Market perspective

ISO/IEC 42001 and SOC 2 implementation for Germany

German cloud and AI service teams may need to answer several different assurance questions. ISO/IEC 42001 structures AI governance; SOC 2 can answer a customer request for a service control report; BSI criteria may be relevant to a cloud offering. Each has its own scope and independent assessment path.

Begin with the AI service inventory

For ISO/IEC 42001, list both AI products offered to customers and AI capabilities used inside the organization. Record the intended use, model or supplier dependencies, data categories, affected parties, ownership, and the decision the system supports. The resulting boundary should be specific enough to guide risk and impact reviews, testing, change control, and management review.

The German BSI also publishes an AI Cloud Service Compliance Criteria Catalogue, AIC4, for particular cloud AI service security assessments. Its applicability is a separate question from an ISO/IEC 42001 management system. A provider should identify the exact service and customer expectation before mapping evidence between them.

Treat BSI C5 as a cloud-specific customer question

BSI C5 addresses cloud service security criteria and the evaluation of cloud assurance reports. It is not a substitute for ISO/IEC 42001 or a SOC 2 report. If a buyer asks about C5, document the relevant cloud service, delivery model, provider and customer responsibilities, and report boundary before promising a mapping.

BSI publishes a C5 to ISO/IEC 27001:2022 cross-reference. That can start a control mapping, but an overlapping control name is not evidence that it operates in the same scope or satisfies every criterion. Owners, frequency, exceptions, and independent report coverage still need review.

Use SOC 2 for the defined service

A German service provider can prepare for a SOC 2 examination if customers request AICPA-style assurance. Define the system description, relevant Trust Services Criteria, subservice organizations, and customer responsibilities. Then make normal operating records available for an independent CPA firm to examine.

A SOC 2 report is not a BSI C5 attestation or an ISO certificate. A buyer may need more than one artifact, so the implementation plan should reuse evidence where sound while showing precisely which service and period each artifact covers.

Build one governance cadence with separate outcomes

ISO/IEC 27001 can anchor security risk assessment, supplier oversight, internal audit, and management review. ISO/IEC 42001 adds AI-specific roles, impacts, and lifecycle controls. When both management systems are used, coordinate owners and review dates but preserve the distinct objectives and records.

Before any audit handoff, test one real change to an AI service: who approved the change, what risks were reconsidered, how it was tested, what monitoring changed, and which customer-facing assurance claims need updating. This exposes gaps that a broad policy inventory misses.

Assess German NIS2 duties under the enacted law

Germany's NIS-2 implementation act entered into force on 6 December 2025. The BSI provides its portal for registration and relevant incident reporting, with transition arrangements for some critical-facility operators. Begin with an entity- and service-level applicability review under the enacted German provisions; a customer's request for SOC 2 or BSI C5 is a different question.

For an in-scope organization, connect management ownership, risk treatment, supplier security, incident response, and reporting procedures to a maintained evidence register. ISO/IEC 27001 controls can provide operating foundations, but an ISO certificate, C5 report, or SOC 2 report should not be described as a single German NIS2 certification or a substitute for the law's specific duties.

Common questions

Clarify the outcome before the work.

Is BSI C5 the same as SOC 2?

No. Both can be used to discuss assurance over a service, but they use different criteria and report scopes. Confirm the artifact a buyer needs.

Does ISO/IEC 42001 cover AIC4?

No automatic equivalence follows. ISO/IEC 42001 concerns an AI management system; BSI AIC4 specifies criteria for certain cloud AI services.

Can existing ISO/IEC 27001 work help?

Yes. Security governance and evidence may be reusable, provided AI-specific controls and each assessment boundary are addressed separately.

Does ISO/IEC 27001 or SOC 2 certify German NIS2 compliance?

No. These are separate assessment outcomes. Covered entities must address the applicable German law and BSI processes directly.

Work with Normstone

Make the next assurance decision clear.

Tell us your service, AI use, and customer requirements. We’ll help shape the scope.

Start a conversation