ISO 27001 vs BSI IT-Grundschutz: Which Route to an ISMS?

A German client or group parent has named IT-Grundschutz and you hold ISO/IEC 27001. What the BSI's methodology is, how its certification route differs, where the effort sits in each, and when the two can be combined rather than chosen between.

ISO/IEC 27001 vs. BSI IT-GrundschutzISMSLast reviewed:

The sentence usually arrives from a German public-sector client, a German group parent, or a prime contractor bidding into German government work: IT-Grundschutz is expected. You hold an ISO/IEC 27001 certificate and cannot tell whether you have just been asked for something you already have, something adjacent, or something else entirely.

What is BSI IT-Grundschutz?

IT-Grundschutz is a methodology for building an information security management system, published by the Bundesamt für Sicherheit in der Informationstechnik (BSI), the German federal cyber security authority. It is not a competing standard so much as a fully worked-out route: a set of BSI-Standards describing the method, plus the IT-Grundschutz-Kompendium, the BSI's compendium of Bausteine, building blocks that spell out concrete requirements for typical processes, applications and IT systems. The BSI-Standards are coordinated with ISO/IEC 27001, and the fullest of the three approaches, the Standard-Absicherung, leads to an ISO 27001 certificate on the basis of IT-Grundschutz.

Who issues ISO 27001 certificates on the basis of IT-Grundschutz?

An ISO 27001 certificate on the basis of IT-Grundschutz is a real ISO 27001 certificate; the difference lies in the route and in who runs it. An ordinary ISO/IEC 27001 certificate comes from a certification body accredited by a national accreditation body, in Germany the DAkkS. The IT-Grundschutz route does not run through that machinery at all. § 1(2) AkkStelleG, the German act governing the national accreditation body, leaves the competence of other authorities to authorise conformity assessment bodies untouched and names "Sicherheit in der Informationstechnik" (security in information technology) among the fields where that saving applies. That is the legal room the BSI scheme occupies: the certificate is awarded by the BSI itself and examined by auditors certified with the BSI. Two institutional tracks, one underlying standard.

How does the IT-Grundschutz method differ from ISO 27001?

ISO/IEC 27001 states requirements and leaves the design to you: which controls are appropriate follows from your own risk assessment, and the standard asks only that the reasoning be documented so that it can be followed. That grants freedom and demands judgement. IT-Grundschutz takes most of those decisions off your hands. Model your Informationsverbund (the information domain in scope) cleanly, and the compendium hands you a list of concrete, testable requirements you never had to derive. The price is a substantial documentation effort in the structure analysis and the modelling that precede it.

The comparison below sets the two against the criteria that actually decide the question: how the rulebook is built, how you get from scope to controls, where the effort lands, what evidence you end up holding, and how each travels outside Germany.

Side by side

CriterionISO/IEC 27001BSI IT-Grundschutz
Who publishes itISO and IEC, two international standards organisations. The standard is drafted in a joint committee and agreed internationally.The Bundesamt für Sicherheit in der Informationstechnik (BSI), the German federal cyber security authority. The standards and the compendium are written and maintained nationally.
What it sets out to doSets the requirements for an information security management system and leaves it to the organisation to decide how they are met.Describes a complete methodology for building an information security management system, including a catalogue of requirements already written out in concrete terms.
Where it is bindingVoluntary. It becomes binding through contracts, tender documents, or a decision of the organisation's own management.Largely binding for German federal authorities and in part for the administrations of the Länder. Public contracting authorities also frequently require it of their service providers, which is how it reaches companies with no public-sector status of their own.
Certification routeCertification through an accredited certification body; in Germany the DAkkS grants the accreditation. The certificate runs, as a rule, for three years with annual surveillance audits.On the basis of the Standard-Absicherung, an ISO 27001 certificate on the basis of IT-Grundschutz is available. It is awarded by the BSI and examined by auditors certified with the BSI; for evidence of a successful implementation of the *Basis-Absicherung* the BSI offers an attestation, which likewise may only be awarded by an auditor certified with the BSI.
Who examines and who decidesAn accredited certification body examines and decides on certification. ISO/IEC 17021-1 applies to it generally and ISO/IEC 27006-1:2024 specifically for ISMS; in Germany, accreditation is granted by DAkkS.The examination is carried out by an ISO 27001 Grundschutz auditor certified with the BSI. The decision to issue the certificate is taken by the BSI itself, on the basis of the audit report. Examination and certification decision therefore sit in a procedure of the federal authority's own, not in the DAkkS accreditation system.
Which edition governs the procedureWhat governs is the edition of the standard certified against. When an edition changes, transition periods on the accreditation side settle by when certificates to the old edition have to be moved over.The BSI names the binding documents in an examination basis of its own, listing there the standard, the BSI-Standard, the compendium edition and the procedural documents with their versions. What governs is the date the audit begins, that is the start of the review of the reference documents; a switch to a newer version is permitted at any time while the procedure is running. Where the examination bases change, the BSI sets out transition periods separately.
How the rulebook is put togetherOne document: clauses 4 to 10 carrying the requirements, and Annex A with 93 reference controls. The detailed explanation of those controls sits in the separate ISO/IEC 27002.Several documents: BSI-Standard 200-1 (management system), 200-2 (the IT-Grundschutz methodology), 200-3 (risk analysis) and 200-4 (business continuity management), together with the IT-Grundschutz-Kompendium containing the building blocks.
Drawing the boundaryThe organisation sets its own scope and justifies it so that the reasoning can be followed: by site, by product, or by service.The Informationsverbund is captured in a structure analysis and then modelled: processes, applications, IT systems, networks, rooms and groups of people are each recorded individually as target objects.
How you arrive at controlsControls follow from your own risk treatment. Annex A then serves as a cross-check that nothing necessary was overlooked. Every decision has to be derived and justified by you.Controls follow from the modelling: each target object is assigned the building blocks that fit it, and their requirements are then implemented. The derivation has already been done in the compendium.
Role of risk analysisAlways required. The standard demands a defined process for assessing and treating risk, with criteria, risk owners and a documented result.For normal protection needs, already covered by the building blocks. A supplementary risk analysis under BSI-Standard 200-3 is required where protection needs are high or very high, or where a target object is not represented by any building block.
How prescriptive it isDeliberately general and technology-neutral. That eases application in heterogeneous environments but requires you to interpret what an appropriate level means.Very concrete, down to individual system types. That eases implementation and examination but requires continual catching-up as the technology in use changes.
Where the effort sitsIn the derivation and the justification: risk methodology, control selection, Statement of Applicability. The documentation stays comparatively lean.In the structure analysis, the assessment of protection needs and the modelling. It grows markedly with the number of target objects, but a large part of deriving controls yourself falls away.
Documented evidenceDocumented information as the standard requires it, among it the policy, the scope, the risk assessment and risk treatment, the Statement of Applicability, internal audits and the management review.Reference documents in the form the BSI prescribes, among them the security policy, the structure analysis, the assessment of protection needs, the modelling, the result of the IT-Grundschutz-Check and any supplementary risk analysis.
Access, cost and reachThe standards are purchased from the national standards bodies, and practical work usually needs ISO/IEC 27002 alongside. Internationally recognised and broadly accepted in tenders, supplier assessments and insurance questions.The BSI publishes the BSI-Standards and the IT-Grundschutz-Kompendium as free downloads. Anchored above all in the German public sector and the companies that supply it; little used elsewhere.
Where the rulebook is headingThe standard is revised on the cycle of the standards committees. In the move from the 2013 to the 2022 edition, 114 controls were consolidated into 93 and 14 themes into 4 thematic areas; Amendment 1:2024 has since been added.IT-Grundschutz is currently being rebuilt: the new IT-Grundschutz is constructed on a fully process-oriented basis and rests on a digital rulebook in the form of a JSON file. The current IT-Grundschutz is maintained alongside it and remains applicable through the transition period, which runs over several years. That matters for a decision pending now, because the structure of the rulebook and the tooling around it change during that time.

Our verdict

If a German counterparty has named IT-Grundschutz, establish first what they are actually asking for, because the phrase covers three different requests. Sometimes it means the certificate: an ISO 27001 certificate on the basis of IT-Grundschutz, awarded by the BSI. Sometimes it means the method, in the sense that you work along the BSI's approach and can show the reference documents. And often, particularly where the requirement has been copied into a supplier questionnaire from a public-sector template, it means the compendium is the yardstick against which individual controls will be judged, and your existing certificate answers the management-system half of the question perfectly well. Those three cost very different amounts. Ask before you scope a project.

Where the choice is genuinely yours, it turns less on security philosophy than on two unglamorous factors: who your customers are, and how large and how fast-changing your environment is.

For the German public sector and the companies around it, IT-Grundschutz is usually settled in advance. Federal authorities are largely bound, and public contracting authorities frequently require it of their suppliers. If your tenders name it, the weighing-up is over and the only remaining question is which of the three approaches you use. The Basis-Absicherung and the Kern-Absicherung both limit the scope. Both the Standard-Absicherung and the Kern-Absicherung lead to the ISO 27001 certificate on the basis of IT-Grundschutz; for the Basis-Absicherung the BSI offers an attestation instead.

For companies with international customers, the direct route through ISO/IEC 27001 is as a rule the more practical one. An ISO/IEC 27001 certificate is accepted worldwide without explanation. The certificate on the basis of IT-Grundschutz is formally an ISO 27001 certificate too, but outside Germany it frequently needs explaining. That is a small friction, though a noticeable one in a sales process where a security questionnaire is being reviewed by someone who has never seen the scheme.

Size and pace tip the effort balance. In a contained, stable environment the modelling is manageable and the pre-written requirements save a great deal of derivation work. In a heterogeneous, fast-moving environment (software development, heavy cloud use) the maintenance burden on the structure analysis and the modelling grows considerably, while the risk-based approach of ISO/IEC 27001 keeps up more easily.

A third route is often overlooked and is frequently the best one, especially for a company outside Germany that has been asked the question but is not bound by anything: run the management system to ISO/IEC 27001 and use the IT-Grundschutz-Kompendium as a free implementation reference. The building blocks are markedly more concrete than the text of ISO/IEC 27002 and are well suited to settling what level is expected for a particular control. You give up no freedom of design and gain a very solid template, and, incidentally, a credible answer when a German counterparty asks how you determined that a control is adequate.

What to avoid is switching mid-project. Structure analysis and modelling on one side, risk treatment and Statement of Applicability on the other, are different ways of thinking with different artefacts. A late switch means, in practice, rebuilding large parts of the documentation.

The BSI certification route in detail

The IT-Grundschutz route leads to an ISO 27001 certificate, but through a different procedure from direct certification. Anyone planning it should know the procedural documents, because they set the sequence bindingly and are publicly available.

Why the procedure sits alongside accreditation. § 1(2) AkkStelleG leaves the competence of other authorities untouched and names security in information technology when it does so. That is why the BSI procedure runs through a system of its own. It is not a sector carve-out: DAkkS continues to accredit the certification bodies for ISO/IEC 27001 on the direct route.

The documents that govern the sequence. The BSI brings them together in an examination basis and names the version binding in each case:

  • a certification scheme, describing the requirements on the procedure
  • an auditing scheme, setting the requirements on the audit team leader and the audit team members, and on the examination itself
  • specifications for the audit report and for making the reference documents available, including a list of the documents belonging to the report
  • the application for certification and a declaration of independence by the audit team members

Which edition applies. What governs is the date the audit begins, that is the start of the review of the reference documents. A switch to a newer version is permitted at any time while the procedure is running, and where the examination bases change the BSI sets out transition periods separately. One feature makes planning easier still: the BSI publishes building blocks in advance as a community draft, and where an applicant has already implemented such a building block, the audit team leader may draw on it as an examination building block.

Not every approach ends in a certificate. The ISO 27001 certificate on the basis of IT-Grundschutz is reached through the Standard-Absicherung and the Kern-Absicherung. For evidence of a successful implementation of the Basis-Absicherung, the BSI offers an attestation instead, which likewise may only be awarded by an auditor certified with the BSI. Anyone promising a certificate in a tender while planning the Basis-Absicherung internally has a gap at exactly this point.

What transfers between the two routes

The question arises in both directions: on a change of methodology, and where the two run side by side because one part of a group takes one route and another part the other. It can be answered phase by phase.

PhaseUnder IT-GrundschutzIn an ISMS to ISO/IEC 27001
Drawing the boundaryThe Informationsverbund, the information domain, recorded in the structure analysisThe scope, set by the organisation and justified so it can be followed
Taking stockTarget objects: processes, applications, IT systems, networks, rooms, groups of peopleAssets, and the processes, systems, sites and providers that carry them
Protection needA Schutzbedarfsfeststellung per target object, with inheritance along the dependenciesThe outcome of the risk assessment; the standard prescribes no fixed protection-need categories
Route to the requirementsModelling: assigning suitable building blocks to the target objectsRisk treatment, Annex A as a cross-check, the result recorded in the Statement of Applicability
Supplementary risk analysisUnder BSI-Standard 200-3, where the protection need is high or very high or no building block fitsNot a special case but the starting point of the whole approach
Target-actual comparisonThe IT-Grundschutz-Check, requirement by requirementInternal audit and measurement of the effectiveness of the controls chosen
Evidence documentsReference documents as specified by the BSIDocumented information under the standard, including the Statement of Applicability

For the comparison at the level of individual requirements, nobody has to build a table of their own: the BSI publishes a mapping table setting ISO/IEC 27001 against IT-Grundschutz. It names, for each clause of the standard, the chapter of the relevant BSI-Standard together with the building block and the requirement in the compendium, marks the primarily relevant area in bold where a topic is dealt with in several places, and states at the outset which editions it rests on. It, too, is a reading aid: what counts in the audit is the examination against the requirements themselves.

Rows two and three carry the largest transferable share: taking stock and mapping dependencies are the same work under either approach and can be carried across without a break. Rows four and five are not. Modelling does not produce a risk treatment, and a Statement of Applicability does not produce an assignment of building blocks, because one side settles the derivation inside the catalogue and the other demands it from the organisation. That is precisely where the cost of a late change of methodology sits.

What of this is modelled in Rizzqo

Rizzqo holds ISO/IEC 27001 and ISO/IEC 27002 as requirement catalogues.

There is a methodological parallel worth knowing, and it makes the decision easier. IT-Grundschutz modelling assigns modules to target objects; in Rizzqo requirements are dispatched to objects through their category and subcategory, and when the classification changes the requirement list adjusts. Anyone already thinking in target objects will recognise the structure. The inventory itself, which is the largest effort in either approach, transfers.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework