Frameworks

Cloud security for the European market with BSI C5 2020

Selling cloud services to German enterprises and public sector buyers means proving you meet the BSI's Cloud Computing Compliance Criteria Catalogue (C5).

Tidal Control builds your C5 2020 evidence base. Implement the basic and additional criteria, map them to controls you already have under ISO 27001, and produce the attestation report your customers ask for in procurement.

Product screenshot

BSI C5 2020 in depth

BSI C5 is built specifically for cloud services. Where ISO 27001 stays abstract about cloud-specific risks, C5 prescribes concrete criteria around shared responsibility, sub-processor management, encryption, and transparency reporting.

Applied as a control framework inside Tidal Control, C5 becomes part of your existing ISO 27001 ISMS rather than a separate programme. Controls are tagged with the C5 criteria they satisfy, evidence is collected once and rolled up to multiple frameworks, and the gap between what you have and what C5 demands is visible at every step.

This turns C5 from a once-a-year audit project into a continuously maintained framework that's audit-ready whenever a German enterprise buyer asks for it.

How Tidal helps you get certified

Why Tidal Control

We understand your challenges because we've been there. Our team of GRC experts and security professionals built Tidal to solve the real problems compliance teams face every day.

Made in Europe

Built and hosted in Europe. Your compliance data stays in the EU for full control and peace of mind.

Continuous automation

Automated evidence collection from cloud providers and development tools working 24/7 for you.

Real security

Build secure systems that protect your business and satisfy auditors, not just check compliance boxes.

Integrate with your existing tools

Testimonials

What our customers say

With a single click, one Tidal test checks dozens of disks for encryption. Doing that manually would take a lot of time.

Profile picture of Chiel Bos
Chiel Bos
COO·CBYTE
CBYTE logo

Frequently asked questions

C5 (Cloud Computing Compliance Criteria Catalogue) is a cloud security standard published by Germany's Federal Office for Information Security (BSI). Cloud service providers selling to German enterprises and public sector buyers are increasingly required to show a C5 attestation as part of procurement. C5:2020 is the version audits are performed against today. The BSI published C5:2026 in March 2026, and its criteria become binding for engagements whose reporting period starts on or after 1 June 2027. A period starting before that date stays entirely on C5:2020 even if it ends later, and the two catalogues cannot be combined in one engagement, so what decides your version is when your period starts rather than which year the report carries. Early adoption of C5:2026 is permitted.

C5 reuses the ISO 27001 controls structure and adds cloud-specific criteria around transparency, sub-processor management, and reporting. If you're already ISO 27001 certified, most of the work is mapping existing controls to C5 criteria and adding the cloud-specific evidence — both supported natively in Tidal.

C5 distinguishes basic criteria (must-haves for any cloud service) from additional criteria (extra controls for higher-assurance services, e.g. those processing sensitive government data). Tidal lets you scope your C5 implementation to the criteria level your customers require, without forcing the full additional set when it isn't needed.

Yes. The attestation report is produced by an external auditor, but Tidal maintains the underlying evidence: control descriptions, test results, exceptions, and the system description. Your auditor pulls from Tidal instead of asking you to assemble evidence from scratch.

SOC 2 is the equivalent US-market attestation. ISO 27017 is the international cloud-extension standard for ISO 27001. C5 is more prescriptive than SOC 2 and adds transparency criteria that ISO 27017 doesn't cover. Many EU-focused cloud providers run C5 alongside ISO 27001/27017.

Yes. Tidal's control model maps one control to many frameworks, so the same evidence rolls up into ISO 27001, ISO 27017, SOC 2, and C5 at once. You don't maintain four separate copies of the same control.