C5 CLOUD COMPLIANCE

Your Cloud Provider Has a C5 Attestation.
You Still Need Your Own.

Since 1 July 2025, § 393 SGB V has required a current C5 Type 2 attestation for the cloud systems in use, along with implementation of the corresponding customer criteria from the audit report. Your cloud provider’s attestation covers their infrastructure, not your application. On the prevailing reading, your application layer needs evidence of its own. We help you close that gap.

Trusted by MedTech Innovators
dermanostic GmbH logoElona Health GmbH logoNoah Labs GmbH logorelios.vision GmbH logo

"My Cloud Provider Is C5-Certified, So I'm Covered".

This is the most common and most dangerous assumption in C5 compliance. Here is what it actually means:

Your Provider's C5 Attestation Covers Infrastructure Only

AWS, Azure, and GCP hold C5 attestations at the infrastructure level. Their audit reports contain corresponding criteria for customers that you must implement under § 393 (3) no. 3 SGB V. For your own application layer, the prevailing reading is that separate evidence is required, because your provider’s attestation does not cover it.

Application-Level Controls Are Your Responsibility

Access management, encryption configuration, monitoring, and incident response for your application are not covered by your cloud provider’s attestation. Their C5 attestation explicitly excludes how you use their services.

The Shared Responsibility Model Has Legal Consequences

The statutory text does not spell out how far your own duty of evidence reaches. On the prevailing reading, you carry the risk if you cannot independently demonstrate compliance for your application layer, regardless of what certifications your cloud provider holds.

Who is affected:

  • Healthcare SaaS providers: Organizations processing health data in cloud systems.
  • Medical device manufacturers (SaMD): Developers of SaMD and DiGA processing data in clinical or practice settings.
  • Connected MedTech & IoT: Companies connecting smart medical devices to cloud infrastructure.
  • Organizations processing health data under § 393 SGB V.

What Is C5?

The BSI's Cloud Computing Compliance Criteria Catalogue, explained.

1BSI C5 at a Glance

The BSI’s Cloud Computing Compliance Criteria Catalogue organizes basis and additional criteria into 17 areas. Basis criteria must all be met for an attestation, while additional criteria describe a higher level of protection, such as for processing patient records. The current edition is C5:2026. It supersedes C5:2020 and adds criteria on container management, supply chain management, post-quantum cryptography, and confidential computing.

2Type 1 vs. Type 2

A Type 1 attestation confirms that the right controls are designed and in place at a point in time. A Type 2 attestation goes further: it verifies that those controls have actually worked over a continuous period, which in our projects runs 6 to 12 months. Under § 393 (4) SGB V, a Type 2 attestation has counted as the current attestation since 1 July 2025. For systems first placed on the market after 30 June 2025, a Type 1 attestation suffices for the first 18 months.

3The Critical Difference from ISO 27001

In an ISO 27001 audit, if the auditor finds issues, you fix them and get certified. In a C5 Type 2 audit, the auditor reviews the preceding evidence period, 6 to 12 months in our projects. If controls were not operational during that period, you fail. There is no retroactive fix. This is why preparation before the audit period begins is essential. In substance the two frameworks still sit close together: for C5:2026, ISO/IEC 27001:2022 and ISO/IEC 27002:2022 head the list of standards whose requirements fed into the catalogue.

The C5:2026 criteria apply to Type 1 reports with an as-of date on or after 1 June 2027 and to Type 2 reports whose audit period begins on or after 1 June 2027. Earlier application is permitted. A Type 2 period that starts before that date and ends after it should cover C5:2020 only, because the two editions must not be mixed within one engagement. We already build our preparation around C5:2026.

Shared Responsibility: What's Covered, What's Not

We help you identify exactly which C5 criteria apply to your product and which are already covered by your provider.

Cloud Provider's C5 Attestation

  • Physical data center security
  • Network infrastructure
  • Hypervisor & host OS
  • Infrastructure monitoring
  • Hardware compliance

Your Responsibility

  • Application-level access controls
  • Data encryption configuration
  • Guest OS patching
  • Application monitoring & logging
  • Identity & access management
  • Incident response procedures
  • Data handling & retention policies
  • Personnel security & training

Your Audit is Led by Senior Experts

Not juniors. Not generalists. Specialists in medical device security.

Dr. Simon Weber Profile

Dr. rer. nat. Simon Weber

Senior Pentester & MedSec Researcher

I evaluate your SaMD with the same industry-defining security insight I contributed to the BAK MV for the revision of the B3S standard.

  • PhD on Hospital Cybersecurity
  • Critical vulnerabilities found in hospital systems
  • Alumni of THB MedSec Research Group
  • gematik Security Hero
Volker Schönefeld Profile

Dipl.-Inf. Volker Schönefeld

Senior Application Security Expert

As a former CTO and developer turned pentester, I work alongside your team to uncover vulnerabilities and find solutions that fit your architecture.

  • 20+ years as CTO, 50M+ app downloads
  • Architected and secured large-scale IoT fleets
  • Certified Web Exploitation Specialist
  • gematik Security Hero

Our Approach

From gap analysis to attestation, a structured path to C5 compliance.

1

Scoping & Gap Analysis

We determine which criteria, both basis and relevant additional, apply to your specific product. We map your cloud provider’s coverage against your responsibilities and identify gaps in processes, documentation, and technical controls.

2

Internal Control System & Documentation

We build your Internal Control System (IKS) following BSI templates. This includes defining controls, measures, and evidence for each applicable criterion, creating your risk control matrix, and documenting everything to auditor expectations.

3

Implementation & Go-Live

We implement the required processes and technical controls, then define the start date from which the auditable period begins. Together we ensure your organization actually lives these processes day-to-day, because paper compliance without practice is the most common reason for failure.

4

Attestation

After 6 to 12 months of operational evidence, we support you through the formal audit process. We work with accredited auditing partners for the attestation itself.

What Makes C5 Expensive

Honest risks you should know about before you start.

Paper Compliance

You document perfect processes but do not actually follow them. The auditor samples real evidence from the past months and finds nothing. This is by far the most common reason for failure.

Starting Too Early

You trigger the audit period before controls are actually running. The clock is ticking on a period you cannot fix later.

Wrong Scope

Over-scoping wastes money. Under-scoping means failing the audit and starting over.

The Leadership Factor

C5 compliance is not just a compliance team project. Leadership commitment, the "Tone at the Top," must be genuine. Auditors can tell.

Preparation costs money. But there is nothing more expensive than failing a C5 attestation, because you pay for the audit and you have to start the entire evidence period over.

Frequently Asked Questions

What you need to know about C5 compliance for medical devices.

What is the difference between C5 Type 1 and Type 2?

Type 1 is a point-in-time design check: are the right controls in place? Type 2 audits a preceding period, 6 to 12 months in our projects: have those controls actually worked? For processing social and health data in the cloud, § 393 (4) SGB V has treated a Type 2 attestation as the current attestation since 1 July 2025.

When do I have to move to C5:2026?

C5:2026 applies to Type 1 reports with an as-of date on or after 1 June 2027 and to Type 2 reports whose audit period begins on or after 1 June 2027. Earlier application is permitted. If your Type 2 period starts before 1 June 2027 and ends after it, the audit covers C5:2020 only, as mixing the two editions is not provided for. If the period ends on or after 28 February 2027, planned changes to controls must be disclosed in the system description. In practice: anyone starting a new Type 2 period in 2027 is better off building the control system on C5:2026 from the outset.

Do I need my own C5 attestation if I use AWS, Azure, or GCP?

On the prevailing reading, yes. Your cloud provider’s C5 attestation covers their infrastructure, not how you use it. Two points are worth separating: the corresponding criteria for customers in your provider’s audit report must be implemented in any case under § 393 (3) no. 3 SGB V. For your application layer itself, meaning access controls, encryption configuration, monitoring, and incident response, the separate duty of evidence follows from how § 393 SGB V is read, not from its wording.

How long does the entire process take from start to Type 2?

Plan for 12 to 18 months minimum. This includes preparation (3 to 6 months), the audit period itself (6 to 12 months), and the formal audit. Starting with a Type 1 attestation as interim proof is possible while building the track record for Type 2.

Can I start with Type 1 and upgrade to Type 2 later?

Yes, and we often recommend this. A Type 1 attestation serves as interim proof of your control design while you accumulate the 6 to 12 months of operational evidence required for Type 2.

What does C5 preparation cost?

It depends on your product scope, the number of applicable criteria, and the maturity of your existing controls. We provide a clear estimate after the initial scoping and gap analysis.

What happens if I fail the attestation?

You pay for the audit and have to start the entire evidence period over. The auditor cannot retroactively accept controls that were not operational. This is why thorough preparation before the audit period is critical.

How does C5 relate to ISO 27001?

They are complementary, not replacements. ISO 27001 certifies your information security management system, while C5 specifically addresses cloud computing controls. With C5:2026 the two sit closer than before: BSI lists ISO/IEC 27001:2022 and ISO/IEC 27002:2022 first among the standards whose requirements fed into the catalogue. C5 basis criterion OIS-01 already requires an ISO/IEC 27001-compliant ISMS, and a valid 27001 certificate whose scope fits satisfies the corresponding sharpening additional criterion. The catalogue also expressly provides that C5 and ISO audits can be combined to some extent. That is why we prepare both together on request: one control base, two forms of evidence. Note that pointing to an ISO certificate alone will not satisfy the auditor, as coverage of each C5 criterion has to be demonstrated individually.

Is C5 required only in Germany?

C5 is a BSI framework. German law (§ 393 SGB V) presupposes it for cloud-based processing of social and health data, but expressly also allows standards ensuring a comparable or higher level of security. Beyond that, C5 is increasingly recognized as a benchmark across Europe and served as a key input to the EU-wide EUCS cloud certification scheme.

From Pentest to MDR Certification

dermanostic GmbH logo
We have been working with Machine Spirits for several years and value their technical expertise and straightforward collaboration. Their actionable recommendations have been instrumental in sustainably strengthening the protection of the patient data entrusted to us.
Lucas Habrich
CTO, dermanostic GmbH

Not Sure If C5 Applies to Your Product?

Let’s find out together. We will assess your cloud setup, determine which C5 criteria apply, and outline a realistic path to your attestation.

Send Us a Message

Response Time

We typically respond to all inquiries within 24 hours during business days.

Average response time: 6-12 hours