Skip to content
08/14StandardOn roadmap

BSI IT-Grundschutz

Germany's structured methodology for building an ISMS.

What it is

Published by the German Federal Office for Information Security (BSI), IT-Grundschutz is a detailed methodology plus a large catalog of standard modules and safeguards. It is designed to be compatible with ISO/IEC 27001 — you can achieve "ISO 27001 certification on the basis of IT-Grundschutz."

Certifiable?

Yes — ISO 27001 certification via the IT-Grundschutz path.

Where it's used

Germany, especially public sector and regulated German organizations.

Effort level

Heavy and prescriptive; very thorough.

Typical trigger

German public-sector procurement or a regulator expects it.

Related frameworks

A German route to ISO 27001.

Why it matters

BSI IT-Grundschutz provides a highly detailed, prescriptive German methodology for building and certifying an ISMS. For organizations in the German public sector or KRITIS operators, it's often the expected path to demonstrating compliance.

When is it needed?

When serving German public sector clients, when operating critical infrastructure (KRITIS) in Germany, or when leadership wants the most thorough, prescriptive ISMS methodology available.

Use cases

  • German public sector IT service providers
  • KRITIS operators (energy, water, health, transport)
  • Organizations seeking ISO 27001 via the BSI path
  • German defense and government contractors
  • Municipal and state-level digital services

Who asks for it?

  • German federal and state agencies (Bundesbehörden)
  • BSI (Federal Office for Information Security)
  • KRITIS regulatory oversight bodies
  • German public-sector procurement
  • Insurance providers in the German market

Benefits

  • Extremely thorough and prescriptive — less ambiguity
  • Leads to ISO 27001 certification (BSI-based path)
  • Well-suited for complex, large-scale IT environments
  • Detailed module catalog covers hundreds of components
  • Recognized and trusted in German government and industry
  • Continuously maintained by BSI with annual updates

Legal requirements

Effectively mandatory for German KRITIS operators under BSI-KritisV and the IT Security Act 2.0. Public-sector procurement often requires BSI IT-Grundschutz certification.

Key control areas

ISMS process modules (policy, risk, organization)
Infrastructure modules (buildings, data centers, cabling)
IT systems modules (servers, clients, mobile, IoT)
Networks modules (network architecture, firewalls, VPN)
Applications modules (web apps, databases, email)
Industrial IT / OT modules

Want to see how Compscan maps your environment to BSI IT-Grundschutz?