At the end of March 2026, Germany's BSI quietly published C5:2026 — the first complete revision of its Cloud Computing Compliance Criteria Catalogue since 2020. Hardly anyone talked about it, yet it contains a hard deadline: for audit periods ending on or after 1 June 2027, the BSI recommends the new version. If you sell cloud services to German companies or the public sector, your next attestation already runs on C5:2026.
That would be a footnote in procurement law if C5 were not the backbone of cloud security purchasing in Germany. The BSI has counted more than a hundred attestations — from German mid-market providers to global hyperscalers. Anyone offering cloud or AI infrastructure to public buyers today cannot get around three catalogues: NIST CSF 2.0, CSA CCM, and C5:2026. The good news: they are deliberately aligned with each other. Once you understand the mapping, you stop doing the work twice.
The three frameworks NIST CSF 2.0, ISO 27001, and CSA CCM feed the C5:2026 shield; the stamp marks the audit-period deadline of 1 June 2027
| Framework | Steward | Version | Size | Role |
|---|---|---|---|---|
| NIST CSF 2.0 | NIST (US) | Feb 2024 | 6 functions, 106 subcategories | International risk vocabulary |
| ISO/IEC 27001:2022 | ISO/IEC | 2022 | 93 controls in 4 themes | Certifiable ISMS |
| CIS Controls v8.1 | CIS | May 2024 | 18 controls, 153 safeguards | Technical hardening |
| CSA CCM v4 | Cloud Security Alliance | Jan 2021 | 197 controls in 17 domains | Cloud role model |
| BSI C5:2026 | BSI (Germany) | Mar 2026 | Successor to C5:2020 | Attestation for the German market |
The NIST Cybersecurity Framework is the most neutral common denominator: voluntary, free, and since version 2.0 explicitly designed for organisations of every size. Its six functions — Govern, Identify, Protect, Detect, Respond, Recover — with Govern as the new roof have become the lingua franca of security management. Even if you never deal with US agencies: when a customer asks how your security programme is structured, a CSF answer is the one understood everywhere.
The CSA Cloud Controls Matrix solves the problem every other catalogue sidesteps: who implements which control — the provider or the customer? 197 control objectives across 17 domains, each with role assignments. Add the CAIQ questionnaire: providers answer standardised, customers read — instead of running every client's bespoke security questionnaire merry-go-round.
C5 is not a law but an audit catalogue with market weight. The model: the cloud provider commissions an auditor directly, the auditor attests compliance with the criteria, and the customer evaluates the report for their own risk management (the BSI itself audits nobody and does not evaluate reports either). For buyers, the attestation is the key pre-filter in provider selection — and for providers, the evidence the German market expects.
The 2026 revision has three essential threads:
Practical bonus: the BSI publishes a cross-reference table from C5 to ISO 27001:2022. If you already run an ISMS, you can reuse evidence instead of documenting everything twice.
For public administration, the frame is bigger than C5 alone:
If you deliver cloud or AI services to German companies or authorities:
| Date | Event |
|---|---|
| 17 Oct 2024 | NIS2 transposition deadline (DE implementation delayed) |
| 17 Jan 2025 | DORA applies to financial entities |
| 2 Feb 2025 | EU AI Act Art. 4 — AI literacy, all providers and deployers |
| 2 Aug 2025 | AI Act obligations for general-purpose AI models |
| End Mar 2026 | BSI C5:2026 published |
| 2 Aug 2026 | AI Act high-risk obligations (Annex III) |
| 1 Jun 2027 | C5:2026 for audit periods ending from this date |
The trend across every catalogue is the same: they map onto each other, and evidence produced once travels. If you build a mapping table of your own controls and evidence today — in essence a bipartite graph between controls and frameworks — you have saved yourself half of tomorrow's audit effort.
Concretely: pull the catalogue and cross-reference table from the BSI C5 page, download the CSA's CCM v4, and sketch your Current position against NIST CSF 2.0. Three downloads, one afternoon — and the next questionnaire from a public buyer stops being a fire drill.