BSI IT-Grundschutz
Germany's structured methodology for building an ISMS.
What it is
Published by the German Federal Office for Information Security (BSI), IT-Grundschutz is a detailed methodology plus a large catalog of standard modules and safeguards. It is designed to be compatible with ISO/IEC 27001 — you can achieve "ISO 27001 certification on the basis of IT-Grundschutz."
Certifiable?
Yes — ISO 27001 certification via the IT-Grundschutz path.
Where it's used
Germany, especially public sector and regulated German organizations.
Effort level
Heavy and prescriptive; very thorough.
Typical trigger
German public-sector procurement or a regulator expects it.
Related frameworks
A German route to ISO 27001.
Why it matters
BSI IT-Grundschutz provides a highly detailed, prescriptive German methodology for building and certifying an ISMS. For organizations in the German public sector or KRITIS operators, it's often the expected path to demonstrating compliance.
When is it needed?
When serving German public sector clients, when operating critical infrastructure (KRITIS) in Germany, or when leadership wants the most thorough, prescriptive ISMS methodology available.
Use cases
- German public sector IT service providers
- KRITIS operators (energy, water, health, transport)
- Organizations seeking ISO 27001 via the BSI path
- German defense and government contractors
- Municipal and state-level digital services
Who asks for it?
- German federal and state agencies (Bundesbehörden)
- BSI (Federal Office for Information Security)
- KRITIS regulatory oversight bodies
- German public-sector procurement
- Insurance providers in the German market
Benefits
- Extremely thorough and prescriptive — less ambiguity
- Leads to ISO 27001 certification (BSI-based path)
- Well-suited for complex, large-scale IT environments
- Detailed module catalog covers hundreds of components
- Recognized and trusted in German government and industry
- Continuously maintained by BSI with annual updates
Legal requirements
Effectively mandatory for German KRITIS operators under BSI-KritisV and the IT Security Act 2.0. Public-sector procurement often requires BSI IT-Grundschutz certification.
Key control areas
Want to see how Compscan maps your environment to BSI IT-Grundschutz?