Five years of the Telecoms Security Act: what the review needs to hear
The government is asking whether the UK's telecoms security framework actually works. The honest answer is “mostly, at a cost”, and the lessons travel well beyond telecoms.
On 17 August, the government opened a call for evidence on the impact and effectiveness of sections 1 to 13 of the Telecommunications (Security) Act 2021. It closes at 11:59pm on 12 October. It has had very little attention outside the operators themselves, which is a shame, because it is the first formal look back at the UK's most prescriptive sector security regime, and the regime that most of the UK's other critical sectors are now being nudged towards.
What the review is actually asking
The call asks everyone who has engaged with the framework (the Act, the 2022 Security Measures Regulations and the Code of Practice) whether it is meeting the objectives the Act set out: overarching duties on public telecoms providers to identify and reduce the risk of security compromise, prepare for it, prevent adverse effects and remedy them when they happen. Responses feed a report the Secretary of State has to produce on how well the Act is working.
The timing is deliberate. A revised Code of Practice, version 1.1, was issued on 14 July after consultation in late 2025. Under the revised Code's timetable, no implementation deadline falls in 2026; the next is 31 March 2027. This is the breathing space in which the government decides whether the regime needs adjusting before the next set of deadlines arrives.
What has worked
Having spent years inside a large operator, I think the Act got one big thing right: it made security a matter of evidence rather than assertion. Ofcom can require information, assess providers against specific measures and enforce against failure, and providers are expected to show that controls operate in practice, not just that a policy exists. That shifted the internal conversation. Security spend stopped being a discretionary line and became a regulatory obligation with a named accountable owner.
The Code's vendor security assessment approach also forced a discipline many operators lacked: judging the security of network equipment through the vendor's own evidence, independent testing and third-party assurance, rather than through the brochure.
What has been hard
The costs have landed unevenly. Three themes come up in almost every conversation I have with people still in the sector.
First, legacy estate. Measures written for a modern, well-segmented network are expensive to retrofit onto equipment that was never designed for them, and the honest answer for some kit is replacement, not remediation. Second, the evidence burden. Proving compliance continuously, control by control, consumes senior engineering time that would otherwise go on reducing risk. Third, the supply chain cascade. Providers are expected to manage security risk across their supply chains, which pushes the regime outward to firms that were never named in the Act and often lack the maturity to respond.
None of those is an argument against the regime. They are arguments for the review to look closely at proportionality: which measures deliver the most risk reduction per pound, and whether tiering is calibrated correctly for smaller providers.
Why this matters if you aren't a telco
The Cyber Security and Resilience Bill, now in its final Lords stages, borrows heavily from the same playbook: sector regulators with information-gathering powers, codes of practice, supply chain obligations and a move from “tell us when it goes wrong” to “show us it's right”. Data centres and managed service providers are being brought into scope. If you are in one of those categories, the telecoms sector's last five years are the closest thing you have to a preview.
The practical lesson is to build the evidence model at the same time as the control. Organisations that treat compliance evidence as something to assemble later find it consumes the same scarce people twice. The ones that cope design their controls to produce evidence as a by-product: logs, configuration baselines, supplier attestations, all mapped to the measure they satisfy.
If you have a view, send it
Calls for evidence are dominated by the largest providers and trade bodies, so the experience of smaller operators, suppliers and the people who actually did the implementation work tends to be underrepresented. A short, specific response describing what a measure cost, what it achieved and what you would change is more useful to a review team than a long general one. The deadline is 12 October.
Working through a sector security regime?
A short conversation on where your controls, evidence and supplier assurance actually stand.