Germany

Europe

German telecom-security regulation combines BNetzA network-security rules with BSI critical-infrastructure (KRITIS) requirements. The BSI Catalogue of Security Requirements is the binding technical reference.

Regulator: BNetzA + BSI

Primary frameworks: TKG (Telekommunikationsgesetz), BSI IT-SiG 2.0, BSI Catalogue of Security Requirements, KRITIS Regulation

BSI Catalogue

The Catalogue of Security Requirements under §165(2) TKG binds operators to specific measures. It includes explicit signaling-security controls, roaming risk management, and vendor-component certification.

5G component certification

Critical 5G core components require BSI certification (Common Criteria or equivalent). Certification scope covers SEPP, UDM, AMF, and other core NFs.

KRITIS obligations

Telecom providers above threshold fall under KRITIS. This adds mandatory incident reporting to BSI and biennial audit obligations.

Key takeaways

  • The BSI Catalogue names controls at implementation-detail level — vaguer policies do not satisfy the audit.
  • Vendor certification changes procurement timelines; multi-year lead is normal.
  • KRITIS status brings binding audit cadence that most other EU regimes lack.