Message 001
Communication from the Commission - TRIS/(2026) 2713
Directive (EU) 2015/1535
Notification: 2026/0525/DE
Notification of a draft text from a Member State
Notification – Notification – Notifzierung – Нотификация – Oznámení – Notifikation – Γνωστοποίηση – Notificación – Teavitamine – Ilmoitus – Obavijest – Bejelentés – Notifica – Pranešimas – Paziņojums – Notifika – Kennisgeving – Zawiadomienie – Notificação – Notificare – Oznámenie – Obvestilo – Anmälan – Fógra a thabhairt
Does not open the delays - N'ouvre pas de délai - Kein Fristbeginn - Не се предвижда период на прекъсване - Nezahajuje prodlení - Fristerne indledes ikke - Καμμία έναρξη προθεσμίας - No abre el plazo - Viivituste perioodi ei avata - Määräaika ei ala tästä - Ne otvara razdoblje kašnjenja - Nem nyitja meg a késéseket - Non fa decorrere la mora - Atidėjimai nepradedami - Atlikšanas laikposms nesākas - Ma jiftaħx il-perijodi ta’ dewmien - Geen termijnbegin - Nie otwiera opóźnień - Não inicia o prazo - Nu deschide perioadele de stagnare - Nezačína oneskorenia - Ne uvaja zamud - Inleder ingen frist - Ní osclaíonn sé na moilleanna
MSG: 20262713.EN
1. MSG 001 IND 2026 0525 DE EN 29-09-2026 DE NOTIF
2. Germany
3A. Bundesministerium für Wirtschaft und Energie, Referat E B 3, 10115 Berlin, Tel.: 0049-30-18615-6392, E-Mail: infonorm@bmwe.bund.de
3B. Bundesministerium für Digitales und Staatsmodernisierung, Referat DI 4-TK, 53175 Bonn, Tel.: 0049-175-7702502, E-Mail: DI4-TK@bmds.bund.de
Bundesnetzagentur für Elektrizität, Gas, Telekommunikation, Post und Eisenbahnen, Referat 217, An der Trift 40, 66123 Saarbrücken, Tel.: 0049-681-9330-471, E-Mail: 217.Postfach@BNetzA.de
4. 2026/0525/DE - V00T - TELECOMS
5. Catalogue of security requirements for the operation of telecommunications and data processing systems and for the processing of personal data pursuant to Section 167 of the Telecommunications Act
6. Description of technical and other measures to ensure data security and data quality, confidentiality and the availability of public telecommunications networks and publicly available telecommunications services.
7.
8. The security catalogue provides for technical precautions and other measures in order to guarantee a high standard of data security, data protection, the guaranteeing of telecommunications confidentiality as well as ensuring a sufficiently high availability of public telecommunications networks and publicly accessible telecommunications services. In particular, for network components with increased risk potential, additional security requirements are defined as well as supplementary protective measures being described. In this context, the network components posing an increased risk are identified in a “List of Critical Functions” (Annex 2 of the Security Catalogue) published by mutual agreement between the Federal Office for Information Security (BSI) and the Federal Network Agency (BNetzA). A key element in this regard is, in particular, the ‘security certification’ of critical components by a recognised body.
9. The measures laid down in the catalogue of safety requirements are regularly reviewed and adapted to keep up with the state of the art.
9a. The catalogue of security requirements promotes the security of public telecommunications networks and publicly offered telecommunications services by requiring measures to ensure the protection of the availability, authenticity, integrity and confidentiality of those networks and services, of stored, transmitted or processed data, or of the related services offered by, or accessible via, those telecommunications networks or services.
9b. There are no less severe means that would be equally suitable for achieving the objectives of the catalogue of safety requirements.
The security catalogue covers a wide range of addressees and possible issues. It affects both very large companies that operate highly safety-critical infrastructure and also smaller companies that have less financial resources but are also not at risk to the same extent.
The security catalogue takes this range into account by classifying the addressees into different categories depending on their risk potential and grades the level of obligations from the catalogue accordingly.
9c. Article 21(1) second subparagraph of the NIS2 Directive may be used to assess the burden in relation to the objective pursued. This states:
The measures referred to in the first subparagraph must ensure a level of security of network and information systems appropriate to the risk involved, taking into account the state of the art and, where appropriate, relevant European and international standards, as well as the costs of implementation.
When assessing the proportionality of these measures, due account is to be taken of the extent of the institution’s risk exposure, the size of the institution and the likelihood of security incidents occurring and their severity, including their social and economic impact.
In general, it may, therefore, be concluded that scalable systems which can be adapted to individual network operators or service providers and take account of their size and systemic importance strike an appropriate balance between the burden imposed and the objective.
The security catalogue scales both with regard to the addressees and with regard to the measures to be taken. On the one hand, the addressees are categorised according to their potential risk in order to prevent business activities that do not pose a risk from being disproportionately burdened. On the other hand, in addition to the mandatory measures, the safety catalogue also contains measures that must be taken into account when drawing up the protection concept; the addressee may also deviate from these measures if necessary. In addition, European and international standards have been taken into account as far as possible in the revision of the catalogue of security requirements in order not to put market participants in Germany at a disadvantage compared to those in other countries of the European internal market.
10. Reference to the basic texts: Basic texts have been forwarded under a previous notification:
2020/0496/D
11. No
12.
13. No
14. No
15. No
16.
TBT aspects: No
SPS aspects: No
**********
European Commission
Contact point Directive (EU) 2015/1535
email: grow-dir2015-1535-central@ec.europa.eu