Close

The Cloud Computing Compliance Criteria Catalogue (C5) is a security framework developed by Germany's Federal Office for Information Security (BSI) that establishes minimum requirements for secure cloud computing. First published in 2016 and revised in 2019, C5 provides an independent assessment mechanism rather than a certification, enabling transparent evaluation of cloud service security controls across areas including identity management, data protection, incident response, and operational resilience. The framework supports German regulatory requirements such as the German IT Security Act, with healthcare cloud services mandated to meet C5 criteria since July 2024.

C5 assessment types

C5 assessments, conducted by independent auditors, evaluate security controls either at a specific point in time (Type 1) or over an extended period (Type 2). These standardized reports provide transparency into Atlassian’s security practices and risk management, enabling organizations to systematically compare cloud providers and make informed decisions about cloud adoption and ongoing risk management.

Shared responsibility in compliance

C5 assessments follow a shared responsibility model where Atlassian provides comprehensive security controls and transparent reporting, while customers retain responsibility for analyzing assessment reports within their own risk management frameworks and determining alignment with their specific security requirements. We encourage customers to review C5 reports annually as part of their vendor risk assessment processes.

Relevant products

Jira 图标
项目和问题追踪

Jira

Confluence 图标
文档协作

Confluence Cloud

Jira Service Management 图标
高速 ITSM

Jira Service Management

我们的团队随时为您提供帮助

对我们的合规计划还有其他疑问?

你们有云认证吗?能否完成我的安全与风险调查问卷?哪里可以下载到更多信息?

信任与安全社区

加入 Atlassian 社区的信任与安全小组,获得我们安全团队的第一手资讯,并且分享以安全、可靠的方式使用 Atlassian 产品的各种信息、提示和最佳实践。

Atlassian 支持

联系我们训练有素的支持工程师,获得您的问题的答案。