Skip to content

Services, Wiki-Artikel, Blog-Beiträge und Glossar-Einträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen
BSI-recognised ISO 27001 compatible

IT-Grundschutz Practitioner

3-day online intensive course for the BSI-certified IT-Grundschutz Practitioner. The German standard for information security management - compatible with ISO 27001, mandatory for NIS-2.

What is BSI IT-Grundschutz? It is Germany's national information security standard, published by the Federal Office for Information Security (BSI). Think of it as the German equivalent of ISO 27001 - in fact, both standards are fully compatible and BSI offers a joint certification. IT-Grundschutz provides detailed implementation guidance specific to the German regulatory environment (GDPR, NIS-2, KRITIS).

3 days / 24 units
Max. 12 participants
Exam on Day 3

Next date: 15-17 June 2026 · Few seats remaining

BSI-recognised ISO 27001 compatible 500+ professionals trained NIS-2 compliant evidence

NIS-2 is in force - mandatory action since December 2025

§38 BSIG requires executives to demonstrably document training in information security - with personal liability. Approximately 29,500 organisations in Germany are newly affected. BSI IT-Grundschutz is a recognised NIS-2 compliance evidence.

Implementing BSI IT-Grundschutz professionally

In three days you learn the systematic application of the BSI IT-Grundschutz Compendium. From structural analysis through modelling to creating a complete security concept - practical and based on real scenarios from our consulting practice.

What is included?

3-day intensive training (24 units) following BSI curriculum
Practical exercises with the current IT-Grundschutz Compendium
Intensive exam preparation with mock exam
Comprehensive training materials
Max. 12 participants for individual coaching
100% GDPR-compliant platform (German servers)
30 days email support after the course
Attendance confirmation (also without exam)

Group Discounts

Want to train multiple team members? The more participants, the lower the price:

Participants Price/person Discount Saving
1€1,990--
2 (Duo)€1,79010%€200/person
3 (Team)€1,69015%€300/person
4-5 (Dept)€1,59020%€400/person
6+Request in-house package →

Curriculum

Three days structured along the BSI IT-Grundschutz methodology.

Day 1 - Fundamentals, Structural Analysis & Protection Needs Assessment
  • The BSI: tasks, organisation and significance for IT security in Germany
  • BSI standards overview: 200-1 (ISMS), 200-2 (IT-Grundschutz methodology), 200-3 (risk analysis), 200-4 (BCM)
  • IT-Grundschutz Compendium: structure, modules, implementation notes and elementary threats
  • Approaches: standard protection, basic protection, core protection - when to use which method
  • Alignment and interaction with ISO 27001, NIS-2 and sector-specific standards
  • Defining and scoping the information domain
  • Structural analysis: business processes, applications, IT systems, communication links, premises
  • Protection needs assessment: categories (normal, high, very high), inheritance, cumulation effects
  • Practical: Navigation in the Compendium, structural analysis and protection needs assessment on a sample organisation
Day 2 - Modelling, IT-Grundschutz Check & Risk Analysis
  • Modelling: systematic assignment of modules to target objects
  • Module layers: processes, systems, networks, applications, infrastructure
  • IT-Grundschutz check: target-actual comparison of requirements against current state
  • Documenting implementation status: yes, partly, no, unnecessary - with justification
  • Risk analysis according to BSI Standard 200-3: when and how in-depth analysis is required
  • Risk assessment: determining probability of occurrence and extent of damage
  • Risk treatment: avoidance, reduction, transfer, acceptance - decision criteria
  • Creating a security concept: implementation plan, measure planning, responsibilities
  • Practical: Modelling an IT domain, IT-Grundschutz check and risk analysis with implementation plan
Day 3 - Deepening, Exam Preparation & Exam
  • Maintaining and continuously improving the security process (PDCA)
  • ISO 27001 certification based on IT-Grundschutz - the path to certification
  • Relationship with NIS-2, KRITIS regulation and sector-specific standards (B3S)
  • Emergency management according to BSI Standard 200-4: business continuity management fundamentals
  • Intensive exam preparation: practice questions, exam strategy tips, open questions
  • Exam: 50 multiple-choice questions, 60 minutes, pass mark 60%

Upcoming Dates

15-17 Jun 2026
Online
Few seats
21-23 Sep 2026
Online
Available
16-18 Nov 2026
Online
Available
19-21 Jan 2027
Online
Available

Frequently Asked Questions

The IT-Grundschutz Practitioner is the entry-level certification in the BSI personal certification scheme for IT-Grundschutz. The qualification demonstrates solid knowledge in using the BSI IT-Grundschutz Compendium, creating security concepts and operationally implementing IT-Grundschutz in organisations. The certificate is recognised by Germany's Federal Office for Information Security (BSI) and is valid for 3 years. It is the German counterpart to the ISO 27001 Lead Implementer, tailored specifically to the BSI framework used across German public administration and critical infrastructure.
BSI IT-Grundschutz is fully compatible with ISO 27001. The BSI even offers its own "ISO 27001 based on IT-Grundschutz" certification that combines both standards. Many organisations - particularly in Germany - use IT-Grundschutz as the methodological foundation for their ISO 27001 certification. For internationally operating organisations, IT-Grundschutz provides the European regulatory context (GDPR, NIS-2, German IT Security Act) that complements ISO 27001. The course covers the interfaces between both standards in detail.
The course is aimed at IT security officers, IT managers and administrators, public sector IT professionals (federal, state, municipal authorities), KRITIS operators and their IT service providers, consultants working on IT-Grundschutz projects, data protection officers expanding their information security expertise, and project managers coordinating IT security projects.
There are no formal admission requirements. Basic IT knowledge (networks, operating systems, IT infrastructure) is recommended, along with ideally some exposure to IT security topics or management systems. Knowledge of ISO 27001 is helpful but not required. The course is deliberately designed as an entry point and covers all necessary fundamentals systematically.
The exam takes place on the last day of training (Day 3) and consists of 50 multiple-choice questions. The exam duration is 60 minutes, and a minimum of 60% correct answers is required to pass. The exam fee of EUR 250 net is not included in the course price. A free retake at a later date is available if you do not pass on the first attempt.
The IT-Grundschutz Practitioner certificate is valid for 3 years. Recertification is achieved by providing evidence of at least 20 hours of continuing education in IT-Grundschutz or professional experience in an IT-Grundschutz project. Alternatively, completing the IT-Grundschutz Consultant course automatically extends the Practitioner certificate.
Since December 2025, §38 of the German IT Security Act (BSIG) requires management of affected organisations to demonstrate documented training in information security - with personal liability. BSI IT-Grundschutz is a recognised NIS-2 compliance evidence because it systematically covers risk analysis (Art. 21 NIS-2), technical and organisational measures, and incident management. With the Practitioner certificate, you document the required training obligation and can use IT-Grundschutz as a framework for your NIS-2 implementation.
Our instructors are active security consultants with experience from hundreds of projects - not just theorists. Group size is capped at 12 participants so individual questions can be addressed. We work with real case examples from our consulting practice. We also offer 30 days of free email support after the course for technical questions.
Our courses run exclusively on a GDPR-compliant platform on German servers - without Zoom, Teams or other US-based providers. You need only a current browser and a stable internet connection. All training materials are available digitally. Interaction with instructors and other participants takes place in real time via video, audio and chat.

Your Instructors

Experienced IT-Grundschutz experts with consulting practice from hundreds of projects. Our instructors are active security consultants - not academic theory, but proven methodology from real engagements.

Ready to become BSI IT-Grundschutz certified?

Reserve your seat now - max. 12 participants per course. Free consultation included.

Kostenlos · 30 Minuten · Unverbindlich