Guide
IT-Grundschutz tools compared
From the end of GSTOOL to tool selection: open source or commercial, self-operated or managed, Grundschutz alone or one data model for four management systems.
What you'll learn
- Read the tool landscape after the end of GSTOOL
- Separate open-source tools from commercial ones by operating effort
- Apply five selection criteria for agencies, KRITIS and the Mittelstand
Why this question is open
The BSI ended support for its own GSTOOL and has since pointed to alternative tools whose vendors sign a licence agreement for the IT-Grundschutz-Kompendium. Since then, tool selection is a project decision of its own: open source or commercial, self-operated or managed, Grundschutz alone or one system for several management systems.
This guide sorts the four tools that sit next to each other most often in German selection processes.
The candidates
verinice: the open-source standard
verinice is the German ISMS tool from SerNet, open source under the AGPL and licensed by the BSI for the IT-Grundschutz methodology. The classic Java client is being replaced by verinice.veo, fully web-based and available as verinice.cloud or verinice.onprem, covering ISO 27001, IT-Grundschutz, data protection, NIS2, TISAX and BCM.
Two properties are unique to verinice in this line-up: the source code is public on GitHub, which satisfies procurement rules that require auditable software. And the classic client runs entirely offline, which matters in classified or air-gapped environments.
HiScout: enterprise GRC for large agencies
HiScout is a German enterprise GRC platform from Berlin, a subsidiary of HiSolutions AG since 2009. The GRC Suite covers Grundschutz, data protection, information security, BCM, audit management and classified-material protection and is widespread in large agencies and among KRITIS operators. It is built for organisations with thousands of assets and a dedicated GRC team.
eramba: open source without Grundschutz
eramba is an international open-source GRC platform that has been around since 2007. The community edition is free without user or data limits; advanced roles and larger automation are reserved for the enterprise edition, which starts at 2,500 euros a year self-hosted and 5,000 euros hosted. BSI IT-Grundschutz content and German-language advisory are missing: whoever wants Grundschutz models the Kompendium themselves.
KaitoSec: Grundschutz on one data model with BCMS, DSMS and AIMS
KaitoSec carries 110+ Bausteine of the Kompendium pre-loaded, the BSI 200-series from 200-1 to 200-4 and the security concept in one tool. The difference is the cut: Grundschutz, ISO 27001 and NIS2 sit on the same data model as the BCMS, the data protection and the AI management system. A requirement is implemented once and evidenced everywhere instead of being maintained four times in four systems. The machine-readable Bausteine are prepared for the transition to Grundschutz++.
It is built for lean security organisations: one ISO, one deputy and the people who own the processes, rather than a dedicated GRC department.
Free and open source: what that means in operation
Free means the same thing in every tool: licence costs disappear, the work stays. Modelling the information domain, maintaining the Kompendium across editions, operations, updates and permissions are your own work. For a team with technical depth and a tight budget, the eramba community edition is a price level no other vendor in this line-up publicly undercuts. For an ISO without an operations team, that same operation is the most expensive line of the calculation.
Source-code transparency and offline operation are requirements of their own, not side effects: in this line-up only verinice offers both, and KaitoSec offers neither.
Five selection criteria
- Certification goal and qualification level. Basis, Standard or Kern protection, and should ISO 27001 certification based on IT-Grundschutz stand at the end? The tool has to carry the 200-series methodically, not just list the Bausteine.
- Who maintains the Kompendium. Every edition changes Bausteine and requirements. Either the vendor ships the update, or your own team remodels.
- One system or four. Where ISMS, BCMS, data protection and AI governance are separate tools, the same control is maintained several times. A shared data model turns four maintenance efforts into one.
- Procurement and operating model. Source-code requirements, offline mandates, cloud permissions and the BSI licence list decide early which candidates are admissible at all.
- Team size. Enterprise tools assume a GRC department. Where one ISO carries the topic next to other roles, the tool has to lead the methodology, not merely record it.
The direct comparisons
For the detailed decision, this site carries reviewed head-to-head comparisons: KaitoSec vs. verinice, KaitoSec vs. HiScout and KaitoSec vs. eramba, each with a feature matrix and the points where the other tool is ahead.