AuditXYZ

Compliance Framework

BSI IT-Grundschutz (IT Baseline Protection) (IT-Grundschutz)

IT-Grundschutz is Germany's comprehensive methodology for baseline IT security. This guide covers the BSI standards, the Grundschutz Compendium, certification process, and comparison with standard ISO 27001.

$30,000–$250,0006–18 monthsAudit Required2023 (IT-Grundschutz Compendium, Edition 2023)
Issuing BodyGerman Federal Office for Information Security (BSI)
First Published1994-01-01
Latest Version2023 (IT-Grundschutz Compendium, Edition 2023)
Typical Cost$30,000–$250,000
Typical Timeline6–18 months
Audit RequiredYes
Audit FrequencyBSI certification follows the ISO 27001 cycle: annual surveillance audits with full recertification every 3 years.
Geographygermany, european-union

IT-Grundschutz: Germany BSI Baseline Security Guide

IT-Grundschutz (IT Baseline Protection) is the German Federal Office for Information Security's (BSI) comprehensive methodology for implementing and maintaining information security. Developed over three decades, it provides an extremely detailed, modular approach to security with hundreds of specific safeguards organized into process, system, and infrastructure modules. BSI certification based on IT-Grundschutz is considered the most rigorous form of ISO 27001 certification available.

What IT-Grundschutz Is and Who Issues It

IT-Grundschutz is issued by the Bundesamt für Sicherheit in der Informationstechnik (BSI) — the German Federal Office for Information Security, established in 1991. The BSI is an independent federal agency under the German Federal Ministry of the Interior, serving as the national authority on cybersecurity for German government, critical infrastructure, and the private sector. Its remit covers technical security standards, certification schemes, vulnerability coordination, and incident response support.

The BSI first published IT-Grundschutz (IT-Sicherheitshandbuch) in 1994, originally as a catalogue-based approach with hundreds of pages of specific technical recommendations for common IT configurations. Over thirty years of development, the framework has evolved significantly: the modern IT-Grundschutz framework (BSI Standards 200-series and the IT-Grundschutz Compendium) represents a complete redesign that aligns with ISO 27001 structure while preserving the depth and specificity that makes IT-Grundschutz distinctive.

The framework is published in German and English, making it accessible to international organizations. The BSI publishes the IT-Grundschutz Compendium as a free online resource (updated annually), and the BSI Standards are freely available as PDF downloads from bsi.bund.de. Certification is conducted by BSI-licensed certification bodies, not by the BSI itself.

IT-Grundschutz is not just a technical standard — it is Germany's primary information security policy instrument. Federal and state government agencies are required to implement IT-Grundschutz. Critical infrastructure operators in Germany are encouraged or required to align with it. The framework's depth and prescriptive guidance make it the reference point for German enterprise security discussions.

Who Needs IT-Grundschutz

German federal and state government agencies are required to implement IT-Grundschutz. All IT systems in federal government must be designed, implemented, and operated in accordance with IT-Grundschutz requirements. This mandatory status for government drives a large ecosystem of IT providers, system integrators, and consultants with IT-Grundschutz expertise in Germany.

Critical infrastructure operators in Germany under the BSI Act (BSIG) and IT Security Act 2.0 (IT-Sicherheitsgesetz 2.0) must meet security requirements that in practice align with or build upon IT-Grundschutz. Critical sectors — energy, water, transportation, digital infrastructure, finance, healthcare, and others — face regulatory scrutiny against IT-Grundschutz-aligned standards.

Defense contractors and companies handling government data who work with German federal or state agencies are frequently required by contract to demonstrate IT-Grundschutz compliance or BSI certification for systems handling government information.

Private-sector enterprises in Germany use IT-Grundschutz to demonstrate security maturity to government customers, meet contractual obligations, and satisfy NIS2 Directive requirements. German enterprise customers in financial services, manufacturing, healthcare, and professional services increasingly expect IT-Grundschutz alignment in their supply chains.

International organizations with German operations may pursue IT-Grundschutz certification to access the German market, particularly in public sector and large enterprise sales where government-aligned security practices are expected.

The Four BSI Standards in Depth

BSI Standard 200-1 — Information Security Management Systems BSI 200-1 defines requirements for establishing, implementing, operating, monitoring, reviewing, maintaining, and improving an ISMS. It is aligned with ISO/IEC 27001 requirements, enabling integration between the IT-Grundschutz approach and the ISO certification framework. Organizations certified under BSI IT-Grundschutz receive an ISO 27001 certificate based on IT-Grundschutz, confirming that the BSI methodology satisfies ISO 27001 requirements.

BSI Standard 200-2 — IT-Grundschutz Methodology The core methodology standard. BSI 200-2 describes the three approaches to IT-Grundschutz implementation:

  • Basis-Absicherung (Basic Protection): A rapid, essential security approach implementing the most critical safeguards from applicable Compendium modules quickly. Designed to give organizations a meaningful security baseline within weeks or months. Basis-Absicherung is the recommended starting point for organizations new to IT-Grundschutz or with limited security maturity.

  • Standard-Absicherung (Standard Protection): Full implementation of the recommended safeguards from all applicable Compendium modules. This is the comprehensive approach that BSI certification requires. It provides a thorough, module-by-module security implementation appropriate for organizations handling sensitive information or requiring formal certification.

  • Kern-Absicherung (Core Protection): Focuses first on the most critical business processes and their IT systems, rather than applying safeguards uniformly. Core Protection is suitable for organizations that need to prioritize security where it matters most due to resource or time constraints, building out to broader coverage over time.

BSI 200-2 also describes the IT-Grundschutz methodology process: structural analysis, protection needs assessment, modeling against the Compendium, basic security check, and risk analysis for residual gaps.

BSI Standard 200-3 — Risk Analysis BSI 200-3 complements the standard IT-Grundschutz approach with a structured risk analysis methodology for systems where the Compendium's standard safeguards are insufficient — either because the system is particularly sensitive or because specific risks require analysis beyond the module-based approach. BSI 200-3 provides a systematic process for identifying threats, estimating likelihood and impact, and determining appropriate risk treatment.

BSI Standard 200-4 — Business Continuity Management The newest addition to the 200-series, BSI 200-4 provides guidance for implementing a Business Continuity Management System (BCMS) aligned with the IT-Grundschutz approach and compatible with ISO 22301. It addresses emergency management, crisis response, and recovery planning.

The IT-Grundschutz Compendium in Depth

The IT-Grundschutz Compendium is the heart of the framework — the detailed, module-based control set that distinguishes IT-Grundschutz from any other security standard in its level of implementation specificity. The 2023 edition contains over 100 modules organized into two categories:

Process Modules (INF, ORG, CON, OPS, APP, SYS, NET, ISMS, DER): Address security governance, organizational practices, and security concepts:

  • ISMS: Information Security Management
  • ORP (Organization and Personnel): Security organization, personnel management
  • CON (Concepts and Procedures): Cryptography, data backup, patch management, software development
  • OPS (Operations): Proper IT administration, protection against malicious code, vulnerability management
  • DER (Detection and Response): Monitoring, security incidents, forensics, emergency management
  • APP: Application management (web applications, office products, identity systems)
  • SYS: IT systems (servers, clients, network components, industrial controls)
  • NET: Networks and communications
  • INF: Infrastructure (data centers, offices, industrial environments)
  • IND: Industrial IT

Each module follows a consistent structure:

  1. Description: What the module addresses and why it matters
  2. Threat overview: Relevant threats from the BSI Elementary Threats catalogue
  3. Requirements: Specific safeguards classified as Basic, Standard, or High requirements
  4. Further information: Implementation notes and references

The requirements structure is particularly valuable. Basic requirements apply to all organizations at all protection needs levels. Standard requirements represent the additional measures needed for standard protection needs. High requirements address elevated protection needs for particularly sensitive systems. This tiered structure enables proportionate implementation.

The IT-Grundschutz Methodology Process

Implementing IT-Grundschutz follows a defined methodology process:

Step 1 — Structural Analysis (Strukturanalyse) Document and categorize all IT systems, applications, communication connections, and infrastructure elements in scope. The structural analysis produces the IT structure documentation — an inventory of the IT landscape that provides the basis for all subsequent work.

Step 2 — Protection Needs Assessment (Schutzbedarfsfeststellung) For each information type and IT system identified in the structural analysis, determine the protection needs in terms of confidentiality, integrity, and availability. Protection needs are classified as Normal, High, or Very High. The protection needs assessment drives the scope of controls required — systems with Very High protection needs require more comprehensive controls than those with Normal needs.

Step 3 — Modeling (Modellierung) Map relevant IT-Grundschutz Compendium modules to each element of the IT structure. The BSI provides mapping guidance in BSI 200-2. Each IT system, application, and infrastructure element should be covered by appropriate modules. The modeling produces a complete list of modules that must be addressed and the specific requirements within each module that apply.

Step 4 — Basic Security Check (IT-Grundschutz Check) For each requirement in the mapped modules, assess whether it is fully implemented, partially implemented, not implemented, or not applicable. The basic security check produces a gap analysis identifying which requirements need implementation or improvement.

Step 5 — Risk Analysis (Risikoanalyse) For any gaps identified in the basic security check, and for systems with High or Very High protection needs where standard safeguards may be insufficient, conduct risk analysis per BSI 200-3. The risk analysis identifies residual risks and drives additional safeguard selection.

Step 6 — Safeguard Implementation and Consolidation Implement the required safeguards, documenting implementation evidence. Prioritize based on risk assessment and business impact.

The BSI Certification Process

BSI certification — formally "ISO 27001 certification based on IT-Grundschutz" — follows a more rigorous process than standard ISO 27001 certification:

BSI IS-Revision (IS Revision): A preliminary assessment that evaluates the organization's IT-Grundschutz implementation maturity. IS-Revision is conducted by BSI-licensed auditors and provides a readiness indicator before formal certification.

Stage 1 Audit: Document review assessing whether the ISMS and IT-Grundschutz documentation are complete and suitable for Stage 2.

Stage 2 Audit: On-site assessment by a BSI-licensed certification body auditor who specifically evaluates IT-Grundschutz implementation — testing the structural analysis, protection needs assessment, module mapping, basic security check, and risk analysis for completeness, accuracy, and consistent implementation.

Certification Decision: The certification body issues a recommendation; the BSI reviews and confirms. The resulting certificate states "ISO 27001 certified based on IT-Grundschutz" — a specific designation recognized differently from standard ISO 27001 by German government and enterprise buyers.

Annual Surveillance: Annual audits verify continued conformance. Full recertification every 3 years.

Costs and Timeline

ActivityTypical CostTimeline
IT-Grundschutz training (key staff)$5,000 – $15,0002–5 days per person
Structural analysis and protection needs assessment$10,000 – $30,0004–8 weeks
Compendium modeling and gap analysis$15,000 – $40,0004–8 weeks
Safeguard implementation$20,000 – $150,0002–6 months
IS-Revision readiness assessment$10,000 – $30,0002–4 weeks
Stage 1 and Stage 2 certification audit$20,000 – $60,0002–3 months
Annual surveillance audit$10,000 – $30,000Ongoing
Full certification program$30,000 – $250,0006–18 months

ISO 27001 (85% overlap): IT-Grundschutz and ISO 27001 are closely aligned — BSI has structured its framework to enable "ISO 27001 based on IT-Grundschutz" certification. IT-Grundschutz adds prescriptive, module-based implementation guidance that ISO 27001 does not provide. IT-Grundschutz is generally 20–40% more expensive and time-consuming than standard ISO 27001 due to the additional Compendium modeling and documentation requirements. However, the certification carries significantly more weight in German government and enterprise contexts.

C5 (Cloud Computing Compliance Criteria Catalogue) (55% overlap): The BSI's C5 scheme is IT-Grundschutz applied specifically to cloud service providers. C5 defines requirements for cloud services offered to German government and regulated-sector customers, building on IT-Grundschutz principles with cloud-specific additions. Organizations pursuing IT-Grundschutz certification may find C5 a natural extension if they operate cloud services.

ENS (Spanish National Security Framework) (contextual): The Spanish Esquema Nacional de Seguridad bears structural similarity to IT-Grundschutz as a national government security framework — both provide prescriptive, government-mandated security requirements more detailed than ISO 27001 alone. Organizations with operations in both Germany and Spain will encounter both frameworks.

For broader EU compliance considerations, see the SOC 2 guide for US-origin security assurance and the GDPR guide for data protection requirements applicable in Germany alongside IT-Grundschutz.

How Automation Helps

IT-Grundschutz implementation requires managing hundreds of module requirements, tracking implementation status across complex IT landscapes, maintaining structural analysis documentation as IT environments change, and coordinating evidence collection for annual audits. This documentation-intensive work is precisely where compliance automation provides the greatest return.

LowerPlane supports IT-Grundschutz and ISO 27001 within its 50+ framework library, providing control mapping, evidence management, and audit-ready reporting. Starting at $4,000 per year with a free tier, it is rated 9.4/10 by AuditXYZ users — particularly valued for managing the documentation burden of complex, multi-module frameworks like IT-Grundschutz. See the best compliance automation platforms comparison for detailed evaluation.

Frequently Asked Questions

Is IT-Grundschutz certification the same as ISO 27001 certification? Not exactly. "ISO 27001 certification based on IT-Grundschutz" is a specific designation that indicates the ISO 27001 management system was implemented using the IT-Grundschutz methodology — a higher bar than standard ISO 27001 certification. Buyers who understand the distinction place higher value on IT-Grundschutz-based certification. Standard ISO 27001 certificates from other methodologies are also valid but do not carry the IT-Grundschutz designation.

Can organizations outside Germany pursue IT-Grundschutz certification? Yes. IT-Grundschutz certification is available globally through BSI-licensed certification bodies. International organizations with German customers or operations, companies bidding for German government contracts, and organizations wanting to demonstrate German market security credibility can all pursue certification. The documentation and audit process is the same regardless of geography, though language considerations (documentation is ideally in German) can add complexity for non-German organizations.

How does the IT-Grundschutz Compendium get updated and how should organizations manage changes? The Compendium is updated annually. The BSI publishes change documentation noting which modules were added, revised, or deprecated. Organizations holding IT-Grundschutz certification must assess the impact of annual updates on their implementation and update their documentation accordingly. New modules may add requirements; revised modules may change implementation specifications. Annual surveillance audits assess whether the organization's implementation remains current with the applicable Compendium edition.

What is the difference between Basis-Absicherung and Standard-Absicherung and which is right for my organization? Basis-Absicherung implements the most critical safeguards quickly, providing meaningful security improvement rapidly. It is appropriate as a starting point or for organizations not pursuing formal BSI certification. Standard-Absicherung implements the full set of recommended safeguards and is required for BSI certification. Most organizations begin with Basis-Absicherung to establish a baseline, then progress to Standard-Absicherung as part of a certification programme.

Does IT-Grundschutz compliance satisfy NIS2 Directive requirements in Germany? IT-Grundschutz is widely recognized in Germany as an appropriate implementation path for NIS2 cybersecurity risk management requirements. Organizations subject to NIS2 (operators of essential services and important entities) can reference their IT-Grundschutz compliance in demonstrating security measure adequacy to the BSI, which serves as Germany's NIS2 competent authority for many sectors. However, NIS2 also has specific incident reporting and supply chain security requirements that IT-Grundschutz addresses only partially — a gap analysis against NIS2 is recommended for entities within scope.

Request a IT-Grundschutz consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

ISO 27001High85%
C5Medium55%

Related frameworks

Get matched with a IT-Grundschutz auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.