CLARITY · Regulation & IT Security
Grundschutz++ from 2027:
What Clinics, Practices and
Care Facilities Need to Know Now
The BSI has confirmed the timeline. NIS2 has been in force since October 2024. What the healthcare sector must implement by 2027 — and why the window is narrower than it looks.
The BSI has officially confirmed it: Grundschutz++ certification starts in 2027. That sounds like plenty of time. It is not.
Three Regulations, One Direction
The current regulatory landscape for healthcare in Germany and across the EU converges on three levels:
NIS2 (since October 2024): The EU directive on network and information security applies to essential and important entities — including hospitals, larger healthcare facilities and parts of the care sector. It requires technical and organisational minimum measures, risk management and mandatory breach reporting. Fines up to €10 million or 2% of global annual turnover are possible.
BSI Grundschutz++ (certification from 2027): The BSI has announced a new certification level that goes beyond the existing IT-Grundschutz certificate. Grundschutz++ makes NIS2 compliance demonstrable under BSI standards. Anyone wanting 2027 certification must begin implementation in 2026.
EU Tech Sovereignty Package (May 2026): US cloud for health data is prohibited for public institutions. Hospitals, social agencies and care facilities must resolve their cloud dependencies — or demonstrate that their systems meet requirements.
Who is Affected
Not every practice is equally covered. NIS2 thresholds:
- Essential entities: 250+ employees or €50M annual revenue (larger clinics, hospitals)
- Important entities: 50+ employees or €10M annual revenue (mid-sized practices, MVZs, care homes)
- Smaller entities: No direct NIS2 obligation, but supply chain requirements of essential entities reach their service providers
In short: anyone providing services to NIS2-obligated facilities — labs, billing software, IT providers — faces obligations indirectly.
The Five Core Areas of Grundschutz++
1. Risk analysis — documented assessment of all IT systems, processes and dependencies.
2. Action plan — for each identified risk, a planned measure with responsible party and deadline.
3. Security reviews — regular patch management, access controls, network segmentation, backup tests. Not once — continuously.
4. Incident management — internal reporting system and mandatory reporting to BSI. Who knows what to do when an attack happens?
5. Supply chain management — which software providers have access to your systems? US cloud providers with CLOUD Act exposure are an explicit problem here.
Why Act Now, Not in 2026
Anyone wanting a Grundschutz++ certificate in 2027 must begin implementation at least 12 months prior — because certification verifies continuous measures over a period, not just a point-in-time snapshot.
Acting under pressure in 2026 costs more — emergency solutions, external consultants, downtime during migration, potential fines. Structured migration now costs less, takes less time, causes less disruption.
Clarity on your current situation
We look together at which of your systems are affected by NIS2 and Grundschutz++ — concretely, without consultant jargon, without panic.
Request a conversation →