Skip to main content
    FastestFibre.co.za
    Policy

    Icasa Wants a Map of Every Fibre Cable in SA - Telkom Warns It's a Gift to Spies and Thieves

    Icasa's draft rapid deployment regulations would force every fibre network operator to hand over a geo-mapped database of routes, poles and ducts twice a year. Telkom warned the plan could become a blueprint for 'construction mafia and spies' - here's what Regulation 7 requires, why the industry is pushing back, and what's next.

    FastestFibre Editorial14 min read
    Abstract illustration of a shield and network map representing Icasa's proposed national fibre infrastructure database and the security concerns raised about it
    In this article(9)
    1. 01A map that's meant to help - and might also help the wrong people
    2. 02What Regulation 7 actually requires
    3. 03Why Icasa thinks the industry needs this
    4. 04"Construction mafia and spies": the backlash, in the industry's own words
    5. 05The industry's fear has a price tag attached, and Icasa put it there
    6. 06What the draft doesn't say - and what industry wants added
    7. 07Who showed up, and where things stand now
    8. 08What this means if you're just trying to get - or keep - fast fibre
    9. 09Frequently asked questions

    A map that's meant to help - and might also help the wrong people

    South Africa's fibre regulator wants a complete, address-level map of the country's fibre network - every route, every duct, every pole, resubmitted twice a year by every licensed operator. On paper, that's exactly the kind of national planning tool a fragmented, fast-growing industry needs: know what's already built before you approve someone else to dig up the same road. In practice, it's triggered one of the sharper fights South Africa's telecoms industry has had with its regulator in years - not over whether the map should exist, but over what happens if it leaks.

    At Icasa's public hearings on rapid deployment regulation, held over two days in Midrand on 13-14 July 2026, Telkom's legal executive Nozipho Mngomezulu put the industry's objection about as bluntly as a regulatory submission gets. The proposed national infrastructure database, she warned, "compromises the security of Telkom's network if exposed in the public where construction mafia associates, anarchists and spies could use it in nefarious ways." That's not a phrase regulatory lawyers reach for lightly, and it's worth unpacking exactly what Icasa is proposing, why the industry thinks the risk is real rather than theoretical, and where the fight over safeguards stands as Icasa now works through what it heard.

    What Regulation 7 actually requires

    The database sits inside a broader package: Icasa's Draft Rapid Deployment of Electronic Communications Networks and Facilities Regulations, gazetted on 10 April 2026 under Section 4 of the Electronic Communications Act, giving legal effect to the national rapid deployment policy the Minister of Communications and Digital Technologies issued back in March 2023. Most of that package deals with permits, property access and dispute resolution - the machinery for actually getting infrastructure built faster. Regulation 7 is the one clause that's become a story of its own.

    It requires every licensed network operator to submit, twice a year, accurate and complete geo-referenced data on the location and type of all their passive physical infrastructure: fibre cable routes, copper lines, ducts, poles, manholes and base stations. Alongside that, operators must disclose who owns or operates each piece of infrastructure, how much physical space or capacity is available on it, service availability mapped down to individual addresses, which technology serves each area - fibre, DSL, 2G through 5G, or other - and forward-looking rollout plans naming designated build areas, projected start and completion dates, and the technologies going in. Submissions have to use the WGS84 coordinate reference system in one of three standard geographic formats (ESRI Shapefile, GeoJSON or GeoPackage), so the result is a genuinely precise, machine-readable map rather than a rough coverage sketch.

    The penalties are real: failing to comply with the GIS obligations, or breaching the regulations' compensation framework, each carry a fine of up to R1 million, with a separate R150,000 ceiling for licensee-responsibility and property-entry violations elsewhere in the package. As gazetted, the GIS obligations were set to become effective six months after publication - meaning operators would have had until October 2026 to be fully compliant, with the first submission window opening well before then.

    Why Icasa thinks the industry needs this

    Icasa's own framing of the regulations is that they exist to "provide a clear, transparent and uniform regulatory framework" that supports "efficient rapid deployment" while keeping the process fair and consultative - language that ties directly back to the 2023 National Policy on Rapid Deployment and South Africa's broader SA Connect broadband-expansion goals. A national infrastructure database is a reasonable tool for that mandate. Regulators, municipalities and rival operators currently have no single, reliable way to see what's already been built where, which is part of why duplicate trenching, conflicting wayleave applications and patchy address-level coverage information are such persistent problems in South African fibre rollout - a related but distinct bottleneck we've covered separately in our piece on municipal wayleave delays, which came out of the same two-day hearing.

    Done well, a database like this could plausibly speed up planning decisions, help municipalities process wayleave applications with actual visibility into what's already in the ground, and - if any of the address-level service data eventually surfaces in a public-facing form - give consumers a more reliable way to check what's coming to their street than scattered, sometimes outdated operator coverage maps. That's the case for the database. It's also, notably, not the part of the proposal industry is objecting to.

    "Construction mafia and spies": the backlash, in the industry's own words

    What operators are pushing back on isn't the existence of a database - it's the absence, in the current draft, of any real answer to who gets to see it. Telkom's warning about "construction mafia associates, anarchists and spies" only makes sense with a bit of local context: "construction mafia" is the term South Africans use for the extortion rackets that have besieged building sites nationwide for years, demanding a cut of a project's value - typically around 30% - before allowing work to continue, and resorting to intimidation, vandalism and violence against contractors who refuse. It's a well-documented, still-active problem in South African infrastructure delivery, which is exactly why invoking it in a regulatory hearing lands as a specific, credible threat rather than vague fearmongering.

    The Association of Comms & Technology (ACT), which represents South Africa's six largest network operators - MTN, Vodacom, Cell C, Telkom, Rain and Liquid Intelligent Technologies - raised the same concern in its own submission, through chief executive Nomvuyiso Batyi: centralising this level of infrastructure detail "may create national security risks if not adequately safeguarded," pointing specifically to Icasa's own published data on infrastructure theft and vandalism as evidence the risk is grounded in current experience, not speculation. Batyi's broader complaint about the whole rapid-deployment package doubles as a fair one-line summary of the database fight specifically: "The biggest risk is that the process becomes more complex rather than faster."

    The Internet Service Providers' Association (Ispa) made a related but slightly different point, calling it "unreasonable to expect licensees to submit commercially sensitive information" - network build-out plans and infrastructure maps are competitive assets, not just security ones - without clarity on who would access the database, for what purpose, and under what safeguards. That's the throughline across all three submissions: not "don't build this," but "the draft doesn't say who's allowed to look at it, and that's not a detail you leave for later."

    The industry's fear has a price tag attached, and Icasa put it there

    It would be easy to read "construction mafia and spies" as a dramatic flourish if South African telecoms infrastructure weren't already being stolen and vandalised at a rising cost - and the figures making that case come from Icasa's own State of the ICT Sector Report of South Africa 2026, the same regulator now proposing the database. Theft and vandalism together cost the telecoms sector R340 million in 2025. Vandalism actually fell 34% year-on-year, from R213.8 million to R140.9 million - a genuine improvement. Theft moved sharply the other way: from R69.6 million in 2024 to R201.5 million in 2025, an increase of 189% in a single year. Icasa's own report reads the trend plainly: "while progress appears to have been made against vandalism, the rapid growth in theft suggests the need for stronger asset protection strategies."

    That's the backdrop the industry is reading Regulation 7 against. Operators are already spending heavily just to keep existing infrastructure resilient against theft, load-shedding and vandalism combined - R387.7 million on backup batteries and R426.8 million on generators in 2025 alone, according to the same report. A precise, centralised, twice-yearly-updated map of exactly where every metre of fibre, every duct and every access point sits doesn't create the theft problem, but it would hand whoever obtains it - legitimately or otherwise - a level of targeting precision that today simply doesn't exist in one place. For an industry already absorbing a 189% jump in theft losses, that's not a paranoid read of the proposal. It's a proportionate one.

    It matters for anyone with a fibre line, not just the operators footing the bill. Cable theft and vandalism are already a recurring, direct cause of the outages and slow-downs fibre customers experience - a severed route means a real repair crew, a real delay, and often a detour through back-up capacity while it's fixed. A database that made theft easier to plan around, rather than harder, would show up eventually as more of exactly that: more cuts, longer repairs, and network operators passing rising theft-mitigation costs through to the prices ISPs pay for wholesale access - and, from there, to what you pay each month.

    What the draft doesn't say - and what industry wants added

    Strip away the rhetoric and the actual gap in Icasa's April draft is narrow and specific: it sets out exhaustively what operators must submit and by when, but says nothing about who within Icasa - or beyond it - would be authorised to query the database, what access-logging or audit controls would exist, whether any of it would be published or shared with third parties, or how a breach would be handled. That silence is precisely what Ispa flagged as unreasonable and what ACT framed as a national security exposure. It's also, importantly, a solvable design problem rather than a reason to abandon the idea - which is the fix industry actually asked for at the hearings, rather than asking Icasa to drop Regulation 7 altogether.

    ACT's specific ask was a phased rollout, extending the compliance window from six months to twelve, paired with tiered security access controls - different levels of database access depending on who's asking and why, rather than a single undifferentiated dataset any authorised party can query in full. That's a materially different regulation from the one gazetted in April: same underlying map, same twice-yearly reporting obligation, but with role-based permissions and a longer runway to build them properly before the fines start applying. Whether Icasa's final regulations land closer to the original six-month, access-control-silent draft or the industry's twelve-month, tiered-access version is the open question the July hearings were meant to help settle.

    Who showed up, and where things stand now

    The written comment period on Icasa's draft closed on 25 May 2026, and the regulator followed up with two days of oral hearings at the Protea Hotel Marriott in Midrand on 13-14 July. Presenters covered most of the industry: ACT (speaking for its six largest-operator members), Telkom, Huawei, the Wireless Access Providers' Association (Wapa), Rain, the City of Cape Town, Digital Council Africa, Ispa, MTN, Vodacom and DigiV8 all made submissions or appeared in person, alongside smaller network and equipment vendors.

    As things stand, no final regulations and no confirmed effective date have been set. The hearings were a consultation step, not a decision - Icasa's own process still requires it to consider every submission before finalising and gazetting a final version of the regulations, including whatever it decides about the GIS database's access controls, timeline and enforcement. Given how long the parallel wayleave provisions in the same draft package have already taken to reach this stage - the underlying national policy dates back to March 2023 - a quick turnaround from here looks unlikely.

    What this means if you're just trying to get - or keep - fast fibre

    None of this changes anything about your fibre line today. The database doesn't exist yet, no operator is required to submit anything under it yet, and Icasa hasn't finalised how - or whether - access controls will be built in before it does. But it's worth understanding as more than an industry squabble, because both directions this could go in eventually reach your household.

    If Icasa lands on something close to ACT's proposed fix - phased implementation, genuine tiered access, real audit controls - a properly secured national infrastructure map is a plausible net positive: better rollout planning, fewer duplicated digs, and potentially more reliable address-level coverage information than the patchwork of operator coverage maps and checker tools available today. If the regulations instead ship close to the original April draft, with broad access and no clearly defined safeguards, the more pessimistic reading - a small but real uptick in theft-driven outages and the repair costs that follow - becomes the more likely one, layered on top of an already-rising theft trend the industry didn't need any help with.

    Either way, the fastest way to know what's actually available at your address right now isn't to wait on a regulatory outcome that's still months, possibly years, from being finalised. Check your own street directly, and if outages linked to cable theft or vandalism are already a recurring issue where you live, that's worth factoring into which network and ISP you choose next.

    Frequently asked questions

    It's a proposal under Regulation 7 of Icasa's draft Rapid Deployment of Electronic Communications Networks and Facilities Regulations, gazetted 10 April 2026. It would require every licensed network operator to submit geo-referenced data on their fibre routes, ducts, poles, towers and base stations to Icasa twice a year, along with address-level service availability and forward-looking rollout plans.

    Telkom's legal executive Nozipho Mngomezulu told Icasa's July 2026 hearings that the database "compromises the security of Telkom's network if exposed in the public where construction mafia associates, anarchists and spies could use it in nefarious ways." The Association of Comms & Technology and the Internet Service Providers' Association raised similar concerns, largely because the draft regulations don't specify who would be allowed to access the database or what safeguards would apply.

    According to Icasa's own State of the ICT Sector Report of South Africa 2026, theft and vandalism cost the telecoms sector R340 million in 2025. Equipment theft specifically rose 189% year-on-year, from R69.6 million in 2024 to R201.5 million in 2025, while vandalism losses fell 34% to R140.9 million over the same period.

    No final regulations or effective date have been confirmed. As gazetted in April 2026, the GIS obligations were set to apply six months after publication, but industry bodies have asked Icasa to extend that to 12 months with tiered access controls added first. Icasa is still reviewing submissions from its 13-14 July 2026 public hearings before finalising the regulations.

    No - they're related but different issues from the same draft regulations and the same July 2026 hearings. The wayleave story is about how long municipalities take to approve permission to dig up roads for cable. This story is about Regulation 7 specifically: the proposed national database of exactly where that cable ends up once it's in the ground, and who should be allowed to see it.

    Help someone else pick the right fibre

    Check what's already live at your address

    Regulatory outcomes like this are months away. See what fibre coverage and pricing already exist on your street today.

    Disclaimer: FastestFibre.co.za is an independent comparison and information service. We do not own any fibre network, and we do not sell internet packages directly. Pricing, speeds and availability shown on this site are indicative and may change without notice; final pricing, terms and contractual obligations are set by the individual ISPs and fibre network operators.

    Some outbound links on this site are affiliate links. If you sign up via one of these links we may earn a commission at no extra cost to you. This never affects which packages we review, recommend or rank. Reviews and editorial content are written independently. For corrections or feedback, contact us via the social channels above.

    © 2026 FastestFibre.co.za - All rights reserved.