Case studies

What cloud assurance regimes have already taught us

Five documented programmes across four jurisdictions, read for one purpose: shortening the route a US vendor takes to a defensible BSI C5:2020 attestation.

Programmes

United StatesFedRAMP High — GSA

30-application federal migration

A US federal agency consolidated thirty applications onto a FedRAMP High authorised platform, retiring duplicated control evidence and shared-service overhead. Documented savings of approximately $2M.

The control set is the direct bridge into the German market: roughly 70% of FedRAMP High controls map onto BSI C5:2020 criteria, so existing authorisation packages become the starting evidence base rather than sunk cost.

United KingdomNCSC CAF — National Cyber Security Centre

NHS England, post-WannaCry

Following WannaCry, NHS England adopted the NCSC Cyber Assessment Framework across its provider estate — an outcome-based, risk-led model rather than a checklist.

The lesson carried into C5 work: objectives-driven assessment survives audit better than control-by-control attestation, because the rationale is documented alongside the control.

AustraliaIRAP — Australian Signals Directorate

Cloud certification programme evolution

The ASD moved from a central certified cloud list to an assessor-led IRAP model, shifting accountability for risk decisions to the consuming agency.

Assessment-based regimes reward providers who can produce continuous evidence, not point-in-time artefacts — the same posture BSI auditors expect at type 2 attestation.

SingaporeMTCS SS 584 — IMDA

The first multi-tier cloud standard

MTCS introduced the world's first tiered cloud security standard, letting buyers match assurance level to workload sensitivity across three tiers.

Tiering is the practical answer to scope creep in German engagements: classify workloads first, then certify to the level the tender actually requires.

GermanyBSI C5:2020 + IT-Grundschutz — BSI

Open Telekom Cloud

Open Telekom Cloud holds both C5:2020 attestation and IT-Grundschutz certification — the combination German federal buyers increasingly treat as the entry threshold rather than a differentiator.

It sets the benchmark for US vendors entering through an EU entity: C5 attestation for the service, IT-Grundschutz alignment for the operating organisation behind it.

Framework comparison

RegionFrameworkAuthorityRelevance to the German market
USAFedRAMP HighGSADirect mapping to C5 controls
UKNCSC CAFNational Cyber Security CentreSimilar risk-based assessment
AustraliaIRAPAustralian Signals DirectorateAssessment-based approach
SingaporeMTCS (SS 584)IMDATiered security model
GermanyBSI C5:2020BSITarget certification
Credentials & certifications