Directive NIS2 European Union
IT-Grundschutz-Kompendium · Edition 2025, transitioning to Grundschutz++

IT-Grundschutz

NIS2 says what you must achieve, never how you demonstrate it. Germany answers with IT-Grundschutz. If you operate there, this is what your regulator reads.

Implementation routes
3
Modules
113
Member states using it
1

Reviewed . Verify against the scheme owner before relying on this for a certification decision.

This framework is not compliance

IT-Grundschutz is formally binding only on the federal administration. The NIS2UmsuCG does not make it mandatory for private entities. It is, however, the benchmark German auditors and insurers apply in practice, which makes it the de facto reference even where no law requires it — and the reason a German implementation plan that ignores it tends to be re-done.

We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 is fully accepted, and IT-Grundschutz offers its own certification route "ISO 27001 on the basis of IT-Grundschutz".

Implementation routes

3 routes, chosen by scope and depth


Basis-Absicherung

Breadth before depth: the essential safeguards across the whole estate. Typically three to six months in a mid-sized company.

First step for an organisation with no ISMS

Kern-Absicherung

Depth before breadth: the most critical business processes first, with a full risk analysis under BSI-Standard 200-3.

Organisations with a small number of critical assets

Standard-Absicherung

The full implementation, and the basis for ISO 27001 certification on the basis of IT-Grundschutz. Typically nine to eighteen months.

A complete ISMS, and the route to certification

What it is built on

IT-Grundschutz does not invent its own taxonomy. It sits on BSI-Standards 200-1 (management), 200-2 (methodology), 200-3 (risk analysis) and 200-4 (business continuity).

The Kompendium carries 113 modules — Bausteine — across ten layers. Unlike CyFun it is not organised as assurance levels but as three implementation routes, chosen by how much of the organisation you secure and how deeply.

Where it is heading

  • Grundschutz++ is the modernised variant being introduced across 2025 and 2026: leaner, more explicitly risk-based, and machine-readable via OSCAL.
  • Organisations whose ISMS is built on the 2024 or 2025 edition can keep that structure through a transition period running to approximately 2029.
Mapping

How it covers article 21(2)


Basis

The Kompendium groups its 113 modules into ten layers: five process layers (ISMS, ORP, CON, OPS, DER) and five system layers (APP, SYS, IND, NET, INF). Each measure is mapped to the layers that carry the relevant modules.

Limit of this mapping

Layer level, not module. Module identifiers change between editions of the Kompendium, so a module-level map would go stale; scope with this, then take the module list from the edition you are working to. The IND layer is mapped to continuity, maintenance and asset control because NIS2 covers OT-heavy sectors — energy, water, manufacturing — where industrial systems carry those outcomes and general IT modules do not reach them.

Mapped at the level of
IT-Grundschutz layer
Units in the framework
10
Units carrying article 21(2)
10
Each of the ten risk-management measures of article 21(2), mapped to the IT-Grundschutz layer units of IT-Grundschutz
Art. 21(2) Measure IT-Grundschutz — IT-Grundschutz layer
(a) Risk analysis and security policies ISMS CON ORP
(b) Incident handling DER OPS
(c) Business continuity CON OPS INF IND
(d) Supply chain security ORP OPS
(e) Security in acquisition, development and maintenance CON APP OPS IND
(f) Assessing the effectiveness of the measures ISMS DER
(g) Basic cyber hygiene and cybersecurity training ORP CON
(h) Cryptography and encryption CON NET
(i) Human resources security, access control and asset management ORP CON SYS APP IND
(j) Multi-factor authentication and secured communications NET SYS APP
10 IT-Grundschutz layer units, in full
  • ISMS — Sicherheitsmanagement — security management
  • ORP — Organisation und Personal — organisation and personnel
  • CON — Konzepte und Vorgehensweisen — concepts and procedures
  • OPS — Betrieb — operations
  • DER — Detektion und Reaktion — detection and response
  • APP — Anwendungen — applications
  • SYS — IT-Systeme — IT systems
  • IND — Industrielle IT — industrial IT and OT
  • NET — Netze und Kommunikation — networks and communication
  • INF — Infrastruktur — physical infrastructure
The chain continues

What you already have, for the same measure


Nobody in scope starts from nothing. IT-Grundschutz is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.

The ten measures of article 21(2), each mapped to IT-Grundschutz and to the enterprise frameworks an organisation is likely to already operate
Art. 21(2) IT-Grundschutz ISO 27001 ISO/IEC 27001:2022 Annex A control NIST 800-53 NIST SP 800-53 Rev. 5 control family
(a) Risk analysis ISMS CON ORP 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 RA PL PM
(b) Incident handling DER OPS 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 IR AU SI
(c) Continuity CON OPS INF IND 5.29 5.30 7.5 7.11 7.12 8.13 8.14 CP PE
(d) Supply chain ORP OPS 5.19 5.20 5.21 5.22 5.23 SR SA
(e) Secure development CON APP OPS IND 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 SA CM MA RA SI
(f) Effectiveness ISMS DER 5.33 5.35 5.36 8.16 CA PM
(g) Hygiene and training ORP CON 5.37 6.3 8.7 AT SI CM
(h) Cryptography CON NET 8.24 SC
(i) HR, access, assets ORP CON SYS APP IND 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 PS AC IA CM MP PE
(j) MFA and comms NET SYS APP 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 IA AC SC

A crosswalk is not an equivalence

Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:

  • ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
  • NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.

Use a row to find the evidence you already hold, then read the requirement itself.

Germany

Germany Transposition Pack (NIS2UmsuCG)

How NIS2 actually applies in Germany: the BSI as competent authority, registration duties, and where German law goes beyond the directive.

  • National reference document (Markdown): what binds you in Germany, not the directive
  • The national law, its adoption and entry-into-force dates, and its current status
  • How Germany numbers the article 21(2) measures, and any measure it adds
  • Registration channel and portal, with the deadline rule
  • Supervision: who inspects, and from when
  • IT-Grundschutz: the three implementation routes, the modules and layers, the move to Grundschutz++, and why it is the de facto benchmark without being legally mandatory
  • Gap-analysis worksheet (CSV, opens in Excel): one row per measure with the national reference, plus status, evidence, gap, remediation, owner and target-date columns
  • Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
  • Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
  • NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
  • Every fact carries its source and a review date — regenerated from our data hub, so it cannot drift from the site
129 € excl. VAT

Instant download · 30-day money-back guarantee

Sources

We are not affiliated with Bundesamt für Sicherheit in der Informationstechnik (BSI). IT-Grundschutz and related marks belong to their owners.

Cart 0