Two frameworks operating within one organisation can consume four months of audit preparation time — or eight seconds per control check using automated systems.
The Regulatory Landscape in Germany
BSI IT-Grundschutz is mandatory for:
- KRITIS operators under BSI-KritisV
- Federal authorities under BSI-Gesetz §8a
- Defence sector and classified systems
- Länder-level public sector entities
ISO 27001 is mandatory for:
- Organisations seeking ISMS certification
- Financial sector (increasingly under DORA)
- Enterprise supply chains (automotive TISAX)
- Cloud providers serving regulated customers
Framework Architecture
| BSI IT-Grundschutz | ISO 27001:2022 | |
|---|---|---|
| Structure | Prescriptive building blocks (111 Bausteine) | Risk-based ISMS + 93 Annex A controls |
| Approach | 3 protection tiers (Basis/Standard/Kern) | Scope → Risk → SoA → Implement → Certify |
| Risk method | BSI 200-3 (simplified) | Any recognised method |
| Certification | BSI-approved auditors only (~120) | Any accredited CAB (DAkkS) |
| Cycle | 3-year + annual maintenance | 3-year + annual surveillance |
| Language | German required | English primary |
| Key differentiator | Prescriptive safeguards per Baustein | Risk-based flexibility; SoA exclusions |
Control Mapping by Layer
Layer 1: ISMS (Management System)
ISMS.1 — Sicherheitsmanagement maps to ISO Clauses 4–10 + A.5.1, A.5.2, A.5.35. Covered by the GRC Agent — risk registers, treatment plans, management review documentation. The GRC Agent generates board briefings in 15 seconds for 7 data categories.
Layer 2: ORP (Organisation and Personnel)
| BSI Baustein | ISO 27001 | Agent |
|---|---|---|
| ORP.1 — Organisation | A.5.2, A.5.3, A.5.4, A.5.36 | Compliance |
| ORP.2 — Personal | A.6.1–A.6.5 | Security Awareness |
| ORP.3 — Sensibilisierung | A.6.3 | Security Awareness |
| ORP.4 — IAM | A.5.15–A.5.18, A.8.2 | IAM Governance |
| ORP.5 — Compliance Mgmt | A.5.31, A.5.36, A.5.37 | Compliance |
Layer 3: CON (Concepts and Procedures)
| BSI Baustein | ISO 27001 | Agent |
|---|---|---|
| CON.1 — Kryptokonzept | A.8.24 | Security Architecture |
| CON.2 — Datenschutz | A.5.34, GDPR | Privacy |
| CON.3 — Datensicherung | A.8.13 | Security Architecture |
| CON.8 — Software-Entwicklung | A.8.25–A.8.31 | AppSec |
| CON.9 — Informationsaustausch | A.5.14 | Policy |
Layer 4: OPS (Operations)
| BSI Baustein | ISO 27001 | Agent |
|---|---|---|
| OPS.1.1.3 — Patch Mgmt | A.8.8 | Vuln Management |
| OPS.1.1.4 — Malware | A.8.7 | SOC/MDR |
| OPS.1.1.5 — Protokollierung | A.8.15, A.8.16 | SOC/MDR |
| OPS.1.2.3 — Vorfallmanagement | A.5.24–A.5.28 | Incident Response |
| OPS.2.1/2.3 — Outsourcing | A.5.19–A.5.22 | Vendor Risk |
| OPS.2.2 — Cloud-Nutzung | A.5.23 | Vendor Risk + SecArch |
The Cost Comparison
Manual Compliance (Both Frameworks)
Internal headcount + external costs
Year 1 total
Ongoing (Year 2+)
AI-Assisted (Security Factory)
5 agents + human oversight + certification
Year 1 total
Ongoing (Year 2+)
The 2022 ISO Controls BSI Doesn’t Yet Cover
- A.5.7 — Threat intelligence: No dedicated Baustein → Threat Intel Agent
- A.5.23 — Cloud services security: OPS.2.2 less prescriptive → Vendor Risk + SecArch Agents
- A.5.30 — ICT readiness for BCM: DER.4 partial → GRC + Compliance Agents
- A.8.10 — Information deletion: CON.6 covers physical only → Privacy Agent
- A.8.11 — Data masking: No equivalent → Security Architecture Agent
- A.8.23 — Web filtering: Partial NET coverage → SOC/MDR Agent
- A.8.12 — Data leakage prevention: No Baustein → AppSec + SecArch Agents
KRITIS Deployment Priority
Phase 1 (Months 1–3): Grundschutz Core
Deploy GRC Agent + Compliance Agent. Map existing controls to BSI Bausteine. The Compliance Agent processes a 50-control gap register in 8 seconds.
Phase 2 (Months 3–6): Operational Evidence
Add Incident Response, IAM Governance, and Policy Agents. These generate evidence BSI auditors scrutinise most.
Phase 3 (Months 6–12): Full Coverage
Add remaining agents based on audit scope. For ISO dual-cert, prioritise Vendor Risk Agent and Security Awareness Agent.
Phase 4 (Ongoing): AI Governance
AI Governance Agent for BSI AI Bausteine (expected 2025/2026) and EU AI Act enforcement.
What US Tools Miss
Drata, Vanta, and Secureframe cover SOC 2 well. They do not cover:
- BSI IT-Grundschutz — zero coverage, no Baustein mapping, no German-language docs
- NIS2UmsuCG — the German NIS2 implementation law
- TISAX — VDA ISA assessment for automotive
- Betriebsrat requirements — BetrVG §87 and §90 for AI agent deployment
- BDSG — German Federal Data Protection Act layered on GDPR
Need help implementing this?
First strategy session is complimentary. We typically respond within 4 hours.
Related Articles
February 27, 2026
Non-Human Identity (NHI) Security Guide for German Enterprises
February 21, 2026
The CISO’s Rosetta Stone: Mapping AI Agent Security Across OWASP, NIST, and Open Security Architecture
February 21, 2026
OWASP LLM Top 10 → NIST 800-53: Your Controls Already Cover This
View all articles →