BSI IT-Grundschutz: Complete Implementation Guide for 2026
August 19, 2026 · by Pentevo
What Is BSI IT-Grundschutz and Who Created It
BSI IT-Grundschutz — literally "IT baseline protection" — is Germany's national information security methodology, published and maintained by the Bundesamt für Sicherheit in der Informationstechnik (BSI), the Federal Office for Information Security. The BSI is Germany's central authority for cybersecurity, operating under the Federal Ministry of the Interior, and has been developing IT-Grundschutz since the early 1990s. What began as a catalog of generic security recommendations has evolved into a rigorous, internationally recognized framework that competes with ISO 27001 in depth and exceeds it in prescriptive detail.
The methodology is built around one central idea: instead of making every organization perform a full threat and vulnerability assessment from scratch, IT-Grundschutz provides pre-validated security safeguards organized into reusable building blocks. Organizations map their IT landscape to these building blocks, assess their specific protection needs, and implement the appropriate controls. The result is a documented, auditable Information Security Management System (ISMS) that is tailored to real-world infrastructure rather than abstract principles.
IT-Grundschutz is not optional for German federal agencies. The BSI mandates its application across the entire federal IT landscape, making it one of the few national cybersecurity frameworks that carries statutory weight. For private-sector organizations and international companies, it provides a rigorous benchmark that German government clients, critical infrastructure regulators, and enterprise procurement teams increasingly expect to see.
Core Methodology: The IT-Grundschutz Compendium and Building Blocks
The IT-Grundschutz Compendium is the living reference at the center of the framework. Updated annually, it contains all the building blocks — self-contained modules covering a specific technology, process, or organizational domain — that organizations use to model their security requirements. As of the 2023 edition, the Compendium contains over 100 building blocks organized into ten layers.
Each building block follows a consistent structure. It opens with a description of the scope and applicability, then lists threats and vulnerabilities relevant to that domain, followed by requirements divided into basic, standard, and high-protection levels. Requirements are labeled with a responsible role — the IT manager, the information security officer, the data center operator — so accountability is explicit. Finally, the building block references applicable standards, providing traceability to ISO 27001 controls, NIST guidance, and sector-specific regulations.
This structure makes IT-Grundschutz unusually actionable. Rather than reading a control statement like "implement secure configurations" and deriving implementation details independently, a security team can open the relevant building block and find specific, technology-aware requirements ready to assign, test, and document.
Three Protection Levels: Basic, Standard, and Core Protection
One of IT-Grundschutz's most practical features is that it does not impose a single implementation profile on all organizations. Instead, it defines three protection profiles that let organizations choose the approach that matches their current maturity, risk posture, and regulatory obligations.
Basic Protection (Basis-Absicherung) is the entry point for organizations that are beginning to formalize their information security programs. It requires implementing the foundational requirements from a prioritized subset of building blocks, focusing on the safeguards that deliver the highest risk reduction with the least complexity. Basic Protection does not lead to formal BSI certification, but it provides a documented starting state and a clear path forward. For smaller agencies or organizations with limited resources, it is a legitimate and recognized security posture.
Standard Protection (Standard-Absicherung) is the full implementation profile and the path to official BSI IT-Grundschutz certification. It requires applying all relevant building blocks to the complete information domain, conducting a protection needs assessment, performing risk analysis where standard safeguards are insufficient, and documenting the entire ISMS. Standard Protection is the level required for German federal agencies and the one that earns formal BSI recognition.
Core Protection (Kern-Absicherung) was introduced to address a common challenge: organizations that have a small number of extremely high-value assets that need maximum security immediately, while the broader IT landscape is still in early maturity. Core Protection focuses the full rigor of IT-Grundschutz on a defined, limited scope — a core set of crown-jewel systems or processes — before expanding coverage. It allows a fast, intensive security uplift where it matters most without waiting for organization-wide readiness.
BSI IT-Grundschutz vs ISO 27001
Both frameworks share the same ultimate goal — a structured, auditable ISMS — and the BSI explicitly recognizes this overlap. An IT-Grundschutz Certificate at the Standard Protection level is accepted as equivalent to ISO 27001 certification within the German public sector. Despite this, the two frameworks differ substantially in philosophy, effort model, and international standing.
| Dimension | BSI IT-Grundschutz | ISO 27001 |
|---|---|---|
| Scope | Prescriptive building blocks per technology/process | Principle-based; controls derived by organization |
| Certification body | BSI-licensed auditors; BSI issues certificate | Accredited certification bodies worldwide |
| Implementation effort | High upfront due to detailed documentation requirements | Flexible; organizations set their own control depth |
| International recognition | Strong in Germany and EU public sector | Global commercial and enterprise recognition |
| Control specificity | Technology-specific requirements per building block | Abstract control objectives in Annex A |
| Mandatory use | Required for German federal agencies and many KRITIS operators | Voluntary; market-driven adoption |
| Risk treatment | Integrated into protection needs assessment | Central to the framework from the start |
For organizations operating in Germany, the two frameworks are often used together: ISO 27001 provides the commercial credential that international clients recognize, while IT-Grundschutz provides the implementation detail and the credential that German government clients and regulators expect. Many organizations maintain a single ISMS that satisfies both.
The IT-Grundschutz Process
Implementing IT-Grundschutz follows a defined workflow that the BSI prescribes in detail. Understanding this process is essential before starting, because the documentation and evidence requirements are significant and must be planned for from the outset.
Structural Analysis is the first step. The organization inventories all IT systems, applications, networks, infrastructure components, and the business processes they support. This inventory is organized into groups of similar assets to make the subsequent modeling manageable. The output is a structured map of the entire information domain.
Protection Needs Assessment assigns each business process and information asset to one of three protection needs categories — normal, high, or very high — across the three classic security dimensions of confidentiality, integrity, and availability. This assessment is business-driven: the information security team works with process owners to understand what a breach of each dimension would mean for the organization. The results cascade from business processes down to the supporting IT systems.
Modeling maps each inventoried asset to the appropriate IT-Grundschutz building blocks from the Compendium. A web application server, for example, would be modeled using the APP.3.2 (Web Server) block, the SYS.1.1 (General Server) block, and relevant OPS and NET blocks. The modeling step produces the target control set for the organization.
Risk Assessment applies where standard building block requirements are insufficient — either because the protection needs assessment identified a very high classification, or because the organization's specific threat environment introduces risks not addressed by the standard safeguards. For these cases, a supplementary risk analysis is performed using the BSI's recommended threat catalog as a starting point.
Key Building Block Layers
The IT-Grundschutz Compendium organizes its building blocks into ten layers, each covering a distinct domain of the IT landscape:
ORP (Organization and Personnel) covers governance structures, roles and responsibilities, security policies, and personnel security — the organizational foundation without which technical controls cannot be effective.
CON (Concepts and Procedures) addresses cross-cutting security concepts such as cryptography, patch management, data backup, and information classification. These blocks apply across technology domains.
OPS (Operations) covers operational processes including incident management, change management, and outsourcing relationships. It bridges the gap between policy and day-to-day security practice.
APP (Applications) contains building blocks for specific application categories — web applications, email systems, databases, office software, and others — with requirements tailored to the security characteristics of each.
SYS (IT Systems) addresses individual system types: general servers, clients, mobile devices, virtualization platforms, and IoT systems, among others.
IND (Industrial IT) covers operational technology environments, including industrial control systems and SCADA infrastructure — a critical area given Germany's strong manufacturing sector and the regulatory requirements on KRITIS operators in the energy and utilities sectors.
NET (Networks and Communication) addresses network architecture, segmentation, firewall placement, remote access, and wireless networks.
INF (Infrastructure) covers physical security: data center design, cabling, power supply, and environmental controls.
For KRITIS operators, the IND, NET, and INF layers are particularly important, as critical infrastructure environments often involve complex OT/IT convergence that generic security frameworks handle poorly.
BSI Grundschutz Certificate vs ISO 27001 Certificate
The BSI issues IT-Grundschutz certificates through licensed auditors. There are two certificate types. An Audit Report (Testat) is an intermediate milestone that validates the ISMS documentation and implementation for a defined scope; it does not carry full certification status but demonstrates measurable progress. A full IT-Grundschutz Certificate confirms that the organization has implemented Standard Protection across the certified scope and has passed an on-site audit by a BSI-licensed auditor.
The certificate is valid for three years, with an interim review in year two. Maintaining certification requires continuous operation of the ISMS — not a point-in-time snapshot — which aligns with how effective security programs actually work.
For organizations already holding ISO 27001 certification, the BSI operates a formal mapping that can reduce the additional effort required to achieve IT-Grundschutz certification. Controls implemented for ISO 27001 Annex A are mapped to building block requirements, and evidence already gathered for the ISO audit can be reused where applicable.
Implementation Roadmap: Six-Phase Approach
Organizations new to IT-Grundschutz typically benefit from a structured phased approach that manages the complexity of the initial implementation.
Phase 1: Initiation and Scope Definition. Secure management commitment, define the ISMS scope, appoint an Information Security Officer (ISO), and establish the governance structure. Without executive sponsorship and a clear scope boundary, subsequent phases stall.
Phase 2: Structural Analysis. Inventory all assets within scope — business processes, information types, IT systems, applications, networks, and physical infrastructure. Group similar assets to keep the model manageable.
Phase 3: Protection Needs Assessment. Work with process owners to classify each asset against confidentiality, integrity, and availability. Establish the inheritance rules for cascading classifications from business processes to IT systems.
Phase 4: Modeling. Map each asset group to the appropriate building blocks from the Compendium. This produces the complete target control set and identifies any gaps against current practice.
Phase 5: Risk Assessment and Gap Remediation. For assets with very high protection needs or atypical threat profiles, perform supplementary risk analysis. Prioritize and implement the remediation measures identified in the gap analysis.
Phase 6: Audit and Certification. Commission a BSI-licensed auditor to perform the independent review. Prepare the required documentation package — security concept, implementation evidence, and ISMS records — and undergo the on-site assessment.
Who in Germany Requires IT-Grundschutz
German federal authorities are required by law to implement IT-Grundschutz under the BSI Act (BSIG). This obligation extends to IT service providers that operate federal systems. State-level agencies, while not subject to the federal mandate directly, typically adopt IT-Grundschutz as the de facto standard for public-sector IT.
Critical infrastructure operators — KRITIS — face overlapping obligations. The BSIG requires KRITIS operators to implement state-of-the-art security measures, and the BSI has published sector-specific security standards (B3S) that reference IT-Grundschutz building blocks extensively. Operators in the energy, water, health, transport, finance, and digital infrastructure sectors who fall above the KRITIS thresholds should treat IT-Grundschutz as a primary reference framework. For more on KRITIS obligations specifically, see our KRITIS compliance guide.
International organizations are increasingly affected. German enterprise procurement standards and public tender requirements often specify IT-Grundschutz or ISO 27001 compliance as a qualification criterion. Organizations supplying software or managed services to German federal agencies should expect to demonstrate ISMS maturity aligned with IT-Grundschutz.
Security teams managing vulnerability disclosure programs alongside their compliance posture should also review our PSIRT guide, as the OPS.1.1.3 building block on patch and vulnerability management intersects directly with how organizations run their security response programs.
Getting Started
BSI IT-Grundschutz rewards organizations that approach it as a genuine security program rather than a compliance exercise. The Compendium's building blocks encode decades of German public-sector security experience, and the protection needs assessment forces exactly the business-impact thinking that makes security decisions defensible to leadership.
For international security teams encountering IT-Grundschutz for the first time, the most practical starting point is the BSI's own IT-Grundschutz Compendium, available in German and increasingly in English summaries. Layer that with a gap analysis against your existing ISO 27001 controls, and you will quickly see which building blocks require net-new work and which can be satisfied by evidence you already hold.
The investment is front-loaded — the structural analysis and modeling phases are time-intensive — but the result is a security program documented at a level of detail that makes audits, incident response, and continuous improvement substantially more effective than a principles-only framework typically allows.
Frequently asked questions
What is BSI IT-Grundschutz?
BSI IT-Grundschutz is a comprehensive information security methodology developed by Germany's Federal Office for Information Security (BSI). It provides organizations with a structured, risk-based framework for establishing and maintaining an Information Security Management System (ISMS), combining standardized building blocks, protection needs categories, and three distinct security profiles to fit organizations of varying complexity and risk exposure.
How does BSI IT-Grundschutz compare to ISO 27001?
Both frameworks target ISMS implementation and are mutually recognized — an IT-Grundschutz Certificate at the standard level is accepted as equivalent to ISO 27001 certification by the BSI. The key difference is depth of prescriptive guidance: IT-Grundschutz provides detailed, pre-built building blocks covering specific technologies and processes, while ISO 27001 is principle-based and requires organizations to derive their own controls. IT-Grundschutz is mandatory for German federal agencies and KRITIS operators in many sectors; ISO 27001 has broader international commercial recognition.
What are the three protection levels in IT-Grundschutz?
IT-Grundschutz defines three protection profiles. Basic Protection (Basis-Absicherung) is an entry-level profile for organizations beginning their security journey, focusing on the most critical safeguards. Standard Protection (Standard-Absicherung) is the full profile that leads to official BSI certification and covers all relevant building blocks in depth. Core Protection (Kern-Absicherung) is a focused, high-intensity profile for organizations that need to secure a small, highly critical subset of assets — such as crown-jewel systems — before expanding scope.
Who needs BSI IT-Grundschutz certification?
BSI IT-Grundschutz certification is mandatory or strongly expected for German federal government agencies and their IT service providers, as well as for operators of critical infrastructure (KRITIS) in sectors including energy, water, transport, health, and finance. State-level agencies in Germany often follow the same requirement. International organizations that handle German government data, operate joint ventures with German public entities, or wish to demonstrate cybersecurity maturity to German enterprise clients increasingly pursue IT-Grundschutz or align their ISO 27001 programs with its building blocks.
Related reading
CVD Policy Template: How to Build a Responsible Disclosure Program
Step-by-step guide to creating a Coordinated Vulnerability Disclosure (CVD) policy: what to include, safe harbor language, response timelines, and a free policy template for your organization.
ComplianceDORA Compliance: Technical Requirements for Financial Institutions
A practical guide to DORA (Digital Operational Resilience Act): ICT risk management, incident classification, TLPT testing, third-party risk, and what financial firms must implement by January 2025.
Practice this hands-on
Pentevo Academy turns these concepts into guided lessons, videos and quizzes — free.
Start learning free