Summary
- The government is reviewing sections 1–13 of the Telecommunications (Security) Act 2021 and associated regulations and guidance.
- Ofcom, the NCSC, telecoms providers, and other stakeholders will contribute evidence on the framework’s impact and effectiveness.
- The review comes weeks after the Telecoms Security Code of Practice was revised to address changing technology and threat conditions.
The UK government has opened a statutory review of its telecoms security regime, beginning an assessment of whether rules introduced after the 2019 telecoms supply chain review have materially improved the security and resilience of public networks.
The Department for Science, Innovation and Technology and the Department for Digital, Culture, Media and Sport opened an eight-week call for evidence on 17 August covering sections 1–13 of the Telecommunications (Security) Act 2021.
The review also encompasses the Electronic Communications (Security Measures) Regulations 2022 and the Telecommunications Security Code of Practice. Responses are due by 12 October.
The 2021 legislation amended the Communications Act 2003 and introduced overarching duties requiring public telecoms providers to identify and reduce security risks, prepare for compromises, limit their effects, and remediate or mitigate resulting harm. It also gave government powers to establish detailed security measures and strengthened Ofcom’s oversight and enforcement role.
The framework was built after the 2019 Telecoms Supply Chain Review concluded that the UK required stronger statutory controls around network security. The National Cyber Security Centre and Ofcom were involved in developing the subsequent regulations and guidance.
The review is not optional. Section 14 of the Telecommunications (Security) Act requires the Secretary of State to examine the impact and effectiveness of the first 13 sections and publish a report to Parliament.
That creates an opportunity to test the framework against operational evidence rather than its original policy intent. The government is asking organisations that have worked with the Act, regulations, and code to assess whether the regime has delivered its stated objectives, including stronger cyber standards, protection against unauthorised access and interference, improved availability, and faster detection and containment of compromises.
The assessment arrives shortly after the government revised the Telecommunications Security Code of Practice in July. Version 1.1 updates guidance for large and medium public telecoms providers in response to changing threats and new telecoms technologies.
That combination — updated technical guidance followed by a statutory effectiveness review — gives the government a basis to distinguish between shortcomings in the legislation itself and problems arising from implementation, compliance, or technological change.
The telecoms sector also differs from many regulated environments because security duties apply to infrastructure that serves as a dependency for almost every other digital service. Mobile connectivity, business networks, cloud access, emergency communications, and increasingly industrial and machine-to-machine systems all rely on public telecoms infrastructure somewhere in their delivery chain.
Consequently, regulatory effectiveness cannot be measured solely by the number of incidents reported or enforcement actions taken. Resilience, detection, supplier assurance, privileged access, management-plane security, network architecture, and recovery capability all form part of whether the regime can limit the consequences of a compromise.
The government has specifically asked respondents to separate improvements attributable to the Act from business-as-usual security investment, pre-existing regulatory requirements, and wider commercial decisions. That is a difficult but necessary distinction if the statutory review is to establish whether legislation has altered provider behaviour rather than simply coincided with broader security spending.
Ofcom and the NCSC will contribute to the government’s assessment alongside evidence from providers and other stakeholders. After the consultation closes, ministers must analyse the evidence, publish the findings, and lay the review before Parliament.
The outcome will show whether the current telecoms framework is judged sufficient as network architecture continues to change, or whether enforcement, technical requirements, or statutory duties need another round of adjustment.


