their data through transparent documentation.
System Development and Change Management
Cloud platforms supporting customer workloads must implement mandatory code review processes for all infrastructure code changes, with documentation of review participants, review comments, and approval authority before deployment.
Organizations must maintain version control systems for all configuration management, implement automated security scanning of container images and infrastructure code before deployment, and maintain audit trails of configuration changes for minimum three years.
The requirement mandates that patches and security updates be tested and deployed within defined timeframes (critical patches within 30 days, non-critical within 90 days) with documented testing evidence and customer notification of applicable patches.
Who Uses & Why
C5 certification becomes mandatory for data centers and cloud service providers in several specific scenarios. Organizations must pursue certification when serving German public sector entities, financial institutions regulated by BaFin, critical infrastructure operators in telecommunications and energy sectors, and healthcare providers processing sensitive patient data. Geographically, the standard is most critical for data centers operating in Germany, Austria, and other German-speaking regions. While not universally required, C5 certification provides significant competitive advantages for providers targeting German market segments. Mid-market data centers (100-500 employees) particularly benefit, as the certification establishes immediate security credibility. Optional but recommended scenarios include: (1) competing with established German cloud providers, (2) targeting medium to large German enterprises, and (3) differentiating service offerings in competitive markets. The certification process typically requires 6-12 months and involves comprehensive third-party audits. Key decision factors include customer base geography, regulatory requirements, internal security maturity, and willingness to maintain data residency within German territory. For international providers, C5 certification is not mandatory but can significantly enhance market positioning and customer trust.