Press
DCSO Receives BSI C5 Type 2 Attestation
DCSO Receives BSI C5 Type 2 Attestation
Following its successful initial Type 1 assessment in 2025, DCSO once again demonstrates compliance with the BSI C5 requirements – now including the operating effectiveness of its established security controls throughout the assessment period.
Berlin, September 2026 – Deutsche Cyber-Sicherheitsorganisation GmbH (DCSO) has successfully extended the BSI C5 attestation of its services to Type 2. The independent assessment confirms not only the appropriate design and implementation of the relevant security controls, but also their operating effectiveness throughout the underlying assessment period.
The attestation builds on DCSO’s successful initial Type 1 C5 assessment, which was completed on August 15, 2025. By extending its attestation to Type 2, DCSO reinforces its commitment to not only establishing high standards for information security and compliance, but also ensuring their effective and sustained implementation in day-to-day operations.
More Than a Point-in-Time Assessment
The Cloud Computing Compliance Criteria Catalogue (C5) issued by the German Federal Office for Information Security (BSI) defines requirements for the information security of cloud services and provides transparency for both providers and customers.
The key difference between the two attestation types lies in the scope of the assessment: Type 1 evaluates the appropriate design and implementation of controls at a specific point in time, while Type 2 additionally assesses their operating effectiveness over a defined period. This provides a more robust basis for demonstrating that security measures are actually applied and effectively implemented in ongoing operations.
A Robust Assurance for Customers and Partners
For DCSO customers, the successful Type 2 attestation provides additional transparency when assessing a specialized cybersecurity service provider. Particularly for organizations with high requirements for information security, compliance and assurance, reliable evidence of effective security controls is an important factor when selecting and evaluating service providers.
“With the successful C5 Type 2 attestation, we demonstrate that our commitment to information security goes beyond defined processes and controls. What ultimately matters is that these measures work effectively in day-to-day operations. The renewed assessment confirms exactly that and therefore provides important assurance to our customers and partners,” says Willot Esbach, Chief Information Security Officer at DCSO.
The successful Type 2 attestation therefore marks another important milestone for DCSO and reinforces its commitment to delivering secure, transparent and reliable Managed Security Services to a high standard.
As a specialized Managed Security Services Provider, DCSO supports organizations with services including Managed Detection & Response, Incident Response, Internet Exposure Monitoring and Threat Intelligence, helping them identify, assess and effectively address cyber risks at an early stage.
PRESS