klarheit

Grundschutz++ from 2027: What Clinics, Practices and Care Facilities Need to Know Now

02. June 2026

CLARITY · Regulation & IT Security

Grundschutz++ from 2027:
What Clinics, Practices and
Care Facilities Need to Know Now

The BSI has confirmed the timeline. NIS2 has been in force since October 2024. What the healthcare sector must implement by 2027 — and why the window is narrower than it looks.

Oct. 2024
NIS2 in force — applies now
2027
Grundschutz++ certification starts
12 months
until certification opens

The BSI has officially confirmed it: Grundschutz++ certification starts in 2027. That sounds like plenty of time. It is not.


Three Regulations, One Direction

The current regulatory landscape for healthcare in Germany and across the EU converges on three levels:

NIS2 (since October 2024): The EU directive on network and information security applies to essential and important entities — including hospitals, larger healthcare facilities and parts of the care sector. It requires technical and organisational minimum measures, risk management and mandatory breach reporting. Fines up to €10 million or 2% of global annual turnover are possible.

BSI Grundschutz++ (certification from 2027): The BSI has announced a new certification level that goes beyond the existing IT-Grundschutz certificate. Grundschutz++ makes NIS2 compliance demonstrable under BSI standards. Anyone wanting 2027 certification must begin implementation in 2026.

EU Tech Sovereignty Package (May 2026): US cloud for health data is prohibited for public institutions. Hospitals, social agencies and care facilities must resolve their cloud dependencies — or demonstrate that their systems meet requirements.


Who is Affected

Not every practice is equally covered. NIS2 thresholds:

  • Essential entities: 250+ employees or €50M annual revenue (larger clinics, hospitals)
  • Important entities: 50+ employees or €10M annual revenue (mid-sized practices, MVZs, care homes)
  • Smaller entities: No direct NIS2 obligation, but supply chain requirements of essential entities reach their service providers

In short: anyone providing services to NIS2-obligated facilities — labs, billing software, IT providers — faces obligations indirectly.


The Five Core Areas of Grundschutz++

1. Risk analysis — documented assessment of all IT systems, processes and dependencies.

2. Action plan — for each identified risk, a planned measure with responsible party and deadline.

3. Security reviews — regular patch management, access controls, network segmentation, backup tests. Not once — continuously.

4. Incident management — internal reporting system and mandatory reporting to BSI. Who knows what to do when an attack happens?

5. Supply chain management — which software providers have access to your systems? US cloud providers with CLOUD Act exposure are an explicit problem here.


Why Act Now, Not in 2026

Anyone wanting a Grundschutz++ certificate in 2027 must begin implementation at least 12 months prior — because certification verifies continuous measures over a period, not just a point-in-time snapshot.

Acting under pressure in 2026 costs more — emergency solutions, external consultants, downtime during migration, potential fines. Structured migration now costs less, takes less time, causes less disruption.


Clarity on your current situation

We look together at which of your systems are affected by NIS2 and Grundschutz++ — concretely, without consultant jargon, without panic.

Request a conversation →

Your digital space is waiting.

Discover Tycho Platform Start freedom check

How much of your IT costs are actually avoidable?

Start the conversation →