German Standard — BSI Bundesamt

BSI C5 Cloud Audit
for AWS & Azure

The BSI C5 (Cloud Computing Compliance Criteria Catalogue) is increasingly required for German public sector contracts. Check your infrastructure against all BSI C5 controls in minutes.

1 free scan/monthNo credit cardHosted in Germany

What ConformScan checks

Identity & access management — MFA, privileged access
Cryptography — encryption standards, key management
Physical security — data center location, EU residency
Operations security — patch management, vulnerability scanning
Incident management — detection, response, reporting
Supplier relationships — third-party and subprocessor controls
Business continuity — backup, recovery, disaster recovery
Compliance — logging, audit trails, policy enforcement

Why automate compliance?

Public sector access

German federal procurement increasingly requires BSI C5 attestation. Without it, you cannot bid on contracts.

Continuous monitoring

BSI C5 is not a one-time audit. ConformScan keeps you compliant with scheduled scans.

Gap analysis

See exactly which BSI C5 controls you fail and get Terraform/CLI remediation snippets.

Hosted in Germany

All data processed on Netcup infrastructure in Karlsruhe. No US subprocessors.

BSI C5 — What you need to know

The BSI C5 (Cloud Computing Compliance Criteria Catalogue) was published by the German Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik). It defines minimum security requirements for cloud services used by German public sector organizations.

Who needs it? Cloud service providers targeting German federal agencies, state governments, and public sector organizations must demonstrate BSI C5 compliance. Increasingly, private sector companies working with public entities are also required to comply.

Scope: 17 control areas covering organization, human resources, asset management, physical security, operations, communications, access control, cryptography, procurement, development, incident management, business continuity, and compliance.

Start free BSI C5 audit

1 free scan/month. No credit card. Results in minutes.

Start free scan →