The C5:2026 readiness checklist cover image

Know where you stand on C5:2026 before your auditor does

Written by
No items found.
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

C5:2026 is the latest update to Germany's Cloud Computing Compliance Criteria Catalogue (C5), following a 2020 revision and its original release a decade ago. It's an imposing framework even by compliance standards: more than 168 criteria across 17 domains, with the 2026 update adding entirely new territory like post-quantum cryptography, confidential computing, and container management. 

For most teams, the hard part is knowing where to start, which criteria actually apply to them, and how to evidence domains they've never had to document before.

This checklist gives you a way in. Work through it domain by domain to see where you already meet the bar, where you have gaps, and which additional criteria are worth flagging based on your customer base. By the end, you'll have a clear picture of your starting point for a C5:2026 audit—not just a sense of how big the framework is.

C5 basics for those new to the framework

C5 is published by Germany's Federal Office for Information Security (BSI) and used to assess the information security of cloud services. 

Who it applies to

C5 is used by cloud service providers to prove their security posture. It’s required as a minimum standard for German federal agencies using cloud services. 

Enterprise buyers and public-sector organizations are increasingly requesting it across the DACH region and the broader EU, especially for providers expanding into or serving customers in those markets.

It's also becoming a hard requirement in specific sectors: As of July 2025, Germany's Digital Modernization Act (DigiG) requires cloud providers handling health insurers' and hospitals' social security data to hold a valid C5 attestation.

Vanta tip: Even if you're not contractually required to obtain a C5 attestation, it's worth considering. C5:2026 is built for compatibility with the EUCS Substantial level and incorporates NIS2 and ISO/IEC 27001:2022 requirements, meaning an early attestation gets you ahead of the EU's broader cloud certification push and cuts down the audit lift if NIS2 or a future EUCS mandate applies to you later.

Attestation

Similar to the SOC 2 framework, organizations engage a third-party auditor to receive a C5 attestation report. As with SOC 2, there are two report types: 

  • A Type 1 evaluates whether controls are designed appropriately at a point in time.
  • A Type 2 tests operating effectiveness over an observation period (typically 6–12 months). This is the type most enterprise and public-sector buyers expect, and the one DigiG requires for healthcare.

What C5 assesses

C5 considers roughly 168 criteria across 17 domains, such as cryptography, asset management, security policies and procedures, and more. 


All organizations do not need to follow all criteria: There is a mandatory baseline that everyone must follow, plus optional, contractually-triggered add-ons.

  • Basic criteria: These are mandatory. Every C5 audit assesses your organization against these, regardless of your customer base. The C5 catalogue marks which criteria are mandatory.
  • Additional criteria: Customers with higher security standards typically request additional criteria. C5 splits additional criteria into two types:
    • Sharpening: These criteria replace an existing basic requirement with a stricter threshold, a shorter timeframe, or a broader scope
    • Complementing: These criteria introduce a distinct requirement that basic criteria don't cover at all

Vanta tip: Before you do anything, figure out which of your enterprise contracts already require additional criteria. If you’re not sure, talk to your sales and legal teams before finalizing your audit scope to determine which additional criteria are most likely to apply.

What’s new in the 2026 edition

If your team looked at C5 before, it’s worth brushing up on the latest edition’s new requirements and criteria. Specifically, look into the following updates:

  • Shared Security Responsibility Model (SSRM): Providers must now explicitly document and communicate which security responsibilities sit with them versus their customers
  • Dozens of net-new criteria: There are new criteria across remote work security, asset inventories, container and confidential computing security, and supply chain transparency
  • A restructured Identity and Access Management domain: This domain has been renumbered from the prior edition

Vanta tip: Treat any gap assessment predating this edition as outdated, not as a starting point.

The C5:2026 self-assessment

Work through the questions below, domain by domain, and note where you already have a documented answer versus where you don't. 

Once you've flagged the gaps, go back through your enterprise contracts to see which additional criteria apply on top of the basics—that's what determines how much further you need to go beyond this checklist.

Vanta tip: Leaving several boxes unchecked in a domain is normal for a first pass—it just tells you where to focus first.

{{c5-readiness="/checklists"}}

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.