BSI C5 Attestation, Explained for SaaS Companies Selling in Germany
Blog post from Qovery
BSI C5 is Germany’s government-issued cloud security criteria catalogue, but compliance is demonstrated through a C5-Testat, an independent auditor’s attestation under ISAE 3000 rather than a public certificate. It is legally required mainly for German federal cloud procurement, while private SaaS providers encounter it as a commercial requirement from enterprises, regulated financial institutions, healthcare organizations, and public-sector tenders. Type 1 reports assess whether controls are suitably designed at a point in time, whereas Type 2 reports assess their effective operation over roughly six to twelve months and are increasingly expected by buyers. C5 overlaps with ISO 27001 and SOC 2 but adds mandatory disclosures on jurisdiction, data-processing locations, subprocessors, certifications, and government-access requests, with reports typically shared under NDA. Although cloud providers such as AWS, Azure, and Google Cloud can cover underlying infrastructure controls within their attested scope, SaaS companies remain responsible for complementary controls including access management, reviewed deployment changes, logging and retention, encryption, patching, portability, incident response, and accurate data-location documentation. The central preparation challenge is producing continuous, auditable operational evidence through infrastructure as code, controlled production pipelines, centralized logging, and well-defined cloud and subprocessor boundaries rather than merely maintaining policies.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Kubernetes | 11 | No monthly metrics for this publish month. | |||
| Observability | 1 | No monthly metrics for this publish month. | |||
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.