{"id":18067,"date":"2026-06-28T14:30:00","date_gmt":"2026-06-28T14:30:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/?p=18067"},"modified":"2026-06-29T10:57:21","modified_gmt":"2026-06-29T10:57:21","slug":"post-quantum-becomes-mandatory-in-cloud-certification","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/06\/28\/post-quantum-becomes-mandatory-in-cloud-certification\/","title":{"rendered":"Post-Quantum becomes mandatory in cloud certification"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">6 min read<\/p>\n<p><strong>The new BSI criteria catalog C5:2026 includes 168 criteria-47 more than its predecessor. One change stands out: for the first time, the BSI demands verifiable handling of quantum threats. Initially, a demonstrable roadmap is required, not an immediate full transition. For those holding or pursuing C5 certification, this sets a clear deadline.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li><strong style=\"color:#69d8ed;\">C5 expands to 168 criteria:<\/strong> The 2020 catalog had 121. New additions include post-quantum cryptography, confidential computing, and container security.<\/li>\n<li><strong style=\"color:#69d8ed;\">The deadline is concrete:<\/strong> Type 2 certifications starting on or after June 1, 2027, will follow C5:2026. While that may seem distant, it\u2019s not for a crypto overhaul.<\/li>\n<li><strong style=\"color:#69d8ed;\">Post-quantum risks are already here:<\/strong> Encrypted data stolen today can be decrypted later with a quantum computer. The threat emerges long before the first practical quantum machine arrives.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#666;margin:20px 0 32px 0;border-top:1px solid #e5e5e5;border-bottom:1px solid #e5e5e5;padding:10px 0;\"><span style=\"color:#0c5460;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related:<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2022\/05\/19\/confidential-computing-why-data-must-remain-encrypted-even-during-processing\/\" style=\"color:#333;text-decoration:underline;\">Confidential Computing: Why encrypted data must stay protected during processing<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2024\/11\/14\/cloud-misconfigurations-the-most-common-breach-cause-that-no-one-fixes\/\" style=\"color:#333;text-decoration:underline;\">Cloud misconfigurations: The most common breach cause no one fixes<\/a><\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What C5:2026 changes in the audit catalog<\/h2>\n<p>In the DACH cloud landscape, C5 isn\u2019t just a nice-to-have-it\u2019s a must. Many tenders require certification. For cloud providers serving the public sector or financial industry, it\u2019s non-negotiable. The version published in April 2026 marks the first major update since 2020, expanding from 121 to 168 criteria and reorganizing them into 17 thematic areas.<\/p>\n<p>The growth isn\u2019t bureaucracy for bureaucracy\u2019s sake. It reflects shifts in the threat landscape and technology. Containers now run in nearly every stack, confidential computing has moved out of niche applications, and the quantum question has leapt from research to compliance. For the first time, the catalog is also available as a machine-readable YAML file, making gap analysis against your own control system significantly easier.<\/p>\n<div style=\"border:1px solid #cfd8dc;border-radius:8px;margin:28px 0;overflow:hidden;\">\n<div style=\"background:#003340;color:#fff;font-weight:700;font-size:0.95em;padding:12px 18px;\"><strong>What is BSI C5?<\/strong><\/div>\n<p style=\"margin:0;padding:16px 18px;line-height:1.7;color:#333;\">The Cloud Computing Compliance Criteria Catalogue, or C5, is a BSI audit framework for cloud service security. An auditor certifies whether a provider meets the defined controls. In the DACH region, this certification is a well-established requirement for cloud procurement.<\/p>\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Why Post-Quantum Needs to Be on Your Roadmap Now<\/h2>\n<p>The most common misconception about post-quantum cryptography is the timeline. A sufficiently powerful quantum computer capable of breaking today\u2019s encryption methods doesn\u2019t exist yet-but the risk is already here. The culprit is an attack strategy with an unassuming name: harvest now, decrypt later. An attacker collects encrypted data traffic today and waits until the necessary computing power becomes available.<\/p>\n<p>In concrete terms, post-quantum cryptography means supplementing classical methods like RSA and elliptic curve cryptography with quantum-resistant algorithms. In 2024, NIST finalized the first standards, including ML-KEM for key exchange and ML-DSA for digital signatures. The algorithms are ready-the challenge lies in integrating them into existing systems, not in their availability.<\/p>\n<p>For data requiring long-term protection, this is a real problem. Medical records, contracts, or engineering designs must remain confidential even a decade from now. Those relying solely on classical public-key cryptography today are betting that quantum computing development will progress slowly enough. C5:2026 turns this implicit assumption into a verifiable requirement. How far protection must extend depends on the processing model, as outlined in this <a href=\"https:\/\/www.securitytoday.de\/en\/2022\/05\/19\/confidential-computing-why-data-must-remain-encrypted-even-during-processing\/\">article on Confidential Computing<\/a>.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What Needs to Be on Your Checklist Before the Deadline<\/h2>\n<p>A cryptographic overhaul isn\u2019t a patch you can deploy overnight. It requires lead time-and that starts with a seemingly mundane inventory. Four steps will determine whether your 2027 certification process runs smoothly.<\/p>\n<ol>\n<li style=\"line-height:1.8;margin-bottom:14px;\"><strong>Create a crypto inventory.<\/strong> If you don\u2019t know where and which encryption methods are in use, you can\u2019t migrate them. Libraries, certificates, protocols, and hardware modules all belong on a list. This work is tedious-and the most critical step.<\/li>\n<li style=\"line-height:1.8;margin-bottom:14px;\"><strong>Build crypto agility.<\/strong> Systems with hardcoded encryption methods are difficult to update. Where algorithms can be swapped out, migration becomes a configuration issue rather than a full-blown project.<\/li>\n<li style=\"line-height:1.8;margin-bottom:14px;\"><strong>Prioritize data by protection lifespan.<\/strong> Not everything needs quantum-safe encryption first. Data requiring long-term confidentiality takes precedence over short-lived session data. This prioritization saves migration budget.<\/li>\n<li style=\"line-height:1.8;margin-bottom:14px;\"><strong>Demand vendor roadmaps.<\/strong> If you use cloud services, ask providers now about their post-quantum plans. A certification is only as strong as the substance behind it.<\/li>\n<\/ol>\n<div style=\"background:#003340;color:#fff;text-align:center;padding:40px 24px;margin:32px 0;border-radius:8px;\">\n<div style=\"font-size:3.4em;font-weight:800;color:#69d8ed;letter-spacing:-0.03em;line-height:1;\">1 June 2027<\/div>\n<div style=\"font-size:1em;color:rgba(255,255,255,0.88);margin-top:12px;max-width:520px;margin-left:auto;margin-right:auto;line-height:1.5;\">From this date, newly initiated Type 2 certifications under C5:2026 will apply. For a crypto overhaul, that\u2019s a tight deadline.<\/div>\n<div style=\"font-size:0.78em;color:rgba(255,255,255,0.5);margin-top:12px;\">Source: BSI, C5:2026<\/div>\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">An Honest Look at the Effort Involved<\/h2>\n<p>No one overhauls their cryptography over a weekend. In large environments, an inventory can take months because encryption lurks in places no one has checked in years. That\u2019s precisely why an early start pays off. Those who wait until 2027 will certify under pressure-and risk overlooking that one legacy system that ultimately fails the audit. C5:2026 sets a deadline, and experience shows that\u2019s when such overhauls actually get underway.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Frequently Asked Questions<\/h2>\n<h3>What\u2019s new in BSI C5:2026 compared to the previous version?<\/h3>\n<p>The catalog expands from 121 to 168 criteria and introduces first-time requirements for post-quantum cryptography, confidential computing, and container security. It\u2019s also now available in a machine-readable YAML format.<\/p>\n<h3>When does C5:2026 become mandatory?<\/h3>\n<p>Type 2 certifications starting on or after 1 June 2027 must comply with the new catalog. Ongoing certifications remain unaffected for now.<\/p>\n<h3>Why is post-quantum cryptography relevant now, even though quantum computers don\u2019t exist yet?<\/h3>\n<p>Because of the &#8220;harvest now, decrypt later&#8221; pattern. Attackers are already storing encrypted data today to decrypt it later. Data requiring long-term protection is therefore at risk now.<\/p>\n<h3>What\u2019s the first practical step in preparing?<\/h3>\n<p>A complete crypto inventory. Without a clear overview of the algorithms, certificates, and libraries in use, no migration can be planned or effort estimated.<\/p>\n<h3>Does C5:2026 affect only cloud providers, or customers too?<\/h3>\n<p>Both. Providers must meet the criteria, while customers should demand their providers\u2019 post-quantum roadmap and align their own data prioritization accordingly.<\/p>\n<h3>Editor\u2019s Reading Recommendations<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/18\/security-operations-center-made-in-germany\/\">Security Operations Center: Made in Germany<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/14\/the-nis2-audit-how-companies-prepare-for-the-first-inspection\/\">The NIS2 Audit: How companies can prepare for the first inspection<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2025\/01\/22\/insider-threats-when-the-danger-comes-from-within-your-own-company\/\">Insider Threats: When the danger comes from within your own company<\/a><\/li>\n<\/ul>\n<p style=\"margin:0 0 12px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.18em;color:#666;\">More from the MBF Media Network<\/p>\n<div style=\"padding:14px 18px;border-left:3px solid #0bb7fd;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#0bb7fd;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">cloudmagazin<\/div>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/2019\/09\/04\/welche-provider-bieten-eine-datenverschluesselung-an\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Which providers offer data encryption<\/a><\/p>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #202528;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#202528;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">mybusinessfuture<\/div>\n<p><a href=\"https:\/\/mybusinessfuture.com\/lieferkettenangriff-software-mittelstand-nis2\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">When the update itself becomes the entry point<\/a><\/p>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #d65663;background:#fafafa;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#d65663;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">digital-chiefs<\/div>\n<p><a href=\"https:\/\/www.digital-chiefs.de\/managed-security-services-ciso-compliance-nis2-haftung\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Managed Security Services: The CISO isn\u2019t solely liable<\/a><\/p>\n<\/div>\n<p style=\"text-align:right;color:#868e96;font-size:0.85em;margin-top:48px;\"><em>Image source: AI-generated (June 2026)<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"Cloud security: The BSI&#8217;s C5:2026 catalog introduces Post-Quantum Cryptography for the first time.","protected":false},"author":10,"featured_media":18063,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"C5:2026","_yoast_wpseo_title":"Post-Quantum becomes mandatory in cloud certification","_yoast_wpseo_metadesc":"Cloud Security: BSI's C5:2026 introduces Post-Quantum Cryptography. What providers must include in their roadmap by 2027.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[3,2],"tags":[],"class_list":["post-18067","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aktuelles","category-innovation"],"evm_reading_time_minutes":6,"wpml_language":"en","wpml_translation_of":18062,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/18067","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=18067"}],"version-history":[{"count":1,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/18067\/revisions"}],"predecessor-version":[{"id":18068,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/18067\/revisions\/18068"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/18063"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=18067"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=18067"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=18067"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}