BSI Standard 200-1 defines the general requirements for an information security management system (ISMS) and is compatible with ISO/IEC 27001. BSI Standard 200-2 describes the actual IT-Grundschutz methodology with its three approaches – Basic, Standard and Core Safeguarding; BSI Standard 200-3 bundles all risk-related work steps of an IT-Grundschutz implementation into a simplified risk management process. These three standards were published in 2017 as successors to the 100-x series. In addition, BSI Standard 200-4 (2023) provides practical guidance for building a business continuity management system (BCMS) and, as a modernised standard, replaces the earlier BSI Standard 100-4.
BSI IT-Grundschutz & Grundschutz++
How the BSI standards, the IT-Grundschutz Compendium and the safeguarding approaches interact – and what the ongoing modernisation towards Grundschutz++ means for your ISMS.
111modules in the IT-Grundschutz Compendium (Edition 2023)
19practices into which the 111 modules are being consolidated under Grundschutz++
4BSI Standards 200-1 to 200-4 as the methodological foundation
3approaches under BSI Standard 200-2: Basic, Standard and Core Safeguarding
The BSI's IT-Grundschutz is the methodology established in Germany for implementing information security systematically and verifiably – from public authorities and KRITIS operators to mid-sized companies. The interplay of BSI Standards 200-1 to 200-4, the IT-Grundschutz Compendium and three safeguarding approaches allows an entry point tailored to protection needs and maturity level. With Grundschutz++, the BSI is currently modernising this methodology from the ground up: process-oriented, machine-readable and designed for automation – the pilot phase has been running since 1 April 2026. Anyone planning an ISMS today should know both worlds and keep the bridge to the internationally established ISO/IEC 27001 in view.
Roadmap of the Grundschutz++ modernisation
From pilot launch to certification — tap a milestone for details.
1 Apr 2026
Pilot phase begins
The pilot phase starts; the pilot version of the methodology aligned with the PDCA cycle is published on the same date.
30 Sep 2026
Pilot phase ends
The pilot phase scheduled by the BSI runs until this date.
27 Oct 2026
Presentation at it-sa
The BSI presents the Grundschutz++ methodology at it-sa.
1 Nov 2026
GS++ training begins
From this date, training as GS++ consultant and GS++ audit team leader starts for already certified individuals.
1 Jan 2027
Certification applications open
From this date, applications for certification to ISO 27001 based on Grundschutz++ can be submitted.
The Essentials at a Glance
Six topic blocks — tap to expand.
Safeguarding approaches at a glance
Basic, Standard and Core — which entry point fits your protection needs and maturity level?
- Enables broad initial protection with the most important requirements — suitable as an entry point.
- Supported in a low-threshold way by the BSI's WiBA offering ("Weg in die Basis-Absicherung").
WiBAInitial protectionIntermediate step
- The complete, classic procedure for the entire information domain.
- Can be developed step by step from Basic and Core Safeguarding.
Information domainBSI Standard 200-2
- Initially concentrates resources on an institution's most valuable assets.
- Designed as an intermediate step from which Standard Safeguarding can be developed step by step.
Most valuable assetsIntermediate step
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
BSI-Standard 200-2: IT-Grundschutz-Methodik
Describes the three approaches – Basic, Standard and Core Safeguarding – at the heart of the classic IT-Grundschutz methodology.
IT-Grundschutz-Kompendium, Edition 2023
Current edition of the requirements catalogue with 111 modules, published on 1 February 2023 as the successor to Edition 2022.
Grundschutz++ (BSI-Themenseite)
Official roadmap: piloting 01.04.–30.09.2026, presentation at it-sa on 27.10.2026, certification available from 01.01.2027.
Leitfaden – Methodik Grundschutz++
Pilot version of 01.04.2026; describes the framework of the modernised Grundschutz, structured around the PDCA cycle.
Stand-der-Technik-Bibliothek
Digital platform through which the BSI publishes its catalogues as machine-readable OSCAL documents; available on GitHub since the end of September 2025 and expanded step by step since then.
Grundschutz++: Mehr Resilienz in der Informationssicherheit?
Independent analysis of the modernisation: consolidation of the 111 modules into 19 practices, two security levels, OSCAL/JSON as the format basis.
Classic IT-Grundschutz or already Grundschutz++?
In a no-obligation initial consultation, we assess which approach, which attestation and which migration path fit your organisation – including in combination with native ISO 27001.