Skip to content

Grundschutz++ - Digital Transformation of IT-Grundschutz

Grundschutz++ is the comprehensive modernization of the established IT-Grundschutz of Germany’s Federal Office for Information Security (BSI). Starting January 1, 2026, the current PDF- and Excel-based compendium will be replaced by a largely digitized, process-oriented, and machine-readable version.

Why is Grundschutz++ relevant?
Digital transformation brings new technologies such as cloud services, artificial intelligence (AI), and the Internet of Things (IoT), creating new security requirements and threat scenarios. At the same time, demand is rising for automated compliance processes and better integration into existing ISMS tools. Grundschutz++ addresses these challenges with a fundamentally modernized approach that preserves proven Grundschutz principles while making their application significantly simpler and more flexible.

Machine-readable format as a paradigm shift

Section titled “Machine-readable format as a paradigm shift”

The biggest change in Grundschutz++ is the switch from static PDF and Excel documents to a machine-readable format based on the Open Security Controls Assessment Language (OSCAL). This transformation enables:

  • Automated compliance checks via direct tool integration
  • Consistent data quality through a single source of truth
  • Dynamic updates without manual transfer errors
  • API-based integration into existing ISMS landscapes
  • Real-time synchronization between BSI specifications and organizational tools

Pro tip: BSI will continue to provide Excel exports generated directly from OSCAL data. However, organizations should move early to OSCAL/JSON-compatible tools to realize the full benefits of digitization.

OSCAL (Open Security Controls Assessment Language) is a NIST-developed standard for the structured modeling of:

  • Security requirements and controls
  • Compliance information and assessment results
  • Risk evaluations and remediation plans
  • System security plans and authorization documents

Its JSON structure allows tool vendors and users to access BSI source data directly and integrate it seamlessly into their security architectures.

Conceptual innovations and structural change

Section titled “Conceptual innovations and structural change”

From rigid building blocks to flexible practices:
Grundschutz++ replaces the former “building blocks” with practices—reusable processes or security measures that can be flexibly combined and adapted to specific organizational structures.

Standardized sentence templates ensure clarity and consistency:

{Practice} [for {Target Object}] {MODAL VERB} <Result> {Action Word}

Example:

  • Practice: “Backup procedure”
  • Target object: “critical business data”
  • Modal verb: “MUST”
  • Result: “restorable copies”
  • Action word: “create”

“Backup procedure for critical business data MUST create restorable copies.”

Hierarchical implementation prioritization

Section titled “Hierarchical implementation prioritization”

Grundschutz++ introduces a six-level prioritization model (Levels 0–5):

  • Mandatory requirements for ISO 27001 compatibility
  • Fundamental governance practices
  • Legal minimum requirements
  • Immediately actionable measures
  • Low cost, high security impact
  • Awareness and sensitization
  • Policies and procedure documentation
  • Basic technical safeguards
  • Initial monitoring implementations

Level 3: Mid-term projects (~1 month effort)

Section titled “Level 3: Mid-term projects (~1 month effort)”
  • Comprehensive technical implementations
  • Process optimization and automation
  • Advanced monitoring and detection systems

Level 4: Long-term transformations (~1 quarter effort)

Section titled “Level 4: Long-term transformations (~1 quarter effort)”
  • Structural organizational changes
  • Complex technical infrastructure projects
  • Comprehensive integration and harmonization
  • Additional requirements for critical infrastructures
  • Specialized security measures
  • Enhanced monitoring and response capabilities

Pro tip: Always begin with Level 0 and work through the levels systematically. This prioritization enables you to quickly achieve a solid security baseline even with limited resources.

Key performance indicators (KPIs) for measurable security

Section titled “Key performance indicators (KPIs) for measurable security”

Quantifying security gains:
Each requirement in Grundschutz++ receives three indicators aligned with the classic security objectives:

  • C (Confidentiality): protection against unauthorized disclosure
  • I (Integrity): protection against unauthorized modification
  • A (Availability): protection against outages or impairment
  • Point values show how strongly a measure reduces the respective risk
  • Summation of all implemented measures yields the overall score
  • Thresholds define the desired security level
  • Objective measurability of ISMS fulfillment
  • Resource optimization: focus on measures with the best cost–benefit ratio
  • Continuous improvement: systematic identification of security gaps
  • Stakeholder communication: objective presentation of the security level
  • Benchmark comparisons: positioning against industry standards

Pro tip: Use the indicators to drive a data-driven security strategy. Define organization-specific thresholds and track their development over time.

Grundschutz++ is designed to seamlessly harmonize with ISO 27001:

  • Control mapping: direct mapping of Grundschutz++ practices to ISO 27001 controls
  • Annex A compatibility: full coverage of ISO 27001 Annex A requirements
  • ISMS process integration: harmonized governance cycles
  • Audit synergy: joint assessment cycles for both standards
  • Reduced effort for dual certifications
  • Consistent documentation for both standards
  • Unified risk assessment methodology
  • Shared KPI dashboards

The new architecture enables flexible integration of additional compliance catalogs:

  • KRITIS extensions for critical infrastructures
  • NIS2 compliance (EU)
  • C5 attestation for cloud security
  • Cloud security modules
  • AI security for AI/ML systems
  • IoT security for connected devices

Pro tip: Plan your ISMS architecture modularly so you can integrate future compliance requirements without changing the core structure.

Continuity despite revolution:
Despite all the technical and structural innovations, the proven IT-Grundschutz methodology remains fundamentally unchanged:

  1. Define scope

    • Define business processes to be protected
    • Delimit IT systems and applications
    • Consider cloud and hybrid infrastructures
  2. Conduct structural analysis

    • Record all target objects and their dependencies
    • Map data flows and system interactions
    • Document the IT architecture
  3. Determine protection requirements

    • Assess the criticality of information and systems
    • Classify by confidentiality, integrity, and availability
    • Consider regulatory requirements
  4. Model with Grundschutz++

    • Select and configure relevant practices
    • Tailor to organizational specifics
    • Integrate additional compliance modules
  5. Grundschutz check

    • Systematically verify implementation
    • Evaluate using KPIs
    • Identify implementation gaps
  6. Risk analysis

    • Assess residual risks
    • Define additional measures
    • Document risk acceptance decisions

Pro tip: Use the continuity of the methodology as the basis for your transformation. Existing processes can largely remain and be supplemented with new digital tools.

1. Establish project team and governance

  • Strengthen the ISO/ISB role: clear assignment of information security responsibilities
  • Cross-functional teams: integrate IT, compliance, risk management, and business
  • Change management: prepare the organization for the paradigm shift
  • Budget planning: allocate resources for tools, training, and external support

2. Build technical prerequisites

  • OSCAL/JSON competence: train teams on the new data formats
  • Tool evaluation: assess OSCAL-compatible ISMS solutions
  • API integration: prepare IT infrastructure for automated data flows
  • Backup strategies: ensure continuity during migration

3. Rethink scope and architecture

  • Cloud-first approach: adapt structural analysis to modern IT architectures
  • Process orientation: shift from object- to process-centric views
  • Modular planning: prepare for future compliance extensions

Phase 1: Foundation (Q4 2025)

  • Select and implement tools
  • Train and certify the team
  • Analyze and prepare existing documentation
  • Identify pilot areas for initial testing

Phase 2: Core migration (Q1–Q2 2026)

  • Fully implement Level 0 requirements
  • Systematically deliver quick wins (Level 1)
  • Establish and measure KPI baselines
  • Perform initial compliance checks

Phase 3: Optimization (Q3–Q4 2026)

  • Implement Levels 2–4 by priority and resources
  • Establish continuous improvement processes
  • Integrate extended modules (KRITIS, NIS2)
  • Prepare for audits and certification

Phase 4: Continuous improvement (from 2027)

  • Regular KPI reviews and optimizations
  • Integrate new BSI modules and updates
  • Benchmarking and best-practice sharing
  • Strategic development of the ISMS

Methodological shift:

  • From object- to process-oriented: focus on end-to-end business processes
  • Dynamic risk assessment: continuous adaptation to changing threats
  • Integrated compliance: harmonize multiple regulatory requirements
  • Quantitative metrics: use KPIs for objective risk quantification

Data-driven decisions:

  • Establish baselines: define organization-specific security goals
  • Continuous monitoring: real-time tracking of security indicators
  • Trend analysis: identify patterns of improvement or deterioration
  • Optimize ROI: prioritize measures with the best security ROI

Pro tip: Use KPIs not only for compliance but as a strategic instrument for continually optimizing your security architecture. Define organization-specific thresholds and establish regular review cycles.

The fuentis Suite is ready for Grundschutz++ and provides comprehensive support:

  • Native OSCAL support: direct processing of BSI JSON data structures
  • Automatic updates: synchronization with BSI releases without manual intervention
  • API-based integration: seamless connection to existing IT service management tools
  • Version control: full traceability of changes and updates
  • End-to-end process mapping
  • KPI dashboard: real-time monitoring of C/I/A indicators
  • Dynamic risk evaluation
  • Threshold management: configurable alerts and escalations
  • Central CMDB
  • Dependency mapping: visualize system dependencies and data flows
  • Cloud integration: support for hybrid and multi-cloud environments
  • IoT device management
  • Multi-standard support: Grundschutz++, ISO 27001, NIS2, KRITIS
  • SoA generator: automated Statement of Applicability
  • Gap analysis and maturity scoring
  • Audit trail: end-to-end change tracking
  • Grundschutz check automation
  • KPI calculation and scoring
  • Report generation: standardized and custom compliance reports
  • Stakeholder dashboards: role-based views
  • SIEM integration
  • Ticketing connectors for service workflows
  • Business intelligence export
  • Mobile-first design
  • Dual compliance with minimal overhead
  • Control mapping between Grundschutz++ practices and ISO controls
  • Shared governance: integrated management reviews and audit cycles
  • Aligned risk treatment
  • CSF compatibility
  • OSCAL synergy through shared data structures
  • Maturity model alignment
  • NIS2 readiness
  • GDPR integration
  • Digital operational resilience: alignment with DORA for the financial sector
  1. Digital revolution from 2026: Grundschutz++ replaces the PDF-based compendium with a machine-readable OSCAL/JSON format enabling automated compliance and seamless tool integration.
  2. Process-oriented modernization: New modular structure with practices instead of building blocks, standardized sentence templates, and a six-level prioritization increases flexibility and efficiency.
  3. Measurable security via KPIs: Each requirement is linked to C/I/A indicators enabling objective measurement and data-driven optimization.
  4. Seamless ISO 27001 integration: Designed for maximum harmonization, enabling dual compliance with minimal additional effort and joint audit cycles.
  5. Early preparation is essential: Organizations should begin strategic preparations in 2025, as migration is not automatic and requires training and tool adjustments.