The BSI C5 (Cloud Computing Compliance Criteria Catalogue) is a German federal standard published by the BSI that defines minimum security requirements for cloud service providers. First released in 2016, the catalogue has undergone two major revisions: C5:2020 and the current C5:2026 (published 7 April 2026, replacing C5:2020). C5:2026 contains 168 criteria (up from 121 in C5:2020, a 39 % increase) structured across 17 domains aligned with ISO/IEC 27001 Annex A. The new version introduces a sub-criteria structure aligned with the European EUCS scheme, and adds five major new requirement areas: Confidential Computing (OPS-32/33: documented policies for Trusted Execution Environments and technical implementation of Remote Attestation), Container Management (OPS-34/35: lifecycle security for containerized workloads), Post-Quantum Cryptography (inventory of cryptographic assets and migration plan to quantum-resistant algorithms), AI transparency (disclosure of AI use in internal control systems), and Supply Chain Security (SBOM requirements, documented sub-processor audits). The catalogue is published in machine-readable YAML format for the first time. C5 is designed as an attestation standard (not a certification): providers undergo a Type 2 audit by an independent auditing firm (under IDW PS 880 or ISAE 3000), which verifies both the design and operational effectiveness of security controls over a period of at least six months. C5 is now effectively mandatory in two key domains: since 1 July 2025, cloud providers processing healthcare data must hold a valid C5 Type 2 attestation under §393 SGB V (Social Code, Fifth Book), and the revised BSI-KritisV (2024) requires KRITIS operators to use C5-attested cloud services in security-relevant contexts. Public-sector procurement in Germany also increasingly demands C5 attestation. C5:2026 becomes mandatory on 1 June 2027 for all audit periods starting on or after that date. During the transition: C5:2020 audits remain valid without additional requirements until 28 February 2027; between 28 February and 31 May 2027, C5:2020 is still permitted but requires a transition roadmap to C5:2026 in the system description.
Red Hat enables cloud service providers and their customers to satisfy C5 requirements at the platform layer — and is particularly well-positioned for the new C5:2026 requirements. For the new Confidential Computing criteria (OPS-32/33): Red Hat OpenShift sandboxed containers with Trustee provide exactly the TEE and Remote Attestation capabilities C5:2026 demands, allowing CSPs to demonstrate hardware-enforced data-in-use protection with cryptographically verified execution environments. For Container Management (OPS-34/35): the OpenShift Compliance Operator, RHACS image scanning, and the Trusted Software Supply Chain portfolio address the full container lifecycle security requirements. For Post-Quantum Cryptography: RHEL’s crypto-agile architecture and system-wide cryptographic policies enable providers to inventory their cryptographic usage and plan migration paths. For the established C5 criteria, Red Hat covers cryptography (domain 10) with FIPS 140-3 validated modules; operations security (domain 12) with the Compliance Operator, Ansible for automated hardening, and RHACS for runtime threat detection; and supplier relationships (domain 15) with SBOMs, Sigstore artifact signing, and CSAF/VEX vulnerability feeds — directly satisfying C5:2026’s new SBOM mandate. C5’s corresponding criteria (Korrespondierende Kriterien), which define the cloud customer’s responsibilities at the interface with the provider, are also relevant: Red Hat’s documentation of shared responsibility models for OpenShift Dedicated and ROSA helps customers understand exactly which C5 controls they inherit from the provider versus those they must implement themselves. For German healthcare organizations subject to the §393 SGB V mandate, running workloads on a C5-attested cloud infrastructure built on RHEL and OpenShift provides a clear compliance path.
