forumNew topic

Client wants vulnerability management compliant with BSI rules — what do we actually need to set up in Germany?

PPerihan K***Member
Job title
Product Manager
Sector
Catering
Organization type
20-person company
Joined
Feb 2024
Message
220

Doki · Corporate website · 2024

#1

We are a 14-person team developing custom software for public enterprises and municipal entities in Germany. In a recently signed framework agreement, the primary client stipulated that the infrastructure we deliver must implement vulnerability management (Schwachstellenmanagement) compliant with standards set by the Federal Office for Information Security (BSI).

Until now, our system administrator applied weekly updates manually, and whenever a critical security advisory surfaced, we remediated it the same day. However, the client is demanding an auditable, documented process with regular reporting. We have allocated a budget of around 8,000 EUR and a 2-month ramp-up window for this effort.

Without going through a full-scale institutional BSI certification from scratch, what exactly must a baseline vulnerability management lifecycle cover to pass the client's audit? From inventory to patch scheduling and log retention, what concrete steps do we need to take?

SSelin K***Member
Job title
Human Resources Specialist
Sector
E-commerce
Organization type
workshop
Joined
Sep 2024
Message
42
Most Helpful#2

Short answer: Unless the client strictly mandates full formal certification, you only need to formalize the baseline vulnerability management steps from the BSI IT-Grundschutz standard into a written policy and produce auditable records. This structure consists of a regular asset inventory, tracking vulnerability feeds, risk scoring, binding remediation SLAs, and audit logs.

First, build a dynamic asset inventory listing all servers, operating systems, databases, and open-source dependencies along with their version numbers. Second, set up automated notification feeds for BSI advisories (CERT-Bund) and national vulnerability databases. Classify incoming vulnerabilities by CVSS score: establish an SLA of at most 72 hours for critical and high-risk flaws, 14 days for medium, and 30 days for low-risk issues.

Third, clearly define role assignments; the policy must document separate duties for discovering the vulnerability, verifying the patch in staging, and deploying it to production. Fourth—and this is what the client will examine most closely—is audit documentation. Run an automated or semi-automated vulnerability scan monthly and archive the reports, associated support tickets, and closure timestamps. If a patch cannot be applied due to compatibility conflicts, you must document what compensating controls were implemented and retain a signed risk acceptance form.

AAhmet Z***MemberCommunity member
Joined
Feb 2024
Message
25
#3

Smaller teams often hear BSI and instantly get overwhelmed by hundreds of pages of IT-Grundschutz documentation. Most of the time, the client doesn't actually mean full certification; they just need operational proof they can present during an audit. If the contract doesn't explicitly require an ISO 27001 or formal BSI certificate, proceed by delivering a documented process and scan reports without burning through your budget.

MMehmet M***Member
Job title
Digital marketing specialist
Sector
Education
Organization type
regional distributor
Joined
Nov 2025
Message
302
#4

To streamline things technically, integrate continuous open-source dependency scanners alongside host-level vulnerability scanners. Hooking up a webhook that pushes new CVE findings straight into your ticketing system will save your sysadmin from keeping manual spreadsheets. BSI auditors typically look for unscanned shadow servers, so make sure every subdomain host is covered under your scope.

İİbrahim K***Member
Job title
Supply chain manager
Sector
Leather
Organization type
120-person company
Joined
Oct 2024
Message
177
#5

On a similar public sector project, we licensed a vulnerability scanner for 2,200 EUR annually. Setting up the system took us 3 weeks. Our sysadmin spends 2 hours every Monday reviewing BSI and CERT bulletins, and 6 hours a month generating reports. Thanks to this routine, we cleared our last two client audits with zero findings.

UUfuk B***Member
Job title
Field sales representative
Sector
Paper
Organization type
chain store
Joined
Nov 2024
Message
2
#6

The quickest things you can do starting tomorrow: 1) Put together a clean spreadsheet listing your servers and libraries. 2) Subscribe to the free CERT-Bund email newsletter. 3) Draft a two-page Security Policy specifying patch timelines and have it signed off internally. When the client comes for an audit, that document is the first thing they'll ask to see.

EErcan B***MemberCommunity member
Joined
Sep 2023
Message
140
#7

We faced the exact same requirement in a healthcare software tender in Munich. During the first audit, they asked us, "How long did it take you to patch that critical kernel vulnerability that came out last month, and where's the log?" We had pushed the patch to prod in 4 hours, but we got flagged because we hadn't opened a ticket and logged the timestamps. The whole secret really boils down to proper record-keeping.

VVildan Y***Member
Job title
Content Editor
Sector
Retail
Organization type
20-person company
Joined
Nov 2024
Message
70
#8

Does your client explicitly reference BSI IT-Grundschutz building block OPS.1.1.3 (Patch- und Änderungsmanagement) in the specs? If that module is mandated you need to link your change management process directly to patch approvals.

AAhmet G***MemberCommunity member
Joined
Apr 2022
Message
30
#9

went through something similar, add automated vuln scanning bots to your git repo. have them scan libraries on every build. tbh even just a flowchart showing you never push code to prod without a green light in staging is enough to satisfy the client.

TTuğçe T***Member
Job title
Agency Founder
Sector
Law
Organization type
120-person company
Joined
Nov 2025
Message
19

Doki · Server maintenance contract · 2025

#10

Because your client is affiliated with the public sector, they are required to guarantee BSI compliance in their subcontractor agreements. The documentation you prepare should include a RACI matrix, an emergency patching procedure, and a commitment to annual external audits. It is essential that these documents are officially approved by company leadership.

YYağmur C***MemberCommunity member
Joined
May 2023
Message
274
#11

We need to make a distinction here. Your time to detect an issue directly determines its cost.

That's all, sorry if I went on too long.

OOya I***Member
Job title
Board member
Sector
Cosmetics
Organization type
40-person manufacturing company
Joined
Aug 2023
Message
225
#12

How did you solve this? The real issue isn't the number, but what it's based on.

UUfuk A***ExpertCommunity member
Joined
Dec 2024
Message
410
#13

Sorry, but this doesn't apply in every case. Most incidents start with a leaked password, not a vulnerability.

Good luck with that.

İİsmail T***MemberCommunity member
Joined
Jan 2024
Message
418
#14

I've been dealing with this for a long time. Everyone rushing into bsi vulnerability management gets stuck at the same point.

DDoruk Ş***MemberCommunity member
Joined
Oct 2024
Message
218
#15

I'd appreciate it if you shared the outcome. Start with a small trial; don't commit to everything at once.

Just leaving this note, it might be useful.

SSultan A***Member
Job title
Administrative manager
Sector
Chemistry
Organization type
workshop
Joined
Jan 2023
Message
53
#16

Following.

AAleyna E***MemberCommunity member
Joined
Aug 2024
Message
80
#17

There's a part I don't understand. An automated scan report is not the same as a penetration test.

Good luck with that.

BBeyza V***Member
Job title
Information Security Specialist
Sector
Education
Organization type
workshop
Joined
Aug 2023
Message
160
#18

Exactly like that. Solutions that work at a small scale collapse when you grow; I learned this late.

If you post the result here, it will help others too.

YYavuz B***MemberCommunity member
Joined
Apr 2022
Message
203
#19

The discussion got scattered, let me summarize. If it's your first time, start small; scaling comes later.

The answer varies greatly by industry; there is no one-size-fits-all rule. Hope this helps.

EEmine S***Veteran
Job title
Country Manager
Sector
Tourism
Organization type
chain store
Joined
Dec 2023
Message
1

Doki · Infrastructure migration · 2025

#20

You're right. I mean hasty decisions become decisions you have to fix six months later.

An automated scan report is not the same as a penetration test. anyway if you post the result here it will help others too.

Reply