IT-Grundschutz
NIS2 says what you must achieve, never how you demonstrate it. Germany answers with IT-Grundschutz. If you operate there, this is what your regulator reads.
Reviewed . Verify against the scheme owner before relying on this for a certification decision.
This framework is not compliance
IT-Grundschutz is formally binding only on the federal administration. The NIS2UmsuCG does not make it mandatory for private entities. It is, however, the benchmark German auditors and insurers apply in practice, which makes it the de facto reference even where no law requires it — and the reason a German implementation plan that ignores it tends to be re-done.
We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 is fully accepted, and IT-Grundschutz offers its own certification route "ISO 27001 on the basis of IT-Grundschutz".
3 routes, chosen by scope and depth
Breadth before depth: the essential safeguards across the whole estate. Typically three to six months in a mid-sized company.
First step for an organisation with no ISMS
Depth before breadth: the most critical business processes first, with a full risk analysis under BSI-Standard 200-3.
Organisations with a small number of critical assets
The full implementation, and the basis for ISO 27001 certification on the basis of IT-Grundschutz. Typically nine to eighteen months.
A complete ISMS, and the route to certification
What it is built on
IT-Grundschutz does not invent its own taxonomy. It sits on BSI-Standards 200-1 (management), 200-2 (methodology), 200-3 (risk analysis) and 200-4 (business continuity).
The Kompendium carries 113 modules — Bausteine — across ten layers. Unlike CyFun it is not organised as assurance levels but as three implementation routes, chosen by how much of the organisation you secure and how deeply.
Where it is heading
- Grundschutz++ is the modernised variant being introduced across 2025 and 2026: leaner, more explicitly risk-based, and machine-readable via OSCAL.
- Organisations whose ISMS is built on the 2024 or 2025 edition can keep that structure through a transition period running to approximately 2029.
How it covers article 21(2)
The Kompendium groups its 113 modules into ten layers: five process layers (ISMS, ORP, CON, OPS, DER) and five system layers (APP, SYS, IND, NET, INF). Each measure is mapped to the layers that carry the relevant modules.
Layer level, not module. Module identifiers change between editions of the Kompendium, so a module-level map would go stale; scope with this, then take the module list from the edition you are working to. The IND layer is mapped to continuity, maintenance and asset control because NIS2 covers OT-heavy sectors — energy, water, manufacturing — where industrial systems carry those outcomes and general IT modules do not reach them.
| Art. 21(2) | Measure | IT-Grundschutz — IT-Grundschutz layer |
|---|---|---|
| (a) | Risk analysis and security policies | ISMS CON ORP |
| (b) | Incident handling | DER OPS |
| (c) | Business continuity | CON OPS INF IND |
| (d) | Supply chain security | ORP OPS |
| (e) | Security in acquisition, development and maintenance | CON APP OPS IND |
| (f) | Assessing the effectiveness of the measures | ISMS DER |
| (g) | Basic cyber hygiene and cybersecurity training | ORP CON |
| (h) | Cryptography and encryption | CON NET |
| (i) | Human resources security, access control and asset management | ORP CON SYS APP IND |
| (j) | Multi-factor authentication and secured communications | NET SYS APP |
10 IT-Grundschutz layer units, in full
- ISMS — Sicherheitsmanagement — security management
- ORP — Organisation und Personal — organisation and personnel
- CON — Konzepte und Vorgehensweisen — concepts and procedures
- OPS — Betrieb — operations
- DER — Detektion und Reaktion — detection and response
- APP — Anwendungen — applications
- SYS — IT-Systeme — IT systems
- IND — Industrielle IT — industrial IT and OT
- NET — Netze und Kommunikation — networks and communication
- INF — Infrastruktur — physical infrastructure
What you already have, for the same measure
Nobody in scope starts from nothing. IT-Grundschutz is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.
| Art. 21(2) | IT-Grundschutz | ISO 27001 ISO/IEC 27001:2022 Annex A control | NIST 800-53 NIST SP 800-53 Rev. 5 control family |
|---|---|---|---|
| (a) Risk analysis | ISMS CON ORP | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | RA PL PM |
| (b) Incident handling | DER OPS | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | IR AU SI |
| (c) Continuity | CON OPS INF IND | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | CP PE |
| (d) Supply chain | ORP OPS | 5.19 5.20 5.21 5.22 5.23 | SR SA |
| (e) Secure development | CON APP OPS IND | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | SA CM MA RA SI |
| (f) Effectiveness | ISMS DER | 5.33 5.35 5.36 8.16 | CA PM |
| (g) Hygiene and training | ORP CON | 5.37 6.3 8.7 | AT SI CM |
| (h) Cryptography | CON NET | 8.24 | SC |
| (i) HR, access, assets | ORP CON SYS APP IND | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | PS AC IA CM MP PE |
| (j) MFA and comms | NET SYS APP | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | IA AC SC |
A crosswalk is not an equivalence
Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:
- ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
- NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.
Use a row to find the evidence you already hold, then read the requirement itself.
Germany Transposition Pack (NIS2UmsuCG)
How NIS2 actually applies in Germany: the BSI as competent authority, registration duties, and where German law goes beyond the directive.
- National reference document (Markdown): what binds you in Germany, not the directive
- The national law, its adoption and entry-into-force dates, and its current status
- How Germany numbers the article 21(2) measures, and any measure it adds
- Registration channel and portal, with the deadline rule
- Supervision: who inspects, and from when
- IT-Grundschutz: the three implementation routes, the modules and layers, the move to Grundschutz++, and why it is the de facto benchmark without being legally mandatory
- Gap-analysis worksheet (CSV, opens in Excel): one row per measure with the national reference, plus status, evidence, gap, remediation, owner and target-date columns
- Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
- Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
- NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
- Every fact carries its source and a review date — regenerated from our data hub, so it cannot drift from the site
Instant download · 30-day money-back guarantee
We are not affiliated with Bundesamt für Sicherheit in der Informationstechnik (BSI). IT-Grundschutz and related marks belong to their owners.