C5 Attestation: Relevance and Challenges in Switzerland
What the C5 attestation is and who issues it
The C5 attestation is an audit report under ISAE 3000 and IDW PS 860 confirming that a cloud provider meets the minimum requirements of the Cloud Computing Compliance Criteria Catalogue (C5) issued by BSI (Germany's Federal Office for Information Security). The catalogue was first published in 2016 and comprehensively revised in 2020 as C5:2020; the current version contains around 121 basic and additional criteria across 17 subject areas.
Unlike a certification, the C5 attestation is a service rendered by an auditor. It can be issued as Type 1 (design suitability of controls at a point in time) or Type 2 (operating effectiveness across a period of typically six to twelve months). Hyperscalers such as AWS, Microsoft Azure and Google Cloud obtain annual C5 attestations; the attestation is primarily addressed to their business customers in the DACH region.
For Swiss consumers, this classification matters because the C5 attestation addresses the due-diligence questions typical of cloud outsourcing: tenant separation, encryption management, data location, foreign authorities' investigative powers and emergency management.
Regulatory context for Swiss cloud consumers
In Switzerland, the C5 attestation does not replace any supervisory obligation in its own right, but serves as evidence under several frameworks. Supervised institutions assess cloud sourcing under FINMA Circular 2018/3 'Outsourcing - Banks and Insurers' and under FINMA Circular 2023/01 'Operational Risks and Resilience - Banks', which has been in force since 1 January 2024. Both require a risk-based outsourcing review with documented due diligence.
From a data-protection perspective, the Swiss DSG (Federal Act on Data Protection / FADP) applies, in force since 1 September 2023. Controllers must, under Art. 8 DSG, ensure appropriate technical and organisational measures and, under Art. 9 DSG, demonstrate the suitability of processors. A C5 Type 2 attestation provides substantial evidence for this review, but does not replace it.
For outsourcing into the EU or affecting EU data subjects, GDPR additionally applies, and since 17 January 2025 also Regulation (EU) 2022/2554 (DORA). Providers serving Swiss financial institutions with EU exposure often combine C5 with ISO/IEC 27001:2022 and SOC 2 Type II into a consolidated assurance package.
Structure of the C5 catalogue
The C5:2020 catalogue groups the requirements into 17 areas, including organisation of information security, personnel security, asset management, physical security, operations, identity and access management, cryptography, procurement and supplier management, incident management, business continuity, compliance, tenant separation, and mobile-device and cloud-specific topics.
Each criterion is classified as a basic requirement or an additional requirement. The catalogue also contains four special areas designated as 'environment parameters', addressed directly to the cloud customer: data-processing location, place of jurisdiction, investigation requests by government bodies and disclosure obligations. These parameters allow Swiss consumers to request information on extraterritorial data exposure in a structured way.
Methodologically, C5 builds on existing frameworks and references controls from ISO/IEC 27001:2022, ISO/IEC 27017, ISO/IEC 27018, BSI IT-Grundschutz and the CSA Cloud Controls Matrix. The C5 attestation therefore delivers an audit opinion on controls that are internationally interoperable.
Distinction from ISO/IEC 27001 and SOC 2
The most frequent misconception is to equate the C5 attestation with ISO/IEC 27001 certification. ISO/IEC 27001:2022 certifies an information security management system (ISMS) with 93 Annex A controls, issued by an accredited certification body. The C5 attestation, by contrast, is an auditor's opinion on a cloud-specific criteria catalogue - substantively deeper but narrower in scope.
SOC 2 Type II audits under the AICPA Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy). In comparison, C5 is more prescriptive: the catalogue defines specific minimum requirements, whereas SOC 2 relies more strongly on control objectives defined by the provider itself.
In practice the three deliverables are complementary. A robust ISMS under ISO/IEC 27001:2022 forms the foundation, C5 covers the cloud-specific due-diligence layer, and SOC 2 supports international interoperability. Guidance on certification logic is provided in the SIDD ISO/IEC 27001 guide.
Evidentiary weight and limits of the attestation
A C5 Type 2 attestation delivers an auditor's opinion on operating effectiveness across the audit period. It is therefore much more meaningful than a self-assessment questionnaire, but covers only the provider's area of responsibility. Customer responsibility - configuration, identity management, data classification and encryption keys - is treated separately in the shared-responsibility model.
Swiss consumers should pay particular attention to two aspects of the attestation: first, the complementary user entity controls listed as preconditions for the effectiveness of the provider's controls, and second, the deviations and exceptions noted in the audit result. An unqualified attestation opinion does not mean there are no findings.
Equally relevant is the scope: often only individual services or regions are attested. Anyone using a particular cloud region or managed service must check whether that service is explicitly named in the attestation's scope list.
Typical challenges in implementation
Swiss organisations encounter recurring difficulties when leveraging a C5 attestation:
- Documentation volume: C5 attestations often run to several hundred pages. Without a structured mapping methodology against the organisation's own ISMS, the added value remains limited.
- Complementary controls: the customer-side controls listed in the attestation must be actively implemented and evidenced in the organisation's own control register.
- Data location and Lex Americana risks: the environment parameters covering jurisdiction and government access require an assessment in the light of the US CLOUD Act and comparable extraterritorial regimes.
- Timeliness: attestations relate to a defined period. Between two reports, configurations or sub-processors may change.
- Sub-processor chains: C5 attestations often address integrated sub-processors only via their own attestations. Consolidating the supply chain remains the consumer's task.
Supervised institutions additionally have to integrate the attestation into the annual outsourcing oversight and into the inventory of material outsourcing arrangements under FINMA Circular 2018/3.
Practical use in procurement and ISMS processes
For a C5 attestation to deliver real assurance in procurement and operations, a four-step approach is recommended:
- Scope reconciliation: verify that the services, regions and deployment models actually used are covered by the attestation's scope.
- Findings analysis: review the deviations, exceptions and limitations in the audit opinion, including the provider's remediation plans.
- Mapping against the organisation's own ISMS: transpose the C5 criteria to the ISO/IEC 27001:2022 Annex A controls and to outsourcing requirements under FINMA Circular 2018/3.
- Implementation of complementary controls: embed customer-side obligations (identity management, key management, logging, incident response) into the organisation's own procedures.
Results are documented in the supplier file and updated at least annually - or ad hoc upon scope changes. For regulated institutions, the evaluation report feeds into the operational-risk inventory, as described in the German-language FINMA/DORA pillar at /einblicke/finma-dora-leitfaden/.
How SIDD supports you
SIDD accompanies Swiss organisations in evaluating and operationalising C5 attestations. We reconcile the attestation's scope against the cloud services you actually use, translate findings into prioritised measures, and embed the complementary controls in your management system.
Our services include building an ISMS to ISO/IEC 27001:2022 as the underlying framework for cloud due-diligence obligations, providing a fractional CISO for ongoing governance, and delivering penetration testing and vulnerability scans for the customer-configured cloud components.
Our certifications are issued through CIS Cert (Quality Austria Group, ISO/IEC 17021-accredited). Get in touch for an initial consultation if you are seeking a structured assessment of your cloud outsourcing arrangements.
