BSI IT-Grundschutz Consulting:
Security According to German Standards

Certification according to BSI IT-Grundschutz is an established way to elevate IT security measures to a robust standard—particularly relevant for public sector clients and their suppliers. At Mint Secure, we guide you through the entire process, from initial analysis to successful certification.

Request consultationAll consulting services
BSI Grundschutz
Certification

Foundation

BSI IT-Grundschutz Compendium

Approach

Module-based

Starting Point

Structural Analysis

Goal

Certification Readiness

When BSI IT-Grundschutz is the Right Choice

  • Public Sector Environment: You work for public sector clients or plan to, and proof of compliance with BSI IT-Grundschutz is required or expected.
  • Concrete Framework: You are looking for a structured, highly actionable entry point into information security rather than an abstract management standard.
  • NIS2 Compliance: NIS2 applies to you, and you want to implement the required measures along an established German framework.
  • ISO 27001 Complement: An existing ISO 27001 certification needs to be supplemented with more specific, German implementation guidelines.
  • Structure: An audit revealed that policies exist, but lack systematic alignment with specific modules and measures.

What BSI IT-Grundschutz Is

BSI IT-Grundschutz is a methodology developed by the Federal Office for Information Security (BSI) for establishing an Information Security Management System (ISMS). At its core is the IT-Grundschutz Compendium: a collection of modules for typical domains such as networks, servers, applications, organization, and personnel—each with concrete requirements rather than general principles.
This distinguishes BSI IT-Grundschutz from ISO 27001, which, as an international management standard, primarily provides the structure while leaving open how specific measures should look in practice. In practice, achieving certification according to BSI IT-Grundschutz also fulfills large parts of ISO 27001, as the certification builds directly upon ISO 27001.

Basic Protection

An initial, broad baseline protection across all domains, ideal as a starting point.

Core Protection

Focuses on the organization’s most critical assets and crown jewels.

Standard Protection

The most comprehensive level, required for full certification.

Which level makes sense depends on what your clients or specific situation actually require. Not every organization immediately needs full standard protection.

What We Do and What You Receive

Structural Analysis
Comprehensive overview of your information domain: systems, applications, facilities, and processes.

Protection Requirements Assessment
Evaluation of which assets are critical and what level of protection is appropriate.

Modeling
Mapping the relevant modules from the compendium to your information domain.

IT-Grundschutz Check
Target-vs-actual comparison to determine which module requirements are already met.

Risk Analysis
In-depth evaluation for areas where baseline protection alone is not sufficient.

Action Plan
Prioritized catalog of measures to close remaining security gaps.

Training & Enablement
Building internal team expertise for the ongoing maintenance of your security level.

Audit Support
Preparation for the certification audit and hands-on guidance throughout the assessment.

How the Consulting Process Works

1

Structural Analysis & Protection Requirements

We assess your information domain and evaluate which areas require which level of protection.

2

Modeling & Grundschutz Check

Mapping the appropriate modules and evaluating what is already fulfilled and where gaps remain.

3

Implementation

Hands-on support in closing identified gaps, prioritized by risk and effort.

4

Certification Audit

Preparation for the audit by an independent certification body accredited by the BSI. We prepare and assist you; the certification body issues the certificate.

How Long It Takes

An initial certification is a multi-month undertaking, not a weekend project:

  • Structural analysis and protection requirements assessment: a few weeks, depending on the size of the information domain.
  • Implementation to certification readiness: usually several months, depending on existing measures and the targeted level of protection.
  • Certification audit: performed by an accredited body, independent of our advisory services.
  • Maintenance: annual surveillance audits and recertification, typically every three years.

For basic protection, the process is noticeably shorter than for full standard protection. You will receive a realistic timeline estimate following the structural analysis.

BSI IT-Grundschutz Consulting

Tell us what leads you to certification. In an initial consultation, we clarify your target protection level and required effort.

  • Guidance from structural analysis to audit
  • Basic, core, or standard protection
  • Covers significant parts of ISO 27001 and NIS2
  • Prioritized catalog of measures

Frequently Asked Questions

As an entry point for many organizations, yes. Whether it is sufficient for your specific requirements—such as a public tender—is something we evaluate during the initial consultation based on your specific criteria.

Inquire Today Without Obligation

Tell us what leads you to certification and which level of protection fits your needs.

Book an appointmentSend an email