IT Baseline Protection Software
Your solution for a future-proof ISMS based on BSI IT Baseline Protection
Leverage BSI IT Baseline Protection,the best-practice approach developed by the German Federal Office for Information Security (BSI),without Excel chaos or duplicate maintenance. Our software is your tailored solution for an ISMS based on baseline protection.
As an official BSI licensing partner, you always receive the latest IT Baseline Protection Compendium and immediately benefit from new developments such as “Baseline Protection++”. You can build a risk-based ISMS in accordance with BSI Standard 200-2, ensuring the highest level of information security.
- Complete BSI standards set: Select relevant modules with a click, and the system guides you through all requirements. Thanks to the licensing agreement with BSI, updates are applied automatically,keeping you up to date at all times.
- Baseline protection check & adaptability: The software supports all three approaches of BSI Standard 200-2 and includes a baseline protection check. This allows you to measure your implementation level at the push of a button. Industry-specific templates (e.g., for critical infrastructure) further accelerate setup.
- Audit and certification support: Whether you are an ISMS beginner or an experienced security manager, the platform prepares you optimally for baseline protection audits or ISO 27001 certification based on IT Baseline Protection.
- From €199/month with a 1-year term
- Enterprise options for advanced requirements available on request
- Note: Officially licensed by the BSI. Includes all modules, threats, and measures from the BSI Compendium,including protection needs assessment, audit preparation, and automated documentation.
Over 14,000 users already trust our software
IT Baseline Protection Software
Efficient. Future-proof. 100% audit-compliant.
With the IT Baseline Protection module from GRASP GRC, you receive a comprehensive solution for seamless implementation of BSI IT Baseline Protection and related standards. The module combines components and processes from GRASP ISMS and BCM modules to efficiently meet the requirements of the BSI Baseline Protection Compendium.
Structured Security with Regulatory Acceptance
BSI IT Baseline Protection is particularly attractive for German companies and public institutions, as it is officially recognized and proven in practice. As a decision-maker, you gain maximum security and compliance in a structured way: you not only meet ISO 27001 requirements but also align with detailed BSI specifications.
Through automation, you significantly reduce effort and costs. At the same time, you gain a future advantage: the upcoming “Baseline Protection++” will be directly supported by our platform.
Key Highlights
Official recognition & trust
IT Baseline Protection is considered a gold standard. A certified ISMS based on it enhances your reputation. Our solution paves the way and ensures full compliance.
Holistic risk management
You gain full visibility into critical processes and assets and understand how failures impact them. This clarity enables targeted investments in the most important security measures.
Compliance with laws & regulations
Ideal for operators of critical infrastructure (KRITIS): the tool includes specific modules and support to demonstrate compliance with regulatory requirements to the BSI at any time,reducing liability risks.
Efficiency Despite Extensive Requirements
BSI IT Baseline Protection is known for its level of detail,our software removes the complexity and makes implementation manageable. As an operational manager, you benefit from having all baseline protection modules already integrated into the platform. No need for manual compilation from the compendium,saving significant time and ensuring nothing is overlooked. Automated protection needs assessments also help maintain oversight, even in complex environments.
Key Highlights
Automated documentation
With integrated version control and audit trail functionality, you can always demonstrate who did what and when,making ISO documentation requirements easy to meet.
Action & task management
All tasks are recorded in the tool and assigned to responsible persons. With reminders and progress tracking, ISMS managers maintain full oversight with minimal effort.
Certification-relevant evidence at the push of a button
All relevant evidence,from controls and risks to measures,is fully exportable, supporting efficient and structured ISO 27001 certification.
Traceability and Comprehensive Reporting
For internal or external auditors as well as top-level decision-makers, our baseline protection solution provides maximum transparency. Every step of implementation is documented in the system,from initial modeling of information networks to the latest implemented measure.
Approvers and auditors can access comprehensive reporting views. Additionally, detailed auditor reports,including justifications and evidence,significantly accelerate audits.
Key Highlights
Audit-ready at the push of a button
You can grant auditors read-only access to the ISMS at any time. External auditors often appreciate this structured preparation, as it simplifies their work.
Reports for executives & authorities
The software generates high-quality PDF reports with your corporate design for board presentations or regulatory authorities, helping you meet reporting obligations.
Cost savings & resource efficiency
Less reliance on external consulting, more efficiency: reduce costs by up to 47%, while also saving time and internal resources.
IT Baseline Protection
Overview of all features
Risk Analysis & Documentation
GRASP German GRC enables transparent risk analysis, helping you identify vulnerabilities and prioritize risks with clarity. It also supports complete documentation of all security measures and requirements, including policy creation and security concept development.
Measure Selection
Easily select the right measures from the BSI IT-Grundschutz Compendium based on your organization’s protection needs. GRASP German GRC enables flexible adaptation of these measures to match your specific context and security goals.
Protection Requirements Assessment
Streamline the classification of confidentiality, integrity, and availability with a systematic approach. GRASP German GRC removes the need for Excel and enables clear assignment of protection levels, with the flexibility to adjust as needed.
Asset Inventory & Structural Analysis
GRASP German GRC provides an intuitive way to capture and visualize all critical assets, IT systems, and business processes. Simplify the mapping of complex IT environments and reduce the time spent on maintaining up-to-date and consistent system documentation.
Benefits for your company
Transparency & Audit Readiness
GRASP delivers a clear, real-time overview of all assets, risks, and safeguards. Every step is traceable, documented, and audit-ready at any time.
Ongoing Monitoring & Improvement
Keep your IT baseline protection program on track with continuous monitoring and data-driven dashboards. Regular reviews ensure full control and ongoing optimization.
Efficiency Gains
Automate and centralize core IT-Grundschutz processes. GRASP helps you cut down on manual work, reduce costs, and simplify complex tasks like risk assessments and protection classification.
Adaptability
Tailor GRASP to your organization’s specific structures and needs. Flexible configuration ensures your processes and measures align perfectly with your operational environment.
Experience GRASP Interactively
Explore our ISMS module in an interactive product tour and see how GRASP makes your IT Baseline Protection efficient and future-proof.
Start interactive product tour
Professional
For teams in small and medium-sized enterprises to ensure professionalism and compliance. Includes 1 user.
199 €
per month
2.388 €, billed annually
Summary:
Dashboard
SoA (Statement of Applicability)
Policy documents
Structure analysis
Protection needs assessment
Modeling
IT Baseline Protection check
Risk management
Audit management
Incident management
Action management
Reports
SSO (Microsoft, LinkedIn & GitHub)
Enterprise
For large, integrated, cross-functional teams to enhance resilience and efficiency.
On request
We are happy to advise you!
Summary:
All Professional package features
SLA
On-prem installation
Whitelabeling
SSO (other services)
Multi-tenancy
Custom workflows
and more
Professional
For teams in small and medium-sized enterprises to ensure professionalism and compliance. Includes 1 user.
179 €
per month
2.148 €, billed annually
Summary:
Dashboard
SoA (Statement of Applicability)
Policy documents
Structure analysis
Protection needs assessment
Modeling
IT Baseline Protection check
Risk management
Audit management
Incident management
Action management
Reports
SSO (Microsoft, LinkedIn & GitHub)
Enterprise
For large, integrated, cross-functional teams to enhance resilience and efficiency.
On request
We are happy to advise you!
Summary:
All Professional package features
SLA
On-prem installation
Whitelabeling
SSO (other services)
Multi-tenancy
Custom workflows
and more
Benefit from an audit-compliant ISMS based on BSI Standard 200-2 and master IT Baseline Protection without Excel chaos.
See for yourself and get to know our IT Baseline Protection module.
Frequently Asked Questions
EU SaaS or on-premises; SSO/MFA, fine-grained roles, encryption in transit and at rest, and optional SIEM integration.
Definition of damage scenarios, likelihood, and impact; derivation of measures and evaluation of residual risks. Reports highlight priorities.
Yes,common import paths with quality checks support migration. Duplicates are detected and mappings verified.
Modules and requirements are versioned. Changes between editions are marked, and implementation statuses can be compared.
Status reports, management summaries, action plans, audit checklists, audit trails/change histories, and export options in PDF/CSV.
Evaluation of confidentiality, integrity, and availability for each object; protection classes are clearly assignable and adjustable. Results directly influence prioritization of measures.
Hierarchical structures, network views, target objects with attributes/relationships, and reusable modules. Bulk editing simplifies updates.
Yes. The module guides you through procedures according to 200-1 and 200-2, as well as risk analysis according to 200-3,including modeling and network functions.
Discover Our Additional Modules
GRASP unfolds its full potential when multiple modules work together – discover more solutions based on a shared data foundation.














