All articles

Grundschutz++ implementation timeline: what changes, and when

The BSI is replacing the IT-Grundschutz Compendium with a machine-readable, OSCAL-based framework. Here is the timeline every ISMS team needs to know.

Pinnipedia Technologies

On 1 January 2026 the BSI officially introduced Grundschutz++, a structural overhaul of the IT-Grundschutz framework. The reform replaces the document-centric Compendium with a machine-readable catalogue built on OSCAL — the Open Security Controls Assessment Language maintained by NIST. For every organisation that runs an ISMS based on IT-Grundschutz, the transition is not optional. It is a question of timing.

This article lays out the confirmed milestones, explains what changes structurally, and outlines the decisions ISMS teams should make now.

The timeline so far

October 2024 — public unveiling at it-sa

BSI President Claudia Plattner presented Grundschutz++ at the it-sa Expo&Congress in Nuremberg, framing it as a fundamental paradigm shift toward a fully digitalised regulatory framework. The launch date of 1 January 2026 was confirmed at this event.

August 2025 — public comment period

The BSI ran a 30-day public comment period under the banner "30 Tage, 1 Kompendium, 200 Meinungen" (30 days, 1 compendium, 200 opinions), inviting expert feedback on the draft Grundschutz++ catalogue.

29 September 2025 — Stand-der-Technik-Bibliothek on GitHub

The BSI published the Grundschutz++ compendium preview on GitHub at BSI-Bund/Stand-der-Technik-Bibliothek in OSCAL format (JSON and XML). This marked the first time the authoritative IT-Grundschutz source was a version-controlled data repository rather than a PDF or Word document.

1 January 2026 — official introduction

Grundschutz++ went live. The first artefacts were published and the framework became a concrete, published standard.

1 April 2026 — Methodikleitfaden and piloting phase

The methodology guide (Leitfaden zur Grundschutz++-Methodik, version 1.4.2026) was published and the formal piloting phase began. The guide replaces BSI Standards 200-2 and 200-3 as the procedural backbone of a Grundschutz-based ISMS. The BSI explicitly scoped this guide for pilot and testing projects, not for immediate migration of existing certifications.

What comes next

DateMilestone
30 September 2026Piloting phase concludes
27 October 2026Public presentation at it-sa 2026, Nuremberg
31 October 2026New training curriculum published
1 November 2026Advanced certifications for already-certified professionals
1 January 2027ISO 27001 certification under Grundschutz++ available
Q1 2027Performance measurement concepts integrated
2027+International expansion; integration of other management systems

Source: BSI official milestone plan, published 26 March 2026.

What changes structurally

Grundschutz++ is not a revision of the old Compendium. It is a different architecture.

From Bausteine to Praktiken

The roughly 111 Bausteine of the 2023 Compendium are consolidated into 19 Praktiken covering 53 target object categories. Each Praktik groups related controls at a higher level of abstraction. The total number of individual requirements drops from approximately 6,567 to around 985 — an 85% reduction.

Two protection levels, not three

The old model defined three qualification levels: Basis, Standard, and Erhöht. Grundschutz++ replaces this with a quantified scoring system where requirements contribute numeric points across confidentiality, integrity, and availability. Organisations meet compliance by reaching defined threshold values.

OSCAL as the native format

The entire catalogue is published in OSCAL version 1.1.3 format through the BSI's GitHub repository. Three catalogue files were released: a methodology catalogue, a kernel catalogue, and a combined user catalogue. The format supports JSON and XML serialisation, with JSON as the primary format for web-based tooling.

Blaupausen replace profiles

The old IT-Grundschutz profiles — pre-configured templates for archetypes such as e-file, 5G, or municipal utilities — become Blaupausen. Unlike profiles, Blaupausen are machine-readable configurations that tools can apply automatically to target objects.

Built-in cross-references

Grundschutz++ includes native mappings to ISO 27001:2022 and NIS2. These are embedded in the OSCAL data model with universally unique identifiers, enabling one implementation — for example, multi-factor authentication — to satisfy requirements across Grundschutz++, ISO 27001, NIS2, TISAX, and DORA simultaneously.

Continuous updates

The old Compendium followed an annual release cycle. Grundschutz++ is versioned continuously through the GitHub repository, allowing the BSI to publish updates in response to emerging threats without waiting for a yearly edition.

The transition window

The BSI has defined a multi-year parallel validity period. The 2023 Compendium and Grundschutz++ will both be accepted for certification until the parallel period ends. Current guidance points to late 2028 or early 2029 as the transition deadline. A hard cutoff for certifications under the old standard is set at 2031 — after that date, no information networks will be certified under IT-Grundschutz Edition 2023.

The 2023 Compendium will receive no further content updates during the transition phase. It remains valid for certification purposes but is effectively frozen.

Tool vendor readiness

ISMS tool vendors are at different stages of Grundschutz++ adoption:

  • verinice: Grundschutz++ beta targeted for 2027, production in 2028
  • Hugo (fraghugo.de): full conformance targeted for Q3 2027
  • opus i: Grundschutz++ support planned for 2028

Tool vendors estimate that migration wizards can handle roughly 60–70% of requirement mapping automatically. The remaining 30–40% requires manual reassessment — a meaningful effort that grows if left until the end of the transition window.

What to decide now

1. Evaluate your tooling

ISMS tools built on the PDF-plus-spreadsheets paradigm of the 2023 Compendium need to add OSCAL ingestion, a Praktiken model, and machine-readable evidence linking. The longer your current tool takes to get there, the more manual effort the transition costs.

2. Map your Bausteine to Praktiken

The consolidation from 111 Bausteine to 19 Praktiken changes how requirements are grouped and referenced. Existing Sicherheitskonzepte need to be remapped. Starting this mapping now, while the parallel period allows both frameworks, avoids a compressed migration later.

3. Check your ISO 27001 alignment

If your organisation also certifies against ISO 27001, the built-in cross-references in Grundschutz++ simplify dual compliance — but only if your data model can represent both frameworks structurally. Document-based processes will need to be rebuilt.

How OrbisGraph handles the transition

OrbisGraph is built as a knowledge graph, not a document store. The same graph-native architecture that models the 2023 Compendium today maps directly to the OSCAL-based Grundschutz++ structure. Sicherheitskonzepte written in OrbisGraph today convert when the new format ships — migration, not restart.

The built-in ISO 27001 and NIS2 cross-references in Grundschutz++ align with how OrbisGraph already represents relationships between frameworks. For organisations using OrbisGraph, the transition to Grundschutz++ is a serialisation exercise, not a rewrite.


This article reflects publicly available BSI publications as of July 2026. Pinnipedia Technologies will update this timeline as the BSI releases further Grundschutz++ milestones.