Certifications
In shortA certificate examines operations, not the ownership chain.
At a glance
- BSI C5
- Criteria catalogue for cloud security; attested by auditors, covering a point in time or a period
- ISO/IEC 27001
- Management system for information security; examines processes, not individual products
- SecNumCloud
- French scheme from ANSSI, with requirements covering ownership and immunity from third-country law
- EUCS
- European certification scheme for cloud services, still in progress; the sovereignty requirements are the point of contention
- What they share
- They examine at a point in time and within a defined scope
- What remains to be checked
- Ownership chain, applicable law, export path — none of which appear in the attestation
Certificates are the most popular argument in procurement conversations because they reduce a complex question to a document. That is useful, and it is routinely overstretched.
The reason is simple: an attestation describes how a provider works. It does not describe who owns it.
The schemes, briefly
BSI C5 is a criteria catalogue for cloud security attested by auditors. It exists as a statement about a point in time and as a statement about a period; the second is considerably more meaningful.
ISO/IEC 27001 examines an information security management system — processes and their effectiveness, not individual products. The scope decides the value of the statement.
SecNumCloud from France is the only widely used scheme that goes beyond operations and sets requirements on ownership and control, with the declared aim of immunity from third-country law.
EUCS, the European scheme, has been in progress for years. The dispute is precisely about whether sovereignty requirements are included — which shows how politically contested the point is.
What an attestation does not answer
Who owns the operating company today, and when did that last change? Which law does the parent answer to? How do you get your data in a dispute?
Those three decide what happens when it matters, and none of them appears in a C5 or ISO attestation. How to check them is set out under Sovereign cloud and, for the exit part, under Exit strategy.
How to read attestations properly
Two details on the first page matter more than the rest: scope and date.
An attestation for data-centre operations says nothing about the application running on top. One from 2023 says little about operations today — least of all if the provider has changed hands since.
For your own side
Small companies regularly ask whether they should get certified. The sober answer: only if a customer explicitly demands it and the contract carries the cost.
For everything else, two well-written pages on responsibility, reporting route, provider access, backup including the last restore, and the leaver process will do. They answer the questionnaires travelling down the supply chain under NIS2 just as well, and cost a day rather than a project.
Common questions
- Is a provider with a C5 attestation sovereign?
- No, those are two different questions. C5 examines operational security and evidence. A provider with an excellent attestation can still belong to a parent in a third country and fall under the CLOUD Act.
- What sets SecNumCloud apart?
- It sets explicit requirements on ownership and control, aiming at immunity from third-country law. That makes it the only widely used scheme that addresses the ownership question at all.
- Is certifying ourselves worth it for a small company?
- Usually not, unless a customer explicitly demands it. Two well-written pages on responsibility, reporting route, provider access, backup including the last restore, and the leaver process answer the usual questionnaires just as well and cost a day.
- What do I look at in an attestation I am shown?
- Scope and date. An attestation for a data centre says nothing about the application, and one from three years ago says little about today. Both are on the first page.