Where do we stand today? As of July 2026, Grundschutz++ is not yet a fully rolled-out successor to the existing IT Baseline Protection methodology. Instead, it is an applicable pilot version that the BSI is testing together with pilot partners.
Nevertheless, the topic remains highly relevant because the direction is clear: IT Baseline Protection is becoming more digital, process-oriented, and structured in a way that allows tools to process its content directly. For companies and public sector organizations, now is therefore the time for preparation and strategic alignment to avoid poor investments, duplicated effort and resource bottlenecks.
Grundschutz++ at a Glance: OSCAL, requirements and timeline
Grundschutz++ is a comprehensive modernisation of the BSI IT Baseline Protection framework. Requirements are provided through the State-of-the-Art Library as machine-readable OSCAL data in JSON format. According to the current BSI status, the framework consists of 19 practices and 921 requirements. The pilot phase runs until 30 September 2026, while publication of the methodology is planned for it-sa 2026 from 27 to 29 October. ISO 27001 certification applications based on Grundschutz++ are expected to be possible from 1 January 2027 onwards.
What is Grundschutz++?
Grundschutz++ is neither a new law nor an additional compliance framework that companies and public sector organizations must implement alongside ISO 27001, NIS2 and DORA. It is a reform of the BSI methodology used by organizations to establish, operate and demonstrate an Information Security Management System.
The existing IT Baseline Protection methodology is characterized by extensive standards and methodology documents, requirement catalogues, implementation guidance and periodic editions. Grundschutz++ shifts the focus towards a process-oriented methodology and a structured data foundation. The BSI's objective is to modernize content and reduce effort within the ISMS, particularly where processes can be automated or data can be reused multiple times. [1][2]
The key change is therefore not “fewer controls” but more manageable controls. The expression ‘controls’ originates from the OSCAL data model, where individual requirements are represented as controls. This refers to the familiar baseline protection requirements, not an additional layer of controls. Requirements are intended to be clearly structured, version-controlled, filterable, and reusable within tools.
This creates opportunities for more data-driven security management through dashboards for implementation status, notifications of catalogue changes or metrics derived from linked evidence. However, it does not remove the organization’s responsibility for decisions, risks, implementation measures or effectiveness reviews.
Strategically, Grundschutz++ also gains importance through NIS2. Essential and important entities must implement appropriate measures that take the state of the art into account. The State-of-the-Art Library makes BSI security requirements available in a machine-readable format and therefore provides valuable guidance. Whether an organisation is affected and which measures are appropriate in a specific context must still be assessed independently.[3][6][7]
OSCAL and Grundschutz++: Making BSI requirements machine-readable
OSCAL stands for Open Security Controls Assessment Language. This open data model describes security requirements and related information in a machine-readable format. The BSI publishes its digitally structured security requirements through the State-of-the-Art Library, where the Grundschutz++ user catalogue is available as a JSON file.[2][3]
For practitioners, five effects are particularly relevant:
- Changes become technically comparable: Instead of manually comparing two PDF versions, tools can analyze versions and deltas.
- Content can be maintained continuously: Changes remain linked to a specific catalogue version and therefore remain traceable.
- Catalogues become official data sources within tools:Supported ISMS and GRC platforms can import the original version-controlled catalogue rather than transferring content into proprietary formats.
- Profiles can be tailored more precisely: A profile is a filtered, organization-specific package of requirements. Organizations adopt the content relevant to their context and process it further.
- Evidence can be linked more systematically: A ticket can document implementation of a requirement, a metric can demonstrate effectiveness, and a policy can provide organizational evidence. Integrated platforms can support assessments through these linked sources.
This creates the foundation for “Compliance as Code”, if processes, data and evidence are integrated properly. A JSON file on its own does not make an organization compliant.
The 19 Grundschutz++ practices at a glance
The current pilot catalogue organizes its content into 19 practices. The BSI differentiates between organizational, technical and overarching ISMS practices. The methodology is therefore aligned more closely with the activities that organizations must perform continuously, ranging from governance and structural modelling to detection, response and continuous improvement in a threat landscape increasingly shaped by the use of AI in cybercrime. [4]
The five ISMS practices form the governance cycle:
- GC – Governance and Compliance: Establish objectives, framework conditions and obligations.
- STM – Structural Modelling: Capture the information domain and derive an appropriate package of requirements.
- UMS – Implementation: Plan, implement and document security measures.
- PERF – Monitoring and Evaluation: Assess effectiveness, progress and suitability.
- VRB – Improvement: Address deviations and continuously develop the ISMS further.
These are complemented by seven organizational and seven technical practices. The purpose of this structure is to align recurring security activities more closely with responsibilities and operational processes. For organizations, this means that future mapping exercises should not only ask, “Which legacy module corresponds to which new entry?”, but also, “Which process provides the evidence, who owns it and from which system does the data originate?”
Grundschutz++ Performance metrics and WiBA checklists explained
According to the BSI, the existing protection levels of Basic, Standard and High Protection Requirements are expected to be replaced by flexible performance metrics with dynamic thresholds. In addition, prioritization and weighting of requirements are intended to support implementation planning. Exactly how these performance metrics will be calculated has not yet been finalized in the pilot version. [1]
A low-threshold entry point is provided by the WiBA checklists (Path to Basic Protection), which are intended to become a permanent component of Grundschutz++. They are based on the machine-readable user catalogue. In the future, requirements should be filtered according to the relevant use case, based on target object categories and institutional context. This enables smaller organizations to implement fundamental security requirements without first establishing a complete ISMS. The BSI continues to refine the exact generation rules as part of the ongoing development process.
When is Grundschutz++ coming in effect? Key dates and milestones
The official roadmap distinguishes between piloting, evaluation, publication and certifiability.
- 1 April 2026: Start of the pilot phase with an applicable version of the methodology.
- 30 September 2026: End of the pilot phase; feedback will be incorporated into further development.
- 27–29 October 2026: Planned publication of the methodology at it-sa 2026.
- 1 January 2027: Grundschutz++ is expected to become certifiable; according to the BSI, ISO 27001 certification applications based on Grundschutz++ can be submitted from this date onward.
For organizational planning: 2026 is the year for preparation and limited piloting. Organizations can already align data structures, roles, tools and processes. However, they should avoid anticipating methodological details that will only be finalized by the BSI after the pilot phase.
The same applies to existing certificates. The current BSI roadmap does not indicate an immediate discontinuation of the 2023 edition, nor does it define a binding end date for the transition phase. Organizations planning a recertification in 2026 or 2027 should therefore align their planning with both their certification body and the latest BSI guidance.
IT-Grundschutz vs Grundschutz++
| Area | Current Methodology | Grundschutz++ |
|---|---|---|
| Format | PDF-based | OSCAL JSON |
| Structure | Modules | Practices |
| Updates | Manual | Machine-readable |
| Evidence | Mostly document-driven | Data-driven |
| Automation | Limited | Stronger support |
| Certification | Available | Expected from 2027 |
What impact does Grundschutz++ have on an existing ISMS?
An established ISMS does not become obsolete because of Grundschutz++. Quite the opposite. Organizations that have already structured their scope, asset and risk ownership, policies, measures, audit processes and evidence management effectively already possess the most important foundational information
The following elements can typically be reused:
- The defined ISMS scope
- The inventory of information assets, processes, applications, infrastructure and service providers
- Roles and approval workflows
- Risk and exception management procedures
- Implementation plans, findings and remediation tracking
- Technical and organisational evidence
What does need to be reconsidered is the underlying data and process logic. Documents should no longer be viewed purely as finished files. What matters is whether an organization can properly manage and relate information: Which requirement applies in which context? Who is responsible? What demonstrates implementation? When was evidence last reviewed? Which catalogue change affects us?
Grundschutz++ can support a more consistent organization of evidence and regulatory requirements. The planned certification remains an ISO 27001 certification based on IT Baseline Protection. It does not replace NIS2 applicability assessments or the independent evaluation of other regulatory obligations.
Preparing for Grundschutz++: Five practical steps for organizations
Establish a reliable scope and information domain
Verify that your structural data reflects today’s reality, including cloud and SaaS services, outsourced operations, interfaces, user accounts and permissions. Also document data flows and critical dependencies. An outdated asset inventory will not improve simply because OSCAL is introduced.
Link responsibilities to processes and evidence
Assign owners not only for assets but also for risks, security processes and evidence. A requirement only becomes manageable when it is clear who decides, who implements and who validates effectiveness.
Structure evidence
Create an evidence inventory. Map policies, tickets, logs, technical metrics and audit reports to relevant requirements. Track version, validity, source and review date. This is already worthwhile regardless of the final Grundschutz++ specification.
Evaluate ISMS and GRC Platforms
Ask vendors specifically about OSCAL import and export functionality, version comparison, profile creation, parameterisation, API integration and complete audit trails. Request demonstrations of actual product capabilities and export options. Avoid solutions that store data exclusively in proprietary formats and unnecessarily complicate future migrations.
Select a limited Pilot Scope
Start with a manageable but meaningful area, such as a cloud service, a critical business process or a clearly defined platform. Map existing controls and evidence to the pilot catalogue. Document not only control gaps but also issues involving data, ownership and tooling. Only then can the effort required for a broader migration be estimated realistically.
Which tools are suitable for Grundschutz++? Key selection criteria
Grundschutz++ is often presented primarily as a tooling topic. That view is too narrow, but tool selection can either significantly simplify or permanently hinder the transition. At a minimum, organizations should be able to answer the following questions:
- Can the platform natively import and export OSCAL JSON??
- Can catalogue versions and changes be compared transparently?
- Can profiles, parameters and organization-specific additions be managed separately?
- Can evidence from ticketing systems, cloud platforms, IAM, vulnerability management and SIEM solutions be connected?
- Are decisions, exceptions, approvals and review histories retained in an audit-proof manner?
- Is it possible to change platforms without rebuilding the entire control and evidence model?
This list is not exhaustive, but it provides a solid starting point before evaluating the full functionality and additional selection criteria of a GRC or ISMS platform.
Conclusion on Grundschutz++: Prepare now and pilot in a controlled way
Grundschutz++ has the potential to resolve several long-standing challenges within the traditional methodology. The State-of-the-Art Library and OSCAL create a foundation for processing security requirements more quickly, identifying changes more efficiently and organizing evidence more consistently.
The transition is not automatic. It shifts effort away from redundant document maintenance and towards structured data management, clear accountability, integration-ready tooling and verifiable effectiveness.
The practical approach is therefore clear: organize the fundamentals, select a pilot area, monitor BSI developments and reassess after the pilot phase. This ensures that Grundschutz++ becomes the logical evolution of a functioning ISMS rather than the next compliance project lost in a big-bang migration.
How well prepared is your ISMS for Grundschutz++
We assess your scope, roles, evidence model and tooling landscape and develop a robust readiness and migration roadmap aligned with ISO 27001, IT Baseline Protection and your regulatory requirements.
Sources:
[1] BSI: Grundschutz++ – Milestones and Current Status
[2] BSI: Pilot Implementation of Grundschutz++ in the User Catalog
[3] BSI: State-of-the-Art Library
[4] BSI: Grundschutz++ User Catalog, OSCAL/JSON, as of June 24, 2026
[5] BSI: IT-Grundschutz++ – Current Scope of the Digital Catalog
Frequently Asked Questions about Grundschutz++
No. Grundschutz++ is not a law and, as of July 2026, remains in the pilot phase. The BSI roadmap schedules the end of the pilot phase for 30 September 2026, publication of the methodology at it-sa from 27–29 October 2026 and certification applications from 1 January 2027.
No. The current BSI roadmap does not indicate an immediate withdrawal of the 2023 edition. As of July 2026, a binding end date for the transition phase has not yet been published. Existing ISMS structures and evidence repositories should therefore not be discarded prematurely.
OSCAL is an open, machine-readable data model for security requirements and compliance information. The BSI uses OSCAL to provide catalogues in structured JSON format through the State-of-the-Art Library. JSON is a lightweight data format that makes information directly consumable by software applications.
According to the current BSI status, Grundschutz++ contains 921 requirements organised into 19 practices. Because the pilot phase is ongoing and the library continues to evolve, this figure should be viewed as a snapshot and verified again before publication or project planning.
It provides machine-readable BSI security requirements in OSCAL/JSON format and maintains version control. The Grundschutz++ user catalogue is a central component. The library supports a data-centric compliance process but does not replace the assessment of which requirements apply in a specific context.
No. Grundschutz++ replaces neither ISO 27001 nor legal obligations under NIS2. The planned BSI certification remains an ISO 27001 certification based on IT Baseline Protection. Applicability assessments, risk assessments and other regulatory obligations remain the responsibility of the organisation.
They should update their scope and asset inventory, clarify responsibilities, structure evidence, evaluate OSCAL readiness within their tools and select a limited pilot area. In most cases, a full migration before the pilot phase concludes is not advisable.
As of July 2026, the BSI has not yet published a binding deadline. In practical terms this means: prepare in 2026, pilot against the finalised methodology from 2027 onward and align migration planning with the published transition roadmap.
The pilot phase ends on 30 September 2026. The methodology is expected to be published at it-sa from 27–29 October 2026, and certification applications based on Grundschutz++ are expected to be possible from 1 January 2027. Additional transition deadlines should always be verified against the latest BSI guidance before making planning decisions.
A fully automated migration should not be expected. The core challenge is mapping existing structures, responsibilities and evidence to new practices and requirements. The workload depends heavily on the quality of the existing data. Reliable estimates can only be made after a limited pilot mapping exercise.
There are currently no official benchmarks because the methodology is still being piloted. As a planning assumption, a limited pilot may take several months, while the complete transition of a mature ISMS may span multiple phases. This is not a BSI requirement but depends on scope, data quality, resources and tool support.
The decisive factor is not the vendor but the platform’s ability to work with machine-readable catalogues: OSCAL import and export, version and delta comparisons, profile creation, parameterisation and the ability to link evidence directly to requirements. Product capabilities should always be validated in practice before making a decision.
The most valuable support comes from organisations that understand both the established IT Baseline Protection methodology and certification processes as well as the new data-driven approach. SITS supports organisations from initial assessments through pilot projects to certification preparation.
Yes. A readiness assessment based on the five preparation steps, scope, responsibilities, evidence, tooling capability and pilot scope, reveals the current maturity of the ISMS and identifies the gaps that should be addressed before transition. The result is a prioritised roadmap for migration and continuous improvement.













