In this article

Germany's Healthcare Cloud Rule: What C5 Compliance Means for Cloud Providers

Germany has introduced new cloud security requirements that significantly affect healthcare organizations and the companies that provide cloud services to them. As healthcare systems continue to adopt cloud technologies, regulators are placing greater emphasis on demonstrating that these environments can securely protect sensitive patient information.

a man with long hair wearing a blue shirt
By Tom Rozen

Updated August 26, 2026

C5 Compliance for Healthcare

What Triggered the New Requirement?

The changes stem from Germany's Digital Act (DigiG), which introduced Section 393 of the German Social Code Book V (SGB V). The legislation, which took effect in July 2024, requires many cloud services used to process healthcare data to demonstrate compliance with the Cloud Computing Compliance Criteria Catalogue (C5).

The goal is to strengthen security across healthcare cloud services by requiring independent assurance that providers have implemented appropriate security controls.

For cloud vendors and healthcare organizations, this represents an important shift. Rather than relying solely on internal security programs or international certifications, organizations serving the German healthcare sector must now demonstrate compliance with Germany's cloud-specific security framework.

» Preparing for C5 attestation? Contact us to assess your current controls, identify gaps, prepare your evidence, and build a clear path toward attestation.

Understanding the C5 Compliance Timeline

Germany introduced C5 compliance requirements in stages to give cloud service providers time to prepare and transition toward stronger security assurance. The timeline focuses on moving organizations from initial control validation (C5 Type 1) to ongoing operational assurance (C5 Type 2).

July 2024: C5 Type 1 Attestation Requirements Begin

Beginning in July 2024, many affected cloud providers were required to obtain a C5 Type 1 attestation. This assessment verifies that required security controls have been properly designed and implemented at a specific point in time.

A C5 Type 1 attestation demonstrates that a cloud provider has established the necessary security controls but does not evaluate whether those controls continue operating effectively over an extended period.

July 2025: Transition to C5 Type 2 Attestation

By July 2025, many affected cloud providers were required to transition from C5 Type 1 to C5 Type 2 compliance.

Unlike Type 1, a C5 Type 2 attestation evaluates whether security controls continue to operate effectively over an observation period, typically six to twelve months. This provides customers with stronger assurance that security practices are consistently maintained rather than implemented only for an assessment.

January 2026: Additional Flexibility Under the BEEP Act

An additional update takes effect in January 2026 through the BEEP Act. Under this legislation, newly launched cloud services entering the market after June 30, 2025, are generally provided with up to 18 months to transition from C5 Type 1 to Type 2 compliance.

This transition period gives new cloud offerings additional flexibility while still establishing a path toward meeting the higher assurance expectations associated with C5 Type 2 attestation.

C5 Compliance Timeline Summary

Date

Requirement

Purpose

July 2024

C5 Type 1 attestation

Confirms security controls are designed and implemented

July 2025

C5 Type 2 transition

Validates that controls operate effectively over time

January 2026

BEEP Act update

Provides additional transition flexibility for new cloud services

Why C5 Type 2 Attestation Matters

Transitioning from C5 Type 1 to C5 Type 2 attestation is more than a compliance milestone, it represents a higher level of security assurance.

A C5 Type 1 attestation confirms that required security controls have been designed and implemented at a specific point in time. In contrast, a C5 Type 2 attestation evaluates whether those controls operate effectively over an extended observation period, typically six to twelve months.

During a Type 2 assessment, auditors review evidence collected throughout the reporting period to verify that security controls continue to function as intended in a live production environment. This provides stronger assurance than a point-in-time review because it demonstrates ongoing compliance rather than temporary audit preparation.

Benefits of C5 Type 2 Compliance

Organizations that achieve C5 Type 2 attestation can demonstrate:

  • Continuous operation of security controls
  • Ongoing monitoring and governance processes
  • Consistent risk management practices
  • Stronger cloud security assurance for customers
  • Greater readiness for regulatory and customer audits

For healthcare organizations, government agencies, and other regulated sectors handling sensitive information, C5 Type 2 compliance provides confidence that security practices are embedded into day-to-day operations rather than implemented solely for assessment purposes.

As a result, C5 Type 2 attestation has become the preferred standard for cloud service providers supporting regulated industries where continuous operational effectiveness and long-term security assurance are critical. It is increasingly viewed as the benchmark for organizations seeking to demonstrate mature cloud security practices in Germany and the broader DACH region.

Who Is Affected?

The new requirements apply to a wide range of organizations operating within Germany's healthcare ecosystem.

This commonly includes:

  • Cloud service providers supporting healthcare organizations
  • SaaS vendors processing healthcare information
  • Digital health platforms
  • Health insurance organizations using cloud services
  • Healthcare providers relying on cloud-based applications

Organizations planning to introduce new healthcare cloud services after June 2025 should also understand the transitional requirements that apply to newly launched offerings.

» Need to determine whether C5 applies to your organization? Get expert guidance to assess your requirements, identify gaps, and prepare for C5 attestation.

Transitional Compliance Options

Germany has introduced transitional measures to help organizations move toward full compliance.

Under the BEEP Act, eligible cloud services launched after June 30, 2025, may initially rely on a C5 Type 1 attestation while working toward Type 2 compliance during an 18-month transition period.

Organizations may also be able to use Germany's Equivalence Regulation as a temporary pathway. In some situations, organizations with ISO 27001 certification and a documented remediation or gap plan may demonstrate interim compliance while completing the additional work needed for full C5 attestation.

These transitional options are intended to support organizations entering the market while maintaining Germany's high standards for cloud security.

» Planning to enter the German cloud market? Learn whether C5, ISO 27001, or both can help you meet customer and security expectations.

How GRSee Consulting Can Help

Preparing for C5 in the healthcare sector requires more than passing an audit. Organizations must demonstrate that security controls are implemented, operating effectively, and supported by ongoing evidence.

GRSee Consulting helps organizations assess their C5 readiness, identify compliance gaps, prepare documentation, and align C5 efforts with existing security programs such as ISO 27001 and SOC 2. We also help organizations plan for Type 2 requirements by building the processes and evidence needed to demonstrate operational effectiveness over time.

» Whether you're working toward C5 Type 2 compliance or launching new healthcare cloud services in Germany, GRSee can help you build a practical roadmap toward C5 compliance.

Elevate Your Cybersecurity Framework With GRSee

Enhance your cybersecurity defenses with NIST standards, providing a well-organized framework for managing risks and building resilience.

Contact Us