Skip to content
Machine BehaviorCTO
Menu

IT-Grundschutz Certification

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Three certification paths: ISO 27001 auf Basis IT-Grundschutz (full), IT-Grundschutz Testat (lower-tier), or standard ISO 27001.

ISO 27001 auf Basis IT-Grundschutz

The flagship certification. Combines:

  • ISO 27001 international standard.
  • IT-Grundschutz Bausteine as implementation methodology.

Issued by BSI-licensed certification bodies. Certificate carries BSI authority + ISO recognition.

Audit process

  1. Vorprüfung (pre-audit): readiness assessment.
  2. Hauptprüfung (main audit): Stage 1 + Stage 2 combined.
  3. Zertifikatserteilung (certification): on successful audit.
  4. Überwachungsaudits (surveillance audits): annual.
  5. Rezertifizierung: 3-year cycle.

Same Annex SL mechanics as standard ISO 27001 but with Grundschutz methodology as the implementation evidence.

BSI-licensed auditors

BSI maintains list of licensed auditors. Audit firms must qualify for both:

  • DAkkS accreditation (for ISO 27001).
  • BSI license (for Grundschutz audit competence).

Smaller list than standard ISO 27001 audit firms.

IT-Grundschutz Testat

Lower-tier confirmation. Used when:

  • Org not pursuing full certification.
  • Specific procurement requirement for Grundschutz alignment evidence.
  • Stepping stone to full certification.

Less rigorous than ISO 27001 auf Basis IT-Grundschutz.

Standard ISO 27001

Some DE orgs pursue standard ISO 27001 (without Grundschutz basis) for international recognition. Uses Annex A controls directly without Grundschutz methodology.

Choosing the path

IT-Grundschutz only / Testat

  • DE-only operations.
  • Limited budget.
  • Public-sector orientation.

ISO 27001 auf Basis IT-Grundschutz

  • DE operations with some international exposure.
  • KRITIS operators.
  • Mittelstand with DE-government customers + international customers.

Standard ISO 27001

  • International operations.
  • Limited DE-specific requirements.
  • Preference for international auditor pool.

Cost orientation

  • IT-Grundschutz Testat: relatively low cost, depending on scope.
  • ISO 27001 auf Basis IT-Grundschutz: similar to standard ISO 27001 (€15-40k+ for small/mid SaaS first-time).
  • Standard ISO 27001: similar.

DE public sector procurement

Many DE government procurement specifies ISO 27001 auf Basis IT-Grundschutz as the acceptable assurance signal. Standard ISO 27001 not always accepted in public-sector tenders.

KRITIS context

KRITIS operators must implement "state-of-the-art" InfoSec per §8a BSIG. Grundschutz commonly used as state-of-the-art evidence. ISO 27001 auf Basis IT-Grundschutz often the chosen path.

See also

From the knowledge vault, pillars/bsi-grundschutz/IT-Grundschutz Certification.md. Built from scripts/docs by build_docs.py.