Which software do you need for C5 attestation, and what does the auditor do?
Key takeaways
- Only a German public auditor (Wirtschaftsprüfer) can issue a C5 attestation, under ISAE 3000 or a national equivalent such as IDW PS 860. No software and no consultancy can take over this step.
- The software carries the preparation and the evidence: it maps the C5 criteria to your controls, collects evidence from connected systems, and monitors the controls across the Type 2 audit period of 3 to 12 months. Your team remains responsible for the system description.
- Kertos maps the C5 criteria to your existing ISO 27001 and SOC 2 controls and collects evidence continuously through more than 100 integrations; certified experts from the Kertos team support your preparation up to the audit report.
- The C5:2026 catalog, with 168 criteria instead of the previous 121, applies to Type 1 reports dated after June 1, 2027 and to Type 2 audit periods that begin on or after that date. If you start a C5 project today, build it against C5:2026.
For C5 attestation, you need a tool that links the C5:2026 criteria to your controls and evidence, and an auditor who performs the audit and issues the attestation. Between the two sits your team's work: it implements the controls, writes the system description, and keeps the controls effective throughout the audit period. Certified experts take on the gap analysis and the pre-audit if you lack that experience in-house. C5 is a catalog of the BSI, Germany's federal cybersecurity authority, and it applies to you as soon as you sell a cloud service to German customers. For cloud services that process social and health data in Germany, a current Type 2 attestation has been a legal requirement under § 393 SGB V since July 1, 2025.
Which software do you need for C5 attestation?
You need a tool that covers six tasks: maintaining the C5:2026 catalog, mapping each criterion to your controls, collecting evidence automatically from your systems, monitoring the controls across the audit period, identifying the corresponding customer criteria, and storing the material for the system description. No tool delivers the attestation itself. The BSI states in its C5 FAQ that, under the applicable regulations, only public auditors may issue a C5 attestation.
A common misconception is that a C5 project is largely done once you have bought a tool. The tool takes the collection work off your hands, meaning the gathering of screenshots, configuration states, ticket histories, and access logs over several months. Implementing the controls, writing the system description, and answering the auditor's questions stay with your company.
One detail saves time when you choose a tool: for the first time, the BSI also publishes C5:2026 as machine-readable YAML files. A vendor can import the catalog directly into its product. So ask precisely which catalog version the tool contains and since when.
| Function | Why you need it in a C5 project | Question for the vendor |
|---|---|---|
| C5:2026 catalog in the tool | C5:2026 and its 168 criteria apply to Type 1 reports dated after June 1, 2027 and to Type 2 periods that begin then; C5:2020 had 121 | Which catalog version is included, and since when? |
| Mapping criteria to controls | One control often covers requirements from ISO 27001, SOC 2, and C5 at once | Can existing ISO 27001 controls be reused? |
| Automated evidence collection | A Type 2 attestation tests effectiveness over 3 to 12 months; evidence missing during that period cannot be produced after the fact | Which systems does the tool collect evidence from, for example cloud accounts, identity provider, and ticketing system? |
| Control monitoring | You spot a failed control before the auditor finds it | How, and how quickly, does the tool report a deviation? |
| Corresponding customer criteria | In German healthcare, your customers must implement these criteria (§ 393(3) no. 3 SGB V) | Does the tool produce a list of the customer criteria that you can hand to your customers? |
| Storage for the system description | The system description is the central document of the audit | Can descriptions and material be stored per criterion, with versioning? |
What does the auditor do, what does the software do, and what does your team do?
The auditor performs the audit and issues the attestation. The software brings criteria, controls, and evidence together. Your team implements the controls and is responsible for the system description; certified experts take on the gap analysis and the pre-audit. The audit follows ISAE 3000 or a national equivalent such as IDW PS 860, as the BSI's C5 FAQ states.
The profession draws a line itself. The audit firm Rödl writes on its C5 attestation page (in German) that it cannot combine preparation and the subsequent audit, for reasons of independence. So plan for two separate parties for preparation and audit. Rödl also describes the system description as the central audit document and makes clear that the audit covers the application layer of cloud services, such as SaaS solutions.
| Step | Software | Your team | Certified experts | Auditor (Wirtschaftsprüfer) |
|---|---|---|---|---|
| Scoping | Inventory of systems, assets, and service providers as the starting point | Decides which cloud service is audited and which subservice providers are involved | Propose the boundaries and review existing attestations of subservice providers | Agrees on the subject of the audit in the engagement letter |
| Gap analysis | Shows, per criterion, which control and which evidence is missing | Provides the current state | Assess the gaps against C5:2026 and prioritize them | No role if the same firm performs the audit later |
| Implementing controls | Tasks, deadlines, and policy templates | Implements technical and organizational measures | Write policies and processes with you | No role |
| System description | Holds material and descriptions per criterion | Writes it and is responsible for it | Check it for completeness | Checks whether the description reflects actual operations |
| Evidence across the audit period | Collects evidence continuously and flags gaps | Fixes deviations | Run a pre-audit | Tests, for Type 2, effectiveness over 3 to 12 months |
| Audit | Makes the evidence available to the auditor | Answers the auditor's questions | Support the audit | Audits under ISAE 3000 or IDW PS 860 |
| Attestation | No role | Shares the audit report with its customers | No role | Issues the attestation, as the only party |
The right-hand column is the one no purchase can replace. Do not underestimate the system description either. It describes your cloud service, its boundaries, and its controls in a way that lets the auditor test them against live operations. A tool supplies material and text building blocks for it; your company is responsible for the description, because the auditor measures it against actual operations.
Which vendors support C5 attestation?
Four compliance platforms list C5 as a supported framework on their own websites: Vanta, Kertos, Secureframe, and secjur (checked September 28, 2026). They differ in the catalog version they state, in the scope of coverage, and in whether in-house experts are involved. The table reflects what each vendor publishes itself. A vendor missing from this list may still support C5; we simply did not find it confirmed on the vendor's own website.
| Vendor | What the vendor states about C5 on its website | Strength | Checked |
|---|---|---|---|
| Vanta | Release notes, week of August 2, 2026: BSI C5:2026 framework with prebuilt criteria, controls, and evidence mappings, in the Essentials, Plus, Professional, and Enterprise plans | States C5:2026 explicitly and provides criteria, controls, and evidence mappings prebuilt | 09/28/2026 |
| Kertos | Maps the C5 criteria to existing controls, automates evidence collection and monitoring, and provides certified experts | Certified experts from the Kertos team support you up to the audit report; existing ISO 27001 and SOC 2 evidence is reused | 09/28/2026 |
| Secureframe | Lists C5 in its framework overview and in its help center article on its framework offering, dated July 16, 2026 | C5 sits in the same catalog as ISO 27001, ISO 27017, NIS2, and TISAX | 09/28/2026 |
| secjur | States partial coverage for C5 and full coverage for ISO 27001, ISO 27017, and ISO 27018 | Covers the two cloud standards ISO 27017 and ISO 27018 in full, by its own account | 09/28/2026 |
None of these vendors issues the attestation, because the BSI reserves that for a public auditor. Beyond the feature set, ask two questions. Who handles the gap analysis and the pre-audit at this vendor? And which catalog version is in the product today? Ask every vendor the second question, including us.
When is C5 attestation mandatory?
In Germany, C5 attestation is binding in two cases: under § 393 SGB V for cloud services that process social and health data, and for cloud services used by federal authorities. For the federal administration, the BSI requires compliance with the catalog through its minimum standard for the use of external cloud services. Otherwise, the BSI describes the catalog as a recommendation; it only becomes mandatory through a contract or a tender that requires the attestation.
§ 393 SGB V, part of Book V of the German Social Code, applies to healthcare providers within the meaning of its fourth chapter, to statutory health and long-term care insurers, and to their processors. Through this last group, it reaches SaaS vendors that work for medical practices, clinics, or insurers. Processing is only permitted in Germany, in the EU, in equivalent states, or in third countries with an adequacy decision, and the entity processing the data must have an establishment in Germany. For a vendor based outside Germany, that last condition matters as much as the attestation itself. In addition, paragraph 3 no. 2 requires a current C5 attestation "of the entity processing the data" (datenverarbeitende Stelle) covering the C5 basic criteria, and no. 3 requires the corresponding customer criteria to be implemented.
| Situation | What counts as a current attestation | Legal basis |
|---|---|---|
| Until June 30, 2025 | C5 Type 1 attestation | § 393(4) sentence 1 SGB V |
| From July 1, 2025 | Current C5 Type 2 attestation | § 393(4) sentence 2 SGB V |
| System first placed on the market after June 30, 2025 | Type 1 for the first 18 months, Type 2 from the 19th month | § 393(4) sentence 3 SGB V |
| Certificate under ISO/IEC 27001, ISO 27001 based on IT-Grundschutz, or Cloud Controls Matrix 4.0 | Equivalent, provided a remediation plan also exists | § 393(4) sentence 4 SGB V with § 1 C5GleichwV |
The open question is whose attestation is meant. If your SaaS service runs on a hyperscaler's infrastructure, the question is whether the hyperscaler's attestation is enough or whether you need your own. Under the narrower reading, the infrastructure operator's attestation covers the cloud systems and technology in use. Under the broader reading, the provider that processes the data directly needs its own attestation. Both specialist analyses we read take the broader reading.
The data protection consultancy activeMind (David Weihbrecht, July 2, 2026) considers it legally unresolved, in its analysis of the datenverarbeitende Stelle (in German), whether the term covers only the controller or also the processor; a binding position from the Federal Ministry of Health (BMG) is still outstanding. In practice, the analysis recommends a risk-minimizing interpretation: a SaaS vendor that processes health data should assume it needs its own attestation, because a hyperscaler's attestation covers only the physical infrastructure, the network, and the hypervisor layer. Attestations of subservice providers can reduce the audit effort, but they do not replace your own. Blackfort Technology (Christian Gebhardt, June 20, 2026) argues the same way: an infrastructure attestation covers neither access controls nor tenant separation at the application level.
In practice, vendors of medical practice software have their own cloud products attested. CGM lists 15 attested cloud products on its C5 page (checked September 28, 2026). This is a professional assessment, not legal advice. Clarify with your legal counsel and with your healthcare customers which reading applies to your service.
What does a C5 attestation cost, and how long does it take?
The BSI publishes no costs; the two public sources we found cite EUR 40,000 to 120,000 for the attestation itself and a mid to high five-figure euro amount for a consulting engagement. According to the BSI, the audit period of a Type 2 attestation covers 3 to 12 months. We found no published auditor fees or day rates.
| Item | Figure | Source | Source date |
|---|---|---|---|
| Gap analysis | EUR 5,000 to 25,000 | ingenieur.de, without stating where the figures come from | 08/24/2025 |
| Consulting and remediation plan | EUR 20,000 to 60,000 | ingenieur.de, without stating where the figures come from | 08/24/2025 |
| Type 1 or Type 2 attestation | EUR 40,000 to 120,000 | ingenieur.de, without stating where the figures come from | 08/24/2025 |
| C5 project of a consultancy | Mid to high five-figure euro amount, lasting several weeks to a few months | GDC Digital, service page on C5 attestation | 07/14/2026 |
| Type 2 audit period | 3 to 12 months | BSI, C5 FAQ | checked 09/28/2026 |
| Follow-up audits for continuous coverage | One to four times a year | BSI, C5 FAQ | checked 09/28/2026 |
| Transition route in German healthcare | Gaps closed within 12 months, Type 1 within 18 months, Type 2 within 24 months of the milestone plan | § 1(2) C5GleichwV | checked 09/28/2026 |
The ingenieur.de figures are the only itemized range we found. The article does not say where they come from; treat them as a rough guide and get two quotes from audit firms for your service. None of the sources puts a figure on your own team's time for implementation and the system description. For comparison, our page on ISO 27001 certification costs breaks down what an ISO 27001 certification costs.
Which C5 version will your attestation be audited against?
C5:2026 applies to Type 1 reports dated after June 1, 2027 and to Type 2 reports whose audit period begins on or after June 1, 2027. The BSI's FAQ puts it this way: "The criteria of C5 (Cloud Computing Compliance Criteria Catalogue):2026 shall be applied in engagements with specified dates (type 1 reports) as of after June 1st, 2027 or specified periods (type 2 reports) beginning on or after June 1st, 2027." If the date of a Type 1 report or the end of a Type 2 period falls on or after February 28, 2027, but before June 1, 2027, the cloud provider must also describe the planned changes in the system description.
The BSI published C5:2026 as a final version at the end of March 2026. The catalog grows from 121 to 168 criteria. New focus areas are container management, supply chain management, post-quantum cryptography, and confidential computing; tenant separation and the technical implementation of sovereignty are covered in more detail. The BSI has announced a cross-reference table from C5:2026 to international standards, but had not made it available for download as of September 28, 2026.
For a project that starts in fall 2026, this means the gap analysis and implementation are best done against C5:2026 from the start. A Type 1 report dated in spring 2027 falls under the transition rule and has to describe the planned changes in the system description anyway. Every Type 2 audit period that begins on or after June 1, 2027 will be audited against C5:2026. If you have built against C5:2020 until then, you will be closing the gap between 121 and 168 criteria under time pressure.
How does an existing ISO 27001 certification get you to C5 attestation faster?
With an ISO 27001 certificate, you reuse your ISMS, your policies, and a large share of your evidence; what remains are the cloud-specific criteria, the system description, and the customer criteria. The BSI took ISO/IEC 27001:2022 into account in the revision that produced C5:2026. As long as the announced cross-reference table is missing, your gap analysis is the only mapping between the two catalogs.
In German healthcare, the legislator has formalized this route. The C5 Equivalence Ordinance (C5-Gleichwertigkeitsverordnung) of March 19, 2025 (BGBl. 2025 I No. 91), in force with effect from July 1, 2024, accepts a certification under ISO/IEC 27001, under ISO 27001 based on IT-Grundschutz, or under the Cloud Controls Matrix 4.0 as equivalent evidence. The condition is a remediation plan with four parts: the C5 basic criteria that the standard does not substantively cover; the measures you take to close those gaps; a milestone plan under which the gaps are closed within twelve months; and the steps toward a C5 Type 1 attestation within 18 months and a Type 2 attestation within 24 months. All deadlines run from the date the milestone plan is drawn up. You present the plan and the certificate without delay to your customers and the competent supervisory authorities on request.
So an ISO 27001 certificate does not replace C5 attestation permanently, even in German healthcare. The ordinance itself requires you to reach a Type 2 attestation within 24 months. An example with real dates: a vendor of medical practice software with an ISO 27001 certificate draws up its milestone plan on October 1, 2026. The substantive gaps to the C5 basic criteria must be closed by October 1, 2027; the remediation plan must show the route to the Type 1 attestation by April 1, 2028 and to the Type 2 attestation by October 1, 2028. Both attestations fall after June 1, 2027 and will be audited against C5:2026.
How tools compare for the ISO 27001 part is covered in our comparison of ISMS software.
When is Kertos not the right choice for C5 attestation?
Kertos is not the right choice if you only want to buy the audit. The attestation is issued by an auditor. If you already keep your controls complete and documented across the audit period, you do not need an additional platform for it.
If your team is looking for a lightweight tool for a single framework, a specialized tool is a better fit. Kertos covers several frameworks and so shows a lot of interface on day one. That shows up in reviews:
"At first the platform is a bit overwhelming and the benefits do not come through."
Verified User in Health, Wellness and Fitness, G2, translated from German
A second customer sums up the same impression more briefly: "a bit overloaded" (Laurin H., G2, translated from German). Both reviews are positive overall; the objection concerns getting started.
If your developers work on Linux machines, check the endpoint evidence closely. A customer writes on G2: "Linux devices are not supported for the device scanner" (Verified User in Computer Software, G2). You will then need to provide that evidence another way. And if your audit period starts in the next few weeks, ask every vendor, Kertos included, to show you the C5:2026 criteria in the product before you commit.
How does Kertos support C5 attestation?
Kertos maps each C5 criterion to your existing policies, controls, and evidence, reusing what you have already built for ISO 27001 or SOC 2. The platform collects evidence through more than 100 integrations, monitors the controls continuously, and flags gaps before your auditor finds them. Certified experts from the Kertos team support you from preparation to the audit report. Your auditor issues the attestation itself; Kertos prepares you for it and keeps the evidence together across the audit period. The page C5 with Kertos shows the full feature set.
On G2, customers rate Kertos 4.8 out of 5 across 63 reviews (as of September 25, 2026). Neither of the two reviews below relates to a C5 project. The first describes an ISO 27001 certification; the second comes from a healthcare customer and concerns data protection:
"Kertos helps us carry out the ISO 27001 certification in an organized and structured way. It defines clear tasks and offers AI-supported suggestions tailored to our company structure."
Martin S., Agentic AI Engineer, G2, translated from German
"Our main concern is not having to worry about our data protection, and Kertos solves that perfectly for us. Working together is straightforward, and I had a dedicated contact person at all times. The exchange with the whole team happened on an equal footing, which made coordination very pleasant."
Verified User in Health, Wellness and Fitness, G2, translated from German
Whether Kertos fits your C5 project is something we can work out in a demo, based on your cloud service and your planned audit period.
Frequently asked questions
Is there a C5 certification?
No. Anyone searching for a C5 certification means C5 attestation. According to the BSI, there is currently no certification procedure for C5, and therefore no C5 certificates. An auditor audits under ISAE 3000 or IDW PS 860 and issues an attestation with an audit report. Unlike ISO 27001 certification, there is no certificate from a certification body.
What is the difference between a C5 Type 1 and Type 2 attestation?
A Type 1 attestation tests whether the controls are suitably designed at a specific date. A Type 2 attestation also tests their effectiveness over a period of 3 to 12 months. In German healthcare, § 393 SGB V has required a Type 2 attestation since July 1, 2025. Our practical guide to C5 attestation explains the basics of both types and of the audit process.
How often does a C5 attestation have to be renewed?
A Type 2 report covers a period of 3 to 12 months in the past. For continuous coverage, the BSI says a provider is audited one to four times a year. § 393 SGB V requires a current attestation without setting a period in months. How often your customers expect a new report is therefore best set out in your contracts.
Is your cloud provider's C5 attestation enough for your own service?
According to activeMind, a hyperscaler's attestation covers only the physical infrastructure, the network, and the hypervisor layer, not your application. Whether you need your own attestation under § 393 SGB V depends on who counts as the entity processing the data. That question is disputed in the specialist literature. Your cloud provider's attestation can reduce your own audit effort. Outside German healthcare, your customer decides which attestation it requires.
Last updated: September 28, 2026. Next content review of this page: November 23, 2026.
Discover our Resources
Find useful whitepapers, videos, and practical tools to help you efficiently achieve your compliance goals.


