Cloud Computing Compliance Criteria Catalogue (C5)
C5 is an audited cloud security standard created by Germany's Federal Office for Information Security (BSI). It sets a mandatory baseline for cloud security and is designed to give transparency and assurance for cloud services used by German government agencies, KRITIS organizations and regulated sectors such as healthcare and finance.
Radware has successfully completed its C5 Type II attestation, performed by KPMG in accordance with the BSI C5:2020 framework. The Type II attestation confirms that Radware's cloud service security controls were suitably designed and implemented, and that they operated effectively throughout the audit period.
This builds on Radware's earlier C5 Type I attestation, which assessed the design and implementation of these controls at a specific point in time.
What C5 Attestation Provides
The report gives independent, auditor-verified assurance on:
- The design, implementation and operating effectiveness of Radware's security controls over a defined audit period
- The auditor's tests of each control and their results
- Alignment with German federal cloud-security expectations (BSI C5:2020)
- Transparency into Radware's cloud-service architecture, security measures, operational processes and supporting environments
- Cloud-provider obligations, including availability, data-center locations, incident handling, subcontractor transparency and evidence-based verification of controls
Applicable Sectors
This information is essential for organizations in:
- Government and the public sector
- KRITIS/critical infrastructure (energy, telecom, IT, financial institutions, healthcare providers, etc.)
- Healthcare, where C5 compliance is legally mandatory under Section 393 of the German Social Code (SGB V)
- Enterprise sectors that need to show security assurance, compliance and the ability to manage risk
Role of C5 Attestation
The attestation supports:
- Customer assurance and transparency when evaluating Radware cloud services
- Regulatory alignment with German federal and KRITIS requirements
- Vendor risk-management processes
- Internal governance, procurement and security oversight
- Public-sector and healthcare tenders, where C5 compliance is a prerequisite for doing business
Many regulated customers and public-sector bodies need evidence that security controls work consistently over time, not only at a single point in time. The Type II report gives the level of assurance their procurement and vendor-risk processes typically ask for.
For many partners and MSSPs, C5 is a mandatory requirement before cloud service discussions can begin.
Independent Assessment
KPMG, a globally recognized independent audit firm that performs BSI-aligned assessments, conducted Radware's C5 Type II attestation. Its examination confirms that Radware's controls meet the requirements of the C5:2020 framework and operated effectively throughout the audit period.
Report Availability
The C5 Type II report is available to customers and partners on request. Because it contains sensitive security information and is subject to the auditor's copyright restrictions, an NDA is required before it can be released.
Request Report