BSI Standards & Compendium: The Foundation for IT Security
We help you connect BSI methodology with the applicable Compendium building blocks: define your information domain, assess protection needs and document implementation gaps, owners and evidence.
- ✓Documented scope and applicable building blocks
- ✓Prioritised implementation backlog with owners
- ✓Traceable control evidence for audit preparation
- ✓Handover of methods and review responsibilities
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
- Your strategic goals and objectives
- Desired business outcomes and ROI
- Steps already taken
Or contact us directly:
Certifications, Partners and more...










BSI Standards Compendium
Our Strengths
- In-depth expertise across all BSI standards and their application
- Support for modelling, implementation planning and evidence review
- Comprehensive implementation approaches for complex organizations
- Ongoing support and updating of standards
Expert Tip
The BSI Standards Compendium offers not just individual standards, but a comprehensive approach to IT security. The systematic application of all relevant standards creates a coherent and resilient security architecture.
ADVISORI in Numbers
11+
Years of Experience
120+
Employees
520+
Projects
We follow a systematic methodology for the complete implementation of the BSI Standards Compendium, tailored to your specific requirements.
Our Approach:
Comprehensive analysis of all applicable BSI standards
Prioritization and roadmap development for implementation
Systematic implementation according to BSI methodology
Integration into existing security architectures
Continuous monitoring and improvement

Sarah Richter
Head of Information Security, Cyber Security
Expertise & Experience:
10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security
Our Services
We offer you tailored solutions for your digital transformation
BSI Standards Assessment
Comprehensive assessment of all relevant BSI standards for your organization.
- Complete inventory of all applicable BSI standards
- Relevance and applicability analysis for your industry
- Gap analysis against current implementation
- Prioritized implementation roadmap
Complete Standards Implementation
Systematic implementation of all relevant BSI standards within your organization.
- Step-by-step implementation according to BSI methodology
- Integration into existing processes and systems
- Training and change management
- Continuous monitoring and optimization
Our Competencies
Choose the area that fits your requirements
BSI certification requires thorough preparation. We guide you through the entire audit process — from documentation through on-site audit to follow-up.
Systematic analysis of BSI Grundschutz building blocks is the foundation for effective IT security architecture. We assess and model the right blocks for your information domain.
The BSI IT-Grundschutz Compendium comprises 113 building blocks across 10 topic areas. Grundschutz++ brings digital modernization in 2026.
ISO 27001 certification based on IT-Grundschutz is the highest evidence of information security under BSI standards.
Banks and financial services providers face stringent information security requirements. BaFin mandates through BAIT and MaRisk the implementation of recognized standards such as BSI IT-Grundschutz. We guide financial institutions through structured implementation based on BSI 200-2 — from structural analysis and protection requirements to measure implementation. Our consultants understand the specific demands of financial supervision and combine IT-Grundschutz with BAIT compliance, DORA readiness, and existing ISMS structures.
Successful BSI IT-Grundschutz implementation requires more than technical execution — it needs strategic implementation frameworks that connect IT security requirements with operational excellence, technology innovation, and sustainable business strategy. Professional BSI Grundschutz implementation combines proven implementation methods with effective RegTech solutions for comprehensive IT security systems. We develop end-to-end BSI IT-Grundschutz implementation solutions that not only ensure regulatory compliance, but also increase operational IT security efficiency, enable innovation, and establish sustainable competitive advantages for German companies.
The BSI Grundschutz methodology (BSI 200-2) defines three protection levels. We implement the right approach for your organization.
Risk analysis per BSI 200-3 is mandatory for elevated protection needs. We identify additional threats beyond standard building blocks and develop effective treatment strategies.
Frequently Asked Questions about BSI Standards Compendium
What are BSI Standards 200-1, 200-2, and 200-3?
BSI Standards 200‑1, 200‑2, and 200‑3 are the three core standards of the IT-Grundschutz framework developed by the German Federal Office for Information Security (BSI). BSI Standard 200‑1 defines general requirements for an Information Security Management System (ISMS), compatible with ISO 27001. BSI Standard 200‑2 describes the IT-Grundschutz methodology with three approaches: basic protection, standard protection, and core protection. BSI Standard 200‑3 consolidates all risk-related steps and governs risk analysis based on IT-Grundschutz. They are supplemented by BSI Standard 200‑4 for Business Continuity Management.
How do basic, standard, and core protection differ in BSI Standard 200-2?
Basic protection offers an initial breadth-first approach. Standard protection applies the methodology across the defined information domain; core protection prioritises especially important assets and processes. Model the applicable building blocks for the chosen scope rather than applying every block in the catalogue. Agree the approach and any certification objective before planning implementation.
What does the IT-Grundschutz Compendium contain?
The Compendium provides process and system building blocks with threats and security requirements. Use it to model the actual information domain and document applicability. Record the edition used and assess published changes; do not assume a new complete edition appears every year.
How does BSI IT-Grundschutz certification work?
ISO 27001 certification based on IT-Grundschutz follows a structured process. First, the information domain is defined and protection needs are assessed. Then modelling according to the IT-Grundschutz Compendium and the IT-Grundschutz check are performed. A supplementary risk analysis per BSI Standard 200‑3 follows. After implementing all required measures, a BSI-certified auditor verifies conformity. ADVISORI supports the entire process and systematically prepares your organization for the audit.
What advantages do BSI standards offer over a standalone ISO 27001 implementation?
IT-Grundschutz offers a structured modelling method and reusable building blocks. This can help teams translate security requirements into an implementation backlog. The appropriate approach depends on scope, customer obligations and the intended assurance outcome. Compare maintenance effort and available expertise as well as the desired certification route.
Which organizations are required to implement BSI standards?
IT-Grundschutz is not automatically mandatory for every KRITIS operator or NIS2 entity. The BSI Act requires appropriate risk-management measures for entities within scope. Whether a specific BSI method or certification is required depends on applicable administrative, sectoral or contractual requirements. Establish those obligations before selecting the method.
How does ADVISORI support BSI standards implementation?
ADVISORI guides organizations through the complete BSI standards implementation process. We begin with a gap analysis to assess your current ISMS maturity level. Based on the findings, we create a prioritized roadmap and support modelling according to the IT-Grundschutz Compendium, protection needs assessment, risk analysis per BSI Standard 200‑3, and implementation of all required measures. Our goal is a sustainable implementation that your organization can independently maintain and evolve.
Let's
Work Together!
Is your organization ready for the next step into the digital future? Contact us for a personal consultation.
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
Ready for the next step?
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
Prefer direct contact?
Direct hotline for decision-makers
Strategic inquiries via email
Detailed Project Inquiry
For complex inquiries or if you want to provide specific information in advance