Cloud computing has long been the backbone of modern, industrial IT landscapes. Whether in business, public administration or critical infrastructures, scalable cloud services enable innovation, efficiency and speed at an unprecedented level. At the same time, the growing dependence on cloud technologies is also increasing the demand for security, transparency and regulatory compliance. This is precisely where recognized security standards come in. They create comparability, strengthen trust and form the basis for a sustainable digital transformation in Europe.
With the publication of C5:2026, the Federal Office for Information Security has taken a decisive step towards meeting these requirements. The new Cloud Computing Compliance Criteria Catalogue builds on the established C5:2020, but takes into account the far-reaching technological, regulatory and operational developments of the past six years. The final version of C5:2026 has been available since the end of March 2026 and sets new standards for secure cloud computing in the European context.
A key feature of C5:2026 is its close alignment with European and international standards and regulations. While C5:2020 already served as the basis for many cloud audits, C5:2026 now builds a clear bridge to the European Cybersecurity Certification Scheme for Cloud Services at the “Substantial” security level. This makes the catalog an important link between national requirements and European certification objectives. For cloud providers and users, this means significantly improved connectivity to future European compliance structures.
In addition, C5:2026 takes into account the latest developments of established standards such as ISO/IEC 27001:2022 and the Cloud Controls Matrix Version 4 of the Cloud Security Alliance. The requirements of the NIS2 directive are also systematically incorporated into the criteria catalog. This makes C5:2026 not only a testing framework for cloud services, but also a strategic tool for organizations that want to align their information security and compliance landscape in a consistent and future-proof manner.
In terms of content, C5:2026 responds to a number of new topics that are becoming increasingly important in practice. These include, in particular, securing container technologies and software supply chains. In view of the complex dependencies in modern cloud architectures, supply chain security is becoming a critical success factor. The new catalog also addresses confidential computing, i.e. the protection of sensitive data during processing, for example through hardware-based security mechanisms.
Another key topic for the future is post-quantum cryptography. C5:2026 takes into account the fact that today’s cryptographic processes could be threatened by powerful quantum computers in the long term and calls for a strategic examination of quantum-resistant processes. In addition, aspects such as client separation, data localization and digital sovereignty are coming more into focus. These issues are not only relevant to security, but are also highly sensitive politically and economically, especially in the European context.
In addition to the additions to the content, the structure of the criteria catalog has also been fundamentally revised. The requirements are now more clearly divided into sub-criteria, which significantly improves traceability and auditability. One major innovation is the explicit distinction between so-called “additional sharpen” and “additional complement” criteria. This makes it more transparent which requirements sharpen existing controls and which require additional measures. This increases the planning security and efficiency of audits for both auditors and audited organizations.
The first-time publication of the entire catalog in a machine-readable YAML version is a real novelty. This step opens up new possibilities for the integration of C5 requirements into automated governance, risk and compliance processes. In the future, this will support continuous compliance approaches and a stronger integration of security, operation and control in cloud environments.
C5:2026 also sends a clear signal internationally. The first publication was in English to enable direct access for globally active cloud providers. German versions and detailed reference tables for other standards have been announced for the second quarter of 2026. This underlines the BSI’s ambition to establish C5 as an internationally compatible quality benchmark for cloud security.
However, the importance of C5:2026 goes beyond technical details. The new catalog makes an important contribution to strengthening European cyber resilience. It supports organizations in systematically implementing regulatory requirements without slowing down innovation. At a time of increasing geopolitical tensions and growing cyber threats, this is a key building block on the path to a resilient digital society.
Syngenity® GmbH provides comprehensive support to organizations in the classification and implementation of C5:2026, including in-depth readiness and gap analyses, the integration of C5 requirements into existing ISMS and internal control systems as well as the targeted preparation and support of C5 audits. In addition, Syngenity® GmbH supports the strategic coordination of C5 with EUCS, NIS2 and modern cloud governance approaches.
The new C5:2026 catalog is available for download at Cloud Computing Compliance Criteria Catalogue (C5:2026). If you want to understand what C5:2026 means in concrete terms for your own cloud strategy, risk management and regulatory future, you should familiarize yourself with the new requirements at an early stage. The course is now being set for secure, sovereign and future-proof cloud computing in Europe.






