For decades, IT-Grundschutz – Germany's national security baseline – was above all a body of text: compendium, standards, and implementation guidance as PDFs, maintained in documents, analyzed in spreadsheets. At the end of September 2025, the BSI officially ended that era and published the Stand-der-Technik-Bibliothek on GitHub – with IT-Grundschutz++ as a machine-readable catalog.
This is more than a new storage format. The requirements are available as an OSCAL catalog in XML, JSON, and YAML. Tools can read them directly, reference them, and link them to an organization's own implementation – no retyping, no guessing versions, no page numbers.
The format decision is remarkable. The BSI could have defined its own national data format – and deliberately chose not to. OSCAL is an internationally established standard led by NIST; adopting it keeps German organizations compatible with international frameworks and with a fast-growing tool ecosystem.
Germany thereby joins a larger movement: in the US, FedRAMP is moving to machine-readable authorization packages, and the tooling around the standard is growing quickly. If you want the foundations first, our introduction What is OSCAL? explains how the standard is structured.
For day-to-day ISMS work, the format change matters more than it first sounds. Today, a substantial share of Grundschutz work consists of transferring requirements from documents into your own structure: into spreadsheets, into GRC tools, into security concepts. Every new edition of the compendium triggers the same exercise again.
With a machine-readable catalog, the logic flips. The tool already knows the requirements, and the actual work shifts to where it belongs: assignment, implementation, evidence, and decisions.
Existing security concepts based on Edition 23 do not lose their value overnight – the modernization is a transition that the BSI is detailing step by step. The direction, however, is unambiguous, and teams that organize their structure early benefit twice: today's work gets cleaner, and the later switch gets smaller.
Three preparations have proven useful in our view. They pay off regardless of when an organization formally moves to IT-Grundschutz++.
We built Secani OSCAL-native from day one – out of the conviction that compliance content should be structured data long before regulators demand it. That the BSI is now taking IT-Grundschutz exactly there confirms the path. If you are preparing the transition to IT-Grundschutz++ and want more than a prettier archive, talk to us.
Secani connects scopes, evidence, tasks, and AI agents in one shared workspace.
Turn IT-Grundschutz from a documentation project into a traceable working model for security owners, business teams, and auditors.
Seven practical questions reveal whether a platform can connect obligations, controls, evidence, risk, and professional judgment in a repeatable system.
OLIR provides mapping content and governance. OSCAL provides the machine-readable structure for using those mappings in gap analysis, evidence reuse, and change-impact workflows.