AI Guide

BSI IT-Grundschutz: Germany's baseline standard for information security

BSI IT-Grundschutz is the information security methodology published by Germany's Federal Office for Information Security (BSI), combining a management framework with concrete, prescriptive security measures for typical IT environments. It is the de facto requirement for suppliers to German public authorities and critical infrastructure operators, and forms the basis for a recognized ISO 27001 certification variant. This article explains how the methodology works, how it differs from generic ISO 27001, and what it means for Mittelstand companies selling into regulated German markets.

Key Facts
  • BSI IT-Grundschutz is published by the Bundesamt fur Sicherheit in der Informationstechnik (BSI), Germany's federal cybersecurity agency.
  • The IT-Grundschutz-Kompendium contains 113 Bausteine (building blocks) organized across 10 topic layers, from applications to industrial IT.
  • Three implementation paths exist: Basis-Absicherung (2 to 4 months), Kern-Absicherung (4 to 8 months), and Standard-Absicherung (6 to 12 months).
  • A 2021 Bitkom survey found 23 percent of German companies ran an ISMS based on BSI IT-Grundschutz, up from 17 percent in 2019, versus 59 percent using ISO 27001.
  • Since January 1, 2026, BSI has rolled out IT-Grundschutz++, a machine-readable, OSCAL-compatible revision, with the 2024/2025 edition staying valid through a multi-year transition.

Definition: BSI IT-Grundschutz

BSI IT-Grundschutz is a German information security methodology, published by the Bundesamt fur Sicherheit in der Informationstechnik, that combines a management-system framework with a catalog of concrete, pre-defined security measures for typical IT, cloud, and industrial environments.

Core characteristics of BSI IT-Grundschutz

Unlike frameworks that leave control selection to the organization, IT-Grundschutz prescribes specific, tested measures for recurring components such as servers, networks, and applications, trading flexibility for speed.

  • Built around the Grundschutz-Kompendium, a catalog of standardized Bausteine (modules) with threats and controls
  • Governed by four BSI-Standards covering ISMS setup, methodology, risk analysis, and business continuity
  • Requires a formal Schutzbedarfsfeststellung (protection-needs assessment) for two of its three implementation variants
  • Recognized by German federal, state, and local authorities as the default expectation for suppliers handling their data

BSI IT-Grundschutz vs. ISO 27001

ISO 27001 is a globally portable standard built on a risk assessment methodology each organization designs itself, choosing freely among 93 Annex A controls. BSI IT-Grundschutz instead prescribes concrete Bausteine for standard IT components, trading flexibility for faster, more consistent implementation. The two combine through “ISO 27001 auf Basis von IT-Grundschutz,” a certification satisfying German public-sector procurement rules and international ISO recognition at once. For Mittelstand suppliers selling mainly to Behorden, Kommunen, or KRITIS operators, IT-Grundschutz compatibility is often a hard requirement, while companies with mostly international customers usually stop at ISO 27001 alone.

Importance of BSI IT-Grundschutz in enterprise AI

IT-Grundschutz matters for AI-enabled organizations because the Kompendium already includes Bausteine for cloud usage, outsourcing, and application security that apply directly to AI deployments. A 2021 Bitkom survey found 23 percent of German companies ran an ISMS based on IT-Grundschutz, up from 17 percent in 2019, as procurement and NIS2 obligations expand. Companies building AI compliance programs on an existing baseline avoid duplicating access control and supplier management work both frameworks require.

Methods and procedures for BSI IT-Grundschutz

Schutzbedarfsfeststellung (protection-needs assessment)

The organization rates every asset, process, and system against three Schutzbedarfskategorien (normal, high, very high) based on potential damage to confidentiality, integrity, and availability.

  • Assess damage across six scenario types, including legal violations and financial impact
  • Assign a protection category to each Zielobjekt in the Informationsverbund
  • Skip this step for Basis-Absicherung, where only baseline requirements apply

Choosing an Absicherung variant

Basis-Absicherung gives fast, uniform coverage without a full needs assessment. Kern-Absicherung concentrates on the organization’s most critical assets. Standard-Absicherung, the recommended approach, covers every process to certification depth. Only Kern- and Standard-Absicherung qualify for the full “ISO 27001 auf Basis von IT-Grundschutz” certificate; Basis-Absicherung earns a BSI Testat instead.

IT-Grundschutz-Check and realization

An IT-Grundschutz-Check then compares required measures against what is implemented, producing a gap list for the realization plan. Remaining risks above the accepted threshold go through the risk analysis defined in BSI-Standard 200-3.

Important KPIs for BSI IT-Grundschutz

Coverage and implementation

  • Baustein coverage: percentage of applicable modules with documented measures
  • Schutzbedarfsfeststellung completion: percentage of assets rated
  • Gap closure rate: percentage of IT-Grundschutz-Check findings remediated
  • Testat or certification renewal: on-time completion rate

Audit and procurement readiness

Companies bidding on public-sector or KRITIS contracts should track how quickly they can produce current evidence during tender due diligence, since delayed documentation often costs time-sensitive bids.

Operational security quality

Incident detection and response times remain the practical measure of whether Bausteine actually function, since auditors increasingly request live evidence over documentation alone.

Risk factors and controls for BSI IT-Grundschutz

Wrong Absicherung variant for the goal

Choosing Basis-Absicherung when a tender requires full certification wastes months of work that cannot be reused directly.

  • Confirm customer or tender requirements before selecting a variant
  • Check whether Kern- or Standard-Absicherung is contractually mandated
  • Revisit the choice if the Informationsverbund scope changes materially

Outdated Baustein mapping

Organizations that map Bausteine once and never revisit them accumulate drift between documented and actual IT systems, which surfaces during recertification audits.

Underestimating AI and cloud scope

New AI tools and cloud services frequently enter production unmapped to any Baustein, leaving a documented Informationsverbund that no longer reflects reality. Extending the same AI audit discipline used for model governance to infrastructure changes closes this gap before it becomes a finding.

Practical example

A 95-employee industrial sensor manufacturer in Baden-Wurttemberg, supplying components to municipal utilities, needed IT-Grundschutz compatibility after a tender required “ISO 27001 auf Basis von IT-Grundschutz” as a qualification criterion. With no prior ISMS, the company started with Kern-Absicherung, focusing on its ERP, engineering data store, and customer portal. The Schutzbedarfsfeststellung classified the engineering data as high protection need, driving stricter access controls than before.

  • Defined Informationsverbund scoping the ERP, CAD repository, and customer-facing systems
  • Schutzbedarfsfeststellung completed for 28 target objects across three protection categories
  • Gap closure plan addressing 19 findings from the initial IT-Grundschutz-Check
  • Successful Testat within eight months, ahead of the tender deadline

Current developments and effects

IT-Grundschutz++ rollout

Since January 1, 2026, BSI has begun rolling out IT-Grundschutz++, converting the Kompendium into a machine-readable, OSCAL-compatible format meant to cut documentation burden.

  • Bausteine published in structured JSON alongside the traditional PDF format
  • Existing 2024/2025-edition certifications remain valid through a transition expected to run into 2029
  • Tooling vendors are building automated compliance mapping against the new format

NIS2 expanding the affected population

Germany’s NIS2 implementation law extends binding cybersecurity obligations to roughly 29,500 companies, many of which reference IT-Grundschutz Bausteine as accepted evidence for risk management and incident reporting, increasing pressure on their supplier chains.

AI systems entering the Informationsverbund

BSI guidance increasingly treats AI components as ordinary Zielobjekte requiring their own Schutzbedarfsfeststellung, meaning organizations must extend existing Bausteine to model access, training data, and inference infrastructure, typically anchored in Zero Trust Architecture principles.

Conclusion

BSI IT-Grundschutz remains the default expectation for companies supplying German public authorities, utilities, and critical infrastructure, and the 2026 shift toward IT-Grundschutz++ makes that baseline more tooling-friendly rather than less relevant. For Mittelstand suppliers, the practical decision is choosing the right Absicherung variant for the actual requirement, not the fastest path. Because the methodology overlaps substantially with ISO 27001 and NIS2 controls, work invested here compounds across future obligations. Companies that keep their Baustein mapping current as AI and cloud systems enter production avoid the gaps that most often surface during recertification.

Frequently Asked Questions

What is the difference between BSI IT-Grundschutz and ISO 27001?

ISO 27001 lets organizations design their own risk-based control selection from 93 Annex A options, while IT-Grundschutz prescribes concrete, pre-defined measures (Bausteine) for standard IT components. Companies can combine both through “ISO 27001 auf Basis von IT-Grundschutz,” recognized internationally and required by many German public-sector tenders.

Is BSI IT-Grundschutz worth pursuing for a company with fewer than 100 employees?

Yes, if the company supplies German public authorities, utilities, or KRITIS operators, since compatibility is frequently a tender requirement regardless of size. Basis-Absicherung offers a realistic entry point before committing to full certification.

What does implementing IT-Grundschutz cost for a Mittelstand company?

For a company with 100 to 250 employees, total first-year cost including internal effort, consulting, and fees typically falls in the low five-figure range for Basis-Absicherung, and higher for Kern- or Standard-Absicherung with formal certification. The official BSI certification fee itself is a small fraction of that total.

How does IT-Grundschutz relate to NIS2 and DSGVO?

BSI references IT-Grundschutz Bausteine as accepted evidence for risk management and incident reporting obligations under Germany’s NIS2 law, which covers roughly 29,500 companies. The methodology also supports DSGVO compliance through its access control measures, and many companies coordinate this work with their Data Protection Officer.

How long does IT-Grundschutz implementation take?

Basis-Absicherung typically takes 2 to 4 months, Kern-Absicherung 4 to 8 months, and Standard-Absicherung 6 to 12 months, depending on the size of the Informationsverbund and the maturity of existing practices. Companies facing a tender deadline often start with Kern-Absicherung focused on the systems the tender actually covers.

Do we need dedicated IT security staff to pursue IT-Grundschutz?

Not necessarily. Many Mittelstand companies assign ownership to an existing IT lead, supported by external consultants for the Schutzbedarfsfeststellung and Baustein mapping, and build internal capability over successive recertification cycles.

Building better software Contact us together