Description

Federal Office for Information Security published Criteria enabling Cloud Computing Autonomy (C3A)

On 27 April 2026, the German Federal Office for Information Security (BSI) published the Criteria enabling Cloud Computing Autonomy (C3A), a non-binding framework setting out verifiable criteria for assessing the degree of self-determination availab…

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
software provider: other software, infrastructure provider: cloud computing, storage and databases
Implementation Level
national
Government Branch
executive
Government Body
other regulatory body

Complete timeline of this policy change

Hide details
2026-04-27
adopted

On 27 April 2026, the German Federal Office for Information Security (BSI) published the Criteria e…