C5 Atte­sta­tion: Insiders Delivers Mea­surable Com­pli­ance Relief for Cloud Customers

The C5 atte­sta­tion confirms the con­ti­nuously audited operation of Insiders‘ cloud services. Customers save on audit effort, acce­le­rate approval processes, and sus­tain­ably reduce their com­pli­ance costs.

Insiders now holds the C5 Type 2 atte­sta­tion for our  cloud services for the use of inno­va­tive AI tech­no­lo­gies in automated document pro­ces­sing (IDP). This confirms that defined security measures have been effec­tively imple­mented over an extended period of time. For customers, this signi­fi­cantly reduces the effort required for their own audits and internal review processes.

C5 Atte­sta­tion as a Reco­g­nised Audit Standard for Cloud Services

The C5 atte­sta­tion is based on the Cloud Computing Com­pli­ance Controls Catalogue — C5 for short — developed by the German Federal Office for Infor­ma­tion Security (BSI). It defines binding minimum requi­re­ments for secure cloud computing and serves as a reco­g­nised benchmark for companies and public sector clients when assessing the security of cloud services.

The audit evaluates more than 120 criteria by inde­pen­dent auditors. These include robust access controls, role-based per­mis­sion concepts, encrypted data trans­mis­sion and storage, GDPR-compliant pro­ces­sing of personal data, docu­mented emergency and recovery plans, redundant system archi­tec­tures to ensure avai­la­bi­lity, and struc­tured processes for incident manage­ment and security reporting. Trans­pa­rency obli­ga­tions towards customers and clear rules on data loca­li­sa­tion are also part of the audit. For users, this means a security level in line with the highest German standards.

The Type 2 audit is con­sidered par­ti­cu­larly rigorous because it does not merely describe the design of security measures — it verifies their con­ti­nuous operation. This makes it a credible form of evidence for regu­la­tory aut­ho­ri­ties, data pro­tec­tion bodies, and internal audits.

Since 1 July 2025, a C5 Type 2 atte­sta­tion has been mandatory when cloud services in Germany process social or health data. In regulated sectors such as financial services, public admi­nis­tra­tion, or critical infra­struc­ture operators, the atte­sta­tion is incre­asingly required as a pre­re­qui­site.

Less Audit Effort, Lower Costs, Faster Approvals

For Insiders customers, the C5 atte­sta­tion has an immediate economic impact. In regulated envi­ron­ments, companies are obliged to regularly audit and document the security of their service providers. Without a stan­dar­dised proof, this generates sub­stan­tial internal workload for risk analyses, supplier assess­ments, audit inter­views, and docu­men­ta­tion requi­re­ments.

The C5 Type 2 atte­sta­tion for Insiders‘ AI cloud services signi­fi­cantly reduces this burden. Customers can rely on a reco­g­nised, audited security cre­den­tial instead of con­duc­ting their own time- and cost-intensive indi­vi­dual audits.

„Regu­la­tory requi­re­ments generate con­siderable indirect costs in many orga­ni­sa­tions,“ says Dr. Alexander Swienty, Head of Channel Manage­ment at Insiders. „With the C5 Type 2 atte­sta­tion, we take on a large share of that audit effort. Our customers benefit from clear proof of com­pli­ance, shorter coor­di­na­tion cycles with regu­la­tory aut­ho­ri­ties, and a signi­fi­cantly reduced burden on internal resources.“

A Com­ple­ment to ISO 27001 Cer­ti­fi­ca­tion

Insiders already holds ISO 27001 cer­ti­fi­ca­tion for its infor­ma­tion security manage­ment system. While this confirms the struc­tured manage­ment of infor­ma­tion security, the C5 atte­sta­tion addi­tio­nally verifies the secure operation of the specific cloud services. Together, they provide customers with a robust security and com­pli­ance foun­da­tion.

Read more about the diffe­rences between the C5 atte­sta­tion and ISO 27001 cer­ti­fi­ca­tion.

Inte­grated Com­pli­ance Proof Without Addi­tional Effort

Insiders inte­grates the C5 atte­sta­tion into its business model through a trans­pa­rent assurance fee. This means customers do not need to initiate a separate audit project — they receive a ready-made, audited security cre­den­tial that can be used directly to meet their own com­pli­ance requi­re­ments.

The atte­sta­tion is renewed annually, ensuring con­ti­nuously veri­fiable security standards. For customers, this means regu­la­tory stability, pre­dic­table costs, and signi­fi­cantly less admi­nis­tra­tive overhead in day-to-day ope­ra­tions.

FAQs

What does the C5 Type 2 atte­sta­tion mean for Insiders‘ cloud services?

L
K

The C5 atte­sta­tion (Cloud Computing Com­pli­ance Controls Catalogue) is a standard developed by the German Federal Office for Infor­ma­tion Security (BSI) that defines minimum requi­re­ments for secure cloud computing. The Type 2 atte­sta­tion confirms not only that security measures have been planned, but that they have been con­ti­nuously and effec­tively imple­mented in operation over an extended period of time. At Insiders Tech­no­lo­gies, this covers the AI cloud services for automated document pro­ces­sing (IDP).

What specific security criteria were audited?

L
K

As part of the audit conducted by inde­pen­dent auditors, more than 120 criteria were evaluated. These include, among others:

  • Robust access controls and role-based per­mis­sion concepts.
  • Encrypted data trans­mis­sion and storage, as well as GDPR-compliant pro­ces­sing.
  • Redundant system archi­tec­tures for high avai­la­bi­lity and docu­mented emergency response plans.
  • Struc­tured processes for incident manage­ment and trans­pa­rency regarding data loca­li­sa­tion.

Why is the atte­sta­tion so important for regulated indus­tries?

L
K

For companies in regulated sectors such as financial services, public admi­nis­tra­tion, or critical infra­struc­ture (KRITIS) operators, such proof of com­pli­ance is often a pre­re­qui­site for col­la­bo­ra­tion. Of par­ti­cular note: since 1 July 2025, a C5 Type 2 atte­sta­tion has been mandatory in Germany when cloud services process social or health data.

How long is a C5 atte­sta­tion valid?

L
K

A C5 atte­sta­tion certifies con­for­mity for a defined audit period in the past. In practice, it is often only accepted for a limited timeframe by regu­la­tory aut­ho­ri­ties and auditors, which is why cloud providers typically conduct annual re-audits. Con­ti­nuous atte­sta­tion ensures that security measures are not only effective on a one-time basis, but remain so on an ongoing basis.

What is the dif­fe­rence from the existing ISO 27001 cer­ti­fi­ca­tion?

L
K

Insiders is already ISO 27001 certified, which confirms a struc­tured infor­ma­tion security manage­ment system. The C5 Type 2 atte­sta­tion goes beyond this by addi­tio­nally verifying the specific secure operation of the concrete cloud services. Together, both cre­den­tials form a robust com­pli­ance foun­da­tion for customers.

How do customers gain access to this security cre­den­tial?

L
K

Insiders inte­grates the atte­sta­tion directly into its business model through a trans­pa­rent assurance fee. This gives customers a docu­mented proof of com­pli­ance without the need for a separate audit project — one that is renewed annually and provides lasting regu­la­tory stability.