ECP vs BSI IT-Grundschutz: CyFun vs the German NIS2 Standard
BSI IT-Grundschutz is Germany's national information security methodology, published and maintained by the BSI (Bundesamt für Sicherheit in der Informationstechnik) since 1994. Its 2023 Kompendium contains 111 modular building blocks across 10 layers, the de facto compliance baseline for German federal bodies and KRITIS operators, and explicitly referenced in Germany's NIS2 transposition law (NIS2UmsuCG, effective December 2025). Easy Cyber Protection is a CyFun audit-readiness platform sold to MSPs. Both sit in the NIS2 space, but for different countries and very different delivery models.
At a glance
| BSI IT-Grundschutz (Germany) | Easy Cyber Protection / CyFun | |
|---|---|---|
| Owning authority | BSI: Bundesamt für Sicherheit in der Informationstechnik (Federal Office for Information Security) | CCB: Centre pour la Cybersécurité Belgique (ECP implements CyFun) |
| Established / last update | Established 1994; current Kompendium Edition 2023 (111 modules). Grundschutz++ reform rolling out from 2026. | CyFun 2025 (aligned with NIST CSF 2.0); CCB-issued and updated |
| Legal status | Mandatory for German federal authorities; explicitly referenced for NIS2 entities under NIS2UmsuCG (effective Dec 6, 2025); voluntary for others but de facto standard | Operational: Belgian CCB-issued NIS2 compliance path; CAB audits running |
| Entity coverage | ~29,500 German entities in scope under NIS2UmsuCG across 18 sectors; federal bodies mandatory regardless | Belgian entities registered under NIS2 (CCB portal); Ireland co-adopting |
| Structure | 111 building blocks (Bausteine) in 10 layers (Schichten); each block has multiple requirements. Total ~6,567 requirements (pre-Grundschutz++). Grundschutz++ reduces to ~985 in OSCAL JSON from 2026. | 4 tiers: Small (34 cumulative), Basic (34), Important (133), Essential (218), each YAML-implemented in ECP |
| Certification / assessment | ISO 27001 on the basis of IT-Grundschutz: BSI-certified auditor inspects on-site, submits report to BSI, BSI issues certificate. Three implementation levels: Basis- (basic), Kern- (core), Standard-Absicherung (standard). | CAB audit by accredited body; ECP generates signed .ecpbundle.zip audit bundle |
| Compliance cost | ~€40,000–€120,000 for SME Standard-Absicherung + certification (consulting + BSI audit). Initial BSI cert fee ~€2,978. Basis-Absicherung (basic level): €15,000–€40,000. | ECP platform licence: one fee per client per month, by employees (Micro €95, Small €195, Medium €395, Large €750, 1,000+ on request); this is the direct end-client price. Partners buy below the published rate; the partner rate card is on request. |
| MSP / portfolio model | No multi-tenant track: entity-level framework. MSPs operating in Germany are themselves in scope as NIS2 entities. | Purpose-built for MSP portfolio delivery: partner dashboard, white-label, per-client management, NL/FR/EN materials |
| ISO 27001 relationship | Native: ISO 27001 certification on basis of IT-Grundschutz is a BSI-recognized path. Grundschutz++ includes OSCAL crosswalk to ISO 27001:2022 Annex A. | CyFun 2025 overlaps significantly with NIST CSF 2.0; dedicated ISO 27001 support planned |
| Geography | Germany (BSI jurisdiction); adopted by some German-speaking public bodies in Austria and Switzerland | Belgium-first (NL/FR/EN built-in); Ireland co-adopting CyFun as of 2026 |
Sources: BSI bsi.bund.de (IT-Grundschutz), NIS2UmsuCG (Dec 2025), advisori.de cost analysis, ccb.belgium.be. Last verified 2026-08-17.
Where BSI IT-Grundschutz applies
- Your clients are German organizations covered by NIS2UmsuCG (effective December 2025), energy, transport, digital infrastructure, health, water, banking, and 12 other sectors, with ~29,500 entities now in scope
- You deliver compliance or ISMS consulting in Germany and your clients need ISO 27001 certification on the basis of IT-Grundschutz, the most recognized path in the German public and corporate market
- Your clients are German federal authorities or KRITIS operators: IT-Grundschutz is mandatory for them under BSI law, not a choice
- You want a deeply documented methodology: 111 modules with step-by-step safeguards, threat catalogues, and an official ISO 27001:2022 crosswalk (expanding further in Grundschutz++)
- You are planning for Grundschutz++: the 2026 reform delivers machine-readable OSCAL JSON with automatic tool integration, reducing compliance overhead for organizations with modern ISMS tooling
Where ECP / CyFun applies
- Your clients are Belgian (or Irish): CyFun is the CCB's official NIS2 compliance path, the one Belgian auditors and the CCB assess against; IT-Grundschutz is not the compliance path in Belgium
- You are an MSP and want to package CyFun audit-readiness as a repeatable service across your client portfolio, not a bespoke €40K–€120K compliance project per client
- You need NL/FR/EN materials with Belgian regulatory context (CCB alignment, VLAIO kmo-portefeuille leverage for Flemish clients)
- You want predictable MSP economics: ECP charges one fee per client per month, by the client's size in employees: Micro (1–9) €95, Small (10–49) €195, Medium (50–249) €395, Large (250–999) €750, 1,000+ on request. Partners buy below the published rate; the partner rate card is on request.
- Your clients need a CAB audit deliverable: ECP generates the signed .ecpbundle.zip that a Belgian accredited audit body accepts
The compliance cost comparison
This comparison is framework-vs-platform, not tool-vs-tool. IT-Grundschutz is a free methodology: the cost is the compliance project it demands. ECP is a platform that MSPs pay for and resell. The numbers below show what each path costs a typical German SME vs a typical Belgian SME served by an MSP.
IT-Grundschutz: German SME, Standard-Absicherung (with certification)
- • IT-Grundschutz Kompendium documents: free (PDF on bsi.bund.de)
- • Basis-Absicherung (basic level): €15,000–€40,000 consulting + internal ISMS work
- • Standard-Absicherung + ISO 27001 certification: €40,000–€120,000 consulting
- • Initial BSI certification audit fee: ~€2,978 (re-certification: ~€2,658)
- • Annual maintenance: ISMS ongoing costs + 3-year recertification cycle
- • Internal ISMS officer or external consultant required throughout
Cost estimates from independent analysis of BSI certification process and market consulting rates (advisori.de, Aug 2026). BSI certification fee from BMI published fee schedule. Costs vary widely by organization size, existing maturity, and scope. BSI-Standard 200-x methodology documentation is freely available at bsi.bund.de.
ECP / CyFun: Belgian SME via MSP (Small-tier client, 10–49 employees)
- • Direct end-client price (Small tier, 10–49 employees): €195 / month
- • Billed per client per month; MSP delivers the service on top
- • Client's annual cost: €2,340, vs €40K–€120K IT-Grundschutz Standard-Absicherung
ECP charges one fee per client per month, by the client's size in employees: Micro (1–9) €95, Small (10–49) €195, Medium (50–249) €395, Large (250–999) €750, 1,000+ on request. Partners buy below the published rate; the partner rate card is on request. Every client gets the full feature set including AI and integrations from day one. Evaluate via the live demo (shared sandbox, no signup).
Framework coverage overlap
IT-Grundschutz and CyFun both implement NIS2 security obligations, in their respective countries. The control areas overlap significantly because both trace back to NIS2 Article 21 and NIST CSF 2.0 influences. The difference is jurisdiction, depth, and delivery model.
| Control area | BSI IT-Grundschutz | CyFun / ECP |
|---|---|---|
| Governance & risk management | BSI-Standard 200-1 (ISMS); 200-3 (risk analysis). Risk management is core to Standard-Absicherung. | CyFun GV controls (governance); ECP wiki enforces policy ownership and review cadence |
| Access control & identity | ORP.4 module (identity & access management); SYS and APP modules include auth requirements | CyFun PR.AC controls; ECP access register + evidence collection per entity |
| Incident detection & response | DER.1 (detection), DER.2 (incident response), DER.4 (BCM). Mapped to NIS2 Art. 21(2)(b). | CyFun DE.CM + RS controls; ECP incident log + CSIRT notification workflow |
| Supply chain / ecosystem | OPS.2.3 (outsourcing usage) + OPS.3.2 (offering outsourcing), revised in Edition 2023. MSPs in scope as entities themselves. | CyFun ID.SC; ECP vendor register template |
| Secure configuration & hardening | Extensive: SYS (IT systems), NET (networks), IND (industrial IT) modules with specific hardening requirements per system type | CyFun PR.IP controls in Basic and above; less granular per system type than Grundschutz |
| Security supervision (SOC/SIEM) | DER.1 (monitoring), DER.3 (audits & reviews). Scales with implementation level. | CyFun DE.CM; included in Important / Essential tiers |
| ISO 27001:2022 mapping | Native: ISO 27001 on IT-Grundschutz is a BSI-recognized certification path. Grundschutz++ includes OSCAL crosswalk to ISO 27001:2022 Annex A. | Overlap significant; dedicated ISO 27001 support planned but not yet shipped |
| NIS2 Article 21 compliance | Yes: §44(2) BSIG references IT-Grundschutz; Kompendium modules confirmed to cover 100% of CIR 2024/2690 requirements | Yes: CyFun is Belgium's implementation of Article 21; CCB-issued |
Sources: BSI IT-Grundschutz Kompendium Edition 2023 (bsi.bund.de), NIS2UmsuCG §44, CCB CyFun 2025 documentation. Mapping is indicative: actual gap analysis requires professional assessment.
Common questions
Does following IT-Grundschutz satisfy NIS2 in Belgium?
No. IT-Grundschutz is Germany's national compliance path, explicitly referenced in German law (§44(2) BSIG / NIS2UmsuCG). Belgium's NIS2 compliance path is CyFun, issued by the CCB. A Belgian entity audited by a Belgian CAB body is assessed against CyFun, not against IT-Grundschutz. The two frameworks overlap in philosophy (both implement NIS2 Article 21) but are not interchangeable across borders. If your clients operate in both Germany and Belgium, they need to satisfy both BSI (IT-Grundschutz) and CCB (CyFun): the frameworks do not mutually recognize each other.
Can ECP help German clients comply with IT-Grundschutz?
Not natively today. ECP implements CyFun (the Belgian CCB framework). The control areas overlap significantly (both derive from NIS2 Article 21 and NIST CSF 2.0 influences), but ECP does not generate a BSI-audit-ready IT-Grundschutz bundle. A German entity using ECP would gain strong coverage on the underlying security principles, but would still need to map evidence to IT-Grundschutz module requirements and engage a BSI-certified auditor for the ISO 27001 on IT-Grundschutz path. ECP's framework engine is designed to support multiple national frameworks; German IT-Grundschutz support is on the product radar but not yet scheduled.
What is Grundschutz++ and does it affect the comparison?
Grundschutz++ is a major BSI reform rolling out from January 2026 with a multi-year transition period (parallel use of old and new until approximately 2029). It replaces the traditional text-based compendium with an OSCAL-compliant JSON format, cutting requirements from ~6,567 to ~985 while adding machine-readable crosswalks to ISO 27001:2022 Annex A and NIS2. For organizations with modern ISMS tooling, Grundschutz++ will significantly reduce compliance overhead. The transition doesn't change the geographic scope: IT-Grundschutz++ remains Germany's standard, and CyFun remains Belgium's.
Why is IT-Grundschutz compliance so much more expensive than CyFun via ECP?
Two reasons: depth and delivery model. IT-Grundschutz is one of the most comprehensive national security frameworks in the world: 111 modules with granular per-system-type requirements. Standard-Absicherung demands a full ISMS implementation before certification. That depth is genuine value for large organizations with complex IT environments, but it translates to €40K–€120K implementation projects for SMEs. ECP packages CyFun compliance into a guided platform with policy templates, evidence collection, and audit bundles. The MSP delivers this as a monthly service. The platform absorbs the complexity; the cost per client drops dramatically.
Deliver CyFun audit-readiness to your Belgian clients
If you are an MSP, CyFun, not IT-Grundschutz, is the compliance path your Belgian clients need. ECP packages it as a monthly MSP service: guided workflows, evidence collection, white-label reports, and a signed audit bundle your CAB auditor accepts.
Related
Fact check
| Claim | Source | Accessed |
|---|---|---|
| IT-Grundschutz first published 1994 by BSI | BSI 25th anniversary press release, October 2019 (bsi.bund.de) | 2026-08-17 |
| IT-Grundschutz Kompendium Edition 2023 contains 111 building blocks (Bausteine) in 10 layers | BSI IT-Grundschutz Kompendium Edition 2023 (multiple secondary sources confirm count) | 2026-08-17 |
| Grundschutz++ reduces requirements from ~6,567 to ~985 in OSCAL JSON, rolling out from 2026 | BSI Grundschutz++ reform documentation (tenmedia.de / fraghugo.de secondary sources) | 2026-08-17 |
| NIS2UmsuCG (Germany's NIS2 transposition) effective December 6, 2025; ~29,500 entities in scope | Greenberg Traurig NIS2 Germany analysis, December 2025; ArvexLab NIS2 Germany registration guide | 2026-08-17 |
| §44(2) BSIG explicitly references IT-Grundschutz as recognized standard for NIS2 compliance | NIS2UmsuCG §44(2) BSIG / multiple legal analyses | 2026-08-17 |
| Standard-Absicherung + ISO 27001 certification: €40,000–€120,000 consulting for SMEs; initial BSI cert fee ~€2,978 | ADVISORI BSI IT-Grundschutz SME cost analysis; BMI fee schedule for BSI certification | 2026-08-17 |
| IT-Grundschutz Kompendium modules cover 100% of CIR 2024/2690 requirements | BSI / NIS2UmsuCG compliance mapping analysis (secondary: nisd2.eu) | 2026-08-17 |
| ECP pricing: one fee per client per month, by employees (Micro €95, Small €195, Medium €395, Large €750, 1,000+ on request); partners buy below the published rate | ECP ADR-0050 per-client pricing by employee count | 2026-09-02 |
| CyFun is Belgium's official NIS2 compliance path, CCB-issued; CyFun 2025 counts: 34 Basic / 133 Important / 218 Essential (cumulative) | CCB Centre pour la Cybersécurité Belgique; CCB mapping workbook rows 163 and 168 | 2026-08-17 |