# C5 Equivalence Ordinance: Impact on Data Protection in Switzerland

> C5 Equivalence Ordinance explained: implications for cloud providers, impact on Swiss consumers, link to DSG, GDPR and ISO/IEC 27001:2022.

- Source: https://www.sidd.swiss/en/insights/the-new-c5-equivalence-regulation-and-its-impact-on-data-protection-in-switzerland/
- Language: en
- Published: 2026-04-14
- Last updated: 2026-05-24
- Author: Philipp Staiger
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## What the C5 Equivalence Ordinance governs

The **C5 Equivalence Ordinance** is a German statutory instrument under which BSI (Germany's Federal Office for Information Security) can determine which attestations from cloud providers are recognised as equivalent to the **Cloud Computing Compliance Criteria Catalogue (C5)**. It sits alongside cloud-related requirements for public bodies and for regulated sectors such as healthcare in Germany.

The ordinance aims to harmonise the formal requirements for cloud security attestations, to reduce duplicate audits and to enable a consistent assessment of international certifications such as **ISO/IEC 27001:2022**, ISO/IEC 27017, ISO/IEC 27018 or SOC 2 Type II against the **C5:2020** catalogue. The review typically consists of a defined mapping of control objectives, taking the ISAE 3000 / IDW PS 860 methodology into account.

For Swiss readers the central point is: the ordinance applies directly only within the German legal sphere. There is no direct binding effect on Swiss organisations. Indirect effects arise, however, as soon as Swiss providers serve German authorities or regulated sectors, or as soon as Swiss consumers use cloud services from German providers.

## Relationship to C5:2016 and C5:2020

BSI **first published** the C5 catalogue **in 2016** and fundamentally revised it in 2020 as **C5:2020**. While C5:2016 was strongly geared towards classic outsourcing constellations, C5:2020 integrates additional criteria on tenant separation, the product-development lifecycle, the use of sub-processors, and requirements relating to DevOps practices. Added to this are the so-called **environment parameters**, which aim to make transparent under which law and in which geographical area processing takes place.

The Equivalence Ordinance ties in with the current version (C5:2020). Cloud providers offering an attestation under an earlier version must expect that it will be recognised only to a limited extent or must be supplemented with additional evidence.

In the Swiss context, the C5 catalogue remains a market standard without a direct supervisory obligation. It is frequently considered in procurement processes as evidence of the duty of care under **Art. 8 and 9 DSG** and as part of outsourcing reviews under **FINMA Circular 2018/3**.

## Impact on Swiss cloud consumers

For Swiss consumers, three practical effects flow from the Equivalence Ordinance. First, **comparability** between cloud attestations increases because providers map their existing certifications systematically against the C5 catalogue. Second, the **documentation effort** decreases when a single consolidated attestation can be submitted in place of a variety of point-in-time certifications. Third, pressure grows on providers to keep the scope of their attestations **cloud-specific and up to date**.

Swiss organisations should nevertheless read the recognition critically: a German equivalence decision does not change obligations under the Swiss DSG (Federal Act on Data Protection / FADP), in force since 1 September 2023, or under GDPR, where EU data subjects or EU establishments are concerned. Nor does an equivalence decision eliminate the risk of extraterritorial access - for example under the US CLOUD Act.

## Impact on providers based in or operating from Switzerland

Cloud providers based in Switzerland that serve German authorities or regulated sectors in Germany benefit from a clear recognition logic. Providers that already hold **ISO/IEC 27001:2022** with the extensions ISO/IEC 27017 and ISO/IEC 27018 can build the mapping to the C5 catalogue in a more targeted way and close the gaps through a supplementary audit.

Operationally this means: providers need a management system that demonstrably covers the areas addressed in the C5 catalogue - in particular cryptography, tenant separation, sub-processor governance, incident management and business continuity. A combined assurance strategy built on ISO/IEC 27001:2022, a C5 attestation and SOC 2 Type II is often advisable. Guidance on the ISMS logic is available in the [SIDD ISO/IEC 27001 guide](https://www.sidd.swiss/en/insights/iso-27001-guide-2026/).

## Links to Swiss data-protection law

The Swiss DSG (Federal Act on Data Protection / FADP) requires controllers to ensure data security through appropriate technical and organisational measures (**Art. 8 DSG**) and to select and supervise processors with due care (**Art. 9 DSG**). A C5 attestation of a cloud provider is substantial evidence, but does not replace either the controller's own risk assessment or the inventory and information obligations enshrined in the DSG.

For **cross-border disclosure** (Art. 16 et seq. DSG) the data location remains relevant. The Equivalence Ordinance is silent on this point; it concerns security requirements, not the data-export regime. Where processing has an EU dimension, **Art. 32 GDPR** and the EU data-export regime under Chapter V of GDPR apply in addition.

A deeper look at the Swiss data-protection regime is provided in the German-language DSG pillar at [/einblicke/dsg-fadp-leitfaden/](https://www.sidd.swiss/einblicke/dsg-fadp-leitfaden/).

## Interface with FINMA and DORA

For supervised financial institutions, the recognition logic of the C5 Equivalence Ordinance fits into a closely meshed outsourcing regime. **FINMA Circular 2018/3 'Outsourcing - Banks and Insurers'** and **FINMA Circular 2023/01 'Operational Risks and Resilience - Banks'**, in force since 1 January 2024, require a risk-based assessment of outsourcing and continuous oversight of providers.

Swiss institutions with EU business also have to take into account **Regulation (EU) 2022/2554 (DORA)**, applicable since 17 January 2025. DORA imposes its own requirements on third-party management, on resilience testing and on the engagement of critical ICT third-party providers. A C5 attestation or an attestation recognised under the Equivalence Ordinance can support these obligations, but cannot fully substitute them. A comparison of Swiss and EU requirements is provided in the German-language FINMA/DORA pillar at [/einblicke/finma-dora-leitfaden/](https://www.sidd.swiss/einblicke/finma-dora-leitfaden/).

## Recommended approach for Swiss organisations

The following approach has proven its value in practice when translating the effects of the Equivalence Ordinance into the organisation's procurement and ISMS processes:

- **Clarify scope:** Which data, processes and cloud services are affected? Are there EU or German public-sector dimensions?
- **Consolidate evidence:** compile the relevant provider certifications (ISO/IEC 27001:2022, 27017, 27018, C5, SOC 2) and reconcile against the organisation's own control catalogue.
- **Implement complementary controls:** embed customer-side obligations on identity, key management, logging and configuration in the management system.
- **Data-transfer review:** separate assessment of data location and extraterritorial access risks; where required, supplementary contractual clauses (e.g. standard contractual clauses) and a transfer impact assessment.
- **Periodic refresh:** annual update of provider documentation and, where applicable, adjustment to changes in the C5 catalogue or the Equivalence Ordinance.

The approach is documented in the supplier file and transferred into the risk inventory.

## How SIDD supports you

SIDD supports Swiss organisations in assessing the impact of the C5 Equivalence Ordinance pragmatically and embedding it in their own management system. We map existing provider attestations against the C5:2020 criteria, translate the results into prioritised measures, and integrate them into your outsourcing and data-protection processes.

Our services include building and operating an [ISMS to ISO/IEC 27001:2022](https://www.sidd.swiss/en/services/iso-27001-isms) as the underlying framework for cloud due-diligence obligations, providing a [fractional CISO](https://www.sidd.swiss/en/services/vciso) for ongoing governance, and technical verification through [penetration testing](https://www.sidd.swiss/en/services/penetration-test) and [vulnerability scans](https://www.sidd.swiss/en/services/vulnerability-scan).

Certifications are issued through **CIS Cert** (Quality Austria Group, ISO/IEC 17021-accredited). Get in touch if you require a structured assessment of your cloud procurement.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
