
Telecoms Security
TSA 2021 security duties, Ofcom enforcement and supply chain requirements
Trigger situation
An operator needs to comply with the Telecommunications (Security) Act 2021 (TSA 2021) security duties. Ofcom has issued a security assessment or enforcement notice. A provider is reviewing its network architecture for compliance with the Electronic Communications (Security Measures) Regulations 2022. A business is assessing the impact of the TSA 2021 on its vendor relationships, particularly regarding high-risk vendors. An operator is planning network upgrades and needs to understand how TSA 2021 security obligations affect procurement and network design.
Why it matters now
The Telecommunications (Security) Act 2021 represented the most material expansion of Ofcom’s enforcement powers since 2003. Ofcom can impose civil penalties of up to 10 per cent of relevant turnover for contravention of a security duty, under section 97 as applied by section 105S. That ceiling is the same as for contravention of a general condition. What the 2021 Act raised is the daily penalty for a continuing contravention, from £20,000 under section 96B(5) to £100,000 under section 105T. The Electronic Communications (Security Measures) Regulations 2022 are the secondary legislation implementing the Act and set out the measures themselves. The Telecoms Security Code of Practice, issued separately by the Secretary of State under section 105E, gives guidance on how to take them. Between them they run to hundreds of pages of specific technical requirements.
The high-risk vendor framework, introduced by the TSA 2021 and developed in the Telecoms Security Code of Practice, has already materially affected the UK telecoms market. The ban on Huawei equipment in 5G networks (with a sunset date of 31 December 2027) is forcing network redesign, vendor diversification, and procurement changes across the industry. The restrictions on high-risk vendors are now widening beyond Huawei to other vendors where government concerns arise. These restrictions have substantial capital expenditure and operational implications.
The TSA 2021 regime is not principles-based. It is prescriptive and detailed. An operator that relies on a general cyber security framework alone does not meet the TSA 2021 duties, because the Regulations impose telecoms-specific requirements those frameworks do not carry.
Common TSA 2021 compliance failures
Compliance with generic cyber security standards (ISO 27001, NIST cybersecurity framework, etc.) does not satisfy the TSA 2021 regime. Generic security standards are not telecoms-specific and do not address the particular risks and vulnerabilities of telecoms networks. The TSA 2021 imposes specific obligations on network architecture, supplier risk management, and vendor access that go well beyond what generic standards require.
The scope of the TSA 2021 regime extends beyond mobile network operators. The security duties in sections 105A to 105D apply to the provider of a public electronic communications network or a public electronic communications service. The designated vendor direction power reaches a wider class, “public communications providers”, defined in section 151(1) of the Communications Act 2003 as providers of a public electronic communications network, providers of a public electronic communications service, and persons making available associated facilities by reference to such a network or service. This is broader than MNOs and includes MVNOs, WISPs, wholesale operators, satellite operators, and other service providers. TSA obligations apply to the MVNO itself, not only to its MNO host; the MVNO itself is a public communications provider and is directly subject to the regime.
Restrictions on a named vendor are not imposed by the Code of Practice. The Secretary of State designates a vendor by notice under section 105Z8 of the Communications Act 2003 and then imposes requirements on named public communications providers by designated vendor direction under section 105Z1. A direction may prohibit use of a vendor’s goods, services or facilities outright, or restrict use on conditions. Where the direction prohibits, no mitigation is available; where it restricts, the operator must meet the conditions the direction itself sets.
Acquisition due diligence on telecoms operators must address TSA 2021 compliance risk. An acquiring party may inherit a network that has not been assessed against the TSA 2021 framework, or that has been assessed and found deficient. The cost of remediation can be substantial. Particular risks include: (1) use of high-risk vendor equipment that must be replaced; (2) network architecture that does not meet the TSA 2021 resilience and security requirements; (3) vendor management processes that do not meet the Code of Practice standards; (4) supply chain security practices that fall short of statutory requirements. Acquisition agreements should shift this risk to the seller; but only if due diligence has identified it in the first place.
TSA 2021 compliance carries procurement cost. Selecting vendors that can be verified to meet TSA 2021 security requirements, implementing supply chain controls, maintaining audit trails of vendor access, and implementing vendor segregation in the network all have costs that are higher than vendor selection based purely on technical capability and price. If procurement is not aligned with security and legal requirements, the operator will end up with a network that either violates the TSA 2021 or requires expensive remediation post-procurement.
The Advisor’s Perspective
The Telecommunications (Security) Act 2021 changed the regulatory framework for network security. Sections 105A to 105D of the Communications Act 2003 have carried a statutory network security duty since 26 May 2011. The 2021 Act replaced those sections with a considerably more demanding regime and added the Regulations, the Code of Practice and the designated vendor direction powers. Now it is a specific statutory obligation with detailed technical requirements in the Electronic Communications (Security Measures) Regulations 2022. Ofcom has enforcement powers including financial penalties. This is not a compliance exercise that can be addressed with a policy document; it requires changes to network architecture, vendor management, and operational processes.
The high-risk vendor restrictions add a geopolitical dimension. Decisions about network equipment suppliers are no longer purely commercial; they carry regulatory consequences. Providers that have invested in equipment from designated high-risk vendors face mandatory removal timelines. Understanding these requirements early, particularly in the context of network upgrades or acquisitions, avoids investment in infrastructure that will need to be replaced.
Telecoms security compliance in practice
The first question for any provider is which of its operations are provided as public electronic communications networks or services, because the TSA 2021 duties apply to the provider of those and to no one else. The second is where its existing security framework already meets the Telecoms Security Code of Practice and where it does not, which is the gap the provider has to close.
An operator must address vendor selection, network architecture and supply chain management to comply with its TSA 2021 duties, so it settles them before it fixes a design or signs a supply contract. Where a vendor is subject to a designated vendor direction the operator must remove or stop using the equipment on the timetable the direction sets, and no mitigation substitutes for that. Where a vendor is treated as high risk but is not the subject of a direction, the question is whether mitigation is available at all, and at what cost.
The Code of Practice sets out what an operator must put in place: network resilience and redundancy, intrusion detection, encryption, vulnerability management, supply chain security and vendor access controls. Those measures are written for telecoms networks and for the risks particular to them, not carried across from a general security standard.
The regime requires operators to maintain security risk registers, implement security measures, document their implementation, and demonstrate compliance. Ofcom’s assessment powers are extensive and can require operators to provide evidence of compliance on demand. An operator that cannot produce that evidence on request is exposed whatever the state of its network.
An operator that receives an assessment notice or an enforcement notification from Ofcom has to establish the scope of what Ofcom is asking, what its findings mean, and what remediation will satisfy it, on Ofcom’s timetable rather than its own.
When to instruct
Instruct immediately if Ofcom has issued a security assessment, enforcement notice, or penalty notice relating to TSA 2021 compliance. TSA 2021 enforcement carries substantial penalties and requires careful response.
Instruct before designing a new network or service if it will be provided as a public electronic communications service. Building TSA 2021 compliance into the design from the outset is substantially cheaper than retrofitting.
Instruct before major procurement decisions affecting network architecture or vendor relationships. TSA 2021 compliance has implications for vendor selection and for how vendors interact with your network.
Instruct before acquiring a telecoms operator. TSA 2021 compliance is a material liability that must be assessed as part of acquisition due diligence.
Instruct on the meaning of the Code of Practice, on how the security duties affect network design, and before responding to Ofcom enforcement action.
How Bratby Law helps
A compliance assessment establishes where an operator’s security framework meets the statutory requirement and where it falls short, and the gaps are then ranked by exposure rather than by ease of fixing. Network design and procurement decisions are made against the same requirement.
An operator using equipment from a vendor subject to a designated vendor direction must plan its removal against the timetable in the direction. For other vendors the operator assesses the risk itself, and carries the security terms it needs into its vendor contracts rather than relying on the vendor’s own assurances.
The Code of Practice requirements on network resilience, intrusion detection, encryption, vulnerability management and supply chain security are each separately evidenced, and an operator that has implemented a measure but cannot document it is in the same position as one that has not.
Ofcom’s assessment powers reach the operator’s documents, its systems and its staff, and an assessment can run through to an enforcement notification and a penalty. Remediation after enforcement is a separate exercise from the response to the notification itself.
An acquirer of a telecoms operator takes on the target’s security duties on completion, and any remediation the target has not done becomes the buyer’s cost. The same network also carries duties under the Investigatory Powers Act 2016 and the rest of the Communications Act 2003 framework, which are assessed together rather than one at a time.
FAQs
What is the Telecoms Security Code of Practice and how is it legally binding?
The Telecoms Security Code of Practice is guidance issued by the Secretary of State under section 105E of the Communications Act 2003, inserted by the Telecommunications (Security) Act 2021. It is not secondary legislation: the secondary legislation is the Electronic Communications (Security Measures) Regulations 2022, which set out the measures themselves. The Code runs to hundreds of pages and gives detailed technical guidance on how operators should take those measures. It is not binding, but departing from it engages section 105I, under which Ofcom may require the provider to explain the departure in writing. Ofcom uses the Code as the benchmark against which it assesses operator compliance. If an operator departs from the Code, it must be able to justify the departure by reference to an alternative approach that meets the statutory security standard. In practice, most operators align their security approach to the Code rather than attempting alternative compliance routes.
What does the TSA 2021 require operators to do?
The TSA 2021 imposes five main obligations on operators: (1) identify and assess security risks to their networks; (2) implement and maintain appropriate security measures to mitigate those risks; (3) maintain and enforce appropriate security measures affecting suppliers and vendors; (4) notify Ofcom of significant security incidents; and (5) cooperate with Ofcom’s security assessments. The Electronic Communications (Security Measures) Regulations 2022 specify the measures themselves, and the Code of Practice gives guidance on taking them. Section 105A(1)(c) adds a sixth duty the list above omits: to prepare for the occurrence of security compromises, which regulation 9 of the Regulations builds out into backup, identification and recovery requirements. Section 105J adds a further duty to inform users where there is a significant risk of a compromise occurring.
What is a high-risk vendor and what restrictions apply?
A high-risk vendor is a vendor the Secretary of State has designated by a designation notice under section 105Z8 of the Communications Act 2003, on the basis that its goods, services or facilities pose a national security risk. Huawei is explicitly identified as a high-risk vendor for 5G networks and is banned as of 31 December 2027. Other vendors (including some Chinese vendors and some Russian-affiliated vendors) have been assessed as high-risk. For vendors assessed as high-risk, Ofcom’s expectation is that operators will not use their equipment, or if mitigation is necessary during a transition period, will implement specific security measures (isolation, access controls, segregation) that limit the risk. The measures required are substantial and expensive. For the highest-risk vendors, no mitigation measures are acceptable; the vendor must be excluded.
If I use equipment from a high-risk vendor, what security measures can I put in place to mitigate the risk?
The answer depends on the vendor and on the requirements the Secretary of State has imposed by designated vendor direction under section 105Z1. A direction may prohibit use outright or restrict it on conditions; where it restricts rather than prohibits, the conditions are those the direction sets, and it is the Secretary of State, not Ofcom, who determines contravention and penalty under section 105Z18. Accepted measures typically include: isolation of the vendor’s equipment from the core network, access controls limiting what the vendor can access, network segregation, continuous monitoring and intrusion detection, and formal security agreements with the vendor. The cost and operational complexity of such measures are substantial and often justify vendor replacement rather than mitigation.
How does Ofcom assess compliance with the TSA 2021?
Ofcom has broad powers to conduct security assessments of operators. The assessment may be triggered by: (1) Ofcom’s periodic compliance reviews; (2) an incident notification from the operator; (3) evidence of potential non-compliance; or (4) Ofcom’s own assessment of developing risks. During an assessment, Ofcom can require the operator to provide information, documents, and evidence of compliance. Ofcom may also conduct technical testing and interviews with operator staff. Following the assessment, Ofcom issues a report setting out its findings and, if it identifies non-compliance, specifying what the operator must do to achieve compliance. If the operator does not remediate within the specified timeframe, Ofcom can issue an enforcement notice and, if the operator persists in non-compliance, can impose penalties of up to 10% of relevant turnover.
What is a significant security incident and when must I notify Ofcom?
The test is in section 105K of the Communications Act 2003, not in the Code of Practice. Notification is required where a security compromise has a significant effect on the operation of the network or service, or where a compromise within section 105A(2)(b) puts a person in a position to bring about a further compromise that would have such an effect. Section 105K(2) lists the matters bearing on significance: the length of the period the operation of the network or service is affected, the number of users affected, the size and location of the geographical area affected, and the extent to which users’ activities are affected. Operators must inform Ofcom as soon as reasonably practicable. The notification must include details of the incident, the impact, the response measures taken, and the operator’s assessment of root cause. The obligation to notify is separate from any obligation to notify affected users or data protection authorities; an operator must do both.
Advice on telecoms security
Bratby Law on telecoms security
Ofcom enforcement and compliance monitoring
Ofcom is responsible for monitoring and enforcing compliance with the security duties imposed by the TSA 2021 and the ECSM Regulations. Under section 105O of the Communications Act 2003 (as inserted by the TSA), Ofcom may issue assessment notices requiring providers to submit to a technical assessment of their security measures. Ofcom may also enforce the security duties under section 105S of the Communications Act 2003, which applies sections 96A to 100, 102 and 103, including the suspension and restriction powers, and may impose financial penalties of up to 10% of relevant turnover under section 97 (as applied by section 105S) or GBP 100,000 per day for continuing contraventions under section 105T.
Ofcom published its procedural guidance on telecoms security enforcement in 2023, setting out how it will investigate potential contraventions, the factors it will consider in determining whether to take enforcement action, and its approach to calculating penalties.
Section 105K of the Communications Act 2003 requires providers to inform Ofcom, as soon as reasonably practicable, of any security compromise that has a significant effect on the operation of the network or service. Section 105K(2) sets out the four matters that bear on significance: the length of the period affected, the number of persons affected, the size and location of the geographical area affected, and the extent to which users’ activities are affected. A separate duty at section 105J requires the provider to inform users who may be adversely affected where there is a significant risk of a security compromise occurring. The interaction between telecoms security incident reporting and data breach notification under UK GDPR Article 33 requires careful management, as the reporting obligations differ in scope, timing, and recipient.
How Bratby Law helps
Bratby Law advises communications providers, network infrastructure operators, and their investors on the full scope of telecoms security regulation under the TSA 2021 and the ECSM Regulations. Our managing partner spent a year on secondment to Oftel from Baker McKenzie and has held senior in-house roles at UK telecoms operators, providing practical insight into how the regulator approaches security compliance.
Our work in this area includes:
- Compliance gap analysis against the ECSM Regulations and the TSA Code of Practice
- Advising on the scope of application of the TSA to specific network architectures, including virtualised and cloud-hosted infrastructure
- Responding to Ofcom assessment notices and enforcement notifications under the TSA
- Designated vendor direction compliance, including equipment removal planning and supply chain restructuring
- Security compromise notification procedures and co-ordination with UK GDPR data breach reporting
- Board and senior management briefings on telecoms security obligations and enforcement risk
- Due diligence on telecoms security compliance for M&A and infrastructure investment transactions
Schedule an initial call
For advice on telecoms security compliance, Ofcom enforcement or designated vendor obligations, book a call with Rob Bratby.
FAQs
Which providers are subject to the TSA 2021?
The TSA 2021 applies to all providers of public electronic communications networks and public electronic communications services as defined in the Communications Act 2003. This includes fixed and mobile network operators, internet service providers, VoIP providers, and providers of over-the-top communications services where those services fall within the statutory definition. The Code of Practice, not the Regulations, sets a three-tier framework by relevant turnover: Tier 1 above £1 billion, Tier 2 between £50 million and £1 billion, and Tier 3 below £50 million for providers that are not micro-entities. Tier 1 providers face the most stringent expectations and the shortest implementation timescales. Ofcom confirms which tier a provider falls into using the thresholds in the Code.
What is the TSA Code of Practice?
The Code of Practice is guidance issued by the Secretary of State under section 105E of the Communications Act 2003 (as inserted by the TSA). It sets out the technical measures that the Government considers appropriate for providers to comply with their security duties. The Code covers network architecture, access controls, supply chain security, security monitoring, incident response and governance. While the Code is not legally binding, Ofcom may have regard to it when assessing whether a provider has complied with its security duties, and deviation from the Code will require the provider to demonstrate that equivalent security outcomes have been achieved by alternative means.
What are the penalties for non-compliance with the TSA?
Ofcom may impose financial penalties of up to 10% of relevant turnover for contravention of the security duties in the TSA, or up to GBP 100,000 per day for continuing contraventions. Ofcom may also issue enforcement notifications requiring the provider to take specific steps to remedy the contravention. For designated vendor directions, the Secretary of State may impose penalties for non-compliance with the direction.
How does the TSA interact with the NIS Regulations?
The Network and Information Systems Regulations 2018 (NIS Regulations) apply to operators of essential services and relevant digital service providers. For telecoms providers, the TSA 2021 is the primary security regime, and Ofcom is the competent authority. However, where a telecoms provider also operates infrastructure that falls within the scope of the NIS Regulations (for example, as an operator of essential services in the energy or transport sectors), it may be subject to both regimes. A provider with operations in more than one sector maps its obligations under both regimes, because compliance with one is not compliance with the other.
Representative experience
Recent and representative matters include:
- Advised a national fixed and mobile operator on compliance with the Telecommunications (Security) Act 2021, including gap analysis against the Code of Practice and remediation planning.
- Supported a fibre altnet in designing its security governance framework to meet the section 105A duty to identify and reduce the risks of security compromises.
- Advised on vendor risk management obligations under the TSA for an operator replacing high-risk vendor equipment across its core and access networks.
- Prepared a security compliance assessment for a managed services provider to confirm its obligations under sections 105A to 105D of the Communications Act 2003.
- Advised a subsea cable operator on the interaction between the TSA security duties and the Network and Information Systems Regulations 2018 applicable to its landing station operations.
Frequently asked questions about telecoms security
Which providers must comply with the Telecommunications (Security) Act 2021?
All providers of public electronic communications networks and services in the UK must comply. The requirements are tiered by provider size: Tier 1 (largest providers), Tier 2 (medium) and Tier 3 (smallest). The specific measures required increase with tier classification.
What is the telecoms security code of practice?
The Telecoms Security Code of Practice, issued by the Secretary of State under section 105E of the Communications Act 2003, gives guidance on the measures providers should take to comply with their security duties. It covers network architecture, access controls, supply chain security, data protection, resilience and incident management. Compliance with the code is not mandatory but is treated as evidence of compliance.
What vendor restrictions apply?
The Secretary of State can issue designated vendor directions under section 105Z1 of the Communications Act 2003 (as amended) prohibiting or restricting the use of equipment from specified vendors. Huawei equipment must be removed from 5G networks by the end of 2027.
What security incidents must be reported?
Providers must inform Ofcom, as soon as reasonably practicable, of any security compromise that has a significant effect on the operation of their network or service. The threshold and the timing are set by section 105K of the Communications Act 2003. There is no separate duty on providers to report to the NCSC: Ofcom shares information with the NCSC under the disclosure regime in section 393 of that Act.
How does Ofcom enforce the security requirements?
Ofcom can issue assessment notices, require information, and impose financial penalties for non-compliance with security duties. The maximum penalty is 10% of relevant turnover or GBP 100,000 per day for continuing contravention. Ofcom published its enforcement approach in 2023.
How does the TSA interact with other security frameworks?
The TSA sits alongside the NIS Regulations 2018 (for providers of essential services), the UK GDPR (security of processing) and sector-specific requirements. Providers should map their obligations across all applicable frameworks to avoid duplication and identify gaps.
Related telecoms regulation pages
Other telecoms regulation pages:
- Interconnection regulation
- Ofcom General conditions of entitlement
- Numbering
- Spectrum
- Lawful intercept and the Investigatory Powers Act 2016
- Ofcom Licence Fees
- Code Powers and access to land
- Am I regulated?
- SMP regulation and market reviews
- Ofcom
- Complaints and investigations
- Connected Vehicles and IoT Regulation
- EU Digital Networks Act
Why Choose Bratby Law?
Sector expertise
Bratby Law advises exclusively across the telecoms, data and payments sectors. That concentration means deeper knowledge of the regulatory environment, faster analysis, and advice that reflects how regulators actually behave: not how the textbook says they should.
Senior delivery
Every instruction is handled by Rob Bratby personally. With 30 years’ experience spanning a secondment to Oftel, senior in-house roles at UK telecoms operators, and partnership at international law firms, you receive the analysis directly: not through a junior team. The firm uses AI tools to extend research capacity and accelerate document review, so senior judgment is applied to more of your matter, not less.
Current appointments
Rob Bratby currently holds fractional General Counsel appointments at TOTSCo, TelXL, Core and the UK Payments Initiative. These ongoing roles keep his advice grounded in how regulated businesses run day to day.
Independent directory rankings
Our specialist expertise is recognised in major independent legal directories:
- Chambers & Partners: Rob Bratby is ranked as a Band 2 lawyer in the UK Guide 2026 in the “Telecommunications” category: Chambers
- The Legal 500: Rob Bratby is listed as a Leading Partner for Telecoms in London (TMT: IT and Telecoms). The Legal 500
- Lexology: Rob Bratby is recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection: Lexology



What clients say about Bratby Law:
Related Services
The telecoms security duties sit alongside the rest of the Communications Act 2003 framework, including Ofcom’s enforcement powers and the General Conditions. The pages below cover how those requirements apply:
- Why Bratby Law? Specialist telecoms, data protection, payments, transactions and digital regulation lawyers
- Services
- Am I Regulated?
- General Conditions of Entitlement
- Code Powers
- Spectrum
- Transactions
- Co-counsel
- Fractional General Counsel
See also: Operational Resilience and DORA.

