Your situation

C5 consulting: preparing your cloud service for the audit

Your customers require C5 evidence for your cloud service. You want to know which requirements are still open and which evidence is missing. Our C5 consulting prepares you for the audit by a public auditor.

Free of charge and without obligation.

  • Cloud testing methods published in iX
  • BSI-certified for IS consulting and IS audit
  • Our own ISO 27001-certified ISMS
A secuvera consultant explaining the joint plan to her team at a map
C5 consulting: your cloud service well prepared for the attestation.

Your situation

You want your cloud service audited against BSI C5 and do not yet know what is missing for the attestation?

Your clients or partners expect evidence for your cloud service based on the BSI's Cloud Computing Compliance Criteria Catalogue (C5). The open questions are then: which requirements apply specifically? Which measures are missing for audit readiness? How much effort does it mean for your organisation? Should you start with a Type 1 or a Type 2 audit? And which existing security measures can you continue to use?

Many consultancies work through the C5 catalogue point by point. We first analyse your existing security measures and processes – for example from an ISMS to ISO/IEC 27001 – and check how they can be used for the C5 requirements. This way, we build on existing structures and avoid unnecessary effort.

The audit and attestation are carried out by a public auditor (Wirtschaftsprüfer). We support you up to audit readiness and provide the technical security evidence that C5 requires, with our own penetration tests if you wish. If you use cloud services yourself and want their configuration reviewed, the cloud security assessment is the better fit.

Services & results

Five steps to C5 audit readiness

You get a C5 gap analysis that maps your existing measures, for example from an ISMS (information security management system) to ISO/IEC 27001, to the BSI criteria catalogue, and a prioritised action plan up to audit readiness – including the decision between a Type 1 and a Type 2 audit. We provide the technical security evidence; the audit and attestation are carried out by your public auditor.

Every organisation starts at a different point. That is why we do not begin with a standard checklist but with a review of the current state – and develop measures that fit your processes and can be embedded in day-to-day work. On request, we also carry out the penetration tests required for C5.

Analysis of the current state

Together, we look at your existing processes and security measures. If your organisation already has an information security management system (ISMS), we build on it. If there is no ISMS yet, we support its structured development.

C5 gap analysis

We compare your current state with the requirements of the C5 criteria catalogue, assess your maturity level and map existing measures to the C5 requirements.

C5 gap analysis

Gap analysis, maturity assessment and mapping of existing measures to the C5 requirements.

Action planning

Together, we prioritise the necessary measures and develop a realistic implementation plan.

Your action plan

A prioritised implementation plan tailored to your organisation, up to audit readiness.

Implementation support

We support you in creating the evidence documentation and accompany the organisational introduction of the necessary processes.

For the technical security evidence, we carry out penetration tests on request. We can also review the configuration of your cloud environment in a cloud security assessment based on the CIS Benchmarks.

Preparing for the audit

Before the actual audit by the public auditor, we jointly assess the implementation status. This allows us to identify possible weaknesses early and reduce surprises in the audit.

Preliminary assessment of audit readiness

An assessment of your audit readiness, with the evidence and implementation steps still open.

Our expertise

C5 combines organisational requirements with technical security measures – and this combination also shapes our consulting. We combine decades of experience in building and further developing information security management systems with technical expertise in cloud security.

As a BSI-certified IT security service provider for penetration testing, we provide the technical evidence that the C5 criteria catalogue requires, for example through penetration tests, ourselves – with robust, traceable and reproducible test results. We review cloud configurations in our cloud security assessment based on the CIS Benchmarks. We have published in the iX Special "Security Tools" (2025) how large cloud environments can be checked reproducibly for misconfigurations and security risks using specialised tools.

Beyond C5, we advise on the BSI's Criteria enabling Cloud Computing Autonomy (C3A), which can be used to systematically assess dependencies on individual cloud providers.

Getting started

Mapping C5 requirements to your cloud service

Defining your cloud service and the C5 scope

We discuss your cloud service, the intended scope and your existing evidence. On this basis, we determine what support you need to reach audit readiness.

Discuss your C5 preparation
The points of a pair of dividers resting on coloured sticky notes above a map
C5 criteria precisely mapped to your cloud services.

The C5 attestation is issued by the public auditor

The actual audit and the issuing of the C5 attestation are carried out by a public auditor. Our consulting supports the preparation and does not replace the audit.

Questions about C5 preparation and attestation

Do we receive the C5 attestation from secuvera?

No. The C5 audit and the issuing of the attestation are carried out by a public auditor. secuvera prepares your cloud service for it: with a gap analysis, action planning, evidence documentation and a preliminary assessment of audit readiness.

Which ISO 27001 evidence can be reused for C5?

Processes and documents of an existing ISMS can support the preparation. We check whether they cover the cloud service in question and can be mapped to the C5 requirements. The measures and evidence still missing are then added.

Does C5 consulting only examine our documentation?

No. C5 combines organisational requirements with technical security measures. The consulting therefore includes ISMS processes and technical cloud configurations. What is documented should be what is actually implemented in operation.

What do we get from a C5 gap analysis?

You receive an assessment of your current maturity level and a mapping of existing measures to the C5 requirements. From this, the remaining areas for action and an action plan for further preparation are derived.

Should we start with a Type 1 or a Type 2 audit?

A Type 1 audit assesses the suitability of the controls as at a specific date; a Type 2 audit also assesses their operating effectiveness over a period of time. Which entry point makes sense for your cloud service is something we clarify in the initial consultation and in the gap analysis, based on your implementation status.

How can we support you with C5?