Skip to content

BSI IT-Grundschutz

BSI IT-Grundschutz software for modelling, checks and certification

Basis, Standard and Kern protection approaches, the BSI 200-series methodology, the Sicherheitskonzept, and a cross-mapping to ISO 27001 and NIS2, all on the same data model as the BCMS, DSMS and AIMS.

Bausteine (modules) pre-loaded
110+
BSI 200-series standards covered (200-1 to 200-4)
4
Grundschutz, ISO 27001, NIS2 on the same data model
1 model
Machine-readable Bausteine, ready for the transition
Grundschutz++

One control, several standards

ISO 27001 certification based on IT-Grundschutz

Operate the detailed BSI methodology as ISMS software and connect approved safeguards to ISO 27001 and NIS2 where the requirements genuinely overlap. Each framework keeps its own scope and assessment logic.

One control, entered once, satisfies a requirement in each of the standards listed below.

One control

Supplier & third-party due diligence

  • BSI IT-GrundschutzRequirement satisfied
  • ISO 27001Requirement satisfied
  • NIS2Requirement satisfied
  • DORARequirement satisfied
  • TISAXRequirement satisfied

From control to policy

Structural analysis and modelling

Record the information domain, applications, systems, rooms, networks and dependencies, then apply the relevant Bausteine. The model remains connected to owners, risks and evidence.

One control feeds the four management systems, which in turn carry it into the policies and procedures listed below.

One control

Supplier & third-party due diligence

Management systems

  • BCMSBusiness continuity
  • ISMSInformation security
  • DSMSData protection
  • AIMSAI governance

Policies and procedures

  • Information security policy
  • Supplier policy
  • Continuity plan

The complete IT-Grundschutz Compendium

Use the Bausteine, requirements and implementation guidance as structured records instead of copying the Compendium from PDFs into a separate working file.

01

Native Grundschutz-Kompendium integration

KaitoSec ships with the complete IT-Grundschutz-Kompendium structured as machine-readable Bausteine. Every module, requirement, and implementation hint is searchable, assignable, and linkable to your asset inventory. No manual copy-paste from PDFs.

02

BSI 200-series methodology end to end

BSI Standard 200-1 (ISMS management), 200-2 (IT-Grundschutz methodology), 200-3 (risk analysis), and 200-4 (business continuity) each have dedicated workflow templates. You follow the prescribed methodology step by step, with evidence captured at every stage. 200-4 lives in the same workspace as your ISO 22301 BCMS.

03

Build the Sicherheitskonzept from accountable records

Bring completed modules, risk decisions and residual-risk documentation together as the basis of the Sicherheitskonzept. The approved, versioned state remains traceable for review.

04

One mapping, three audits served

Many German organisations carry Grundschutz, ISO 27001 and NIS2 obligations in parallel. KaitoSec maintains bidirectional control mappings between all three. Evidence collected once feeds every framework it belongs to. One preparation carries three audits.

Grundschutz Check and risk analysis under BSI 200-3

Document implementation status in the Grundschutz Check and carry risks that need additional analysis into risk management software for BSI 200-3, including treatment, owner and review date.

01

Track implementation per Baustein

Assign Bausteine to your IT systems, applications, and infrastructure components. KaitoSec tracks implementation status per requirement, shows your implementation level across the entire security concept, and generates the Umsetzungsplan for certification.

02

Schutzbedarfsfeststellung (Protection Needs Analysis)

KaitoSec guides the protection-needs assessment for every asset and documents classification as normal, high or very high. Relevant modules and the risk scope are suggested for review.

03

Cross-Mapping to ISO 27001 and NIS2

Map Grundschutz, ISO 27001 and NIS2 to the same controls where requirements genuinely align. Approved evidence can then be reused without hiding differences between the frameworks.

Frequently asked questions about BSI IT-Grundschutz

Which software is suitable for BSI IT-Grundschutz?

BSI IT-Grundschutz software must represent the Compendium with all its Bausteine and support structural analysis, protection-needs assessment, modelling, the Grundschutz Check and risk analysis under BSI 200-3. KaitoSec covers all six phases and uses migration to import existing registers from Excel, verinice or HiScout. Our BSI IT-Grundschutz starter guide walks through all six phases in order.

What is the difference between Basic, Standard and Core Protection?

Basic Protection implements only the basic requirements; Standard Protection is the route to an ISO 27001 certificate based on IT-Grundschutz, while Core Protection focuses on the most critical assets. KaitoSec lets you choose the approach for each information domain.

How does modelling work in IT-Grundschutz?

In IT-Grundschutz modelling, the relevant Compendium Bausteine are assigned to the target objects from the structural analysis. The KaitoSec agent proposes the mapping and reports unmodelled Bausteine as findings, as shown in the import demo.

Is KaitoSec an alternative to verinice and HiScout?

Yes. KaitoSec imports exports from both tools and retains target objects, Bausteine and status. The tool comparison explains what changes when you switch, and migration describes the process. This comparison of IT-Grundschutz tools goes deeper on verinice and HiScout specifically.

What does Grundschutz++ mean, and is KaitoSec prepared for it?

Grundschutz++ is the BSI's machine-readable evolution of IT-Grundschutz. KaitoSec works with OSCAL-based catalogues and is therefore designed for machine-readable requirements, which is particularly relevant for municipalities moving from WiBA to Grundschutz++.

Alternatives to verinice and HiScout

Compare methodology depth, operating model, migration paths and cross-framework work directly. The comparison pages state where each product differs instead of hiding the trade-offs.

Connect IT-Grundschutz with ISO 27001 and NIS2

Connect your Grundschutz programme to ISO 27001, NIS2 and the frameworks that reuse its approved safeguards and evidence.