Security Policy
pursuant to Section 166 of the Telecommunications Act (TKG)

Take Advantage of Our Expertise!

Under the Telecommunications Act, network operators and service providers are required to implement technical and organizational measures. These measures are intended, in particular, to:

  • to protect personal data and the confidentiality of telecommunications
  • to protect the telecommunications infrastructure from disruptions and risks
  • ensuring the availability of telecommunications services

The measures taken are documented in the security policy pursuant to Section 166 of the Telecommunications Act (TKG). The security policy must be demonstrated to the Federal Network Agency in accordance with legal requirements or submitted for review upon request.

Compliance with legal requirements is of particular importance in this context. Violations of relevant security requirements, reporting obligations, or regulations regarding the protection of telecommunications secrecy and personal data may result in substantial fines.

We have many years of experience in developing and updating telecommunications security concepts and also support network operators and service providers in their interactions with the Federal Network Agency. Through our structured approach, we make the process as efficient as possible for you and reduce internal administrative burden to the absolute minimum.

Request a free quote now

The requirements of the Telecommunications Act are further specified by the Federal Network Agency in a catalog of security requirements. Among other things, this catalog requires a clear and well-defined organizational structure and operational procedures to achieve the defined security objectives. In addition to the actual security concept, the company must therefore clearly define areas of authority, responsibilities, and organizational processes.

With our sample organizational concept, we support network operators and service providers in systematically establishing the necessary structures and documenting them in a transparent manner.

In addition to the Telecommunications Act, the legal requirements surrounding NIS 2 and critical infrastructure also play an important role. Depending on their size, activities, and significance, telecommunications companies may be subject to different regulatory requirements. Under the NIS 2 Implementation Act, classification as an important or particularly important facility may be particularly relevant. Depending on the specific classification, additional requirements under the KRITIS regulation may also apply.

If needed, we can assist you in developing or updating your security strategy, as well as in the structured implementation of the legal requirements relevant to your company.

Request a free quote now

Additional Security Concepts

The Energy Industry Act requires electricity and gas grid operators and facility operators to establish and operate an “information security management system” (ISMS). The basis for this is the “IT Security Catalog pursuant to Section 11(1a) of the Energy Industry Act” issued by the Federal Network Agency (BNetzA) and the DIN EN ISO 27001 standard. Unlike in other industries (e.g., telecommunications), external certification of the ISMS is mandatory here.

In addition to the Energy Industry Act, legislation on critical infrastructure also requires corresponding security concepts and measures. Depending on their size and significance, companies in the “energy” sector may be considered critical infrastructure in their own right and/or, under the NIS-2 Implementation Act, may also be classified as “important” or “particularly important facilities.” The KRITIS Umbrella Act may also contain additional requirements if it applies to an energy company based on the number of “residents to be supplied.”

The Federal Network Agency (BNetzA) has already announced the publication of a revised version of the IT Security Catalog, which will introduce stricter IT security rules in the future. 

If you need to create, revise, or update your security concept, we are the right partner for you. We support you with expert advice as well as sample concepts and
documents to minimize the effort required on your part. Please contact us. As a consulting firm, however, we are not permitted to certify our own work. Therefore, we only offer consulting services for establishing an ISMS that complies with legal requirements and ISO standards. Certification must be carried out by appropriately accredited certification service providers.

According to the IT Security Act and the KRITIS Regulation, district heating network operators are considered part of critical infrastructure. Accordingly, they are required, among other things, to establish an information security management system (ISMS). The applicable standard for this industry is the so-called “B3S District Heating Networks,” which sets out the relevant requirements. This document is an industry standard that has been reviewed by the BSI (Federal Office for Information Security) and approved for a period of three years. The current standard remains valid through January 2027. 

Under the NIS-2 Implementation Act, district heating and district cooling systems were defined as “sectors of particularly important and important facilities” and are thus included within the scope of the law. Consequently, additional security management requirements may need to be observed.

The KRITIS Framework Act (KRITISDachG) aims to further advance the protection of critical infrastructure and to establish standards for physical security. Here, too, the “energy” sector is generally considered the target of the relevant regulation. A implementing regulation, analogous to the KRITIS Regulation, specifies the critical services and facilities that, based on certain criteria, are essential for the provision of critical services under the KRITISDachG. Accordingly, additional security management requirements under this law may also need to be implemented.

If you need to develop, revise, or update your security concept, we are the right partner for you. We support you with expert advice.

Additional Information

In the German telecommunications market, there are four key obligations for providers of telecommunications services. These are:

  • Obligation to report to the Federal Network Agency (BNetzA)
  • The obligation to appoint a security officer
  • Obligation to develop and implement a security plan
  • The obligation to submit the security plan to the BNetzA

For network operators, it can generally be stated that all of these obligations must be fulfilled. However, the situation is more nuanced for service providers. The new Telecommunications Act, which took effect on December 1, 2021, has redefined telecommunications services. Service providers that were classified as so-called “over-the-top providers” were previously not subject to the regulatory framework of the TKG. This article first addresses the obligations under Section 166 of the TKG (formerly Section 109—Security Officer and Security Policy) and Section 165 (Technical and Organizational Security Measures), as well as the reporting obligation to the Federal Network Agency (BNetzA).

How is a telecommunications service defined? The new TKG contains several important provisions on this point:
Section 3, “Definitions,” states:

61. “Telecommunications services” means services generally provided for a fee via telecommunications networks, which—with the exception of services that offer content via telecommunications networks and services or exercise editorial control over such content—include the following services:

a) Internet access services,
b) interpersonal telecommunications services, and
c) services that consist entirely or predominantly of the transmission of signals, such as transmission services used for machine-to-machine communication and for broadcasting;

Furthermore, paragraph 24 of this section states the following:
24.  “person-to-person telecommunications service” means a service, usually provided for a fee, that enables a direct, person-to-person, and interactive exchange of information via telecommunications networks between a finite number of persons, whereby the recipients are determined by the persons initiating the telecommunications or participating therein; This does not include services that merely enable interpersonal and interactive telecommunications as a subordinate ancillary function inseparably linked to another service;
According to our understanding, telecommunications services thus include all Internet access services, all interpersonal telecommunications services that do not constitute a subordinate ancillary function, as well as certain signal transmission services.

Consequently, there is no longer an exception for so-called “over-the -top services,” such as e-mail services, which are essentially provided via the networks of network operators but are not themselves provided by those operators as service providers (as is the case, for example, with Google’s e-mail service).

The only exception still provided for is when the telecommunications service would be classified as “a subordinate ancillary function inseparably linked to another service.” This is the case, for example, when a chat service is offered as a secondary function within an online game and is inseparably linked to the main function—the game itself.
What obligations now apply to the providers of these telecommunications services with regard to reporting requirements, security policies/security officers, and the requirement to submit the security policy to the Federal Network Agency (BNetzA)?

Pursuant to Section 166 of the Telecommunications Act (TKG), the operator of a telecommunications network and the provider of a publicly available telecommunications service (see above) must, among other things, appoint a security officer and develop a security plan.

Pursuant to Section 166, this obligation applies to network operators. Service providers must maintain a security plan and may be required by the BNetzA to submit it.

The requirement to report the “commencement, modification, and termination of their activities, as well as changes to their name or business name, legal form, and address” pursuant to Section 5 of the Telecommunications Act (TKG) applies to all network operators and providers of telecommunications services “that are not number-independent interpersonal telecommunications services.” Thus, this provision again applies without exception to network operators as well as certain service providers. The exception for service providers therefore applies to number-independent interpersonal telecommunications services—such as, for example, messaging services that operate independently of national or international numbering plans.

Develop or Update Your Security Plan Now

Request a free quote now