BSI IT-Grundschutz
Certification readiness for an ISMS based on the German Federal Office for Information Security IT-Grundschutz methodology.
Certification readiness for an ISMS based on the German Federal Office for Information Security IT-Grundschutz methodology.
Who typically pursues this path
Organizations using the BSI information-security methodology commonly use readiness work to determine scope, identify missing or immature controls, improve the quality of evidence, and reduce avoidable surprises in the formal process.
What makes this outcome distinct
The expected result is certification. A readiness assessment is preparatory and independent from the organization or authority that issues, accepts, or relies on the final result.
Questions to settle early
- Which current version and program rules apply?
- What legal entities, products, services, locations, systems, and third parties are in scope?
- Which assessor qualifications or independence rules apply to the formal process?
- How much operating history and sampling will be required?
- What customer, contract, regulatory, or market deadline is driving the work?
What a readiness assessment should establish
- The correct scope, boundary, entities, locations, systems, and exclusions.
- Which requirements apply and how each maps to an implemented control.
- Whether evidence is complete, current, consistent, and attributable to an owner.
- Which controls need operating history, sampling, testing, or independent validation.
- A sequenced remediation plan with owners, dependencies, target dates, and closure evidence.
The path to the formal outcome
Readiness work prepares the organization for the applicable independent auditor, certification body, assessor, regulator, authorizing official, or validation authority. The formal outcome can only be issued by the party authorized under that program.