Skip to main content Skip to search Skip to main navigation
Menu
Important Standards & legislation Score: 8/10

Grundschutz++: BSI Sets Certification Date Starting 2027

The BSI has specified the timeline for the new IT-Grundschutz version: Training starts November 1, certification possible from January 1, 2027.

What Happened?

After more than two years of development work on the new version of IT-Grundschutz, the German Federal Office for Information Security (BSI) has announced concrete dates for its further implementation. On November 1, training will begin for already certified consultants and audit team leaders on the new standard, which goes by the name Grundschutz++ and is based on ISO 27001. Organizations aiming for certification under the new standard can mark January 1, 2027 as the official deadline – from this date onward, certifiability under Grundschutz++ will be in effect.

The Details

The BSI's announcement answers several questions that have been raised in practice for some time. Until now, it was unclear when certification under the new standard would even become possible and what would happen to existing personal certifications. With the timeline now published, the authority has provided clarity on these points.

One piece of news important to many users concerns the checklists for "WiBA – Weg in die Basis-Absicherung" (Path to Basic Protection). According to the BSI, these will remain a fixed component of Grundschutz even in the new version. This means that smaller organizations in particular will continue to have a comparatively unbureaucratic and simple entry point into IT security, without having to switch to a more elaborate set of rules.

The minimum standards for "selected areas of application" will also remain in place. These are primarily aimed at federal institutions in accordance with the BSIG (Act on the Federal Office for Information Security) and are intended to ensure a consistent level of security there.

What remains unclear, however, is how these minimum standards will apply in the future to companies falling under the NIS-2 Directive. The BSI has not yet communicated a precise assessment basis for this area. The methodology guide also remains a point of criticism: the linked version has not changed since March of this year and still shows clear gaps.

Assessment

For organizations dealing with IT security and certifications, these announcements carry significant practical relevance. The BSI's IT-Grundschutz has for years served as a central reference for building information security management systems in Germany – particularly in the area of critical infrastructure and public institutions, where security technology such as access control, video surveillance, and physical protective measures are closely intertwined with organizational IT security requirements.

The transition to ISO 27001 as the basis for Grundschutz++ signals a stronger international orientation and compatibility with globally recognized standards. At the same time, the continuation of the WiBA checklists preserves the low-threshold entry point, which is especially relevant for smaller businesses and organizations with limited resources.

The unresolved question surrounding NIS-2, however, carries considerable weight: numerous companies that will fall under this EU directive in the future need clarity about which assessment bases will apply to them. As long as the BSI does not provide concrete statements on this, affected organizations will continue to face a significant degree of planning uncertainty.

Practical Tips

  • Organizations already certified under IT-Grundschutz should keep an eye on the training start date of November 1 in order to qualify consultants and audit team leaders early.
  • Those planning a new certification should factor in January 1, 2027 as a binding reference point in their own planning.
  • Smaller organizations can continue to rely on the WiBA checklists to find a structured entry point into basic protection without having to implement the full scope of Grundschutz.
  • Companies falling under the NIS-2 Directive should closely follow the BSI's further communications regarding the minimum standards, as a final assessment basis has not yet been established here.
  • Since the methodology guide is currently incomplete, newcomers to the subject are advised to exercise some patience or consult with experienced advisors until the documentation is updated.

Outlook

With the dates now announced, the BSI has taken an important step toward establishing the binding nature of the new Grundschutz standard. However, there remains a considerable amount of work to be done before the official start of certifiability on January 1, 2027 – particularly updating the methodology guide and clarifying the assessment bases for companies affected by NIS-2. Organizations and consultants who engage with Grundschutz++ early will gain a head start, but should keep an eye on further publications from the BSI, as key questions have not yet been fully resolved.