HomeFrameworksNational Cyber & Cloud SchemesIT-Grundschutz

Framework  National Cyber & Cloud Schemes

IT-Grundschutz

IT-Grundschutz is the German Federal Office for Information Security's (BSI) methodology and control catalog for building an information security management system.

It consists of the BSI Standards (200-1 on ISMS requirements, 200-2 on the IT-Grundschutz methodology with its basic, standard, and core protection approaches, 200-3 on risk analysis, and 200-4 on business continuity) and the IT-Grundschutz-Kompendium, a catalog of modules (Bausteine) covering processes, applications, systems, networks, and infrastructure, each with specific requirements.

The 2023 edition of the Kompendium, with 111 modules in ten layers, is the current certification basis while BSI develops its successor, Grundschutz++ (verify status on the BSI site).

IT-Grundschutz is compatible with ISO/IEC 27001 and the BSI issues an "ISO 27001 certificate on the basis of IT-Grundschutz", which is the standard expectation for German federal agencies and common in German critical infrastructure and public sector supply chains.

In writing, an organization following IT-Grundschutz needs the security policy and ISMS scope, a structure analysis of the information domain (assets, applications, systems, networks, rooms), protection requirement determinations, the modeling that assigns Kompendium modules to assets, the IT-Grundschutz check recording each requirement's implementation status, a risk analysis for assets with high protection needs, the implementation plan, and the usual management system records.

The BSI certificate requires an audit by a BSI-certified auditor and is valid for three years with annual surveillance.

AI-compiled
Share
Sponsored
IT-Grundsc
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with IT-Grundschutz
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

German federal agencies are required to follow it under the federal IT security guideline (UP Bund); voluntary elsewhere but widely required in German public sector procurement, by KRITIS operators as a recognized route under the BSI Act, and by German enterprises that prefer a BSI-branded certificate over a plain ISO/IEC 27001 certificate.

What the assessor asks to see

Security policy and ISMS scope; structure analysis and asset register; protection requirement determination; modeling of Kompendium modules to assets; IT-Grundschutz check results per requirement; risk analysis for high protection needs; implementation plan and status; documented procedures for modules in scope; awareness training records; incident and business continuity documentation (BSI 200-4); internal audit and management review; the auditor's report and BSI review correspondence.

Assessors

Who assesses IT-Grundschutz

Auditors certified by the BSI for ISO 27001 audits on the basis of IT-Grundschutz; the audit report is reviewed by the BSI, which issues the certificate. Plain ISO/IEC 27001 certification against IT-Grundschutz-aligned controls can also be obtained from accredited certification bodies, but only the BSI issues the IT-Grundschutz certificate.

Accredited by BSI (as certification body and auditor licensor) for the IT-Grundschutz certificate; DAkkS-accredited certification bodies for conventional ISO/IEC 27001 certificates.

Public register of assessors: https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Zertifizierung-und-Anerkennung/Zertifizierung-von-Managementsystemen/ISO-27001-Basis-IT-Grundschutz/ErteilteZertifikate/iso27001zertifikate_node.html

No firm has claimed a IT-Grundschutz assessor listing yet. Claim yours →

Consultants

Who helps with IT-Grundschutz

A large German consultancy market and dedicated ISMS tool vendors support IT-Grundschutz implementation; BSI also licenses IT-Grundschutz practitioners and consultants through training schemes. Engagements run one to two years for a first BSI certification of a substantial scope.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a IT-Grundschutz consultant listing yet. Claim yours →

Software

Tools for IT-Grundschutz

Tools that name this framework in their own material.

Related reading

  1. IT-Grundschutz: audits and ISMS certificationAudit body's account of the ISO 27001 on the basis of IT-Grundschutz certification route and what the auditor examines.TUViT
  2. Germany IT-Grundschutz workbookShows how the OPS.2.2 Cloud Usage module is applied to a cloud deployment, and who produced the underlying workbook.Microsoft

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for IT-Grundschutz

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with IT-Grundschutz

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.