HL komm Telekommunikations GmbH

Germany · www.hlkomm.de · 15 vendors

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 2 categories; runs on 15 sub-vendors.

Insights

Last updated 2026-08-03 · revision 2

15 direct vendors, 143 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

HL komm Telekommunikations GmbH exhibits a high degree of migration readiness, largely due to its core business model and existing technological landscape. The company actively provides Infrastructure-as-a-Service (VPC / IaaS) based on VMware vSphere 7, Cloud PBX solutions, and SD-WAN, demonstrating significant internal expertise and infrastructure aligned with cloud adoption and modern network architectures. Their use of modern platforms like VMware vSphere 7 and Pure Storage flash storage for their own operations further underscores their capability to manage and migrate to contemporary environments. The company's strong emphasis on regulatory compliance, including GDPR adherence for its VPC hosted exclusively in Germany and specialized KRITIS Cloud offerings, indicates a sophisticated understanding and capability to manage complex data residency and regulatory requirements during any migration process. This proactive approach to compliance is a significant asset for readiness. While the data does not explicitly detail the company's internal adoption of containerization or microservices architectures, their offerings clearly position them as a facilitator and operator within the cloud ecosystem. The presence of multiple distinct vendors in their internal tech stack (e.g., VMware, Pure Storage, Veeam, Check Point, Innovaphone, DE-CIX, Contentful), with geographic diversity, suggests a lower risk of vendor lock-in compared to a monolithic single-vendor environment, although explicit vendor lock-in risk is noted as "Unknown." The primary missing component for a perfect score is the lack of financial stability data, which is crucial for assessing the company's ability to fund significant migration initiatives. Despite this, their existing cloud-centric operations and robust compliance framework position them very well for future migrations.

Compliance

11 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

HL komm Telekommunikations GmbH operates in the telecommunications and digital infrastructure sector, which is explicitly listed as an 'Essential Entity' sector under Annex I of the NIS2 Directive (providers of public electronic communications networks or services). As a licensed German telecommunications provider operating fiber-optic networks, data centers, carrier services, and cloud infrastructure, the company almost certainly meets the NIS2 size thresholds (medium or large enterprise: 50+ employees or €10M+ annual turnover) given its 25+ years of operation, two high-security data centers (Leipzig and Berlin), a 100 Gbit/s fiber backbone, and its position as a subsidiary of Tele Columbus AG. Germany transposed NIS2 into national law via the NIS2UmsuCG (NIS-2-Umsetzungs- und Cybersicherheitsstärkungsgesetz), which entered into force in 2024. The risk level is High because: (1) the sector match is near-certain (telecom/digital infrastructure = Essential Entity); (2) non-compliance with NIS2 carries fines up to €10M or 2% of global annual turnover for Essential Entities; (3) NIS2 imposes mandatory incident reporting (24h initial notification, 72h detailed report), security measures, supply chain security, and management accountability; (4) Germany's BSI (Bundesamt für Sicherheit in der Informationstechnik) actively enforces NIS2 obligations. The company's ISO 27001 certification and KRITIS cloud offering suggest awareness of these obligations, but no public NIS2 compliance assessment has been found.

Evidence: https://www.pyur.com/business/zertifizierungen, https://www.pyur.com/business/loesungen/cloud/iaas/kritis-cloud, https://www.pyur.com/business/datacenter/rechenzentrum-leipzig, https://www.pyur.com/business/loesungen/it-sicherheit, https://www.pyur.com/business/ueber/unternehmen

KRITIS — Assessment Required

Germany's KRITIS framework (BSI-Gesetz + BSI-KritisV) designates operators of critical infrastructure in sectors including information technology and telecommunications as subject to enhanced security obligations. Telecommunications providers meeting certain threshold criteria (number of subscribers, network reach) are classified as KRITIS operators and must: (1) implement state-of-the-art security measures; (2) conduct regular security audits (every 2 years); (3) report significant disruptions to BSI; (4) maintain a contact point for BSI. HL komm explicitly markets 'KRITIS Cloud' services and states its data centers are 'KRITIS- und DSGVO-konform', strongly suggesting the company either is itself a KRITIS operator or serves KRITIS operators. The risk level is High because: (1) KRITIS obligations are legally binding under BSI-Gesetz; (2) non-compliance can result in fines up to €1M (BSI-Gesetz § 14); (3) the company's explicit KRITIS branding suggests regulatory awareness but formal compliance status is unconfirmed; (4) the NIS2UmsuCG (2024) significantly expanded KRITIS-equivalent obligations, increasing compliance complexity.

Evidence: https://www.pyur.com/business/loesungen/cloud/iaas/kritis-cloud, https://www.pyur.com/business/datacenter/rechenzentrum-leipzig, https://www.pyur.com/business/datacenter/rechenzentrum-berlin, https://www.pyur.com/business/zertifizierungen

SOC 2 (source) — Assessment Required

HL komm Telekommunikations GmbH operates data centers (Leipzig and Berlin), colocation services, private cloud (IaaS), KRITIS cloud, and cloud telephony services for business customers. SOC 2 is a US-origin framework (AICPA) but is increasingly required by international enterprise customers, particularly for cloud and data center service providers. The company's business customers (including Zayo Europe, a major international network infrastructure provider) may contractually require SOC 2 reports. The risk level is Medium because: (1) SOC 2 is not legally mandated in Germany (unlike ISO 27001 or NIS2); (2) the company holds ISO 27001 and TSI Level 3 certifications which partially address the same trust service criteria; (3) however, the absence of a SOC 2 report may be a competitive disadvantage for international enterprise clients; (4) no SOC 2 report has been found publicly. The risk is primarily commercial rather than regulatory.

Evidence: https://www.pyur.com/business/zertifizierungen, https://www.pyur.com/business/datacenter/rechenzentrum-leipzig, https://www.pyur.com/business/datacenter/rechenzentrum-berlin, https://www.pyur.com/business/loesungen/cloud/iaas

Financials

Three-year financials

Financial Resilience Score: 6/10

HL komm Telekommunikations GmbH is a well-positioned regional B2B telecommunications and data-centre operator in eastern Germany, benefiting from strong parent backing by Tele Columbus AG, which is in turn controlled by Morgan Stanley Infrastructure Partners (Kublai). This ownership structure provides access to deep-pocketed infrastructure capital supportive of long-cycle fibre and data-centre investments. The company owns proprietary fibre network infrastructure of several thousand kilometres in Saxony/Saxony-Anhalt and operates two certified data centres (Leipzig, Berlin), creating high barriers to entry and generating recurring, contracted revenue streams. The company's diversified B2B portfolio spanning connectivity, telephony, colocation, cloud, security and carrier services reduces dependency on any single service line. A sticky customer base of SMEs, corporates, public sector clients (with KRITIS-compliant offerings) and carriers such as Zayo Europe supports revenue stability. Certifications including ISO 27001 and 'Cloud Services Made in Germany' bolster enterprise and KRITIS sales opportunities. However, resilience is constrained by parent-group leverage, as Tele Columbus has historically carried substantial debt tied to network build-out, creating indirect refinancing risks. Regional concentration in Leipzig/Halle/central Germany limits geographic diversification, and outside this footprint services depend on wholesale inputs. Capex intensity from continuous fibre and data-centre expansion weighs on free cash flow, and competition from Deutsche Telekom, Vodafone, 1&1 Versatel, Colt and regional fibre carriers is intense. The upcoming leadership transition (new Managing Director from July 2026) also introduces short-term execution risk.

Key strengths: Strong parent backing by Tele Columbus AG / Morgan Stanley Infrastructure Partners (Kublai), Proprietary fibre network across Saxony/Saxony-Anhalt with two certified data centres (Leipzig, Berlin), Diversified B2B portfolio: connectivity, telephony, colocation, cloud, security, carrier services, Sticky enterprise, public sector and carrier customer base with long-term contracts, ISO 27001 and 'Cloud Services Made in Germany' certifications enabling KRITIS/enterprise sales, 25+ years of operating history in the region

Risk factors: Parent-group leverage at Tele Columbus tied to network build-out, Regional concentration in eastern Germany (Saxony, Saxony-Anhalt, Thuringia, Brandenburg, Berlin), High capex intensity of fibre and data-centre expansion weighing on free cash flow, Intense competition from Deutsche Telekom, Vodafone, 1&1 Versatel, Colt and regional fibre carriers, Governance transition with new Managing Director effective 1 July 2026, Dependence on wholesale inputs outside proprietary footprint

Revenue by geography

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report