IT-Grundschutz-Check
Carrying out the IT-Grundschutz-Check: from interview answer to a defensible status
Implementation status, justification, evidence and the open measure belong together. Otherwise the check remains a self-assessment.
8 minute read · Content as of 21.07.2026
Prepare interviews per target object
Interviewees should know which target objects and requirements are being considered. Existing evidence is collected beforehand; technical or physical statements are supplemented by spot checks and site inspections.
A status without a justification cannot be managed
Every requirement needs a traceable implementation status. Deviations are linked to cause, risk, measure, owner and due date. Requirements that are not relevant need a defensible justification.
- Separate interview statements from evidence
- Document the spot check and the check date
- Assign deviations unambiguously to a target object
- Prioritise and track measures
The free check starter is import-friendly
The CSV template uses unambiguous fields for module, requirement, target object, status, evidence and measure. That keeps a later move to an ISMS tool possible.
Sources used
- BSI Standard 200-2 · BSI · Version 1.0 · October 2017
- IT-Grundschutz Compendium · BSI · Edition 2022
- Grundschutz practice patterns · KaitoSec