Three certification paths: ISO 27001 auf Basis IT-Grundschutz (full), IT-Grundschutz Testat (lower-tier), or standard ISO 27001.
ISO 27001 auf Basis IT-Grundschutz
The flagship certification. Combines:
- ISO 27001 international standard.
- IT-Grundschutz Bausteine as implementation methodology.
Issued by BSI-licensed certification bodies. Certificate carries BSI authority + ISO recognition.
Audit process
- Vorprüfung (pre-audit): readiness assessment.
- Hauptprüfung (main audit): Stage 1 + Stage 2 combined.
- Zertifikatserteilung (certification): on successful audit.
- Überwachungsaudits (surveillance audits): annual.
- Rezertifizierung: 3-year cycle.
Same Annex SL mechanics as standard ISO 27001 but with Grundschutz methodology as the implementation evidence.
BSI-licensed auditors
BSI maintains list of licensed auditors. Audit firms must qualify for both:
- DAkkS accreditation (for ISO 27001).
- BSI license (for Grundschutz audit competence).
Smaller list than standard ISO 27001 audit firms.
IT-Grundschutz Testat
Lower-tier confirmation. Used when:
- Org not pursuing full certification.
- Specific procurement requirement for Grundschutz alignment evidence.
- Stepping stone to full certification.
Less rigorous than ISO 27001 auf Basis IT-Grundschutz.
Standard ISO 27001
Some DE orgs pursue standard ISO 27001 (without Grundschutz basis) for international recognition. Uses Annex A controls directly without Grundschutz methodology.
Choosing the path
IT-Grundschutz only / Testat
- DE-only operations.
- Limited budget.
- Public-sector orientation.
ISO 27001 auf Basis IT-Grundschutz
- DE operations with some international exposure.
- KRITIS operators.
- Mittelstand with DE-government customers + international customers.
Standard ISO 27001
- International operations.
- Limited DE-specific requirements.
- Preference for international auditor pool.
Cost orientation
- IT-Grundschutz Testat: relatively low cost, depending on scope.
- ISO 27001 auf Basis IT-Grundschutz: similar to standard ISO 27001 (€15-40k+ for small/mid SaaS first-time).
- Standard ISO 27001: similar.
DE public sector procurement
Many DE government procurement specifies ISO 27001 auf Basis IT-Grundschutz as the acceptable assurance signal. Standard ISO 27001 not always accepted in public-sector tenders.
KRITIS context
KRITIS operators must implement "state-of-the-art" InfoSec per §8a BSIG. Grundschutz commonly used as state-of-the-art evidence. ISO 27001 auf Basis IT-Grundschutz often the chosen path.