Grundschutz baseline, standard and core profiles, the BSI 200-series methodology, the Sicherheitskonzept, and a cross-mapping to ISO 27001 and NIS2, all on the same data model as the BCMS, DSMS and AIMS.
Bausteine (modules) pre-loaded
BSI 200-series standards covered (200-1 to 200-4)
Grundschutz, ISO 27001, NIS2 on the same data model
KaitoSec ships with the complete IT-Grundschutz-Kompendium structured as machine-readable Bausteine. Every module, requirement, and implementation hint is searchable, assignable, and linkable to your asset inventory. No manual copy-paste from PDFs.
BSI Standard 200-1 (ISMS management), 200-2 (IT-Grundschutz methodology), 200-3 (risk analysis), and 200-4 (business continuity) each have dedicated workflow templates. You follow the prescribed methodology step by step, with evidence captured at every stage. 200-4 lives in the same workspace as your ISO 22301 BCMS.
The Sicherheitskonzept is the central deliverable of any Grundschutz implementation. KaitoSec assembles it automatically from your completed Bausteine, risk decisions and residual risk documentation. Audit-ready, always current.
Many German organisations carry Grundschutz, ISO 27001 and NIS2 obligations in parallel. KaitoSec maintains bidirectional control mappings between all three. Evidence collected once feeds every framework it belongs to, so a single audit cycle defends three artefacts.
Assign Bausteine to your IT systems, applications, and infrastructure components. KaitoSec tracks implementation status per requirement, calculates your overall Grundschutz compliance score, and generates the Umsetzungsplan for certification.
KaitoSec guides you through the structured protection needs assessment for every asset, categorising requirements as normal, high, or very high. The analysis drives automatic Baustein selection and risk scope definition.
Many organisations must simultaneously demonstrate compliance with Grundschutz, ISO 27001, and NIS2. KaitoSec maintains bidirectional control mappings so evidence collected for one framework automatically contributes to the others.
Built on open catalogs: BSI, MITRE, OWASP, ENISA
Related platform features