Landing Zone Accelerator Now Has an Independent C5:2020 Assessment — Here’s Why That’s a Big Deal for Compliance Teams

If your organization operates in Germany or elsewhere in Europe, you’ve probably run into C5:2020 — the Cloud Computing Compliance Criteria Catalogue published by Germany’s Federal Office for Information Security (BSI). It’s one of the more rigorous cloud security standards in the region, and until now, proving you met it meant doing most of the mapping work yourself. AWS just made that considerably easier.

On August 11, 2026, AWS announced that an independent assessment report evaluating how Landing Zone Accelerator (LZA) aligns with C5:2020 is now available on AWS Artifact. Here’s what that actually means, and why it’s worth a look if compliance is part of your job.

What Landing Zone Accelerator is

LZA is AWS’s automated solution for standing up a secure, multi-account cloud environment. Rather than architecting a security baseline account-by-account, LZA provisions the infrastructure with security controls already configured, and it’s built to scale as your organization’s footprint grows. It ships in a standard deployment as well as a container-based option, including support for the AWS European Sovereign Cloud.

What’s actually new here

AWS’s own compliance coverage — the C5 Type 2 attestation — already exists, but it covers what AWS calls “security of the cloud”: the underlying infrastructure. It says nothing about how you configure what you build on top of it, which is the part that’s traditionally been on you.

That’s the gap this report closes. AWS brought in Schellman Compliance, LLC, an independent third-party assessor, to evaluate LZA specifically against C5:2020’s criteria for “security in the cloud” — in other words, whether the baseline LZA provisions for your accounts actually satisfies what C5:2020 requires. The assessment’s conclusion: LZA can help implement 325 security controls in aggregate, mapping to technical requirements across eight C5:2020 control areas.

Put simply, this doesn’t replace your compliance work, but it gives you a validated, pre-built starting point instead of a blank page — and it gives your auditors a third-party opinion to point to instead of just AWS’s word for it.

An example scenario

Say you’re a cloud security engineer at a German logistics company that needs to demonstrate C5:2020 compliance for a new multi-account AWS environment you’re standing up this quarter. Historically, that meant sitting down with the C5:2020 catalogue, mapping each control area to your account structure, IAM policies, logging configuration, and network design by hand — then bringing in an auditor to check your work, often after the environment was already built.

With this assessment in place, you deploy LZA to provision your baseline, then pull the LZA C5:2020 Independent Assessment Report and the accompanying LZA Compliance Workbook from AWS Artifact. The workbook maps LZA’s configuration directly to the specific C5:2020 controls it addresses, so instead of starting your compliance documentation from zero, you’re starting from a baseline that’s already been independently evaluated — and you can focus your own review on the workload-specific configuration on top of it, rather than re-litigating the foundational account structure.

How to get it

Both documents are available now to anyone signed into the AWS Management Console, through AWS Artifact — no separate request or NDA process. Worth noting: this specific report is tied to the current C5:2020 catalogue, and AWS has already flagged that it will be updated in 2027 to reflect the pending C5:2026 revision, so treat it as current-cycle documentation rather than a permanent artifact.

The takeaway

This is a shared-responsibility story, and AWS is explicit about that framing: security and compliance remain a shared responsibility between AWS and the customer. What’s changed is that the “in the cloud” half of that equation — the part that used to be entirely on your team to design and defend — now has independent, third-party validation for customers using LZA. If C5:2020 is on your compliance roadmap, this is worth pulling from AWS Artifact before you start that mapping exercise from scratch.


Sources: AWS Security Blog: Landing Zone Accelerator Independent Assessment Report for C5:2020 now available on AWS Artifact.