GRASP German GRC
IT-Grundschutz Modul

IT Baseline Protection Software

Your solution for a future-proof ISMS based on BSI IT Baseline Protection

Product Description

Leverage BSI IT Baseline Protection,the best-practice approach developed by the German Federal Office for Information Security (BSI),without Excel chaos or duplicate maintenance. Our software is your tailored solution for an ISMS based on baseline protection.

As an official BSI licensing partner, you always receive the latest IT Baseline Protection Compendium and immediately benefit from new developments such as “Baseline Protection++”. You can build a risk-based ISMS in accordance with BSI Standard 200-2, ensuring the highest level of information security.

Functionality
  • Complete BSI standards set: Select relevant modules with a click, and the system guides you through all requirements. Thanks to the licensing agreement with BSI, updates are applied automatically,keeping you up to date at all times.
  • Baseline protection check & adaptability: The software supports all three approaches of BSI Standard 200-2 and includes a baseline protection check. This allows you to measure your implementation level at the push of a button. Industry-specific templates (e.g., for critical infrastructure) further accelerate setup.
  • Audit and certification support: Whether you are an ISMS beginner or an experienced security manager, the platform prepares you optimally for baseline protection audits or ISO 27001 certification based on IT Baseline Protection.
Pricing Overview
  • From €199/month with a 1-year term
  • Enterprise options for advanced requirements available on request
  • Note: Officially licensed by the BSI. Includes all modules, threats, and measures from the BSI Compendium,including protection needs assessment, audit preparation, and automated documentation.
Over 14,000 users already trust our software

IT Baseline Protection Software

Efficient. Future-proof. 100% audit-compliant.

With the IT Baseline Protection module from GRASP GRC, you receive a comprehensive solution for seamless implementation of BSI IT Baseline Protection and related standards. The module combines components and processes from GRASP ISMS and BCM modules to efficiently meet the requirements of the BSI Baseline Protection Compendium.

IT-Grundschutz App - Auswahl der Anforderungen

Structured Security with Regulatory Acceptance

BSI IT Baseline Protection is particularly attractive for German companies and public institutions, as it is officially recognized and proven in practice. As a decision-maker, you gain maximum security and compliance in a structured way: you not only meet ISO 27001 requirements but also align with detailed BSI specifications.

Through automation, you significantly reduce effort and costs. At the same time, you gain a future advantage: the upcoming “Baseline Protection++” will be directly supported by our platform.

Key Highlights

Official recognition & trust

IT Baseline Protection is considered a gold standard. A certified ISMS based on it enhances your reputation. Our solution paves the way and ensures full compliance.

Holistic risk management

You gain full visibility into critical processes and assets and understand how failures impact them. This clarity enables targeted investments in the most important security measures.

Compliance with laws & regulations

Ideal for operators of critical infrastructure (KRITIS): the tool includes specific modules and support to demonstrate compliance with regulatory requirements to the BSI at any time,reducing liability risks.

Efficiency Despite Extensive Requirements

BSI IT Baseline Protection is known for its level of detail,our software removes the complexity and makes implementation manageable. As an operational manager, you benefit from having all baseline protection modules already integrated into the platform. No need for manual compilation from the compendium,saving significant time and ensuring nothing is overlooked. Automated protection needs assessments also help maintain oversight, even in complex environments.

IT-Grundschutz App - Übersicht der Anforderungen als Liste

Key Highlights

Automated documentation

With integrated version control and audit trail functionality, you can always demonstrate who did what and when,making ISO documentation requirements easy to meet.

Action & task management

All tasks are recorded in the tool and assigned to responsible persons. With reminders and progress tracking, ISMS managers maintain full oversight with minimal effort.

Certification-relevant evidence at the push of a button

All relevant evidence,from controls and risks to measures,is fully exportable, supporting efficient and structured ISO 27001 certification.

IT-Grundschutz App - Übersicht Dashboard

Traceability and Comprehensive Reporting

For internal or external auditors as well as top-level decision-makers, our baseline protection solution provides maximum transparency. Every step of implementation is documented in the system,from initial modeling of information networks to the latest implemented measure.

Approvers and auditors can access comprehensive reporting views. Additionally, detailed auditor reports,including justifications and evidence,significantly accelerate audits.

Key Highlights

Audit-ready at the push of a button

You can grant auditors read-only access to the ISMS at any time. External auditors often appreciate this structured preparation, as it simplifies their work.

Reports for executives & authorities

The software generates high-quality PDF reports with your corporate design for board presentations or regulatory authorities, helping you meet reporting obligations.

Cost savings & resource efficiency

Less reliance on external consulting, more efficiency: reduce costs by up to 47%, while also saving time and internal resources.

Made und Hosted in Germany 2024 Allianz fuer Cyber Sicherheit smig german 2026 Lizenzierter GS ISO Zertifizierung Logo 2025

IT Baseline Protection
Overview of all features

Get to know GRASP’s IT Baseline Protection

Free Trial
Get in touch

Risk Analysis & Documentation

GRASP German GRC enables transparent risk analysis, helping you identify vulnerabilities and prioritize risks with clarity. It also supports complete documentation of all security measures and requirements, including policy creation and security concept development. 

Measure Selection

Easily select the right measures from the BSI IT-Grundschutz Compendium based on your organization’s protection needs. GRASP German GRC enables flexible adaptation of these measures to match your specific context and security goals. 

Protection Requirements Assessment

Streamline the classification of confidentiality, integrity, and availability with a systematic approach. GRASP German GRC removes the need for Excel and enables clear assignment of protection levels, with the flexibility to adjust as needed. 

Asset Inventory & Structural Analysis

GRASP German GRC provides an intuitive way to capture and visualize all critical assets, IT systems, and business processes. Simplify the mapping of complex IT environments and reduce the time spent on maintaining up-to-date and consistent system documentation. 

Benefits for your company

transparency

Transparency & Audit Readiness

GRASP delivers a clear, real-time overview of all assets, risks, and safeguards. Every step is traceable, documented, and audit-ready at any time.

eye

Ongoing Monitoring & Improvement

Keep your IT baseline protection program on track with continuous monitoring and data-driven dashboards. Regular reviews ensure full control and ongoing optimization. 

upwards

Efficiency Gains

Automate and centralize core IT-Grundschutz processes. GRASP helps you cut down on manual work, reduce costs, and simplify complex tasks like risk assessments and protection classification. 

Adaptability

Tailor GRASP to your organization’s specific structures and needs. Flexible configuration ensures your processes and measures align perfectly with your operational environment. 

Experience GRASP Interactively

Explore our ISMS module in an interactive product tour and see how GRASP makes your IT Baseline Protection efficient and future-proof.

Start interactive product tour
Interaktive Demo

Professional

For teams in small and medium-sized enterprises to ensure professionalism and compliance. Includes 1 user.

199 €

per month

2.388 €, billed annually

Buy now

Summary:

Dashboard

SoA (Statement of Applicability)

Policy documents

Structure analysis

Protection needs assessment

Modeling

IT Baseline Protection check

Risk management

Audit management

Incident management

Action management

Reports

SSO (Microsoft, LinkedIn & GitHub)

Enterprise

For large, integrated, cross-functional teams to enhance resilience and efficiency.

On request

We are happy to advise you!

Get in touch

Summary:

All Professional package features

SLA

On-prem installation

Whitelabeling

SSO (other services)

Multi-tenancy

Custom workflows

and more

Professional

For teams in small and medium-sized enterprises to ensure professionalism and compliance. Includes 1 user.

179 €

per month

2.148 €, billed annually

Buy now

Summary:

Dashboard

SoA (Statement of Applicability)

Policy documents

Structure analysis

Protection needs assessment

Modeling

IT Baseline Protection check

Risk management

Audit management

Incident management

Action management

Reports

SSO (Microsoft, LinkedIn & GitHub)

Enterprise

For large, integrated, cross-functional teams to enhance resilience and efficiency.

On request

We are happy to advise you!

Get in touch

Summary:

All Professional package features

SLA

On-prem installation

Whitelabeling

SSO (other services)

Multi-tenancy

Custom workflows

and more

Benefit from an audit-compliant ISMS based on BSI Standard 200-2 and master IT Baseline Protection without Excel chaos.

See for yourself and get to know our IT Baseline Protection module.

Call to Action

Frequently Asked Questions

What deployment and security options are available?

EU SaaS or on-premises; SSO/MFA, fine-grained roles, encryption in transit and at rest, and optional SIEM integration.

How does risk analysis according to 200-3 work?

Definition of damage scenarios, likelihood, and impact; derivation of measures and evaluation of residual risks. Reports highlight priorities.

Are imports supported (Excel/GSTOOL/verinice)?

Yes,common import paths with quality checks support migration. Duplicates are detected and mappings verified.

How does GRASP work with the IT Baseline Protection Compendium?

Modules and requirements are versioned. Changes between editions are marked, and implementation statuses can be compared.

What standard reports does GRASP provide?

Status reports, management summaries, action plans, audit checklists, audit trails/change histories, and export options in PDF/CSV.

How does protection needs assessment work?

Evaluation of confidentiality, integrity, and availability for each object; protection classes are clearly assignable and adjustable. Results directly influence prioritization of measures.

How does GRASP model structures, target objects, and networks?

Hierarchical structures, network views, target objects with attributes/relationships, and reusable modules. Bulk editing simplifies updates.

Does GRASP support BSI Standards 200-1/200-2/200-3?

Yes. The module guides you through procedures according to 200-1 and 200-2, as well as risk analysis according to 200-3,including modeling and network functions.

Discover Our Additional Modules

GRASP unfolds its full potential when multiple modules work together – discover more solutions based on a shared data foundation.