C5 Attestation Services for Cloud Providers | A-LIGN
  • Services
        • SOC Assessments 

        • SOC 1
        • SOC 2
        • ISO Certifications 

        • ISO 27001
        • ISO 27701
        • ISO 22301
        • ISO 42001
        • ISO 45001 
        • ISO 14001
        • ISO 9001
        • Federal Assessments 

        • All Government
        • FedRAMP
        • GovRAMP
        • FISMA
        • CMMC
        • NIST 800-171
        • Healthcare Assessments 

        • All Healthcare
        • HITRUST
        • HIPAA
        • Cybersecurity 

        • Penetration testing
        • Red team services
        • Ransomware preparedness assessment
        • Social engineering
        • Vulnerability assessment service
        • Privacy 

        • GDPR
        • CCPA/CPRA
        • PCI Assessments 

        • PCI DSS
        • PCI SSF
        • Additional Services 

        • International Services
        • Multi-Framework
        • AI Governance
        • AS9100
        • Microsoft SSPA
        • NIS2
        • C5
        • SOX 404
        • CSA STAR
        • Business Continuity & Disaster Recovery
        • Limited Access Death Master File
        • All Services
  • Platform
  • Company
        • About Us
        • Partners
        • Meet our team
        • Board of Directors
        • Careers
        • Community
        • image

          With audit demands at an all-time high, A-LIGN is enabling global organizations to modernize compliance,…

          Learn more
  • Customers
  • Resources
        • Quick links

        • Resource Center
        • Blogs
        • Case Studies 
        • Videos
        • Events
        • By service

        • SOC 2 
        • ISO 27001 
        • ISO 42001 
        • CMMC
        • FedRAMP
        • HITRUST 
        • PenTest
        • Featured Resources

          image
          image
          image
          image
  • A-SCEND Login
  • Careers
CONTACT US
C5 Attestation

Demonstrate secure cloud infrastructure with C5 attestation

Achieving C5 attestation is essential for security-conscious CSPs operating in Germany that want to demonstrate their commitment to security to clients and customers.

By embracing C5, organizations trading in the German market can establish a foundation for secure cloud services, improve their security posture, and gain a competitive edge in the market.

Talk to an expert
SOC 2 attestations completed

17.5K+

Client satisfaction rating

96%

Global clients

6.4K+

Auditors globally

400+

Why A-lign

Secure your place in the European cloud market

C5 is a German-based attestation with a goal of establishing a foundation for secure cloud services, improved security posture, and higher stringency for organizations processing health data using cloud computing. This attestation provides a comprehensive framework of standard security controls for CSPs providing cloud services.

Get started
image c5 a scend 6 0

Gain competitive edge in market

By complying with the C5 requirements, CSPs can demonstrate a high level of security maturity and gain a competitive advantage in the market.

Ensure health data is processed securely

Processing health data using cloud computing? In the context of the new German regulations for processing health data using cloud computing, cloud service providers must obtain a C5 certificate to demonstrate they meet these stringent security standards. This ensures that health data is processed securely, aligning with the new legal requirements to protect sensitive information.

Demonstrates security maturity

Increased trust with customers through meeting C5’s high security standards.

OUR SERVICES

C5 offerings tailored to your specific needs

Contact A-LIGN to learn more about C5 attestation.

Contact us

SOC 2 + C5 Readiness Assessment

There’s over 80% overlap in the requirements to obtain a SOC 2 attestation and a C5 attestation. A-LIGN can help you understand the requirements, assess your current status, and identify potential gaps.

This is a good place to start, if you’re looking to obtain both a SOC 2 and C5 attestation. After the readiness assessment is completed, your team will have a roadmap to follow that can make the final examination easier for all parties involved.

C5 Attestation

C5 attestation provides a comprehensive framework of standard security controls for cloud service providers. A-LIGN is permitted to issue C5 attestation via the AT-C 105 and 205 attestation standard, which is approved by the German Government.

SOC 2 + C5 Attestation with ISAE 3000 Integration

Whether a readiness assessment is needed or not, full compliance can be achieved by combining a SOC 2 plus a type 2 C5 attestation with the ISAE 3000 integration. A Type 2 engagement tests the design, implementation, and operating effectiveness of the organization’s controls as they meet the SOC 2 and C5 criteria; a type 1 report no longer meets the latest requirements.

Service Grid side image 6 0

A-LIGN by the numbers

audits completed
36k+
customer satisfaction
96%
clients globally
6.4k+
auditors globally
400+
SUCCESS STORIES

Why security leaders trust A-LIGN

"It’s one thing to claim that we’re secure, but validation from a third-party independent certification body like A-LIGN really showcases that we’re serious about security and that it’s important to us.”

Learn more

Director of IT

Erika Fry

Boomi

boomi n1

“A-LIGN's collaborative approach streamlined our audit readiness, accelerated evidence collection, and enabled our team to redirect focus toward innovation and growth. This partnership helped us evolve our compliance program from a reactive checklist to a strategic foundation for resilience and scale.”

Learn more

Business Systems & Security

Parag Jain

Picarro

client testimonial Picarro

“We chose A-LIGN for their flexibility, high-level of professionalism, technical support when needed, and professional support from the auditor.”

Regulatory Affairs and IP Director

Taly Cohen

Medical Electronic Systems

client testimonial Medical Electronic Systems

“A-LIGN is professional and checks in at every point of the way ensuring we meet our objectives.”

Security Project Manager

Andrew Imms

Serko

Testimonial logo serko
Helpful Resources

Support for your compliance journey

From guides to whitepapers, we've got the resources to move your compliance program forward.

View resources
Resource Article Explaining C5 Attestation 1 0
BLOG
C5:2026 Attestation: A Comprehensive Guide for Cloud Service Providers
Learn more
Blog
SOC 2 Checklist: Preparing for a SOC 2 Audit 
Learn more
Resource Article Audit Smarter
SOC 2 & ISO27001 1 0
Blog
The Case for Consolidating Your SOC 2 and ISO 27001 Audits
Learn more
Whitepaper
2026 Compliance Benchmark Report
Learn more

Frequently asked questions

Contact us

What is included in a C5 attestation?

A C5 attestation covers 17 control categories initially based on ISO 27001 Annex A, including areas such as Asset Management, Physical Security, Identity and Access Management, and Cryptography. The C5 criteria also incorporates cloud-specific requirements and references a range of international standards including the AICPA Trust Services Criteria, ISO 27017, and the CSA Cloud Controls Matrix.

How long does a C5 attestation take?

The timeline for a C5 attestation depends on the complexity of the cloud service in scope, the maturity of existing controls and documentation, and the degree of overlap with other frameworks already in place. Organizations that pursue a combined SOC 2 + C5 engagement with A-LIGN typically benefit from a significantly more efficient process than pursuing each attestation separately.

What changes are coming with C5:2025?

The updated C5:2025 incorporates elements of the European Cloud Certification Scheme (EUCS), aligns with ISO 27001:2022 and the NIS 2 Directive, and adds new and restructured control areas. A-LIGN’s team stays current on these updates to ensure clients are always prepared for what’s next.

Is C5 required for cloud providers outside of Germany?

While C5 is not a universal legal requirement, it is increasingly expected by German government customers and organizations in regulated German and EU industries. Non-German cloud providers that want to serve these markets will likely need to pursue C5 to remain competitive and meet customer requirements.

Ready to get started?

Contact us

A-LIGN is the leading cybersecurity compliance partner, trusted by over 6,400 organizations worldwide to navigate the complexities of compliance, audit, and risk. With a tech-enabled delivery model and deep domain expertise, A-LIGN delivers high-quality, efficient audits across frameworks including SOC 2, ISO 27001, FedRAMP, CMMC, ISO 42001, PCI, and HITRUST.

CONTACT US
  • Services
  • SOC 1
  • SOC 2
  • ISO 27001
  • ISO 42001
  • CMMC
  • HITRUST
  • FedRAMP
  • Penetration Testing
  • PCI DSS
  • HIPAA
  • International Services
  • Multi-Framework
  • AI Governance
  • All Services
  • Company 
  • About us
  • Partners
  • Platform
  • Careers
  • Our Team
  • Community
  • Trust Center
  • Contact Us
  • Customers 
  • Customer Stories 
  • Resources
  • Resource Center
  • Blogs
  • Case Studies
  • Videos
  • Events
  • Newsletter Sign-up
  • Guides
  • SOC 2 Compliance
  • ISO 27001 Certification
  • CMMC Compliance
  • ISO 42001 Compliance
  • HITRUST Certification
  • ISO Certificate Directory
  • Privacy Policy
  • Cookie Policy
  • Impartiality and Inquiries
  • Acceptable Use Policy
  • Sitemap
  • AI Information

Price and Associates CPAs, LLC dba A-LIGN ASSURANCE is a licensed certified public accounting firm registered with the Public Company Accounting Oversight Board (PCAOB). A-LIGN Compliance and Security, Inc. dba A-LIGN is a leading cybersecurity and compliance professional services firm.

A-LIGN 2026. All rights reserved.

  • Services
    • SOC Assessments
      • SOC 1
      • SOC 2
    • ISO Certifications 
      • ISO 27001
      • ISO 27701
      • ISO 22301
      • ISO 42001
      • ISO 45001 
      • ISO 14001
      • ISO 9001
    • Healthcare Assessments 
      • All Healthcare
      • HITRUST
      • HIPAA
    • Federal Assessments
      • All Government
      • FedRAMP
      • StateRAMP
      • FISMA
      • CMMC
      • NIST 800-171
    • PCI Assessments
      • PCI DSS
      • PCI SSF
    • Cybersecurity
      • Penetration testing
      • Red team services
      • Ransomware preparedness assessment
      • Social engineering
      • Vulnerability assessment service
    • Privacy
      • GDPR
      • CCPA/CPRA
    • Additional Services
      • International Services 
      • Multi-Framework 
      • AS9100
      • Microsoft SSPA
      • NIS2
      • C5
      • SOX 404
      • CSA STAR
      • Business Continuity & Disaster Recovery
      • Limited Access Death Master File
    • All Services
  • Platform
  • Company
    • About Us
    • Partners
    • Meet our team
    • Board of Directors
    • Careers
    • Community
  • Customers
  • Resources
    • Resource Center
    • Blogs
    • Case Studies 
    • Videos 
    • Events
    • By Service
      • SOC 2 
      • ISO 27001 
      • ISO 42001 
      • CMMC
      • FedRAMP
      • HITRUST
      • PenTest 
  • A-SCEND Login
  • Careers
CONTACT US