Skip to content
SECURITYSQUAD
Back to the blog

ISO 27001 based on IT-Grundschutz: the road to certification

2026-08-07 · by SECURITYSQUAD

ISO 27001 based on IT-Grundschutz: the road to certification

A certificate on the wall does not make an organisation secure. Even so, certification to ISO 27001 on the basis of IT-Grundschutz is a sensible goal for many companies and public bodies – not for the seal, but for the road there. It forces you to build information security systematically instead of leaving it to chance.

Two routes to the same certificate

There are two variants, and confusing them routinely costs time in the first conversation.

Native ISO 27001 describes what an information security management system must achieve. It is deliberately technology-neutral and leaves a great deal of latitude on the how. The controls sit in Annex A, which points to ISO 27002 – objectives, not build instructions.

The BSI variant – "ISO 27001 on the basis of IT-Grundschutz" – fills precisely that gap. It is not a different standard but the same one with a prescribed methodology behind it: the BSI's IT-Grundschutz. That provides concrete modules for typical components, from servers through cloud to mobile working, and the associated requirements for each module.

The practical difference: with native ISO 27001 you derive your controls yourself from your risk analysis. With IT-Grundschutz you get a proven catalogue and justify your deviations from it. That is more prescription, but also less blank page.

The framework behind the BSI variant

Four standards carry the whole thing:

| Standard | Content | |---|---| | BSI-Standard 200-1 | Information security management systems – compatible with ISO 27001 | | BSI-Standard 200-2 | IT-Grundschutz methodology with its three approaches | | BSI-Standard 200-3 | Risk management on an IT-Grundschutz basis | | BSI-Standard 200-4 | Business continuity management |

On top of these sits the IT-Grundschutz-Kompendium with the modules and their requirements.

Worth knowing when you plan: the BSI is currently modernising IT-Grundschutz from the ground up. The text-based Kompendium is becoming a digital, machine-readable rule set, and the existing protection levels are to give way to more flexible metrics. Today's IT-Grundschutz remains applicable during the transition – but anyone starting now should know about the rebuild and avoid structuring their documentation so that it has to be recreated from scratch.

The three approaches – and which one fits you

BSI-Standard 200-2 offers three entry points, and the choice determines effort and duration.

Basic protection (Basis-Absicherung). Broad baseline coverage across the whole organisation, initially with the basic requirements only. Quick to take effect, but not certifiable on its own. The right entry point when little structure exists so far.

Core protection (Kern-Absicherung). Full protection for a small, particularly important slice – the "crown jewels". Sensible when one clearly delimited area carries the actual risk.

Standard protection (Standard-Absicherung). The complete route across the entire information domain. This is the variant that leads to certification.

Many organisations run it in two stages: basic protection for breadth first, then standard protection within a defined scope.

The road in five stages

1 · Establish where you stand. A gap analysis shows the distance to the target state. It is uncomfortable and saves the most later, because it makes the scope realistic.

2 · Define the scope. The single biggest lever on effort. A scope drawn too widely is the most common reason projects tip over. The area must be delimitable in business terms – not simply "all of IT".

3 · Build. Structure analysis, protection requirement assessment, modelling against the modules, the IT-Grundschutz check, and a supplementary risk analysis for anything above standard protection needs. Plus the documentation: policy, procedures, records.

4 · Let it live. Everything is decided here. An ISMS that is only brought out for the audit shows – and helps nobody. It needs at least one full cycle in operation: internal audits, management review, corrective actions.

5 · Audit. An auditor certified by the BSI examines the documentation first (stage 1), then implementation on site (stage 2). The certificate is valid for three years, with annual surveillance audits.

Realistically, plan twelve to eighteen months for the first run if you are starting from nothing. Shorter is possible with groundwork in place; much shorter rarely ends well.

Where projects typically get stuck

The scope is too large. The classic. Better a small area done properly than a large one done halfway.

Documentation becomes an end in itself. If you produce policies nobody reads and nobody maintains, you have produced paper, not security. Rule of thumb: if you would not apply it day to day, do not write it.

Management is not really on board. The standard requires top management commitment, and auditors ask about it. An ISMS that hangs in IT alone has no mandate for decisions that cost money or change processes.

Nobody has the time. The information security officer does it "on the side" at twenty per cent, which never actually gets freed up. The answer is either honest relief of other duties or an external officer.

What this has to do with NIS2

Germany's NIS2 implementation act has been in force since 6 December 2025, with no general transition period. Roughly 29,500 companies newly fall under BSI supervision and must evidence risk management measures.

ISO 27001 certification is not mandatory for that – but an existing ISMS already covers large parts of the required measures and supplies the evidence that otherwise has to be assembled piece by piece. If you intend to certify anyway, treat NIS2 as an accelerator rather than a second project.

The value beyond the seal

Anyone who follows the road properly gains clear responsibilities, documented processes and an improvement cycle that also catches new risks. In tenders and supplier assessments the certificate is often the entry ticket anyway – but the real return is that someone is named as accountable, and that decisions are documented in a way that can be traced.

As a provider certified to ISO 27001 on the basis of IT-Grundschutz, we have walked this road ourselves. That helps with the question of where effort can be saved – and where it cannot.

As at August 2026. Statements on the BSI standards and the IT-Grundschutz modernisation follow BSI publications; on the German NIS2 act see our NIS2 guide.

Read more: Our certifications · NIS2 for SMEs · External information security officer · Vulnerability Management