Grundschutz++ - Digital Transformation of IT-Grundschutz
Grundschutz++ is the comprehensive modernization of the established IT-Grundschutz of Germany’s Federal Office for Information Security (BSI). Starting January 1, 2026, the current PDF- and Excel-based compendium will be replaced by a largely digitized, process-oriented, and machine-readable version.
Why is Grundschutz++ relevant?
Digital transformation brings new technologies such as cloud services, artificial intelligence (AI), and the Internet of Things (IoT), creating new security requirements and threat scenarios. At the same time, demand is rising for automated compliance processes and better integration into existing ISMS tools. Grundschutz++ addresses these challenges with a fundamentally modernized approach that preserves proven Grundschutz principles while making their application significantly simpler and more flexible.
The Revolution: From PDF to OSCAL/JSON
Section titled “The Revolution: From PDF to OSCAL/JSON”Machine-readable format as a paradigm shift
Section titled “Machine-readable format as a paradigm shift”The biggest change in Grundschutz++ is the switch from static PDF and Excel documents to a machine-readable format based on the Open Security Controls Assessment Language (OSCAL). This transformation enables:
- Automated compliance checks via direct tool integration
- Consistent data quality through a single source of truth
- Dynamic updates without manual transfer errors
- API-based integration into existing ISMS landscapes
- Real-time synchronization between BSI specifications and organizational tools
Pro tip: BSI will continue to provide Excel exports generated directly from OSCAL data. However, organizations should move early to OSCAL/JSON-compatible tools to realize the full benefits of digitization.
Technical foundations of OSCAL
Section titled “Technical foundations of OSCAL”OSCAL (Open Security Controls Assessment Language) is a NIST-developed standard for the structured modeling of:
- Security requirements and controls
- Compliance information and assessment results
- Risk evaluations and remediation plans
- System security plans and authorization documents
Its JSON structure allows tool vendors and users to access BSI source data directly and integrate it seamlessly into their security architectures.
Conceptual innovations and structural change
Section titled “Conceptual innovations and structural change”Modular, process-oriented architecture
Section titled “Modular, process-oriented architecture”From rigid building blocks to flexible practices:
Grundschutz++ replaces the former “building blocks” with practices—reusable processes or security measures that can be flexibly combined and adapted to specific organizational structures.
New requirement structure
Section titled “New requirement structure”Standardized sentence templates ensure clarity and consistency:
{Practice} [for {Target Object}] {MODAL VERB} <Result> {Action Word}Example:
- Practice: “Backup procedure”
- Target object: “critical business data”
- Modal verb: “MUST”
- Result: “restorable copies”
- Action word: “create”
→ “Backup procedure for critical business data MUST create restorable copies.”
Hierarchical implementation prioritization
Section titled “Hierarchical implementation prioritization”Grundschutz++ introduces a six-level prioritization model (Levels 0–5):
Level 0: Mandatory foundations
Section titled “Level 0: Mandatory foundations”- Mandatory requirements for ISO 27001 compatibility
- Fundamental governance practices
- Legal minimum requirements
Level 1: Quick wins (~1 day effort)
Section titled “Level 1: Quick wins (~1 day effort)”- Immediately actionable measures
- Low cost, high security impact
- Awareness and sensitization
Level 2: Short projects (~1 week effort)
Section titled “Level 2: Short projects (~1 week effort)”- Policies and procedure documentation
- Basic technical safeguards
- Initial monitoring implementations
Level 3: Mid-term projects (~1 month effort)
Section titled “Level 3: Mid-term projects (~1 month effort)”- Comprehensive technical implementations
- Process optimization and automation
- Advanced monitoring and detection systems
Level 4: Long-term transformations (~1 quarter effort)
Section titled “Level 4: Long-term transformations (~1 quarter effort)”- Structural organizational changes
- Complex technical infrastructure projects
- Comprehensive integration and harmonization
Level 5: Elevated protection needs
Section titled “Level 5: Elevated protection needs”- Additional requirements for critical infrastructures
- Specialized security measures
- Enhanced monitoring and response capabilities
Pro tip: Always begin with Level 0 and work through the levels systematically. This prioritization enables you to quickly achieve a solid security baseline even with limited resources.
Key performance indicators (KPIs) for measurable security
Section titled “Key performance indicators (KPIs) for measurable security”Quantifying security gains:
Each requirement in Grundschutz++ receives three indicators aligned with the classic security objectives:
- C (Confidentiality): protection against unauthorized disclosure
- I (Integrity): protection against unauthorized modification
- A (Availability): protection against outages or impairment
How the indicators work
Section titled “How the indicators work”- Point values show how strongly a measure reduces the respective risk
- Summation of all implemented measures yields the overall score
- Thresholds define the desired security level
- Objective measurability of ISMS fulfillment
Practical benefits
Section titled “Practical benefits”- Resource optimization: focus on measures with the best cost–benefit ratio
- Continuous improvement: systematic identification of security gaps
- Stakeholder communication: objective presentation of the security level
- Benchmark comparisons: positioning against industry standards
Pro tip: Use the indicators to drive a data-driven security strategy. Define organization-specific thresholds and track their development over time.
Integration and harmonization
Section titled “Integration and harmonization”Stronger ISO 27001 compatibility
Section titled “Stronger ISO 27001 compatibility”Grundschutz++ is designed to seamlessly harmonize with ISO 27001:
Structural alignment
Section titled “Structural alignment”- Control mapping: direct mapping of Grundschutz++ practices to ISO 27001 controls
- Annex A compatibility: full coverage of ISO 27001 Annex A requirements
- ISMS process integration: harmonized governance cycles
- Audit synergy: joint assessment cycles for both standards
Practical advantages
Section titled “Practical advantages”- Reduced effort for dual certifications
- Consistent documentation for both standards
- Unified risk assessment methodology
- Shared KPI dashboards
Modular extensibility
Section titled “Modular extensibility”The new architecture enables flexible integration of additional compliance catalogs:
Available and planned modules
Section titled “Available and planned modules”- KRITIS extensions for critical infrastructures
- NIS2 compliance (EU)
- C5 attestation for cloud security
- Cloud security modules
- AI security for AI/ML systems
- IoT security for connected devices
Pro tip: Plan your ISMS architecture modularly so you can integrate future compliance requirements without changing the core structure.
Proven methodology remains
Section titled “Proven methodology remains”Continuity despite revolution:
Despite all the technical and structural innovations, the proven IT-Grundschutz methodology remains fundamentally unchanged:
The six phases of IT-Grundschutz
Section titled “The six phases of IT-Grundschutz”-
Define scope
- Define business processes to be protected
- Delimit IT systems and applications
- Consider cloud and hybrid infrastructures
-
Conduct structural analysis
- Record all target objects and their dependencies
- Map data flows and system interactions
- Document the IT architecture
-
Determine protection requirements
- Assess the criticality of information and systems
- Classify by confidentiality, integrity, and availability
- Consider regulatory requirements
-
Model with Grundschutz++
- Select and configure relevant practices
- Tailor to organizational specifics
- Integrate additional compliance modules
-
Grundschutz check
- Systematically verify implementation
- Evaluate using KPIs
- Identify implementation gaps
-
Risk analysis
- Assess residual risks
- Define additional measures
- Document risk acceptance decisions
Pro tip: Use the continuity of the methodology as the basis for your transformation. Existing processes can largely remain and be supplemented with new digital tools.
Preparation and implementation strategies
Section titled “Preparation and implementation strategies”Strategic preparation
Section titled “Strategic preparation”Organizational readiness
Section titled “Organizational readiness”1. Establish project team and governance
- Strengthen the ISO/ISB role: clear assignment of information security responsibilities
- Cross-functional teams: integrate IT, compliance, risk management, and business
- Change management: prepare the organization for the paradigm shift
- Budget planning: allocate resources for tools, training, and external support
2. Build technical prerequisites
- OSCAL/JSON competence: train teams on the new data formats
- Tool evaluation: assess OSCAL-compatible ISMS solutions
- API integration: prepare IT infrastructure for automated data flows
- Backup strategies: ensure continuity during migration
3. Rethink scope and architecture
- Cloud-first approach: adapt structural analysis to modern IT architectures
- Process orientation: shift from object- to process-centric views
- Modular planning: prepare for future compliance extensions
Implementation approach
Section titled “Implementation approach”Phased migration
Section titled “Phased migration”Phase 1: Foundation (Q4 2025)
- Select and implement tools
- Train and certify the team
- Analyze and prepare existing documentation
- Identify pilot areas for initial testing
Phase 2: Core migration (Q1–Q2 2026)
- Fully implement Level 0 requirements
- Systematically deliver quick wins (Level 1)
- Establish and measure KPI baselines
- Perform initial compliance checks
Phase 3: Optimization (Q3–Q4 2026)
- Implement Levels 2–4 by priority and resources
- Establish continuous improvement processes
- Integrate extended modules (KRITIS, NIS2)
- Prepare for audits and certification
Phase 4: Continuous improvement (from 2027)
- Regular KPI reviews and optimizations
- Integrate new BSI modules and updates
- Benchmarking and best-practice sharing
- Strategic development of the ISMS
Risk-based implementation
Section titled “Risk-based implementation”Process-oriented risk analysis
Section titled “Process-oriented risk analysis”Methodological shift:
- From object- to process-oriented: focus on end-to-end business processes
- Dynamic risk assessment: continuous adaptation to changing threats
- Integrated compliance: harmonize multiple regulatory requirements
- Quantitative metrics: use KPIs for objective risk quantification
KPI-driven steering
Section titled “KPI-driven steering”Data-driven decisions:
- Establish baselines: define organization-specific security goals
- Continuous monitoring: real-time tracking of security indicators
- Trend analysis: identify patterns of improvement or deterioration
- Optimize ROI: prioritize measures with the best security ROI
Pro tip: Use KPIs not only for compliance but as a strategic instrument for continually optimizing your security architecture. Define organization-specific thresholds and establish regular review cycles.
Support with the fuentis Suite
Section titled “Support with the fuentis Suite”The fuentis Suite is ready for Grundschutz++ and provides comprehensive support:
OSCAL/JSON integration
Section titled “OSCAL/JSON integration”- Native OSCAL support: direct processing of BSI JSON data structures
- Automatic updates: synchronization with BSI releases without manual intervention
- API-based integration: seamless connection to existing IT service management tools
- Version control: full traceability of changes and updates
Process-oriented risk management
Section titled “Process-oriented risk management”- End-to-end process mapping
- KPI dashboard: real-time monitoring of C/I/A indicators
- Dynamic risk evaluation
- Threshold management: configurable alerts and escalations
Asset and target object management
Section titled “Asset and target object management”- Central CMDB
- Dependency mapping: visualize system dependencies and data flows
- Cloud integration: support for hybrid and multi-cloud environments
- IoT device management
Modular compliance management
Section titled “Modular compliance management”- Multi-standard support: Grundschutz++, ISO 27001, NIS2, KRITIS
- SoA generator: automated Statement of Applicability
- Gap analysis and maturity scoring
- Audit trail: end-to-end change tracking
Automated assessment workflows
Section titled “Automated assessment workflows”- Grundschutz check automation
- KPI calculation and scoring
- Report generation: standardized and custom compliance reports
- Stakeholder dashboards: role-based views
Integration and interoperability
Section titled “Integration and interoperability”- SIEM integration
- Ticketing connectors for service workflows
- Business intelligence export
- Mobile-first design
Bridge to other standards and frameworks
Section titled “Bridge to other standards and frameworks”ISO 27001 harmonization
Section titled “ISO 27001 harmonization”- Dual compliance with minimal overhead
- Control mapping between Grundschutz++ practices and ISO controls
- Shared governance: integrated management reviews and audit cycles
- Aligned risk treatment
NIST framework integration
Section titled “NIST framework integration”- CSF compatibility
- OSCAL synergy through shared data structures
- Maturity model alignment
EU compliance standards
Section titled “EU compliance standards”- NIS2 readiness
- GDPR integration
- Digital operational resilience: alignment with DORA for the financial sector
Key takeaways at a glance
Section titled “Key takeaways at a glance”- Digital revolution from 2026: Grundschutz++ replaces the PDF-based compendium with a machine-readable OSCAL/JSON format enabling automated compliance and seamless tool integration.
- Process-oriented modernization: New modular structure with practices instead of building blocks, standardized sentence templates, and a six-level prioritization increases flexibility and efficiency.
- Measurable security via KPIs: Each requirement is linked to C/I/A indicators enabling objective measurement and data-driven optimization.
- Seamless ISO 27001 integration: Designed for maximum harmonization, enabling dual compliance with minimal additional effort and joint audit cycles.
- Early preparation is essential: Organizations should begin strategic preparations in 2025, as migration is not automatic and requires training and tool adjustments.