Secure your place in the European cloud market
C5 is a German-based attestation with a goal of establishing a foundation for secure cloud services, improved security posture, and higher stringency for organizations processing health data using cloud computing. This attestation provides a comprehensive framework of standard security controls for CSPs providing cloud services.
Get started
Gain competitive edge in market
By complying with the C5 requirements, CSPs can demonstrate a high level of security maturity and gain a competitive advantage in the market.
Ensure health data is processed securely
Processing health data using cloud computing? In the context of the new German regulations for processing health data using cloud computing, cloud service providers must obtain a C5 certificate to demonstrate they meet these stringent security standards. This ensures that health data is processed securely, aligning with the new legal requirements to protect sensitive information.
Demonstrates security maturity
Increased trust with customers through meeting C5’s high security standards.
C5 offerings tailored to your specific needs
Contact A-LIGN to learn more about C5 attestation.
Contact usSOC 2 + C5 Readiness Assessment
There’s over 80% overlap in the requirements to obtain a SOC 2 attestation and a C5 attestation. A-LIGN can help you understand the requirements, assess your current status, and identify potential gaps.
This is a good place to start, if you’re looking to obtain both a SOC 2 and C5 attestation. After the readiness assessment is completed, your team will have a roadmap to follow that can make the final examination easier for all parties involved.
C5 Attestation
C5 attestation provides a comprehensive framework of standard security controls for cloud service providers. A-LIGN is permitted to issue C5 attestation via the AT-C 105 and 205 attestation standard, which is approved by the German Government.
SOC 2 + C5 Attestation with ISAE 3000 Integration
Whether a readiness assessment is needed or not, full compliance can be achieved by combining a SOC 2 plus a type 2 C5 attestation with the ISAE 3000 integration. A Type 2 engagement tests the design, implementation, and operating effectiveness of the organization’s controls as they meet the SOC 2 and C5 criteria; a type 1 report no longer meets the latest requirements.
A-LIGN by the numbers
Why security leaders trust A-LIGN
Support for your compliance journey
From guides to whitepapers, we've got the resources to move your compliance program forward.
View resourcesFrequently asked questions
What is included in a C5 attestation?
A C5 attestation covers 17 control categories initially based on ISO 27001 Annex A, including areas such as Asset Management, Physical Security, Identity and Access Management, and Cryptography. The C5 criteria also incorporates cloud-specific requirements and references a range of international standards including the AICPA Trust Services Criteria, ISO 27017, and the CSA Cloud Controls Matrix.
How long does a C5 attestation take?
The timeline for a C5 attestation depends on the complexity of the cloud service in scope, the maturity of existing controls and documentation, and the degree of overlap with other frameworks already in place. Organizations that pursue a combined SOC 2 + C5 engagement with A-LIGN typically benefit from a significantly more efficient process than pursuing each attestation separately.
What changes are coming with C5:2025?
The updated C5:2025 incorporates elements of the European Cloud Certification Scheme (EUCS), aligns with ISO 27001:2022 and the NIS 2 Directive, and adds new and restructured control areas. A-LIGN’s team stays current on these updates to ensure clients are always prepared for what’s next.
Is C5 required for cloud providers outside of Germany?
While C5 is not a universal legal requirement, it is increasingly expected by German government customers and organizations in regulated German and EU industries. Non-German cloud providers that want to serve these markets will likely need to pursue C5 to remain competitive and meet customer requirements.



