Back to blog
EU & UK

The UK Telecommunications (Security) Act: duties for network and service providers

A specific, enforceable security regime for UK public telecoms providers, with a code of practice, tiered expectations and Ofcom enforcement. Who it binds and what it requires.
GRC Copilot Team
The UK Telecommunications (Security) Act: duties for network and service providers

The UK Telecommunications (Security) Act creates a specific security framework for public telecoms providers, backed by a code of practice and enforced by Ofcom. It is narrow in population and unusually detailed in expectation — which makes it easy to overlook and hard to meet late.

Who it binds

Providers of public electronic communications networks and services in the UK. Expectations are tiered by size and significance, so the largest providers face the fullest measures on the earliest timelines, with proportionately lighter expectations further down. Smaller providers are not exempt — they are expected to apply measures proportionately.

Suppliers to those providers are affected indirectly but materially, because supply chain duties push requirements into contracts.

What it requires

The duties are broad in statute and given specificity by the code of practice. In practice they cover:

  • Protecting the network and service from compromise, including the signalling and management planes rather than only customer traffic.
  • Separating and protecting management functions — restricting how and from where the network can be administered, which is frequently the largest engineering item.
  • Controlling privileged access, with strong authentication and monitoring.
  • Monitoring and audit capable of detecting compromise, with log retention.
  • Supply chain security — assessing vendors, controlling third-party access, and managing equipment through its lifecycle.
  • Patching and vulnerability management on defined timescales.
  • Governance with board-level accountability for security.
  • Reporting of security compromises to Ofcom, and notifying users where appropriate.
The management plane requirements are what make this expensive. Restricting administration to controlled paths and separated workstations touches operational practice deeply, and it is not something that can be retrofitted quickly before an inspection.

Map telecoms duties onto one control set

GRC Copilot maps sector duties alongside ISO 27001 and other frameworks so overlapping requirements are evidenced once.

Enforcement

Ofcom supervises and can require information, inspect, issue directions and impose significant penalties. The regime is designed to be actively supervised rather than self-attested, so evidence quality matters in a way it does not under voluntary schemes.

Relationship to other obligations

An ISO 27001 programme covers a good share of the governance and control substance, and providers frequently hold one. What it does not cover is the telecoms-specific technical measures — signalling security, management plane separation, equipment lifecycle and vendor controls — nor the Ofcom reporting duty. Map the code of practice onto your existing control set and close the specific delta rather than building a parallel programme.

Providers also handle substantial personal data, so UK data protection obligations run alongside, with their own separate breach notification route and clock.

Where to start

  1. Confirm whether you are in scope and which tier applies.
  2. Gap assess against the code of practice specifically, not against a general standard.
  3. Prioritise management plane separation and privileged access — the longest lead items.
  4. Review supplier contracts for the required security terms and access controls.
  5. Establish the Ofcom reporting route and internal trigger criteria in advance.

Frequently asked questions

Does it apply to smaller providers?

Yes, proportionately. Tiering affects the depth and timing of expected measures, not whether duties exist.

Does ISO 27001 satisfy it?

It covers governance and general controls. The telecoms-specific technical measures and the Ofcom reporting duty are not covered.

What about equipment vendor restrictions?

Supply chain duties and separate designated vendor arrangements can constrain equipment choices. Treat procurement as a compliance decision.

What is the hardest requirement?

Management plane separation and privileged access control — deep operational change with long lead times.

Key takeaways

  • Narrow population, unusually specific expectations, actively supervised.
  • Management plane separation is the largest engineering commitment.
  • Supply chain duties make procurement a compliance decision.
  • ISO 27001 covers governance, not the telecoms-specific measures.
#uk-telecoms-security-act #tsa #ofcom #providers #supply-chain #network-security