Automating compliance for cybersecurity certifications like BSI C5 is a central challenge for European cloud providers. EMERALD addresses this by combining different evidence streams — particularly, policy documents, infrastructure, and source code — into a single continuous compliance workflow. On September 23, 2026, DNV Cyber (formerly Nixu) conducted an audit in the IONOS Pilot 1 test environment, and by that, put this approach to the test for the first time in a real-world audit context.
WHY THIS AUDIT MATTERS
Cloud compliance today is largely a manual, document-heavy process. An auditor arrives, requests evidence, reviews spreadsheets, and forms a judgment. It is slow, resource-intensive, and provides only a point-in-time snapshot. The question EMERALD is trying to answer is whether meaningful parts of this process can be automated, made continuous, and made more transparent. DNV Cyber’s audit report framed the objective clearly: “to demonstrate how the EMERALD approach can support selected compliance controls within a practical audit context.” What that meant in practice was a 6.5-hour session in which auditors worked directly inside the EMERALD platform rather than switching between tools and spreadsheets.
WHAT THE EMERALD APPROACH BRINGS TO A SECURITY AUDIT
The most important thing to understand about EMERALD is its architecture. Rather than treating compliance as a single-source activity, EMERALD pulls evidence from multiple independent streams simultaneously. In this audit, that meant the platform could assess whether IONOS infrastructure met a control requirement by combining automated technical checks on live resources, AI-assisted extraction from policy documents, and (once integrated) analysis of source code repositories. EMERALD’s Clouditor Discovery component connected directly to the IONOS API and pulled real-time state data on virtual machines, storage volumes, network interfaces, and load balancers. This happened automatically, not by request. Evidence was there before the auditor asked for it. The AMOE component extracted structured compliance-relevant data from policy documents, cross-referencing them against control requirements. Where a document stated that asset inventories were updated continuously, AMOE surfaced that statement and mapped it to the relevant BSI C5 control. The auditor could then review the evidence and make a compliance judgment within the platform.
WHAT WORKED, AND WHAT WE LEARNED
The IONOS test environment is set up with 25 controls drawn from the BSI C5:2020 framework. They represent a curated subset of the controls assessed in IONOS’s BSI C5 Type 1 certification audit conducted in October 2023, specifically those where EMERALD’s three extractor layers could demonstrate meaningful automated evidence. Hence, while IONOS holds BSI C5 certification, the EMERALD pilot asks a different question: how much of that certification evidence could be collected automatically, continuously, and without manual intervention?
Six controls out of the 25 were assessed as compliant by the audit team. That number is less meaningful than what it reveals about the methodology. For several controls in the asset management and identity management domains — AM-01, OPS-13, OPS-17, COS-03, PS-01 — the EMERALD platform successfully delivered supporting evidence that auditors could evaluate and confirm. For access rights controls like IDM-05 and IDM-06, AMOE correctly identified the presence of least privilege, need-to-know, and separation of duties policies within IONOS documentation.
The clearest finding, however, was about API coverage rather than about security posture. A significant number of non-compliant results did not reflect misconfigured infrastructure, but gaps in what the IONOS Cloud API currently exposes as queriable properties. Encryption at rest for storage volumes is a clear example: IONOS implements AES-XTS 256-bit encryption at both logical volume and drive level as a platform guarantee — but this is not surfaced as a per-volume property in the API, which means automated tools cannot confirm it programmatically. The result is a non-compliant finding that reflects an API coverage gap, not an absence of encryption. The same applies to malware protection configuration on compute instances, which is a guest OS-level setting not exposed through the IaaS API. EMERALD correctly records these as non-compliant — the safe default when evidence cannot be confirmed — and in doing so makes the gap visible, specific, and actionable. That is exactly the kind of concrete output a pilot audit should produce.
OUTLOOK AND CONCLUSION
We will work with the EMERALD platform team on improvements to the user interface, where several display inconsistencies were noted during the session. The underlying compliance logic was sound in most cases, but auditors need to be able to trust what they see on screen without workarounds. That is a reasonable expectation and one the team is actively working to meet.
The September 2026 audit was a proof of concept that succeeded in its primary objective: demonstrating that an end-to-end compliance workflow using automated, multi-source evidence collection is operationally feasible for a public cloud environment.
Figure: Putting all layers of evidence in one integrated view in EMERALD UI.
(Source: Conceptual rendering generated via AI, based on EMERALD project technical documentation and the audit report.)