Figma clears Germany’s C5 cloud security bar
Figma has obtained C5 accreditation, the Cloud Computing Compliance Criteria Catalogue established by the German Federal Office for Information Security (BSI). The certification strengthens the company’s security and compliance posture for customers in Germany, Austria, and Switzerland (DACH).
C5 is a widely recognized framework for evaluating cloud services across security, availability, and confidentiality. Independent accreditation confirms that Figma meets strict standards for information security, risk management, and operational transparency, addressing the needs of organizations in the region that handle sensitive data and operate under complex regulatory obligations.
The company is now listed on the BSI C5 register, providing customers with direct visibility into Figma’s security controls and operational processes. This is particularly relevant for sectors such as government, public sector, and finance, where internal compliance teams must validate third-party tools against specific assurance requirements.
“Achieving C5 accreditation is an important milestone for Figma in the DACH region,” said Mareike Busche, senior director of DACH and CEE at Figma. “It demonstrates our commitment to meeting the high security and compliance expectations of customers in Germany, Austria and Switzerland, and enables us to serve organizations with complex regulatory needs.”
The accreditation builds on Figma’s broader investment in the region. That work includes full German-language localization and the availability of EU-local data storage for enterprise customers. The company reports that nearly 90% of DAX 40 companies use Figma for product design and collaboration.
With C5 in place, Figma adds another enterprise-grade compliance credential to its portfolio, extending the assurance it can offer teams building and designing together across the DACH market.



