← All Articles

BSI Grundschutz vs ISO 27001 — Which AI Agents Cover What

February 24, 2026 · 25 min read

Two frameworks operating within one organisation can consume four months of audit preparation time — or eight seconds per control check using automated systems.

The Regulatory Landscape in Germany

BSI IT-Grundschutz is mandatory for:

  • KRITIS operators under BSI-KritisV
  • Federal authorities under BSI-Gesetz §8a
  • Defence sector and classified systems
  • Länder-level public sector entities

ISO 27001 is mandatory for:

  • Organisations seeking ISMS certification
  • Financial sector (increasingly under DORA)
  • Enterprise supply chains (automotive TISAX)
  • Cloud providers serving regulated customers

Framework Architecture

BSI IT-Grundschutz ISO 27001:2022
StructurePrescriptive building blocks (111 Bausteine)Risk-based ISMS + 93 Annex A controls
Approach3 protection tiers (Basis/Standard/Kern)Scope → Risk → SoA → Implement → Certify
Risk methodBSI 200-3 (simplified)Any recognised method
CertificationBSI-approved auditors only (~120)Any accredited CAB (DAkkS)
Cycle3-year + annual maintenance3-year + annual surveillance
LanguageGerman requiredEnglish primary
Key differentiatorPrescriptive safeguards per BausteinRisk-based flexibility; SoA exclusions
Approximately 85% of ISO controls have direct Grundschutz equivalents. The remaining 15% (particularly new 2022 controls like threat intelligence, cloud services, data masking) require separate evidence.

Control Mapping by Layer

Layer 1: ISMS (Management System)

ISMS.1 — Sicherheitsmanagement maps to ISO Clauses 4–10 + A.5.1, A.5.2, A.5.35. Covered by the GRC Agent — risk registers, treatment plans, management review documentation. The GRC Agent generates board briefings in 15 seconds for 7 data categories.

Layer 2: ORP (Organisation and Personnel)

BSI Baustein ISO 27001 Agent
ORP.1 — OrganisationA.5.2, A.5.3, A.5.4, A.5.36Compliance
ORP.2 — PersonalA.6.1–A.6.5Security Awareness
ORP.3 — SensibilisierungA.6.3Security Awareness
ORP.4 — IAMA.5.15–A.5.18, A.8.2IAM Governance
ORP.5 — Compliance MgmtA.5.31, A.5.36, A.5.37Compliance

Layer 3: CON (Concepts and Procedures)

BSI Baustein ISO 27001 Agent
CON.1 — KryptokonzeptA.8.24Security Architecture
CON.2 — DatenschutzA.5.34, GDPRPrivacy
CON.3 — DatensicherungA.8.13Security Architecture
CON.8 — Software-EntwicklungA.8.25–A.8.31AppSec
CON.9 — InformationsaustauschA.5.14Policy

Layer 4: OPS (Operations)

BSI Baustein ISO 27001 Agent
OPS.1.1.3 — Patch MgmtA.8.8Vuln Management
OPS.1.1.4 — MalwareA.8.7SOC/MDR
OPS.1.1.5 — ProtokollierungA.8.15, A.8.16SOC/MDR
OPS.1.2.3 — VorfallmanagementA.5.24–A.5.28Incident Response
OPS.2.1/2.3 — OutsourcingA.5.19–A.5.22Vendor Risk
OPS.2.2 — Cloud-NutzungA.5.23Vendor Risk + SecArch

The Cost Comparison

Manual Compliance (Both Frameworks)

Internal headcount + external costs

€560–640K

Year 1 total

€450–510K/yr

Ongoing (Year 2+)

AI-Assisted (Security Factory)

5 agents + human oversight + certification

€350–400K

Year 1 total

€325–365K/yr

Ongoing (Year 2+)

CFO-ready: Running both frameworks manually costs €450–510K/yr. Security Factory compliance bundle runs €325–365K/yr. Savings: ~€130–150K/yr. Additional: audit-readiness every day instead of four months before audit.

The 2022 ISO Controls BSI Doesn’t Yet Cover

  • A.5.7 — Threat intelligence: No dedicated Baustein → Threat Intel Agent
  • A.5.23 — Cloud services security: OPS.2.2 less prescriptive → Vendor Risk + SecArch Agents
  • A.5.30 — ICT readiness for BCM: DER.4 partial → GRC + Compliance Agents
  • A.8.10 — Information deletion: CON.6 covers physical only → Privacy Agent
  • A.8.11 — Data masking: No equivalent → Security Architecture Agent
  • A.8.23 — Web filtering: Partial NET coverage → SOC/MDR Agent
  • A.8.12 — Data leakage prevention: No Baustein → AppSec + SecArch Agents

KRITIS Deployment Priority

Phase 1 (Months 1–3): Grundschutz Core

Deploy GRC Agent + Compliance Agent. Map existing controls to BSI Bausteine. The Compliance Agent processes a 50-control gap register in 8 seconds.

Phase 2 (Months 3–6): Operational Evidence

Add Incident Response, IAM Governance, and Policy Agents. These generate evidence BSI auditors scrutinise most.

Phase 3 (Months 6–12): Full Coverage

Add remaining agents based on audit scope. For ISO dual-cert, prioritise Vendor Risk Agent and Security Awareness Agent.

Phase 4 (Ongoing): AI Governance

AI Governance Agent for BSI AI Bausteine (expected 2025/2026) and EU AI Act enforcement.

What US Tools Miss

Drata, Vanta, and Secureframe cover SOC 2 well. They do not cover:

  • BSI IT-Grundschutz — zero coverage, no Baustein mapping, no German-language docs
  • NIS2UmsuCG — the German NIS2 implementation law
  • TISAX — VDA ISA assessment for automotive
  • Betriebsrat requirements — BetrVG §87 and §90 for AI agent deployment
  • BDSG — German Federal Data Protection Act layered on GDPR
Security Factory is built for German enterprises with German regulatory context embedded. This means generating compliant NIS2UmsuCG incident reports your German lawyer can actually use.

Need help implementing this?

First strategy session is complimentary. We typically respond within 4 hours.