What is the C5 certificate?

Benchmark for secure cloud services in Germany
A bright blue, three-dimensional padlock, whose surface looks like a circuit board, stands on a stylized, blue cyber network. The image symbolizes cyber security, data encryption, network protection and the digital security of IT systems.

July 21, 2026, Reading time: 7 minutes

At a Glance: The C5 Certification for the STACKIT Cloud

  • Highest Level of Security According to the BSI Standard: The STACKIT Cloud is certified according to the C5 Criteria Catalog (Cloud Computing Compliance Criteria Catalog) of the German Federal Office for Information Security (BSI).
  • Comprehensive and ongoing verification: STACKIT meets more than 120 stringent criteria across 17 security areas. The C5 Type 2 certification confirms not only the fundamental design but also—through independent auditors—the ongoing effectiveness of security measures during live operation.
  • Maximum compliance & data sovereignty: The certification gives companies and the public sector the assurance that their data is strictly protected in a GDPR-compliant, sovereign cloud infrastructure with data centers in Germany and Austria.
  • For Regulated Industries: In combination with other standards (such as ISO 27001, ISAE 3000 / SOC 2), the C5 certification provides a reliable and immediately usable basis for demonstrating compliance with the highest regulatory requirements.

The introduction of the C5 certificate by the German Federal Office for Information Security (BSI) has created a central standard for information security and data protection in German cloud computing.

Especially for the public sector, for municipalities, federal states and the federal government as well as for companies in the healthcare sector, the C5 certificate is a decisive proof: It guarantees that cloud providers meet the highest standards for the protection of sensitive data and the security of information - and that they only apply current criteria that are recognized in Germany.

What is the C5 certificate?

The C5 certificate stands for tested security, transparency and reliability in cloud services. It offers public clients and health companies a clear advantage: the selection and awarding of a cloud service is made easier by comprehensible test reports and the disclosure of relevant information. Compared to other certificates, the C5 certificate specifically focuses on German standards and thus creates trust in the security and protection of the processed data.

Added value for the public sector and health

The secure processing and storage of large volumes of data is essential for public authorities, local authorities and companies in the healthcare sector. The C5 certificate helps them to comply with legal requirements and ensure information security for all cloud services. This means that citizens, patients and customers all benefit from modern, secure and reliable digital services.

Definition: Everything you need to know about the Cloud Computing Compliance Criteria Catalogue (C5)

STACKIT and the C5 certificate: Systematic security - advantages at a glance

STACKIT not only meets the formal requirements of the C5 certificate - it also creates real added value for companies, authorities and organizations. The following advantages show why working with STACKIT is worthwhile.

Security made in Germany

STACKIT meets the BSI’s current C5 criteria. This means the highest standards in data protection, information security, and compliance—all verified and documented.

Full transparency

Customers gain insight into security measures and audit reports. This builds trust and simplifies their own compliance efforts.

Legal and Future Certainty

With STACKIT, companies and government agencies can comply not only with current but also with future legal and regulatory requirements.

Support from Experts

The experienced STACKIT team supports you at every stage—from consulting to implementation to ongoing operations.

Scalable cloud solutions

The STACKIT portfolio includes high-performance services that can be flexibly tailored to individual requirements.

Data sovereignty through geographical advantage

Data processing takes place exclusively in European data centers. This is particularly important for projects in the public sector and for the federal government, compliance with the C5 guidelines is a key selection criterion.

The C5 certificate in detail: security with traceable standards

The BSI's C5 certificate is regarded as the authoritative standard for assessing cloud security in Germany. It defines binding guidelines in various control areas - from technical security measures to organizational processes. The underlying catalog of criteria covers all relevant aspects for trustworthy cloud operations.

The focus is on the following areas, among others

Risk management

This involves systematically identifying and evaluating potential risks within the cloud infrastructure and defining suitable measures to mitigate these risks. The aim is to deal with security-related vulnerabilities in a transparent and comprehensible manner.

Operational security

The secure and stable operation of cloud services is ensured by defined processes for controlling, monitoring and documenting the IT systems. These include regular system checks, emergency plans and a clear allocation of roles in the operating team.

Access and identity management

It is ensured that only authorized persons can access systems and data. This includes the management of user accounts, roles and authorizations as well as multi-factor authentication.

Data encryption

Sensitive information is protected using the latest cryptographic methods - both during transmission and storage. The selection of procedures is based on recognized security standards.

Incident management

In the event of security incidents, processes must be defined to quickly identify, report and process events. This also includes analyzing causes and implementing preventive measures.

Compliance and transparency

All security-relevant processes and measures are fully documented. This documentation forms the basis for internal controls and external evidence for customers, supervisory authorities and auditors.

Availability and reliability

The aim is to ensure a high level of operational readiness of the cloud services - even in the event of disruptions or attacks. To this end, technical and organizational measures such as redundancies, backups and emergency tests are implemented.

Regular updating of the catalog

The C5 criteria catalog is continuously developed by the BSI. This means that new threat scenarios and technological developments are taken into account promptly - for example in the areas of AI, remote work or zero trust.

The C5 certificate in detail: security with traceable standards

The BSI's C5 certificate is regarded as the authoritative standard for assessing cloud security in Germany. It defines binding guidelines in various control areas - from technical security measures to organizational processes. The underlying catalog of criteria covers all relevant aspects for trustworthy cloud operations.

The focus is on the following areas, among others

  • Risk management: This involves systematically identifying and evaluating potential risks within the cloud infrastructure and defining suitable measures to mitigate these risks. The aim is to deal with security-related vulnerabilities in a transparent and comprehensible manner.
  • Operational security: The secure and stable operation of cloud services is ensured by defined processes for controlling, monitoring and documenting the IT systems. These include regular system checks, emergency plans and a clear allocation of roles in the operating team.
  • Access and identity management: It is ensured that only authorized persons can access systems and data. This includes the management of user accounts, roles and authorizations as well as multi-factor authentication.
  • Data encryption: Sensitive information is protected using the latest cryptographic methods - both during transmission and storage. The selection of procedures is based on recognized security standards.
  • Incident management: In the event of security incidents, processes must be defined to quickly identify, report and process events. This also includes analyzing causes and implementing preventive measures.
  • Compliance and transparency: All security-relevant processes and measures are fully documented. This documentation forms the basis for internal controls and external evidence for customers, supervisory authorities and auditors.
  • Availability and reliability: The aim is to ensure a high level of operational readiness of the cloud services - even in the event of disruptions or attacks. To this end, technical and organizational measures such as redundancies, backups and emergency tests are implemented.
  • Regular updating of the catalog: The C5 criteria catalog is continuously developed by the BSI. This means that new threat scenarios and technological developments are taken into account promptly - for example in the areas of AI, remote work or zero trust.

Certification: an overview of the testing process

Before a cloud provider receives the C5 certificate, it undergoes a multi-stage testing process. This ensures that not only individual objectives are met, but also that the entire security concept is comprehensibly documented and effectively implemented.

After successful completion, the C5 certificate is awarded. It is limited in time and must be renewed regularly. For customers, it is transparent proof of the provider's security quality - and an important tool for their own risk and compliance assessment.
 

1. Gap analysis

It starts with an inventory: A gap analysis determines the differences between the current security level and the requirements of the C5 catalog. The existing documentation of the cloud provider serves as the central basis.

2. List of Measures

Based on the analysis, a concrete action plan is developed. The goal is to systematically address all outstanding requirements. This process is often undertaken with the help of external consultants or auditors, for example through workshops or technical recommendations.

3. Audit and Attestation

The actual audit is conducted by independent, qualified auditors in accordance with the internationally recognized auditing standard ISAE 3000. The audit verifies whether the defined controls are effective and whether all supporting evidence has been documented in a complete and traceable manner.

4. The Different Types of Audit Reports

Depending on the scope of the audit, you can choose between two options:

  • Option 1: Confirmation that all requirements were met at the time of the audit (point-in-time audit).
  • Version 2: Evidence that the requirements were consistently met over a longer period of time—usually 6 to 12 months.

Practical tips and information about the C5 audit report: find out what you should look out for

We offer you audited cloud services that meet the highest security and compliance requirements.

  • Choose your cloud provider carefully: When selecting your cloud partner, make sure they have a current C5 audit certificate - ideally type 2. This provides the most comprehensive proof of ongoing compliance with security requirements.
  • Check the certificate regularly: Ask to see the valid C5 certificate and - if available - the associated test report. This will give you clarity about the current security status of the service provider and possible restrictions.
  • Use C5 as part of your compliance strategy: Integrate the C5 test certificate specifically into your own risk analysis. It provides reliable information for audits, documentation and internal review processes.
  • Don't forget your duty to cooperate: Customers also have responsibilities - for example in the secure configuration of services, in access management or in the selection of suitable protection mechanisms.
  • Involve support from STACKIT: The STACKIT team is experienced and available to advise you - from implementation to compliance documentation. This allows you to meet all requirements efficiently and proactively.
  • Combine security modules: Supplement C5-certified cloud services with additional measures such as ISO certifications, zero-trust architectures or backup solutions. This increases protection and strengthens your overall strategy.

Our tip: The BSI offers further information and topics relating to cloud computing standards on its website.

Get started in the cloud with tested security

The C5 certificate is the binding benchmark for a secure, trustworthy and legally compliant cloud service in Germany - and is therefore a key selection criterion, especially for the public sector and regulated industries such as healthcare.

With STACKIT, you are choosing a cloud provider that not only fulfills the current C5 objectives, but also accompanies you competently and in partnership on your way to the secure cloud - from implementation to support.

FAQ - frequently asked questions about the C5 certificate