Share this article

Know where you stand on C5:2026 before your auditor does
Accelerating security solutions for small businesses Tagore offers strategic services to small businesses. | A partnership that can scale Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. | Standing out from competitors Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market. |
C5:2026 is the latest update to Germany's Cloud Computing Compliance Criteria Catalogue (C5), following a 2020 revision and its original release a decade ago. It's an imposing framework even by compliance standards: more than 168 criteria across 17 domains, with the 2026 update adding entirely new territory like post-quantum cryptography, confidential computing, and container management.
For most teams, the hard part is knowing where to start, which criteria actually apply to them, and how to evidence domains they've never had to document before.
This checklist gives you a way in. Work through it domain by domain to see where you already meet the bar, where you have gaps, and which additional criteria are worth flagging based on your customer base. By the end, you'll have a clear picture of your starting point for a C5:2026 audit—not just a sense of how big the framework is.
C5 basics for those new to the framework
C5 is published by Germany's Federal Office for Information Security (BSI) and used to assess the information security of cloud services.
Who it applies to
C5 is used by cloud service providers to prove their security posture. It’s required as a minimum standard for German federal agencies using cloud services.
Enterprise buyers and public-sector organizations are increasingly requesting it across the DACH region and the broader EU, especially for providers expanding into or serving customers in those markets.
It's also becoming a hard requirement in specific sectors: As of July 2025, Germany's Digital Modernization Act (DigiG) requires cloud providers handling health insurers' and hospitals' social security data to hold a valid C5 attestation.
Vanta tip: Even if you're not contractually required to obtain a C5 attestation, it's worth considering. C5:2026 is built for compatibility with the EUCS Substantial level and incorporates NIS2 and ISO/IEC 27001:2022 requirements, meaning an early attestation gets you ahead of the EU's broader cloud certification push and cuts down the audit lift if NIS2 or a future EUCS mandate applies to you later.
Attestation
Similar to the SOC 2 framework, organizations engage a third-party auditor to receive a C5 attestation report. As with SOC 2, there are two report types:
- A Type 1 evaluates whether controls are designed appropriately at a point in time.
- A Type 2 tests operating effectiveness over an observation period (typically 6–12 months). This is the type most enterprise and public-sector buyers expect, and the one DigiG requires for healthcare.
What C5 assesses
C5 considers roughly 168 criteria across 17 domains, such as cryptography, asset management, security policies and procedures, and more.
All organizations do not need to follow all criteria: There is a mandatory baseline that everyone must follow, plus optional, contractually-triggered add-ons.
- Basic criteria: These are mandatory. Every C5 audit assesses your organization against these, regardless of your customer base. The C5 catalogue marks which criteria are mandatory.
- Additional criteria: Customers with higher security standards typically request additional criteria. C5 splits additional criteria into two types:
- Sharpening: These criteria replace an existing basic requirement with a stricter threshold, a shorter timeframe, or a broader scope
- Complementing: These criteria introduce a distinct requirement that basic criteria don't cover at all
Vanta tip: Before you do anything, figure out which of your enterprise contracts already require additional criteria. If you’re not sure, talk to your sales and legal teams before finalizing your audit scope to determine which additional criteria are most likely to apply.
What’s new in the 2026 edition
If your team looked at C5 before, it’s worth brushing up on the latest edition’s new requirements and criteria. Specifically, look into the following updates:
- Shared Security Responsibility Model (SSRM): Providers must now explicitly document and communicate which security responsibilities sit with them versus their customers
- Dozens of net-new criteria: There are new criteria across remote work security, asset inventories, container and confidential computing security, and supply chain transparency
- A restructured Identity and Access Management domain: This domain has been renumbered from the prior edition
Vanta tip: Treat any gap assessment predating this edition as outdated, not as a starting point.
The C5:2026 self-assessment
Work through the questions below, domain by domain, and note where you already have a documented answer versus where you don't.
Once you've flagged the gaps, go back through your enterprise contracts to see which additional criteria apply on top of the basics—that's what determines how much further you need to go beyond this checklist.
Vanta tip: Leaving several boxes unchecked in a domain is normal for a first pass—it just tells you where to focus first.
{{c5-readiness="/checklists"}}





FEATURED VANTA RESOURCE
The ultimate guide to scaling your compliance program
Learn how to scale, manage, and optimize alongside your business goals.















.png)






