BSI IT-Grundschutz

Get certified and keep it running

evoila guides German organisations through BSI IT-Grundschutz from gap analysis to certification, with the engineering depth to make the controls real.


A standard that rewards experience

For public-sector organisations, KRITIS operators and many German enterprises, BSI IT-Grundschutz is the expected standard for information security. It is thorough and methodical, which is exactly why it becomes difficult for teams trying to handle it alone.

evoila has delivered IT-Grundschutz projects in demanding environments and brings both the BSI methodology and the technical capability to implement the measures properly. We help you scope the right information network, model the environment correctly and close the gaps in a way that stands up in certification.

We can also support ISO 27001 certification on the basis of IT-Grundschutz.

Business benefits:

  • A structured path through IT-Grundschutz, from scoping to certification
  • Controls that are technically implemented, not just documented
  • Deep fit for public sector, KRITIS and German enterprise requirements

IT-Grundschutz projects that stall usually fail in the same two places

Scoping that was never right, and documentation that looks complete until an auditor reviews it. Both can be avoided with the right experience on the project from the beginning.

The Challenge

What needs to be right from the start

IT-Grundschutz is comprehensive by design. The Grundschutz-Kompendium covers a broad set of modules, and modelling an information network correctly, selecting the right building blocks and producing audit-ready documentation takes method, experience and time.
Public-sector and KRITIS organisations often have to comply, but rarely have spare capacity with deep Grundschutz experience. The typical consequences are easy to recognise.

Scoping and modeling take time

If the information network boundaries are wrong from the start, the result is often months of rework. Correct scoping is the single most important starting point in any IT-Grundschutz project.

Documentation can pass the first review and fail the audit

Documentation that looks complete internally often does not survive external certification review. Audit-ready means more than thorough. It means structured, traceable and defensible.

Technical controls need more than a concept

Many projects define safeguards that are never properly implemented in the real environment. A concept without implementation leaves the actual risk in place.

Compliance obligations are non-negotiable

For KRITIS operators and many public-sector organisations, IT-Grundschutz is not optional. Delays or gaps create direct regulatory exposure.

The good news:
IT-Grundschutz rewards experience.

Organisations that bring the right method and engineering depth in from the start typically reach certification more efficiently and avoid unnecessary detours.

Our Solution

Full support from concept to certificate


evoila supports the full IT-Grundschutz lifecycle and adapts the depth to your goal, whether that is a structured security concept or full certification.
We bring both the BSI methodology and the engineering capability to implement the measures. That is where many consultancies stop. Because evoila also builds and operates the platforms underneath, our security concepts reflect systems that actually exist, and the safeguards we specify are ones we can help you implement. Our services include:

Structure analysis and scoping

Defining the information network and getting the boundaries right from the start.

Modeling with the Grundschutz-Kompendium

Selecting and applying the right building blocks for your environment.

Gap analysis and risk treatment

Comparing target and actual state, then defining the measures that close the gap.

Implementation support

Putting technical and organisational safeguards in place with our security engineering teams.

Certification path

Preparing for and supporting ISO 27001 certification on the basis of IT-Grundschutz.

Grundschutz-ready platforms

Designing and securing private cloud and infrastructure environments to meet Grundschutz requirements.

Tech-Deep-Dive

The IT-Grundschutz process in practice

evoila follows the BSI methodology and keeps it grounded in the real environment.

Standards and method

We work along the BSI 200-x standards: 200-1 for the management system, 200-2 for the IT-Grundschutz methodology and 200-3 for risk analysis. Depending on your protection needs, we apply the basic, standard or core safeguard approach so the effort matches the requirement.

Modeling

Using the Grundschutz-Kompendium, we model your information network with the appropriate building blocks, covering infrastructure, networks, applications and operations. Correct modelling at this stage is what keeps the whole project efficient.

Risk treatment

Where protection needs are high or there is no matching module, we carry out a risk analysis in line with BSI Standard 200-3 and define supplementary safeguards.

Implementation and platforms

This is a key differentiator. We do not stop at the concept. Our engineering teams implement the technical safeguards and can build private cloud and platform environments that are Grundschutz-ready by design.

Container & Kubernetes Security

Certification

Where certification is required, we prepare the reference documentation and support you through ISO 27001 certification on the basis of IT-Grundschutz.

Technical Advantages

Six reasons why IT-Grundschutz works with evoila

1. Right-sized effort

Basic, standard or core safeguard approaches matched to your actual protection needs.

2. Efficient modeling

Correct building-block selection from the start avoids months of rework later.

3. Implemented, not assumed

Safeguards are put in place by engineers, not left behind as paper specifications.

4. Grundschutz-ready platforms

Private cloud and infrastructure built to meet Grundschutz requirements from the ground up.

5. Audit-ready documentation

Every concept is prepared to withstand certification review, not just internal sign-off.

6. NIS2 and KRITIS alignment

A properly built IT-Grundschutz concept covers much of the evidence needed for NIS2 and KRITIS obligations at the same time.

Your partner of choice

Grundschutz experience with engineering behind it

evoila has delivered IT-Grundschutz projects in demanding German environments, so the method we bring has been tested in real audits, not just described in theory.
The difference is the engineering depth behind the concept. Because we build and operate private cloud and platform infrastructure, we can deliver environments that are Grundschutz-ready and implement the safeguards the concept requires.
We work along the BSI 200-x standards and the Grundschutz-Kompendium, and evoila is itself ISO 27001 certified. For organisations that also face NIS2 requirements, the same work supports those obligations as well.

ISO 27001 certified organisation

We hold the certificate ourselves. Our security concepts are built by a team that works under the same standard we help you achieve.

BSI 200-x methodology applied in production

We use BSI Standard 200-1, 200-2 and 200-3 in real projects, not as a theoretical reference but as the method behind the work.

Engineering teams that implement, not just advise

Our security engineers put the safeguards in place. No handover to a separate implementation team, and no accountability gap between concept and reality.

KRITIS and public-sector project track record

We have delivered IT-Grundschutz projects in environments where compliance is mandatory and audits are real. The method we bring has already been tested under those conditions.

Technologies & Partners

How we work and with whom

We work tool-agnostically and align requirements with recognised frameworks such as ISO 27001 and BSI IT-Grundschutz. Technical measures are implemented together with evoila’s security engineering and managed-services teams. Because evoila is ISO 27001 certified, the work is grounded in an audited operating model.


Services & Starter Deals

Start the way that works best for you

1 | IT-Grundschutz Readiness Check

A fixed-scope assessment that clarifies your scope, identifies key gaps and provides a prioritised path towards certification.

2 | IT-Grundschutz Project

End-to-end support from structure analysis and modelling through implementation to certification support – built around your organisation, systems and compliance requirements.

IT-Grundschutz does not get easier by waiting

Get the scope right, close the gaps and reach certification with a team that has done it before.

Let’s turn IT-Grundschutz into real security

Tell us where you are today and we will help you define the path to compliance and certification.

FAQs

Commonly asked questions about BSI IT-Grundschutz