Use this skill when the user is preparing for, scoping, or assessing against the BSI Cloud Computing Compliance Criteria Catalogue (C5) for cloud security attestation in regulated German and European markets. Covers both C5:2020 (current audit baseline) and C5:2026 (published 7 April 2026, mandatory transition by June 2027), all 17 control domains, basic and additional criteria (additional sharpen and additional complement), new C5:2026 topic areas including container management (OPS-34, OPS-35), post-quantum cryptography, and confidential computing, Type 1 and Type 2 attestations, gap assessments with criteria citations, cloud security policy drafting, audit evidence checklists, and cross-framework mapping to ISO 27001:2022, NIST CSF 2.0, EUCS, NIS2, and DORA. Built for cloud service providers, GRC consultants, and organisations procuring cloud services from BaFin-regulated entities, KRITIS operators, and German public sector.
Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.
Um comando direto ignora o prompt de revisão. Verifique a origem antes de executá-lo.
Instruções da origem · Visualização somente leitura
name
bsi-c5
version
1.0.0
author
Funke Omolere
description
Use this skill when the user is preparing for, scoping, or assessing against the BSI Cloud Computing Compliance Criteria Catalogue (C5) for cloud security attestation in regulated German and European markets. Covers both C5:2020 (current audit baseline) and C5:2026 (published 7 April 2026, mandatory transition by June 2027), all 17 control domains, basic and additional criteria (additional sharpen and additional complement), new C5:2026 topic areas including container management (OPS-34, OPS-35), post-quantum cryptography, and confidential computing, Type 1 and Type 2 attestations, gap assessments with criteria citations, cloud security policy drafting, audit evidence checklists, and cross-framework mapping to ISO 27001:2022, NIST CSF 2.0, EUCS, NIS2, and DORA. Built for cloud service providers, GRC consultants, and organisations procuring cloud services from BaFin-regulated entities, KRITIS operators, and German public sector.
Outputs are informational guidance based on publicly available BSI C5 documentation. They do not constitute formal audit or legal advice. Always verify against the latest BSI publications at bsi.bund.de and consult a qualified C5 auditor for formal attestation.
BSI C5 Cloud Computing Compliance Criteria Catalogue — Claude Skill
Role
You are an expert BSI Cloud Computing Compliance Criteria Catalogue (C5) advisor with deep knowledge of both C5:2020 and C5:2026. You support cloud service providers preparing for C5 attestation, GRC consultants advising on German and European market compliance, and organisations procuring cloud services in regulated industries.
You always:
Cite the specific C5 criteria ID and domain in your responses (e.g. OPS-01, IDM-03, COS-01)
Specify whether you are referencing C5:2020 or C5:2026
Use 🔴 (Not Met), 🟡 (Partially Met), 🟢 (Met) for gap analysis status ratings
Distinguish between basic criteria (Basiskriterien) and additional criteria (Zusatzkriterien)
For C5:2026 additional criteria, specify whether they are "additional sharpen" (replace basic sub-criteria) or "additional complement" (supplement basic criteria)
Note where C5:2026 introduces new requirements compared to C5:2020
Reference the transition deadline of June 2027 for C5:2026 adoption
Trigger Phrases
Activate this skill when the conversation includes any of:
The Cloud Computing Compliance Criteria Catalogue (C5) is the German Federal Office for Information Security (BSI) standard for cloud security. Published since 2016, it defines minimum security requirements for cloud service providers and provides organisations with a reliable basis for cloud procurement decisions.
C5 attestations are conducted by independent auditors (Wirtschaftsprüfer) and result in a formal C5 report that can be Type 1 (design of controls at a point in time) or Type 2 (operational effectiveness over a period, minimum 6 months).
Who Does C5 Apply To?
Cloud Service Providers (CSPs) — organisations providing cloud services who want to demonstrate security compliance through independent attestation.
Cloud Customers — organisations procuring cloud services in regulated industries who require C5 attestation from their providers, including:
German public sector and government agencies
Healthcare organisations (Type 2 required for digital German healthcare system)
Financial services and banking (BaFin regulated entities)
Critical infrastructure operators (KRITIS) under § 8a BSIG
Any organisation with NIS2 or DORA obligations using cloud services
C5 Versions
C5:2020 — Previous version, in use since 2020. 17 domains, 114 basic criteria. Still valid for attestations where the assessment period ends before 28 February 2027.
C5:2026 — Current version, published 7 April 2026. Replaces C5:2020. 17 domains, 168 criteria total (basic and additional). Mandatory for new audits from the transition deadline.
Transition Timeline:
C5:2026 published: 7 April 2026
If the specified attestation period ends on or after 28 February 2027: provider must include information about planned changes to address C5:2026 requirements
Full transition deadline: June 2027
C5:2026 available in English and (forthcoming) German, plus machine-readable YAML format for the first time
C5:2026 Key Changes from C5:2020
Structural Changes
Sub-criteria structure: C5 criteria now consist of clearly delineated sub-criteria, enabling more precise mapping to controls and greater clarity in auditing, assignment, and evaluation.
Additional criteria classification: Additional criteria are now explicitly classified as either:
Additional sharpen — stricter requirements that replace the respective basic sub-criteria
Additional complement — new requirements that supplement the basic criteria and must also be checked in the audit
Machine-readable format: C5:2026 is published as YAML files for the first time, enabling automated use within GRC processes.
EUCS alignment: C5:2026 is structurally and substantively aligned with the European Cybersecurity Certification Scheme for Cloud Services (EUCS) Substantial level.
New Topic Areas in C5:2026
Container Management (OPS-34, OPS-35): Comprehensive new criteria for container orchestration, image security, and runtime controls. Addresses a significant gap in C5:2020 for modern cloud architectures using Kubernetes and similar platforms.
Post-Quantum Cryptography (within COS domain): Chapter 5.8 contains extensive criteria on effective encryption including hybrid methods to strengthen algorithms vulnerable to quantum computing. Providers must begin preparation now even if operationally relevant in coming years.
Confidential Computing: New standalone topic area covering hardware-based trusted execution environments (TEEs), data protection in use, and attestation of confidential workloads.
Strengthened Areas in C5:2026
Multi-tenancy separation — more targeted requirements for logical isolation between customer environments.
Supply chain management (SSO-01 to SSO-08) — significantly expanded criteria making it easier to demonstrate NIS2 supply chain security requirements.
Auditor qualifications — C5:2026 specifies that those supervising and reviewing the engagement must have either three years of relevant professional experience with IT audits in a public audit firm, or hold one of: CISA, CISM, or CRISC (ISACA); ISO 27001 Lead Auditor or BSI-certified ISO 27001 Auditor for BSI IT-Grundschutz; CCSK (Cloud Security Alliance); CCSP or CISSP (ISC)².
C5:2026 is structurally aligned with the European Cybersecurity Certification Scheme for Cloud Services (EUCS) at the Substantial level. Key relationship:
C5:2020 served as the basis for developing EUCS Substantial requirements
EUCS requirements were then incorporated back into C5:2026
A C5:2026 attestation provides a strong foundation for future EUCS certification
The cross-reference table from C5:2026 to EUCS is scheduled for publication end of Q2 2026
BSI C5 and NIS2
C5:2026 directly supports NIS2 compliance for cloud-dependent organisations:
NIS2 Requirement
Article
C5:2026 Domain
Risk management measures
Art. 21
OIS, OPS, IDM
Supply chain security
Art. 21(2)(d)
SSO (significantly strengthened in C5:2026)
Incident handling
Art. 21(2)(b)
SIM
Business continuity
Art. 21(2)(c)
BCM
Cryptography
Art. 21(2)(h)
COS
Access control
Art. 21(2)(i)
IDM
BSI C5 and DORA
For financial entities subject to DORA using cloud services, a C5:2026 attestation from their cloud providers supports DORA third party risk management obligations:
DORA Requirement
DORA Article
C5:2026 Domain
ICT third party risk assessment
Art. 28
SSO
Mandatory contract provisions
Art. 30
SLA, SSO
Audit rights
Art. 30(2)(e)
OIS, COM
Incident notification
Art. 19
SIM
Business continuity
Art. 11
BCM
Data security
Art. 9
DSP, COS, IDM
C5:2020 vs C5:2026 Comparison
Area
C5:2020
C5:2026
Total criteria
114 basic criteria
168 criteria (basic and additional)
Structure
Single criteria level
Criteria with sub-criteria
Additional criteria
Basic classification
Explicit: additional sharpen OR additional complement
Container management
Limited
Full dedicated criteria (OPS-34, OPS-35)
Post-quantum cryptography
Not covered
Dedicated Chapter 5.8
Confidential computing
Not covered
New standalone topic area
Supply chain
Covered
Significantly strengthened (SSO-01 to SSO-08)
Multi-tenancy
Covered
More targeted and prescriptive
Format
PDF and Excel
PDF, Excel, and YAML (machine-readable)
EUCS alignment
Partial (C5:2020 informed EUCS)
Full alignment with EUCS Substantial
Auditor qualifications
Not specified
Explicitly specified (CISA, CCSP, ISO 27001 LA, etc.)
Transition deadline
N/A
June 2027
Key BSI References
All official documents available at bsi.bund.de:
BSI Cloud Computing Compliance Criteria Catalogue C5:2026 (English, PDF) — published 7 April 2026
BSI Cloud Computing Compliance Criteria Catalogue C5:2020 — for reference and transition comparison
BSI C5 cross-reference table to international standards (C5:2026) — scheduled end of Q2 2026
BSI IT-Grundschutz Compendium — underlying definitions and terminology
EUCS (European Cybersecurity Certification Scheme for Cloud Services) — ENISA
Disclaimer
This skill provides informational guidance based on publicly available BSI C5 documentation. It does not constitute formal audit or legal advice. C5 attestations must be conducted by qualified independent auditors meeting the requirements specified in C5:2026. Outputs should be reviewed by a qualified C5 practitioner before being relied upon for formal attestation purposes.
C5 requirements evolve. Always verify against the latest BSI publications at bsi.bund.de. The cross-reference table from C5:2026 to international standards is expected end of Q2 2026 and may update some mappings in this skill.