The stopgap becomes a fixture
WiBA looked like an entry aid for small municipalities, to be swapped later for the real thing. The BSI has since decided otherwise: the checklists become a fixture of the successor to the IT-Grundschutz-Kompendium.
IT-Grundschutz has a reputation for being thorough and demanding. For small municipalities, even basic protection was too much, which is exactly why the BSI developed the path into basic protection, WiBA for short: 19 topic-based checklists with 258 test questions that can be answered without knowing the methodology.
Seeing something like that for the first time, you file it as a stopgap. You start with it, and at some point you swap it for the real thing. That filing is now wrong.
What the BSI has decided
IT-Grundschutz is currently being rebuilt, under the name Grundschutz++. On the page about it sits a sentence that reclassifies WiBA: the checklists proven with WiBA have shown their worth in practice and become a fixture of Grundschutz++.
And further: in future, checklists are to be generated automatically from the requirements of the user catalogue, adapted to the specific use case.
That reverses the direction of view. The checklist is not a simplified precursor to the catalogue. It becomes the form in which the catalogue reaches those who run no ISMS. The BSI states this explicitly: small institutions should be able to implement fundamental requirements without building and operating a management system. Larger ones lay the foundation with it and expand step by step.
The catalogue becomes machine-readable
The second part of the news is the technical one. The user catalogue replaces the IT-Grundschutz-Kompendium and resides in the state-of-the-art library. Every requirement is captured as a rule in a standardised format, and those rules can be evaluated by programs.
Anyone following the past months recognises the pattern. For the Cyber Resilience Act, the BSI attached its selection of measures in the OSCAL format. For Grundschutz, the entire catalogue now takes that path. A rule set published only as a PDF gets retyped and goes stale in spreadsheets. One published as data can be imported and linked to your own inventory.
One change in it will cause discussion: the familiar protection levels basic, standard and elevated are replaced by flexible performance figures with dynamic thresholds. And the rule set is being sharpened; in future it describes only solution-independent requirements for processes.
The dates
The BSI milestone plan, as of 26 March 2026, names concrete dates. The pilot phase ran from 1 April to 30 September 2026. On 27 October 2026, the methodology is published at it-sa in Nuremberg. From 1 January 2027, certification to ISO 27001 on the basis of Grundschutz++ becomes possible, along with certification as GS++ consultant and GS++ audit team leader. By 31 March 2027, every requirement is to carry performance indicators.
What follows from this today
Anyone starting with the WiBA checklists now is not working into a dead end. The answers stay usable because the checklists stay, and the BSI mapping table shows which requirements of the IT-Grundschutz profile are already met.
The converse holds just as much: waiting for the October publication gains nothing. The test questions do not change just because the catalogue beneath them does.
We carry the 19 checklists with their 258 test questions in the module, with completion status, effort estimate, responsibilities and history. More on the WiBA module page.
Questions about this update?
Talk to us – we are happy to show you this feature in a demo.