BSI IT-Grundschutz position

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

What it does well

  • DE national standard. Mandatory or expected in DE public sector, KRITIS, many Mittelstand.
  • Methodology is prescriptive. Practitioner gets clear guidance via Bausteine.
  • Threat catalog rich. Specific threats and counter-measures mapped.
  • ISO 27001 harmonized. ISO 27001 + IT-Grundschutz combined certification path exists.
  • BSI authority weight. Carries weight in DE procurement.
  • Free. Methodology and catalog free; Kompendium download free.

What it does poorly

  • German-language primary. International recognition limited.
  • Compendium-heavy. Bausteine catalog is large; navigation cost.
  • Bureaucratic reputation. Public-sector lineage produces ceremonial-implementation patterns.
  • Update lag. Annual catalog updates trail threat-landscape evolution.
  • Limited AI / cloud-native depth. Building blocks for cloud / AI evolving but less mature.

Evidence

  • Widely used in DE public sector, KRITIS operators, Mittelstand security-conscious firms.
  • International recognition outside DE limited.
  • ISO 27001 + IT-Grundschutz combined path common.
  • NIS2UmsuCG implementation references Grundschutz methodology.

Personal calibration

  • For DE-only client engagements: Grundschutz vocabulary load-bearing.
  • For international + DE clients: ISO 27001 primary; Grundschutz as DE supplement.
  • For KRITIS / public sector: Grundschutz often required.

See also