Summary
- The government has opened an eight-week call for evidence examining the impact and effectiveness of Sections 1–13 of the Telecommunications Security Act 2021.
- The framework places security duties on public telecoms providers, gives Ofcom monitoring and enforcement powers, and is supported by detailed regulations and a security code.
- The review will test how the regime works in practice as telecom networks absorb newer technologies and face evolving cyber and supplier risks.
The UK government has opened a statutory review of the country’s telecom security regime, asking network operators and other affected organisations whether rules introduced after concerns over cyber and supplier risk are working as intended. The call for evidence, published on 17 August, covers Sections 1 to 13 of the Telecommunications Security Act 2021 and will remain open until 12 October.
The legislation amended the Communications Act 2003 to impose stronger security duties on providers of public electronic communications networks and services. Operators are required to identify and reduce the risk of security compromises, prepare for incidents, limit their effects when they occur, and remedy or mitigate the resulting harm. The framework also gave government powers to set more detailed requirements and strengthened Ofcom’s role in monitoring and enforcing compliance.
Those duties were followed by the Electronic Communications (Security Measures) Regulations 2022 and a Telecommunications Security Code of Practice, which translated broad statutory obligations into more specific operational expectations. The regulations came into force in October 2022, while the government revised the accompanying code in July 2026 to reflect changing security threats and newer telecom technologies. The present review is therefore assessing a framework that has already been adjusted as implementation has progressed.
Under the Act, the Secretary of State must review the impact and effectiveness of the relevant provisions and publish the findings to Parliament. The government says it will use responses alongside engagement with the National Cyber Security Centre and Ofcom, with particular interest in evidence from companies providing public communications networks and services. Respondents have also been asked to distinguish the effects of the legislation from security improvements that would have happened anyway, allowing the review to test whether regulation has changed behaviour rather than merely documented it.
Telecom security becomes an operational discipline
The framework was created after the 2019 Telecoms Supply Chain Review exposed weaknesses in the way security risks were managed across nationally important communications infrastructure. Although political attention at the time concentrated heavily on equipment suppliers and high-risk vendors, the legislation that followed is broader. It treats resilience as a continuing operational responsibility covering systems, access, networks, data, incident detection, recovery, and the processes through which providers manage security.
That wider approach reflects the structure of modern telecom networks, where risk rarely sits within a single piece of hardware. Operators depend on software, virtualised network functions, cloud infrastructure, identity systems, outsourced maintenance, physical sites, and long chains of technology suppliers. As networks become more programmable and software-defined, weaknesses in configuration, administration, or access control can be as consequential as defects in physical equipment.
The government’s objectives include making networks difficult to compromise, ensuring intrusions are detected quickly, limiting resulting harm, and making remediation as straightforward as possible. Those goals become expensive and technically demanding when applied across nationwide networks that cannot simply be shut down for maintenance. Telecom security consequently sits in permanent tension with availability, upgrade cycles, interoperability, and the commercial need to operate infrastructure efficiently.
The review can expose implementation costs
The most useful evidence may come from areas where the framework has proved difficult to apply. Large telecom operators typically have established security teams and mature risk-management processes, but regulation can still require changes to architecture, monitoring, supplier contracts, record-keeping, assurance, and governance. Smaller providers face the same direction of travel with fewer people and less internal capacity, even though the Code of Practice applies its most detailed guidance particularly to larger and medium-sized providers.
Ofcom’s enforcement role also turns technical judgements into regulatory ones. A provider deciding what constitutes a proportionate control must consider not only the engineering threat but whether it can demonstrate compliance to a regulator after an incident. That can improve discipline and documentation, although overly rigid interpretation could make networks harder or slower to modernise if operators become reluctant to introduce new architectures whose compliance treatment is less established.
The July revision of the security code shows why the framework needs to evolve as technology does. Telecoms infrastructure is absorbing cloud platforms, virtualisation, automation, AI-assisted operations, private networks, and new generations of mobile technology, while attackers are adapting at the same time. Security legislation written around outcomes can accommodate some of that movement, but supporting rules and guidance still have to remain technically credible if providers are expected to follow them across long investment cycles.
Responses to the call for evidence will feed into the government’s review report, which must be laid before Parliament. The exercise does not itself propose weaker or stronger obligations, and any eventual policy change will depend on what the evidence shows. After nearly four years of detailed regulation, government is moving from designing a tougher telecom security regime to measuring whether it has made networks harder to attack without imposing requirements that age faster than the infrastructure they are intended to protect.












