Kaamos

Framework reference

BSI C5 for EU B2B software companies.

BSI C5 gives cloud providers and their customers a common basis for independent assurance over cloud-security controls. It is relevant when procurement or a customer asks for a C5 report.

Kaamos support
Supported in Kaamos
Category
Voluntary security frameworks
Obligation
Voluntary
Last updated

Who it applies to

  • Cloud providers preparing for a C5 assurance engagement.
  • Software companies facing C5 requirements in customer procurement.
  • Cloud customers reviewing a provider’s control environment.

What you need to do

  • Define the cloud service and control environment covered by the assessment.
  • Document responsibilities, security controls and the evidence of their operation.
  • Work with an independent auditor on the assurance report and its scope.

How Kaamos helps

  • Track the C5 control catalog with owners, status and linked evidence.
  • Organize cloud-security findings and supplier evidence around the controls.
  • Prepare audit exports; independent auditors issue the C5 assurance report.

Sources

Supported in Kaamos

Manage BSI C5 controls, owners and evidence in Kaamos. Talk to us about the framework scope and connected systems you need.