BSI IT-Grundschutz Compendium
BSI IT-Grundschutz Consulting:
Security According to German Standards
Certification according to BSI IT-Grundschutz is an established way to elevate IT security measures to a robust standard—particularly relevant for public sector clients and their suppliers. At Mint Secure, we guide you through the entire process, from initial analysis to successful certification.
Request consultationAll consulting servicesFoundation
Approach
Module-based
Starting Point
Structural Analysis
Goal
Certification Readiness
When BSI IT-Grundschutz is the Right Choice
- Public Sector Environment: You work for public sector clients or plan to, and proof of compliance with BSI IT-Grundschutz is required or expected.
- Concrete Framework: You are looking for a structured, highly actionable entry point into information security rather than an abstract management standard.
- NIS2 Compliance: NIS2 applies to you, and you want to implement the required measures along an established German framework.
- ISO 27001 Complement: An existing ISO 27001 certification needs to be supplemented with more specific, German implementation guidelines.
- Structure: An audit revealed that policies exist, but lack systematic alignment with specific modules and measures.
What BSI IT-Grundschutz Is
BSI IT-Grundschutz is a methodology developed by the Federal Office for Information Security (BSI) for establishing an Information Security Management System (ISMS). At its core is the IT-Grundschutz Compendium: a collection of modules for typical domains such as networks, servers, applications, organization, and personnel—each with concrete requirements rather than general principles.
This distinguishes BSI IT-Grundschutz from ISO 27001, which, as an international management standard, primarily provides the structure while leaving open how specific measures should look in practice. In practice, achieving certification according to BSI IT-Grundschutz also fulfills large parts of ISO 27001, as the certification builds directly upon ISO 27001.
Basic Protection
An initial, broad baseline protection across all domains, ideal as a starting point.
Core Protection
Focuses on the organization’s most critical assets and crown jewels.
Standard Protection
The most comprehensive level, required for full certification.
Which level makes sense depends on what your clients or specific situation actually require. Not every organization immediately needs full standard protection.
What We Do and What You Receive
Structural Analysis
Comprehensive overview of your information domain: systems, applications, facilities, and processes.
Protection Requirements Assessment
Evaluation of which assets are critical and what level of protection is appropriate.
Modeling
Mapping the relevant modules from the compendium to your information domain.
IT-Grundschutz Check
Target-vs-actual comparison to determine which module requirements are already met.
Risk Analysis
In-depth evaluation for areas where baseline protection alone is not sufficient.
Action Plan
Prioritized catalog of measures to close remaining security gaps.
Training & Enablement
Building internal team expertise for the ongoing maintenance of your security level.
Audit Support
Preparation for the certification audit and hands-on guidance throughout the assessment.
How the Consulting Process Works
Structural Analysis & Protection Requirements
We assess your information domain and evaluate which areas require which level of protection.
Modeling & Grundschutz Check
Mapping the appropriate modules and evaluating what is already fulfilled and where gaps remain.
Implementation
Hands-on support in closing identified gaps, prioritized by risk and effort.
Certification Audit
Preparation for the audit by an independent certification body accredited by the BSI. We prepare and assist you; the certification body issues the certificate.
How Long It Takes
An initial certification is a multi-month undertaking, not a weekend project:
- Structural analysis and protection requirements assessment: a few weeks, depending on the size of the information domain.
- Implementation to certification readiness: usually several months, depending on existing measures and the targeted level of protection.
- Certification audit: performed by an accredited body, independent of our advisory services.
- Maintenance: annual surveillance audits and recertification, typically every three years.
For basic protection, the process is noticeably shorter than for full standard protection. You will receive a realistic timeline estimate following the structural analysis.
BSI IT-Grundschutz Consulting
Tell us what leads you to certification. In an initial consultation, we clarify your target protection level and required effort.
- Guidance from structural analysis to audit
- Basic, core, or standard protection
- Covers significant parts of ISO 27001 and NIS2
- Prioritized catalog of measures
Frequently Asked Questions
Do you perform the certification yourselves?
No. We prepare you for the audit; the certificate is issued by an independent certification body accredited by the BSI.
BSI IT-Grundschutz or ISO 27001 – which is better?
There is no general hierarchy. BSI IT-Grundschutz is more prescriptive and widely used in Germany, especially across the public sector, while ISO 27001 is more recognized internationally. In most cases, the deciding factor is who requires compliance from you, rather than which standard is objectively better.
Is basic protection sufficient?
As an entry point for many organizations, yes. Whether it is sufficient for your specific requirements—such as a public tender—is something we evaluate during the initial consultation based on your specific criteria.
What if we already have security policies and measures in place?
In that case, we review which requirements of the modules are already fulfilled during the Grundschutz check, rather than starting from scratch.
Does this also make sense for small businesses?
Yes, the scope scales with the size of your information domain. Core protection focused on the most critical areas is often a realistic first step.
Does BSI IT-Grundschutz also cover NIS2?
A large portion of NIS2 requirements regarding technical and organizational measures can be systematically mapped through IT-Grundschutz modules. However, this does not replace the statutory applicability assessment and registration, for which we offer our [NIS2 Consulting](https://mint-secure.de/en/service-post/nis2-consulting/).
Inquire Today Without Obligation
Tell us what leads you to certification and which level of protection fits your needs.

