01The BSI Standards 200-1 to 200-4
BSI Standard 200-1 defines the general requirements for an information security management system (ISMS) and is compatible with ISO/IEC 27001. BSI Standard 200-2 describes the actual IT-Grundschutz methodology with its three approaches – Basic, Standard and Core Safeguarding; BSI Standard 200-3 bundles all risk-related work steps of an IT-Grundschutz implementation into a simplified risk management process. These three standards were published in 2017 as successors to the 100-x series. In addition, BSI Standard 200-4 (2023) provides practical guidance for building a business continuity management system (BCMS) and, as a modernised standard, replaces the earlier BSI Standard 100-4.
02IT-Grundschutz Compendium: Modules as a Requirements Catalogue
The IT-Grundschutz Compendium translates the methodology into concrete requirements. The current Edition 2023 (published on 1 February 2023) contains 111 modules – from ISMS and organisational topics through applications and IT systems to networks and infrastructure, including newly added modules such as OPS.1.1.1 (General IT Operations) or APP.5.4 (Unified Communications and Collaboration). Each module describes the threat landscape of its topic and formulates tiered requirements for Basic Safeguarding, Standard Safeguarding and increased protection needs. During the modernisation towards Grundschutz++, classic IT-Grundschutz remains applicable and certifiable in parallel; the BSI has scheduled a multi-year transition period for this.
03Safeguarding Approaches: Basic, Standard and Core
BSI Standard 200-2 provides for three approaches. Standard Safeguarding is the complete, classic procedure for the entire information domain. Basic Safeguarding enables broad initial protection with the most important requirements and is suitable as an entry point – supported in a low-threshold way by the BSI's WiBA offering ("Weg in die Basis-Absicherung", the route into Basic Safeguarding); Core Safeguarding initially concentrates resources on an institution's most valuable assets. Basic and Core Safeguarding are designed as intermediate steps from which Standard Safeguarding can be developed step by step.
04The "ISO 27001 Certificate based on IT-Grundschutz"
With the certificate "ISO 27001 based on IT-Grundschutz", the BSI, acting as certification body, confirms that an ISMS fulfils both the requirements of ISO/IEC 27001 and the considerably more concrete requirements of IT-Grundschutz. The basis is an implemented Standard or Core Safeguarding; for Basic Safeguarding an attestation is available, but no certificate. The audit is conducted by an auditor certified by the BSI – including document review, on-site assessment and audit report; the BSI decides on the award of the certificate. The certificate is valid for three years and is confirmed by surveillance audits in the first and second year after issuance.
05Grundschutz++: Status of the Modernisation (mid-2026)
With Grundschutz++, the BSI is evolving IT-Grundschutz into a fully process-oriented, machine-readable body of rules. Its core components are the methodology aligned with the PDCA cycle (pilot version of 1 April 2026), the user catalogue containing the technical and organisational requirements, and the State-of-the-Art Library (Stand-der-Technik-Bibliothek), through which the BSI publishes its catalogues as machine-readable OSCAL documents on GitHub; the Compendium's previous 111 modules are being consolidated into 19 practices. The previous safeguarding levels are replaced by flexible performance figures combined with dynamic thresholds. The BSI's roadmap: pilot phase from 1 April to 30 September 2026, presentation of the methodology at it-sa on 27 October 2026, start of training as GS++ consultant and GS++ audit team leader for already certified individuals from 1 November 2026 – and from 1 January 2027, applications for certification to ISO 27001 based on Grundschutz++ can be submitted.
06Dual Compliance: Combining IT-Grundschutz and Native ISO 27001
A native ISO/IEC 27001 certificate from an accredited certification body and a BSI certificate based on IT-Grundschutz are not mutually exclusive: both attestations can be served from a single integrated ISMS, as the control areas largely overlap. ISO/IEC 27001 is internationally recognised and formulated in a generic, risk-based way; IT-Grundschutz supplies the concrete implementation requirements that public authorities, KRITIS operators and public-sector clients in particular expect. According to the BSI, Grundschutz++ will also remain compatible with ISO 27001, so existing ISO structures can continue to be used. Such a dual-compliance strategy avoids duplicate structures, strengthens your ability to provide evidence to customers and supervisory authorities, and supports preparation for European requirements such as NIS-2.