<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Audit on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/audit/</link><description>Recent content in Audit on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/audit/index.xml" rel="self" type="application/rss+xml"/><item><title>BSI C5</title><link>https://lesitedefrancois.be/en/compliance/bsi-c5/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/bsi-c5/</guid><description>&lt;p&gt;The &lt;strong&gt;BSI C5&lt;/strong&gt; (Cloud Computing Compliance Criteria Catalogue) is a German federal standard published by the BSI that defines minimum security requirements for cloud service providers. First released in 2016, the catalogue has undergone two major revisions: &lt;strong&gt;C5:2020&lt;/strong&gt; and the current &lt;strong&gt;C5:2026&lt;/strong&gt; (published 7 April 2026, replacing C5:2020). C5:2026 contains &lt;strong&gt;168 criteria&lt;/strong&gt; (up from 121 in C5:2020, a 39 % increase) structured across 17 domains aligned with ISO/IEC 27001 Annex A. The new version introduces a &lt;strong&gt;sub-criteria structure&lt;/strong&gt; aligned with the European EUCS scheme, and adds five major new requirement areas: &lt;strong&gt;Confidential Computing&lt;/strong&gt; (OPS-32/33: documented policies for Trusted Execution Environments and technical implementation of Remote Attestation), &lt;strong&gt;Container Management&lt;/strong&gt; (OPS-34/35: lifecycle security for containerized workloads), &lt;strong&gt;Post-Quantum Cryptography&lt;/strong&gt; (inventory of cryptographic assets and migration plan to quantum-resistant algorithms), &lt;strong&gt;AI transparency&lt;/strong&gt; (disclosure of AI use in internal control systems), and &lt;strong&gt;Supply Chain Security&lt;/strong&gt; (SBOM requirements, documented sub-processor audits). The catalogue is published in machine-readable YAML format for the first time. C5 is designed as an &lt;strong&gt;attestation standard&lt;/strong&gt; (not a certification): providers undergo a &lt;strong&gt;Type 2 audit&lt;/strong&gt; by an independent auditing firm (under IDW PS 880 or ISAE 3000), which verifies both the design and operational effectiveness of security controls over a period of at least six months. C5 is now &lt;strong&gt;effectively mandatory&lt;/strong&gt; in two key domains: since 1 July 2025, cloud providers processing healthcare data must hold a valid C5 Type 2 attestation under §393 SGB V (Social Code, Fifth Book), and the revised BSI-KritisV (2024) requires KRITIS operators to use C5-attested cloud services in security-relevant contexts. Public-sector procurement in Germany also increasingly demands C5 attestation. &lt;strong&gt;C5:2026 becomes mandatory on 1 June 2027&lt;/strong&gt; for all audit periods starting on or after that date. During the transition: C5:2020 audits remain valid without additional requirements until 28 February 2027; between 28 February and 31 May 2027, C5:2020 is still permitted but requires a transition roadmap to C5:2026 in the system description.&lt;/p&gt;</description></item><item><title>SOC 2</title><link>https://lesitedefrancois.be/en/compliance/soc2/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/soc2/</guid><description>&lt;p&gt;&lt;strong&gt;SOC 2&lt;/strong&gt; (System and Organization Controls 2) is an auditing framework developed by the &lt;strong&gt;AICPA&lt;/strong&gt; (American Institute of Certified Public Accountants). It is not government legislation or a certification scheme but a &lt;strong&gt;voluntary attestation standard&lt;/strong&gt; — however, it has become a de facto market requirement for any technology company, cloud service provider, or SaaS vendor serving enterprise customers, particularly in the US. A SOC 2 report is produced by an independent &lt;strong&gt;CPA firm&lt;/strong&gt; that evaluates an organization&amp;rsquo;s controls against the AICPA&amp;rsquo;s &lt;strong&gt;Trust Services Criteria (TSC)&lt;/strong&gt;, organized in five categories: &lt;strong&gt;Security&lt;/strong&gt; (mandatory for all SOC 2 reports, covering Common Criteria CC1–CC9), &lt;strong&gt;Availability&lt;/strong&gt;, &lt;strong&gt;Processing Integrity&lt;/strong&gt;, &lt;strong&gt;Confidentiality&lt;/strong&gt;, and &lt;strong&gt;Privacy&lt;/strong&gt; (each optional depending on the organization&amp;rsquo;s services and customer commitments). The Common Criteria (CC1–CC9) are derived from the COSO Internal Control Framework and cover control environment, risk assessment, monitoring, logical/physical access, system operations, change management, and risk mitigation. There are two report types: &lt;strong&gt;Type I&lt;/strong&gt; (evaluates control design at a point in time) and &lt;strong&gt;Type II&lt;/strong&gt; (evaluates both design and operating effectiveness over 6–12 months — the standard enterprise customers demand). SOC 2 reports are restricted-use documents shared with customers under NDA. While not legally mandatory, major enterprises, financial institutions, and regulated industries routinely require SOC 2 Type II reports from their vendors before signing contracts, making it an essential market-access requirement for technology service providers.&lt;/p&gt;</description></item></channel></rss>