Grundschutz++ implementation timeline: what changes, and when
The BSI is replacing the IT-Grundschutz Compendium with a machine-readable, OSCAL-based framework. Here is the timeline every ISMS team needs to know.
Pinnipedia TechnologiesOn 1 January 2026 the BSI officially introduced Grundschutz++, a structural overhaul of the IT-Grundschutz framework. The reform replaces the document-centric Compendium with a machine-readable catalogue built on OSCAL — the Open Security Controls Assessment Language maintained by NIST. For every organisation that runs an ISMS based on IT-Grundschutz, the transition is not optional. It is a question of timing.
This article lays out the confirmed milestones, explains what changes structurally, and outlines the decisions ISMS teams should make now.
The timeline so far
October 2024 — public unveiling at it-sa
BSI President Claudia Plattner presented Grundschutz++ at the it-sa Expo&Congress in Nuremberg, framing it as a fundamental paradigm shift toward a fully digitalised regulatory framework. The launch date of 1 January 2026 was confirmed at this event.
August 2025 — public comment period
The BSI ran a 30-day public comment period under the banner "30 Tage, 1 Kompendium, 200 Meinungen" (30 days, 1 compendium, 200 opinions), inviting expert feedback on the draft Grundschutz++ catalogue.
29 September 2025 — Stand-der-Technik-Bibliothek on GitHub
The BSI published the Grundschutz++ compendium preview on GitHub at BSI-Bund/Stand-der-Technik-Bibliothek in OSCAL format (JSON and XML). This marked the first time the authoritative IT-Grundschutz source was a version-controlled data repository rather than a PDF or Word document.
1 January 2026 — official introduction
Grundschutz++ went live. The first artefacts were published and the framework became a concrete, published standard.
1 April 2026 — Methodikleitfaden and piloting phase
The methodology guide (Leitfaden zur Grundschutz++-Methodik, version 1.4.2026) was published and the formal piloting phase began. The guide replaces BSI Standards 200-2 and 200-3 as the procedural backbone of a Grundschutz-based ISMS. The BSI explicitly scoped this guide for pilot and testing projects, not for immediate migration of existing certifications.
What comes next
| Date | Milestone |
|---|---|
| 30 September 2026 | Piloting phase concludes |
| 27 October 2026 | Public presentation at it-sa 2026, Nuremberg |
| 31 October 2026 | New training curriculum published |
| 1 November 2026 | Advanced certifications for already-certified professionals |
| 1 January 2027 | ISO 27001 certification under Grundschutz++ available |
| Q1 2027 | Performance measurement concepts integrated |
| 2027+ | International expansion; integration of other management systems |
Source: BSI official milestone plan, published 26 March 2026.
What changes structurally
Grundschutz++ is not a revision of the old Compendium. It is a different architecture.
From Bausteine to Praktiken
The roughly 111 Bausteine of the 2023 Compendium are consolidated into 19 Praktiken covering 53 target object categories. Each Praktik groups related controls at a higher level of abstraction. The total number of individual requirements drops from approximately 6,567 to around 985 — an 85% reduction.
Two protection levels, not three
The old model defined three qualification levels: Basis, Standard, and Erhöht. Grundschutz++ replaces this with a quantified scoring system where requirements contribute numeric points across confidentiality, integrity, and availability. Organisations meet compliance by reaching defined threshold values.
OSCAL as the native format
The entire catalogue is published in OSCAL version 1.1.3 format through the BSI's GitHub repository. Three catalogue files were released: a methodology catalogue, a kernel catalogue, and a combined user catalogue. The format supports JSON and XML serialisation, with JSON as the primary format for web-based tooling.
Blaupausen replace profiles
The old IT-Grundschutz profiles — pre-configured templates for archetypes such as e-file, 5G, or municipal utilities — become Blaupausen. Unlike profiles, Blaupausen are machine-readable configurations that tools can apply automatically to target objects.
Built-in cross-references
Grundschutz++ includes native mappings to ISO 27001:2022 and NIS2. These are embedded in the OSCAL data model with universally unique identifiers, enabling one implementation — for example, multi-factor authentication — to satisfy requirements across Grundschutz++, ISO 27001, NIS2, TISAX, and DORA simultaneously.
Continuous updates
The old Compendium followed an annual release cycle. Grundschutz++ is versioned continuously through the GitHub repository, allowing the BSI to publish updates in response to emerging threats without waiting for a yearly edition.
The transition window
The BSI has defined a multi-year parallel validity period. The 2023 Compendium and Grundschutz++ will both be accepted for certification until the parallel period ends. Current guidance points to late 2028 or early 2029 as the transition deadline. A hard cutoff for certifications under the old standard is set at 2031 — after that date, no information networks will be certified under IT-Grundschutz Edition 2023.
The 2023 Compendium will receive no further content updates during the transition phase. It remains valid for certification purposes but is effectively frozen.
Tool vendor readiness
ISMS tool vendors are at different stages of Grundschutz++ adoption:
- verinice: Grundschutz++ beta targeted for 2027, production in 2028
- Hugo (fraghugo.de): full conformance targeted for Q3 2027
- opus i: Grundschutz++ support planned for 2028
Tool vendors estimate that migration wizards can handle roughly 60–70% of requirement mapping automatically. The remaining 30–40% requires manual reassessment — a meaningful effort that grows if left until the end of the transition window.
What to decide now
1. Evaluate your tooling
ISMS tools built on the PDF-plus-spreadsheets paradigm of the 2023 Compendium need to add OSCAL ingestion, a Praktiken model, and machine-readable evidence linking. The longer your current tool takes to get there, the more manual effort the transition costs.
2. Map your Bausteine to Praktiken
The consolidation from 111 Bausteine to 19 Praktiken changes how requirements are grouped and referenced. Existing Sicherheitskonzepte need to be remapped. Starting this mapping now, while the parallel period allows both frameworks, avoids a compressed migration later.
3. Check your ISO 27001 alignment
If your organisation also certifies against ISO 27001, the built-in cross-references in Grundschutz++ simplify dual compliance — but only if your data model can represent both frameworks structurally. Document-based processes will need to be rebuilt.
How OrbisGraph handles the transition
OrbisGraph is built as a knowledge graph, not a document store. The same graph-native architecture that models the 2023 Compendium today maps directly to the OSCAL-based Grundschutz++ structure. Sicherheitskonzepte written in OrbisGraph today convert when the new format ships — migration, not restart.
The built-in ISO 27001 and NIS2 cross-references in Grundschutz++ align with how OrbisGraph already represents relationships between frameworks. For organisations using OrbisGraph, the transition to Grundschutz++ is a serialisation exercise, not a rewrite.
This article reflects publicly available BSI publications as of July 2026. Pinnipedia Technologies will update this timeline as the BSI releases further Grundschutz++ milestones.