BSI C5: penetration tests that meet OPS-22

The independent external testing partner for the penetration tests your C5 attestation requires.

As a BSI-certified IS penetration testing service provider (provider ID BSI-APS-9080), we deliver the independent external penetration tests that the BSI C5 requires in OPS-22. The C5 attestation itself is issued by your auditor; we provide the penetration tests it depends on.

What the BSI C5 requires

The BSI’s Cloud Computing Compliance Criteria Catalogue (C5) defines minimum requirements for secure cloud services, organized into 17 topic areas with basic criteria and additional criteria for higher protection needs. Proof is not provided as a certificate but as an attestation: an auditor (Wirtschaftsprüfer) confirms, after their examination (framework: ISAE 3000), that the criteria are met.

  • Type 1 assesses the appropriateness of the measures at a specific date.
  • Type 2 additionally examines their effectiveness over a period. The BSI recommends Type 2.

There are currently two versions: the established C5:2020 (121 criteria) and the revised C5:2026 (168 criteria across the same 17 topic areas). The additional criteria are newly structured as “additional sharpen” (a stricter replacement of a basic criterion) and “additional complement” (new security aspects). What matters for the switch is the start of the reporting period: type 2 audits whose period begins on or after 1 June 2027 run under C5:2026, while periods starting earlier still run under C5:2020. Earlier voluntary adoption is possible, and existing C5:2020 attestations remain valid until their expiry date. If your attestation ends after 28 February 2027, the system description has to describe the planned switch to C5:2026.

Who needs C5

  • Federal authorities. C5 is the binding minimum standard when external cloud services are procured to process official data.
  • Healthcare. Section 393 SGB V has, since 1 July 2024, required a C5 attestation or comparable evidence for certain services. Since 1 July 2025, type 1 is no longer sufficient there; type 2 is required.
  • Regulated customers and tenders. For cloud providers, a C5 attestation is increasingly a market prerequisite for making the shortlist at all.

What OPS-22 requires for penetration testing

In C5:2026, OPS-22 governs penetration testing. The key requirements:

  • At least annually and in case of significant changes to the cloud service, in line with your vulnerability management policies (basic criterion OPS-22.01B, referencing OPS-18).
  • For higher protection needs, at least every six months, by independent external penetration testers (additional criterion OPS-22.01AS). Internal personnel may support them.
  • Qualification and competence of the testers: to be defined in the framework (OPS-22.02B); as example credentials, C5 names the BSI-certified IS penetration tester and the CREST-certified Cyber Security Professional (supplementary information to OPS-22.01B/.01AS).
  • A documented penetration testing framework: the number and types of the tests are defined in a framework (OPS-22.02B), the components to be tested are selected on a risk basis (OPS-22.03B) and captured in test plans that cover all relevant components (OPS-22.04B). For higher protection needs, threat modeling is added (OPS-22.03AS, .04AC).
  • Multi-year test plan: with multi-year planning, each relevant component is tested at least once within a maximum of three years (OPS-22.05B).
  • Severity rating of vulnerabilities per CVSS, root cause analysis, and testing both before and after go-live.

Note on versions: in the predecessor version C5:2020, penetration tests are covered under OPS-19; there, OPS-22 concerns vulnerability scans. We align scope, cadence, and report format with the version of your attestation.

How we support you

  • Penetration tests as independent external testers in the sense of OPS-22, on an annual or semi-annual cycle and as a re-test after significant changes. Which qualification you require is something you define in your framework under OPS-22.02B. The BSI certification in IS penetration testing that C5 names as an example, we hold at the level of the testing organization (provider ID BSI-APS-9080).
    • Cloud-specific test depth: misconfigurations of object storage and permissions, IAM and role models, serverless functions, and container and orchestration layers in AWS, Azure, and Google Cloud.
  • Security conception: we create the documented penetration testing framework that OPS-22 requires, including risk-based component selection and, where useful, a multi-year test plan.
  • Reports that feed into your attestation: with CVSS ratings, prioritized measures, and a management summary, prepared so that your auditor can use them as evidence.
  • Architecture reviews and threat modeling for the risk-based selection of the cloud components to be tested.
  • Attack simulation and red teaming when you want to know, beyond the test scope, how far an attacker would get.
  • Building an ISMS as the organizational framework that many other C5 topic areas presuppose.
  • One test, several forms of evidence: if you also fall under NIS-2 or DORA, we plan the C5 penetration test so that it also covers their requirements for regular technical testing.

We are ourselves certified to ISO 27001 on the basis of IT-Grundschutz. Your project data is therefore processed in a demonstrably secured environment.

Effective security for your organization.

We plan your assessments so that one test covers several forms of evidence, and we process your project data in our ISO 27001-certified environment. Arrange a free initial call.