Book an Appointment

BSI IT-Grundschutz & Grundschutz++

How the BSI standards, the IT-Grundschutz Compendium and the safeguarding approaches interact – and what the ongoing modernisation towards Grundschutz++ means for your ISMS.

The BSI's IT-Grundschutz is the methodology established in Germany for implementing information security systematically and verifiably – from public authorities and KRITIS operators to mid-sized companies. The interplay of BSI Standards 200-1 to 200-4, the IT-Grundschutz Compendium and three safeguarding approaches allows an entry point tailored to protection needs and maturity level. With Grundschutz++, the BSI is currently modernising this methodology from the ground up: process-oriented, machine-readable and designed for automation – the pilot phase has been running since 1 April 2026. Anyone planning an ISMS today should know both worlds and keep the bridge to the internationally established ISO/IEC 27001 in view.

The Essentials at a Glance

01

The BSI Standards 200-1 to 200-4

BSI Standard 200-1 defines the general requirements for an information security management system (ISMS) and is compatible with ISO/IEC 27001. BSI Standard 200-2 describes the actual IT-Grundschutz methodology with its three approaches – Basic, Standard and Core Safeguarding; BSI Standard 200-3 bundles all risk-related work steps of an IT-Grundschutz implementation into a simplified risk management process. These three standards were published in 2017 as successors to the 100-x series. In addition, BSI Standard 200-4 (2023) provides practical guidance for building a business continuity management system (BCMS) and, as a modernised standard, replaces the earlier BSI Standard 100-4.

02

IT-Grundschutz Compendium: Modules as a Requirements Catalogue

The IT-Grundschutz Compendium translates the methodology into concrete requirements. The current Edition 2023 (published on 1 February 2023) contains 111 modules – from ISMS and organisational topics through applications and IT systems to networks and infrastructure, including newly added modules such as OPS.1.1.1 (General IT Operations) or APP.5.4 (Unified Communications and Collaboration). Each module describes the threat landscape of its topic and formulates tiered requirements for Basic Safeguarding, Standard Safeguarding and increased protection needs. During the modernisation towards Grundschutz++, classic IT-Grundschutz remains applicable and certifiable in parallel; the BSI has scheduled a multi-year transition period for this.

03

Safeguarding Approaches: Basic, Standard and Core

BSI Standard 200-2 provides for three approaches. Standard Safeguarding is the complete, classic procedure for the entire information domain. Basic Safeguarding enables broad initial protection with the most important requirements and is suitable as an entry point – supported in a low-threshold way by the BSI's WiBA offering ("Weg in die Basis-Absicherung", the route into Basic Safeguarding); Core Safeguarding initially concentrates resources on an institution's most valuable assets. Basic and Core Safeguarding are designed as intermediate steps from which Standard Safeguarding can be developed step by step.

04

The "ISO 27001 Certificate based on IT-Grundschutz"

With the certificate "ISO 27001 based on IT-Grundschutz", the BSI, acting as certification body, confirms that an ISMS fulfils both the requirements of ISO/IEC 27001 and the considerably more concrete requirements of IT-Grundschutz. The basis is an implemented Standard or Core Safeguarding; for Basic Safeguarding an attestation is available, but no certificate. The audit is conducted by an auditor certified by the BSI – including document review, on-site assessment and audit report; the BSI decides on the award of the certificate. The certificate is valid for three years and is confirmed by surveillance audits in the first and second year after issuance.

05

Grundschutz++: Status of the Modernisation (mid-2026)

With Grundschutz++, the BSI is evolving IT-Grundschutz into a fully process-oriented, machine-readable body of rules. Its core components are the methodology aligned with the PDCA cycle (pilot version of 1 April 2026), the user catalogue containing the technical and organisational requirements, and the State-of-the-Art Library (Stand-der-Technik-Bibliothek), through which the BSI publishes its catalogues as machine-readable OSCAL documents on GitHub; the Compendium's previous 111 modules are being consolidated into 19 practices. The previous safeguarding levels are replaced by flexible performance figures combined with dynamic thresholds. The BSI's roadmap: pilot phase from 1 April to 30 September 2026, presentation of the methodology at it-sa on 27 October 2026, start of training as GS++ consultant and GS++ audit team leader for already certified individuals from 1 November 2026 – and from 1 January 2027, applications for certification to ISO 27001 based on Grundschutz++ can be submitted.

06

Dual Compliance: Combining IT-Grundschutz and Native ISO 27001

A native ISO/IEC 27001 certificate from an accredited certification body and a BSI certificate based on IT-Grundschutz are not mutually exclusive: both attestations can be served from a single integrated ISMS, as the control areas largely overlap. ISO/IEC 27001 is internationally recognised and formulated in a generic, risk-based way; IT-Grundschutz supplies the concrete implementation requirements that public authorities, KRITIS operators and public-sector clients in particular expect. According to the BSI, Grundschutz++ will also remain compatible with ISO 27001, so existing ISO structures can continue to be used. Such a dual-compliance strategy avoids duplicate structures, strengthens your ability to provide evidence to customers and supervisory authorities, and supports preparation for European requirements such as NIS-2.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2017

BSI-Standard 200-2: IT-Grundschutz-Methodik

Describes the three approaches – Basic, Standard and Core Safeguarding – at the heart of the classic IT-Grundschutz methodology.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2023

IT-Grundschutz-Kompendium, Edition 2023

Current edition of the requirements catalogue with 111 modules, published on 1 February 2023 as the successor to Edition 2022.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

Grundschutz++ (BSI-Themenseite)

Official roadmap: piloting 01.04.–30.09.2026, presentation at it-sa on 27.10.2026, certification available from 01.01.2027.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

Leitfaden – Methodik Grundschutz++

Pilot version of 01.04.2026; describes the framework of the modernised Grundschutz, structured around the PDCA cycle.

BSI (GitHub-Repository BSI-Bund) · 2025

Stand-der-Technik-Bibliothek

Digital platform through which the BSI publishes its catalogues as machine-readable OSCAL documents; available on GitHub since the end of September 2025 and expanded step by step since then.

HiSolutions Research · 2026

Grundschutz++: Mehr Resilienz in der Informationssicherheit?

Independent analysis of the modernisation: consolidation of the 111 modules into 19 practices, two security levels, OSCAL/JSON as the format basis.

Classic IT-Grundschutz or already Grundschutz++?

In a no-obligation initial consultation, we assess which approach, which attestation and which migration path fit your organisation – including in combination with native ISO 27001.