Grundschutz++ is the next generation of BSI baseline protection guidance, designed to make security requirements easier to structure and apply. It shifts emphasis toward clearer prioritisation and more practical implementation, helping organisations distinguish mandatory controls from recommended and optional measures across real target objects.
Expanded Definition
Grundschutz++ refers to the BSI’s evolving baseline-protection approach that moves beyond a static checklist and toward clearer prioritisation, more practical implementation, and easier mapping of requirements to real target objects. In NHI and IAM discussions, it is best understood as an operational refinement of baseline security guidance rather than a completely separate control model. That distinction matters because organisations often treat it as a document to read once, when its actual value lies in structuring decisions about which controls are mandatory, which are recommended, and which are optional for a given system or identity domain.
Its logic aligns with broader risk-based security thinking seen in the NIST Cybersecurity Framework 2.0, but no single standard governs Grundschutz++ usage across all environments. In practice, teams use it to make control application more consistent across infrastructure, cloud workloads, and non-human identities such as service accounts, workload identities, and API keys. The most common misapplication is treating Grundschutz++ as a universal compliance shortcut, which occurs when organisations copy baseline measures without first classifying the target object or implementation context.
Examples and Use Cases
Implementing Grundschutz++ rigorously often introduces scoping overhead, requiring organisations to weigh faster, more consistent control selection against the time needed to classify each target object correctly.
- A platform team uses the structure to decide which controls are mandatory for a workload identity that signs internal service-to-service requests, and which measures can remain recommended based on exposure.
- A security architect maps a Kubernetes service account to baseline requirements, then separates secret handling, rotation, and access review tasks into mandatory and optional workstreams.
- A cloud operations team applies the approach to an API key estate after reviewing guidance from Ultimate Guide to NHIs, using the prioritisation model to reduce control drift.
- A governance group aligns control selection with NIST Cybersecurity Framework 2.0 so that baseline measures can be translated into measurable security outcomes.
- A compliance team uses the model to separate inherited controls from compensating controls when a legacy system cannot immediately meet the preferred technical baseline.
Used well, Grundschutz++ helps teams avoid over-engineering low-risk environments while still preserving a defensible baseline for identities, secrets, and privileged paths.
Why It Matters in NHI Security
In NHI security, the value of Grundschutz++ is that it can turn broad guidance into action before identity sprawl becomes an incident driver. That is especially important when organisations are already dealing with weak secret hygiene and unclear ownership. NHI Mgmt Group data shows that 96% of organisations store secrets outside secrets managers in vulnerable locations, and only 5.7% have full visibility into their service accounts, both of which make prioritised baseline protection essential. The Ultimate Guide to NHIs also notes that 97% of NHIs carry excessive privileges, which means a baseline model that does not force clear control decisions can leave the highest-risk identities underprotected.
For practitioners, the key governance benefit is traceability: security leaders can explain why one control is mandatory for externally reachable secrets while another is optional for a constrained internal workload. That clarity supports auditability, reduces argument over control interpretation, and makes remediation more repeatable across teams. Organisations typically encounter the urgency of Grundschutz++ only after an identity review, breach investigation, or failed audit reveals that baseline controls were never actually applied to service accounts and API keys, at which point the framework becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207), NIST AI RMF and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.PO | Risk-based control prioritisation mirrors the framework's policy and governance outcomes. |
| OWASP Non-Human Identity Top 10 | NHI-02 | Secret handling and prioritised protection align with improper secret management concerns. |
| NIST Zero Trust (SP 800-207) | 5.1 | Baseline scoping supports zero trust decisions by tying protections to each identity and resource. |
| NIST AI RMF | Structured prioritisation supports governance, mapping, and measurement of risk treatments. | |
| NIST SP 800-63 | AAL2 | Assurance thinking helps distinguish stronger controls for higher-risk identities and sessions. |
Translate baseline guidance into documented policy decisions that rank controls by business and identity risk.
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org