BSI IT-Grundschutz for SMBs

BSI IT-Grundschutz for SMBs: Do you actually need it?

Is BSI IT-Grundschutz mandatory for your SMB? Learn how it relates to ISO 27001 and NIS2, when it's required, and which core measures matter most.

200+ companies already trust deeploi

Direct Answer

BSI IT-Grundschutz is the German Federal Office for Information Security's methodology for building and running an information security management system. For most private companies with 30 to 150 employees, it is not a legal obligation. It becomes relevant when a public tender, a regulated customer or a specific certification goal calls for it. For everyone else, the useful move is to implement its core measures (device management, patching, access control, backups, documented processes) and to clarify whether NIS2 applies to you.

Key Takeaways

  • Check your contracts and tenders first, and adopt IT-Grundschutz only where one of them names it.

  • Run a NIS2 scope check this quarter, since management carries personal responsibility for implementation once you are in scope.

  • Implement the core measures now, because they answer most questionnaires, insurers and auditors without any certificate.

  • Pick the lightest framework your customers accept, then scale up when a deal or a regulator forces the question.

  • Automate the evidence trail so proof is a byproduct of daily operations rather than a project before each audit.

What BSI IT-Grundschutz actually is

IT-Grundschutz is a methodology, not a product and not a single checklist. The BSI (Bundesamt für Sicherheit in der Informationstechnik, Germany's federal cybersecurity authority) publishes it as a structured way to build an information security management system, or ISMS: the roles, policies and recurring processes that govern how your organization protects information.

Two components make up the framework. The BSI Standards 200-1, 200-2 and 200-3 describe the management system, the implementation methodology and the risk analysis. The IT-Grundschutz-Kompendium then adds modules, known as Bausteine, each covering one topic such as clients, servers, cloud usage or backups, together with the typical threats and the requirements that address them.

The three implementation paths

Your choice of path decides how much work you are signing up for.

  • Basis-Absicherung: an entry level that applies basic requirements broadly across the organization. Good for companies starting from scratch.
  • Standard-Absicherung: the complete methodology, including risk analysis and full documentation. This is the basis for certification.
  • Kern-Absicherung: a focused approach that secures the few assets whose loss would hurt most, before widening the scope.

Protection requirement categories

People often confuse the three paths with the three protection requirement categories, which are a separate concept. Each business process and system gets classified as normal, high or very high, depending on what damage a loss of confidentiality, integrity or availability would cause. That classification drives how deep your measures need to go, not which implementation path you follow.

How does IT-Grundschutz relate to ISO 27001 and NIS2?

Two routes lead to an ISO 27001 certificate in Germany. The native route audits your management system against ISO 27001 and the Annex A controls, and an accredited certification body signs off. The alternative, "ISO 27001 on the basis of IT-Grundschutz", uses the BSI methodology as the implementation path and is certified under the BSI's own scheme. Most small and mid-sized companies choose the native route, because international customers recognize it immediately and the documentation load is lighter.

NIS2 is a different question entirely. In Germany the NIS2 implementation act (NIS2UmsuCG) has been in force since December 6, 2025, and it rewrote the BSIG. Section 30 BSIG requires risk management measures according to the state of the art and names concrete areas: risk analysis, incident handling, business continuity, supply chain security, cryptography, multi-factor authentication and more. Nothing in that text prescribes IT-Grundschutz. The BSI framework is one recognized way to get there, and so is ISO 27001. If you are weighing both, our breakdown of the difference between NIS2 and ISO 27001 maps where they overlap and where they do not.

When does IT-Grundschutz actually become relevant?

For a private company, IT-Grundschutz is almost never a legal duty. It arrives through contracts.

Public sector work and regulated supply chains

IT-Grundschutz is binding for the German federal administration, and authorities routinely expect the same discipline from the IT service providers who work for them. Public tenders sometimes name it explicitly, or they ask for ISO 27001 on the basis of IT-Grundschutz as an equivalent proof. Operators of critical infrastructure (KRITIS) face their own evidence obligations and may use sector-specific security standards, the B3S, instead of IT-Grundschutz.

Suppliers to those organizations inherit the pressure. In the automotive supply chain, the requirement that lands on your desk is usually TISAX rather than anything from the BSI. The practical lesson is the same: read the contract or the tender document before you decide which framework to adopt, because the requirement is rarely what you assumed.

Security questionnaires and cyber insurance

Most SMBs meet these expectations for the first time through a supplier security questionnaire from a large customer, or through a cyber insurance application. Both ask the same style of question: who administers your devices, how fast do you patch, who has admin rights, when did you last test a restore, who do you call at 2am.

Neither one demands a certificate by default. They demand answers you can back up. A credible "no, but here is the plan with an owner and a date" beats an unverifiable yes, because procurement teams increasingly check. If a questionnaire has already landed on your desk, our guide to preparing for your first IT audit in Germany walks through what reviewers ask for.

Which core measures matter regardless of certification?

Strip the frameworks back and the same operational floor appears in all of them. These measures satisfy the bulk of section 30 BSIG, most of Annex A, and almost every customer questionnaire.

  • Device management: a central inventory plus enforced settings for encryption, screen lock and firewall on every laptop and phone.
  • Patch management: automated updates for operating systems and applications, with visibility into which machines lag behind.
  • Access control: least privilege, multi-factor authentication everywhere, and offboarding that actually revokes access on the last day.
  • Backups: separate copies, tested restores, and a documented recovery time expectation.
  • Awareness training: short, regular, and recorded so you can prove attendance.
  • Incident response: a named decision-maker, a contact list and a reporting path, written down before anything breaks.

Patching is where companies underestimate themselves most. Among organisations covered by ENISA's NIS Investments study, 50% named patching as a key NIS2 implementation challenge, ahead of business continuity at 49% and supply-chain risk at 37%, while 28% took more than three months to apply critical patches and 30% had run no cybersecurity assessment in the previous 12 months (European Union Agency for Cybersecurity). Attackers notice: exploitation of vulnerabilities accounted for 20% of initial access vectors in breaches, up 34% from the previous year, and ransomware appeared in 88% of breaches affecting SMBs compared with 39% of breaches at larger organisations (Verizon).

Backups show a similar gap by company size. In 2024, 77.09% of small EU enterprises backed up to a separate location, against 88.48% of medium-sized and 94.95% of large enterprises (Eurostat). Having them is only half the job. Only 54% of ransomware-hit organisations used backups to restore their data, the lowest level in six years of surveys, and 63% said resourcing issues contributed to them falling victim at all (Sophos). For a fuller picture of what to prioritize first, see our overview of IT security measures for SMEs.

Documentation as the thing audits really test

Auditors, insurers and enterprise buyers do not assess intent. They assess evidence. A policy nobody can produce is the same as no policy, and a patch cycle that happens informally cannot be shown to a third party six months later.

That evidence problem is widespread. Only 23% of UK businesses had a formal incident response plan, and 39% had assigned roles for dealing with an incident, in a year when 43% of businesses reported a breach or attack, rising to 67% of medium-sized firms (UK Department for Science, Innovation and Technology). Our walkthrough of the nine ISO 27001 Stage 2 checks shows what a defensible answer looks like in practice, and the same logic applies to a GDPR IT compliance checklist, since Article 32 GDPR obliges every company processing personal data to maintain appropriate technical measures.

How do you choose the right level of effort?

Lighter options versus full certification

There is a ladder between "nothing formal" and a full ISMS, and climbing one rung at a time usually makes more sense than jumping.

  • CyberRisikoCheck (DIN SPEC 27076): a guided assessment designed for companies with fewer than50 employees, delivered by qualified IT service providers. It gives you a prioritized action list rather than a certificate.
  • VdS 10000: a German standard aimed squarely at SMEs, with a lighter requirement set than ISO 27001 and an optional audit. Insurers know it.
  • IT-Grundschutz Basis-Absicherung: a sensible entry point if your customers are public sector bodies or their suppliers, since it speaks the vocabulary they use.
  • ISO 27001: the right answer when a contract demands a certificate, when enterprise sales keep stalling at security review, or when you expect NIS2 evidence obligations.

A 40-person agency with private sector clients rarely needs more than the core measures plus a documented self-assessment. A 120-person software supplier selling into banks, hospitals or energy companies should budget for ISO 27001, because its customers must manage supply chain risk and will push their obligations down the chain.

Where an IT management platform fits

The scarce resource is not the framework, it is the person to run it. 94% of SMEs reported difficulty attracting cybersecurity personnel and 90% reported difficulty retaining them, against 83% and 80% of large enterprises (European Union Agency for Cybersecurity). That is why the operational layer matters more than the paperwork layer for teams of this size.

A platform that handles device management, patching, account lifecycle and logging turns most of these requirements into settings rather than projects. In deeploi, for example, the Controls area includes an ISO 27001 device standard that switches on automatic updates, disk encryption, password rules, screen lock and firewall across managed devices, and each control page shows when a value was set by that standard. The company itself is ISO 27001 certified, hosts in the EU only and offers NIS2 compliance support. Your own certification still runs through an external auditor. Teams building this foundation from zero may also find our notes on security without an IT department and our layered security guide for small businesses useful starting points.

The pragmatic path for most SMBs

IT-Grundschutz is a genuinely good framework. It is also, for the vast majority of German SMBs, optional. The risk it protects against is very real: 22% of EU businesses experienced an ICT security incident with consequences in 2024 (Eurostat), and Bitkom Research found that 87% of German companies were affected by data theft, espionage or sabotage in the preceding 12 months (Bitkom Research). Implement the measures, clarify your legal status, and pursue certification when a customer or contract makes it worth the investment.

Frequently asked questions

Does NIS2 apply to a company with 30 to 150 employees?

It depends on your sector and your size together. The size threshold is reached from 50 employees, or with annual turnover and balance sheet total above 10 million euros, and it only matters if you operate in one of the sectors listed in the annexes of the BSIG. Some services, such as DNS providers and qualified trust service providers, fall in regardless of size. Companies must assess their own status and register with the BSI if they are in scope. Our NIS2 guidance for German SMBs walks through the check.

Is IT-Grundschutz mandatory for my company?

In most cases, no. It is binding for the federal administration and can be imposed contractually through public tenders or supply chain requirements. A contractual requirement is just as real as a legal one for your business, but it applies only to the customers who ask for it.

Can I pass an enterprise security questionnaire without ISO 27001?

Yes, in most cases. Questionnaires typically ask about device encryption, patch cycles, admin rights, MFA, backup and restore testing, offboarding, incident reporting and subprocessors. Documented answers with evidence behind them are usually accepted, and open gaps paired with a dated remediation plan are accepted more often than people expect.

What are management's obligations under NIS2?

For companies in scope, section 38 BSIG requires the management body to approve and monitor the risk management measures and to take part in regular training. Culpable breaches of that duty create liability. Independently of NIS2, Article 32 GDPR obliges every company that processes personal data to maintain appropriate technical and organizational measures.

Where should I start without an IT department?

Start with central device management, automated patching and multi-factor authentication, because those three close the gaps attackers use most. Add a tool that produces audit-ready records automatically, so evidence accumulates on its own. A CyberRisikoCheck is a structured, affordable way to get an outside view of where you stand.

Founded
Customer Size
Headquarters
Industry
KEY RESULTS
CUSTOMER STORIES
This field is required
This field is required
This field is required
Choose
This field is required
This field is required
Thank you for your interest!

We’ll get back to you shortly.

Oops! Something went wrong while submitting the form.

Download the professional onboarding checklist for free

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Get the checklist