Blackfort Technology
German security obligations for your telecom services
NIS2 for telecom providers

For providers registered with the Bundesnetzagentur

German security obligations for your telecom services

Under NIS2, telecom providers fall under the jurisdiction of each Member State in which they provide services (Art. 26(1)(a) NIS2). For your German activities the Telecommunications Act (TKG) applies. Check in ten questions what is still open for you.

What applies to your German activities

The Telecommunications Act applies to everyone who operates telecommunications networks or provides telecommunications services in Germany, regardless of where the company is headquartered (Section 1(2) TKG). Three points matter most:

Significant incidents

go to the Bundesnetzagentur (Federal Network Agency) and the Federal Office for Information Security (BSI): early warning within 24 hours of becoming aware, notification within 72 hours, final report at the latest one month after that notification (Section 168 TKG).

Security officer and security concept

You need a security officer, a contact person established in the EU and a security concept; network operators submit it to the Bundesnetzagentur (Section 166 TKG), whose official language is German.

Management duties

Management must implement and oversee the security measures and attend regular training (Section 165(2b) and (2d) TKG).

If you have an establishment in Germany, such as a branch or subsidiary, BSI registration is usually also required (Section 33 BSIG); it is possible without a German tax number. The Bundesnetzagentur is also revising its catalogue of security requirements: the published draft has three risk levels and is not yet adopted.

Self-check: ten questions, five minutes

Answer the questions for your company. Your answers stay in your browser and are not transmitted.

  1. 1.If you have an establishment in Germany: is your company registered with the BSI?

  2. 2.Have you appointed a security officer for your German activities?

  3. 3.Have you named a contact person established in the EU?

  4. 4.Do you have a security concept that describes your current network and services in Germany?

  5. 5.Does your security concept cover the ten minimum measures?

  6. 6.Could you report a significant incident affecting your German services to both the Bundesnetzagentur and the BSI within 24 hours?

  7. 7.Is it clear who decides on a report at night and at weekends?

  8. 8.Does management attend regular cybersecurity training?

  9. 9.Does management oversee the measures in a traceable way, for example through a regular report?

  10. 10.Do you know your likely level under the Bundesnetzagentur's draft catalogue of security requirements?

10 questions left.

Your fixed-fee starter package, in English

  • classification of your company under the German rules and, where needed, support with BSI registration
  • review of your security concept against the minimum measures (Section 165(2a) TKG)
  • reporting template and a German cover text for the authorities
  • a prioritised list of open items, delivered in English

EUR 4,900 net for a small enterprise as defined by the EU, otherwise EUR 5,900 net.

Small enterprise under Commission Recommendation 2003/361/EC: fewer than 50 employees and annual turnover or balance sheet total of no more than EUR 10 million, including linked and partner enterprises. Per legal entity, remote, plus VAT where due; EU businesses: reverse charge as a rule. Not included: multiple legal entities, on-site or technical audits, full drafting or revision of the security concept, ongoing correspondence with authorities, legal advice, certified translations.

The first 30-minute call is free of charge.

Since 2019 we have written security concepts under Sections 109 and 166 TKG for telecom providers, aligned them with the Bundesnetzagentur and acted as security officers under Section 166 TKG. More on the security concept itself: TKG security concept.

Compliance card: telecom security in Germany

For providers of public telecommunications networks and publicly available services in Germany. As of September 2026. BNetzA: Bundesnetzagentur (Federal Network Agency); BSI: Federal Office for Information Security.

ObligationWhat should be in placeDeadlineLegal basis
Notification to BNetzAStart, changes and end of activity; changes of name, legal form, address.without delaySection 5 TKG
BSI registrationUsually required with an establishment in Germany (branch or subsidiary); possible without a German tax number.3 months; changes 2 weeksSection 33 BSIG
Security officer, EU contact, security conceptAppoint a security officer, name a contact person established in the EU, prepare and update the concept; network operators submit it with an implementation declaration, service providers on request.network operators: submit without undue delay after starting operations; BNetzA should review at least every 2 yearsSection 166 TKG
Minimum measuresRisk analysis, incident handling, backup and continuity, supply chain, vulnerabilities, effectiveness, training, encryption, access control, MFA.ongoingSection 165(2a) TKG
ManagementImplement and oversee the measures, attend regular training.ongoingSection 165(2b)-(2d) TKG
Incident reportingSignificant incidents, to BNetzA and BSI: early warning, notification with initial assessment, final report (progress report if still ongoing).without delay, max. 24 h; 72 h; 1 monthSection 168 TKG
LanguageGerman is the official language; for documents in other languages the authority is, as a rule, to request a translation without delay.on submissionSection 23 VwVfG
New catalogueBundesnetzagentur draft with three risk levels, not yet adopted. Check your level, prepare a plan.usually 1 year after entry into forceSection 167 TKG

Summary of German statutory obligations, not legal advice; there is no official English version of TKG or BSIG. German version: NIS2 für TK-Anbieter.