Blackfort Technology
TKG §166 Security Concept

Telecommunications Security

TKG §166 Security Concept

Mandatory security concept for public telecommunications network operators and service providers in Germany, aligned with the Bundesnetzagentur's catalogue of security requirements and with NIS2.

TKG §166: Legal Obligation for Telecom Operators in Germany

The German Telecommunications Act (Telekommunikationsgesetz, TKG) requires operators of public telecommunications networks and providers of publicly available telecommunications services in Germany to appoint a security officer, to name a contact person established in the European Union and to prepare a security concept (Section 166(1) TKG). The protective measures themselves are governed by Section 165 TKG and specified in the Bundesnetzagentur's catalogue of security requirements under Section 167 TKG.

All companies that operate a public telecommunications network or provide publicly available telecommunications services are affected, from classic network operators and internet providers to companies providing voice or data services for third parties. The obligations apply regardless of company size; the scope and depth of the security concept reflect the specific infrastructure and threat situation.

Network operators submit the security concept to the Bundesnetzagentur (BNetzA) without undue delay after starting operations; service providers do so on request (Section 166(2) TKG). It must be accompanied by a declaration that the measures have been implemented or will be implemented without undue delay (Section 166(3) TKG). Whoever is obliged to submit the concept must update it without undue delay when the underlying circumstances change and resubmit it, indicating the changes (Section 166(4) sentence 2 TKG). If the Bundesnetzagentur finds security deficiencies in the concept or its implementation, it can require them to be remedied without undue delay (Section 166(4) sentence 1 TKG). Failing to submit the concept after starting network operations or after an update, or submitting it incorrectly, incompletely or late, is an administrative offence (Section 228(2) no. 38 TKG), as is failing to comply with an enforceable order to submit it or to remedy deficiencies (Section 228(2) no. 3(c) TKG). The authority can also order an audit by a qualified independent body or a competent national authority (Section 165(9) sentence 1 TKG).

§109 TKG (old) and §166 TKG (new): What the 2021 TKG Reform Changed

The new TKG, in force since 1 December 2021, reorganised the security obligations of the former Section 109 TKG: Section 165 covers technical and organisational protective measures including critical components, Section 166 the security officer and the security concept, Section 167 the catalogue of security requirements and Section 168 the reporting of security incidents. The core requirement remains: network operators submit their security concept to the Bundesnetzagentur, service providers do so on request.

Since 6 December 2025 the TKG also implements the NIS2 Directive for telecom providers: ten minimum measures (Section 165(2a)), management duties including regular training (Section 165(2b) to (2d)) and the reporting of significant incidents to the Bundesnetzagentur and the BSI within 24 hours, 72 hours and one month (Section 168). Anyone with a concept under the old Section 109 TKG should check it against these requirements.

For companies with a Section 109 TKG concept from before 2021, a targeted gap analysis against today's requirements is recommended. Blackfort Technology prepares new concepts under Section 166 TKG and revises existing ones, with a focus on the changes since 2021 and the NIS2 obligations.

Required Content: What the TKG §166 Security Concept Must Cover

The security concept must show which public telecommunications network is operated and which publicly available telecommunications services are provided, which threats are to be expected, and which technical and other protective measures have been taken or are planned to meet the obligations under Section 165(1) to (7) TKG (Section 166(1) no. 3 TKG). The benchmark is the catalogue of security requirements; where it only sets security objectives, the concept must show that the measures fully achieve them. In practice this covers network architecture and redundancy, physical protection of network nodes, access control, incident handling and contingency planning, and the protection of the secrecy of telecommunications and of personal data.

Network operators and service providers with an increased risk potential face additional obligations: they must use attack detection systems (Section 165(3) sentence 2 TKG). Network operators with an increased risk potential may only use critical components that have been checked and certified by a recognised certification body before first use (Section 165(4) TKG), and must undergo an audit by a qualified independent body or a competent national authority every two years (Section 165(9) sentence 2 TKG).

The obligations under Sections 165 and 166 TKG largely overlap with NIS2, because the TKG itself implements NIS2 for telecom providers, which are essential or important entities regardless of size (Section 28(1) sentence 1 no. 3, (2) sentence 1 no. 2 BSIG). Blackfort develops security concepts that meet both frameworks and avoids duplication through a shared documentation structure.

Our Approach: From Analysis to Submitted Concept

We begin with an analysis of your telecommunications infrastructure: which networks and services do you operate? Where are the critical nodes? Which third-party providers and suppliers are involved? On this basis, we create a security concept that describes your actual infrastructure.

The concept is aligned with the catalogue of security requirements. From accompanying several TKG projects we know the level of detail the Bundesnetzagentur expects and the typical points it asks to be improved.

After preparation, we can accompany the submission to the Bundesnetzagentur, clarify queries from the authority and support ongoing updates to the concept. For companies that already have a concept in place, we also offer review and revision, particularly in light of the NIS2 obligations.

The Implementation Declaration: More Than a Compliance Formality

The Umsetzungserklärung (implementation declaration) is submitted together with the security concept (Section 166(3) TKG). In it, the company declares that the measures set out in the concept have been implemented or will be implemented without undue delay. It turns a conceptual document into a binding statement about the actual situation.

Since December 2025 a telecom provider's concept must also cover the ten minimum measures of Section 165(2a) TKG: risk analysis and information system security, incident handling, business continuity including backup management, disaster recovery and crisis management, supply chain security, security in acquisition, development and maintenance including vulnerability management and disclosure, assessment of effectiveness, basic practices and training, cryptography and encryption, human resources security with access control and asset management, and multi-factor or continuous authentication, secured voice, video and text communication and, where appropriate, secured emergency communication.

We support you in preparing the concept and the implementation declaration and accompany submission, queries from the Bundesnetzagentur and audits.

Our Services

  • Full TKG §166 security concept preparation
  • Review and update of existing concepts
  • Alignment with BNetzA requirements
  • NIS2 alignment for telecom operators
  • Support during regulatory queries and audits
  • Integration into existing ISMS structures

Regulatory Framework

  • TKG §166 (2021)
  • NIS2 Directive
  • BSI IT-Grundschutz
  • ISO/IEC 27001
  • KRITIS Regulation

Get Expert Advice

Talk to our regulatory experts about your specific TKG compliance situation.

Request Consultation

Related service

TKG Customer Data: §§ 172-174 TKG

Obligations, protection requirements and disclosure duties for customer data under §§ 172-174 TKG, to be taken into account in protective measures and the security concept.

Read more →

Frequently asked questions

Which companies are required to prepare a security concept under §166 TKG?

All operators of public telecommunications networks and providers of publicly available telecommunications services in Germany, from classic network operators and internet providers to companies providing voice or data services for third parties. The obligation applies regardless of company size; the scope and depth of the concept reflect the specific infrastructure. Network operators submit the concept to the Bundesnetzagentur without undue delay after starting operations; service providers do so on request.

What must a TKG §166 security concept contain?

The concept must show which public telecommunications network is operated and which publicly available telecommunications services are provided, which threats are to be expected, and which technical and other protective measures have been taken or are planned to meet the obligations under Section 165(1) to (7) TKG (Section 166(1) no. 3 TKG). The benchmark is the Bundesnetzagentur's catalogue of security requirements. Since December 2025 this includes the ten minimum measures of Section 165(2a) TKG.

What is an Umsetzungserklärung (implementation declaration) under TKG §166 and why is it so important?

The implementation declaration is submitted together with the security concept. In it, the company declares that the measures set out in the concept have been implemented or will be implemented without undue delay (Section 166(3) TKG). It turns the concept into a binding statement about the actual situation.

How does the preparation of a TKG §166 security concept with Blackfort Technology work?

We begin with an analysis of your telecommunications infrastructure, prepare a security concept aligned with the catalogue of security requirements and support submission, regulatory queries and ongoing updates. For existing concepts we also offer review and revision, in particular with regard to the NIS2 obligations that apply since December 2025.

What did §109 TKG regulate and why does it no longer exist?

Section 109 TKG in the version before 1 December 2021 contained the security obligations of telecommunications companies, including the security officer, the security concept, the implementation declaration and submission to the Bundesnetzagentur. With the new TKG these obligations were split across Sections 165 to 168: protective measures including critical components (Section 165), security officer and security concept (Section 166), catalogue of security requirements (Section 167) and reporting of security incidents (Section 168).

Which reporting deadlines apply to telecom providers since NIS2?

Significant security incidents must be reported to the Bundesnetzagentur and the Federal Office for Information Security (BSI): an early warning without undue delay and at the latest within 24 hours of becoming aware, an incident notification with an initial assessment at the latest within 72 hours of becoming aware, and a final report at the latest one month after that notification (Section 168 TKG). The 24-hour and 72-hour deadlines also run at night, at weekends and on public holidays.

Kontakt aufnehmen

TKG §166 Compliance for Your Telecom Operations

Let us prepare a security concept aligned with the Bundesnetzagentur's catalogue of security requirements.