BDO AG Updates Cloud Security Standard C5:2026
BDO AG is involved in the implementation of the updated C5:2026 cloud security standard. This new standard replaces the previous C5:2020 version and addresses technological advancements and regulatory changes.

BDO AG Wirtschaftsprüfungsgesellschaft has announced updates regarding the C5:2026 standard, established by the German Federal Office for Information Security (BSI). This standard, effective since April 7, 2026, represents a significant evolution of German cloud security requirements, superseding the C5:2020 framework. The revision addresses emerging technologies like containerization, confidential computing, and post-quantum cryptography, alongside new regulatory demands from NIS2, DORA, and ISO/IEC 27001:2022.
The BSI aims to elevate cloud security to a level commensurate with current threats and modern cloud architecture realities through C5:2026. The standard maintains its nature as an auditable catalog of criteria, with attestations provided by auditors under an ISAE 3000-based audit procedure. BDO AG is assisting companies in navigating and meeting the requirements of this updated standard.
Key enhancements in C5:2026 include stronger alignment with European regulations such as NIS-2 and DORA, and refined requirements for cloud sovereignty, detailing data localization, access restrictions, and jurisdictional control. Significant updates also encompass a modernized control structure with consolidated and clarified controls for improved auditability, akin to international frameworks like SOC reports. Furthermore, transparency demands have been increased, requiring providers to report more extensively on sub-service providers, architectural decisions, and risk assumptions.
A transition period is in effect for the application of the standards. While voluntary early audits under C5:2026 are possible, audits under the older C5:2020 standard are permissible until February 28, 2027. During a transitional phase from February 28, 2027, to May 31, 2027, providers must provide supplementary information regarding system control updates if opting for a C5:2020 report. From June 1, 2027, the C5:2026 criteria catalog will be mandatory. BDO offers readiness assessments, audit planning, and reporting services to ensure compliance.