C5 vs. ISO 27001. Not the same.
Both standards address information security. They do it in different ways, for different audiences, with different outcomes. Anyone treating an ISO 27001 certificate as a substitute for C5 has misread one of the two standards.
Not sure which standard comes first for you? The Self-Check shows you in 2 minutes.
Outcome: certificate vs. Testat
ISO 27001 ends in a certificate issued by an accredited certification body. C5 ends in a Testat issued by a Wirtschaftsprüfer under ISAE 3000 or IDW PS 860. The examination formats are fundamentally different: certification audit vs. attestation engagement.
In practice: an ISO 27001 certificate states „the ISMS conforms to the standard“. A C5 Testat states „these controls operated effectively over the audit period“, with specific findings and an auditor's opinion.
Audience and purpose
ISO 27001 is written for the organization itself and its customers. It is the international standard for an Information Security Management System (ISMS). C5 is written for cloud customers in Germany, especially in regulated sectors. The BSI catalogue was designed so cloud customers can assess vendor risk with real depth.
For DiGA vendors and SaaS providers in German healthcare, C5 has been de facto mandatory since §393 SGB V. ISO 27001 is not, but sales teams often expect it.
Use the 2-minute Self-Check to focus on what matters for you
Where they overlap
Roughly 60 to 70 percent of controls address the same topics: access management, cryptography, change management, incident response, supplier security, business continuity. A clean ISO 27001 ISMS gives you a substantial head start for C5. Conversely, C5 demands evidence depth that ISO does not require.
The overlap is real but not 1:1. C5 is more precise on cloud specifics: tenant isolation, hyperscaler responsibility split, audit rights, data location. ISO 27001 is broader on organizational governance.
Sequencing: ISO first or C5 first?
For SaaS vendors in the German healthcare, financial, or public-sector market, the pragmatic answer is usually: ISO 27001 as the foundation, C5 as market access. The ISMS structures the organization; C5 delivers the trust signal for the specific customer.
If you are already ISO 27001 certified, C5 preparation takes 4 to 6 months instead of 9 to 12. Running both in parallel saves evidence work but costs focus. Doing only C5 means a later ISO certificate still requires additional organizational work.
Cost and effort compared
ISO 27001 initial certification: market signal €20k to €60k for the auditor, plus 6 to 12 months of internal preparation. Recertification every 3 years, annual surveillance audits. C5 Type 2 Testat: €60k to €120k for the Wirtschaftsprüfer, plus preparation, plus 3 to 6 months of auditor waitlist. Testat repeated typically each year.
In both cases the biggest cost lever is preparation quality. Weak evidence extends both engagements substantially.
What to clarify before you decide
Which customers require what? Is §393 SGB V or KRITIS in scope? Do you already run an ISMS, or are you starting greenfield? What is your hyperscaler split, and what does their C5 already cover? These four questions decide the sequence, not the standard.
Frequently asked questions about C5 and ISO 27001
- Does ISO 27001 replace C5?
- No. ISO 27001 certifies a management system; C5 tests specific cloud controls. An ISO certificate is useful, but it is not a substitute for a C5 Testat.
- Do I need both?
- Usually yes, if you offer SaaS in regulated industries. ISO 27001 is the international trust signal, C5 is the German market signal for cloud security.
- Which should I do first?
- Typically ISO 27001 first, then C5. The ISMS provides the structure and evidence framework that C5 deepens.
- How long does C5 take if ISO 27001 is already in place?
- Typically 4 to 6 months of preparation, plus waiting time for a qualified auditor. The biggest lever is the quality of existing evidence.
- Is C5 mandatory for every cloud application?
- Not universally. For healthcare providers under § 393 SGB V it is effectively indispensable. KRITIS and financial services operators have additional reasons.
- What does C5 cost compared to ISO 27001?
- ISO 27001 initial certification often runs €20k to €60k for the auditor. C5 Type 2 is more often €60k to €120k for the Wirtschaftsprüfer. In both cases the real cost driver is preparation.
Orientation, not evidence. This guide is not legal or auditor advice.
awedit provides readiness tooling and expert judgment. awedit does not perform reserved examination acts and does not issue certificates or Testate. The C5 Testat (Wirtschaftsprüfer, ISAE 3000 / IDW PS 860), the MDR notified-body certificate, and every other reserved act belong to the licensed examiner the law names. A Self-Check or scan result is orientation, not proof of compliance, and satisfies no legal requirement. awedit is a sumthink brand operated by Die Quadratur UG, Hamburg. No legal advice.