
NSIA Clearances
National security investment screening for telecoms, data and digital infrastructure transactions
Short answer: a telecoms acquisition is mandatorily notifiable under the NSIA only if the target is a qualifying entity carrying on an activity described in a mandatory-sector schedule and the acquisition crosses a section 8 control threshold. The thresholds are an increase from 25% or less to more than 25%, from 50% or less to more than 50%, from less than 75% to 75% or more, or the acquisition of voting rights enabling the acquirer to secure or prevent the passage of any class of resolution governing the affairs of the entity. For the public electronic communications network or service limb of the Communications schedule, the target must also have relevant UK turnover of at least £50 million. Other communications activities are covered by separate descriptions. See NSIA 2021, section 8 and SI 2021/1264, Schedule 5. Last updated 2 September 2026.
How does the NSIA 2021 affect my transaction?
The NSIA 2021 gives the Secretary of State power to review any acquisition that could harm UK national security. The regime applies to acquisitions of shares, voting rights and assets in entities carrying on activities in the UK, regardless of whether the acquirer is UK-based or foreign. It operates separately from the competition merger control regime administered by the CMA under the Enterprise Act 2002.
For transactions in the telecoms, data and payments sectors, NSIA clearance is relevant because several of the 17 mandatory notification sectors directly overlap with these industries. Communications, data infrastructure, artificial intelligence and computing hardware are all specified sectors under the National Security and Investment Act 2021 (Notifiable Acquisition) (Specification of Qualifying Entities) Regulations 2021, SI 2021/1264. An acquisition of a qualifying entity active in one or more of these sectors must be notified to the ISU and cleared before completion.
The regime catches acquisitions that cross specified shareholding thresholds: from 25% or less to more than 25%, from 50% or less to more than 50%, and from less than 75% to 75% or more (NSIA 2021, section 8). An acquisition of voting rights enabling the investor to secure or prevent the passage of any class of resolution governing the affairs of the entity is also caught. Below these thresholds, an acquisition of material influence over the policy of the entity may still be reviewable on the government’s own initiative, although it does not trigger a mandatory notification.
Which sectors trigger mandatory notification?
Seventeen sectors are designated for mandatory notification. Those most relevant to telecoms, data and digital infrastructure transactions are:
| Sector | What it covers | Key consideration for acquirers |
|---|---|---|
| Communications | Public electronic communications network or service providers with relevant UK turnover of at least £50m, plus separately specified communications-infrastructure activities | Test the target against the exact Schedule 5 description; a telecoms label or Ofcom status alone is insufficient |
| Data Infrastructure | Owning, operating or managing relevant data infrastructure, and services or software that give physical or administrative access to it. Relevant data infrastructure is defined by use, not size: infrastructure used to store, process or transmit data for a listed public sector authority under contract or sub-contract, peering or interconnection infrastructure between public network or service providers that is not owned by one, and infrastructure that interconnects a public network with a submarine cable system. No turnover or capacity threshold applies | A commercial data centre or cloud platform is caught only through one of those defined uses. Check the target’s public sector contracts (HMRC, DWP, HM Treasury, the Bank of England and the FCA are all listed authorities), its peering and interconnection role and any submarine cable links |
| Artificial Intelligence | Research into artificial intelligence, or developing or producing goods, software or technology that use it, for one or more of three purposes: identification or tracking of objects, people or events; advanced robotics; cyber security. The government proposes to confine the schedule to entities that create or modify AI systems, but that change is not yet law | Apply the purpose test. Fraud detection or network security tooling may be identification of events or cyber security; an AI feature with no listed purpose is not enough on its own |
| Computing Hardware | Intellectual property in computer processing units and memory chips, including their designs, instruction sets and low-level control code; secure provisioning of roots of trust; and fabrication or packaging of such units. The government proposes to fold this schedule into a new Semiconductors schedule | Relevant to acquisitions of chipset or hardware businesses supplying telecoms equipment |
| Defence | Research, development, production or application of goods or services used or provided for defence or national security purposes, where the entity is a government contractor or in its sub-contract chain, or has been notified that it may hold classified information | A telecoms provider that is an MoD contractor or sub-contractor, or that holds classified material, may fall within this schedule |
| Critical Suppliers to Government | A party to a public contract with a contracting authority where the contract involves processing or storing SECRET or TOP SECRET material, requires List X accreditation, or requires staff vetted at Security Check level or above | Criticality of the service is not the test. Telecoms and data centre operators with government contracts should check the security features written into each contract |
The Communications schedule does not catch every telecoms company. Its paragraph 2 limb covers a qualifying entity that provides a public electronic communications network or service only where relevant UK turnover is at least £50 million. Separate paragraphs address specified associated facilities, submarine-cable activities and other defined communications infrastructure. Each statutory description has its own conditions, so a sector label, an Ofcom status or the use of telecoms technology is not enough by itself.
Forthcoming changes: In March 2026, the government published its response to the consultation on the Notifiable Acquisition Regulations. For our sectors, the response confirms that the Communications schedule would gain a £5 million relevant-turnover threshold for associated facilities providers (cable landing stations excepted), lose the £50 million threshold for submarine cable systems and for their repair and maintenance, and confine the repair and maintenance limb to companies that operate a cable repair vessel; that the Artificial Intelligence schedule would be refocused on entities that create or modify AI systems, with end users excluded; that the Data Infrastructure schedule would add third-party operated data centres and certain cloud and managed service providers, with no materiality threshold, and would hand its public sector authority limb to Critical Suppliers to Government; that the Critical Suppliers to Government schedule would be limited to a list of ministerial departments and named bodies, replace List X with Facility Security Clearance and add Industry Personnel Security Assurance status; and that Computing Hardware would merge with the semiconductor elements of Advanced Materials into a standalone Semiconductors schedule. A new Water schedule would also be added. These changes require secondary legislation, which the government intends to lay before Parliament later in 2026. Until then, the existing sector definitions remain in force.
What about acquisitions of payments and financial services businesses?
There is no standalone “financial services” sector in the 17 mandatory notification schedules. However, acquisitions of payments and fintech businesses can still engage the NSIA 2021 through several routes. A payments processor that stores, processes or transmits data for a listed public sector authority under contract or sub-contract may fall within the Data Infrastructure schedule (HMRC, DWP, HM Treasury, the Bank of England and the FCA are all listed); operating its own data centre is not enough on its own. A fintech company developing AI fraud detection may fall within the Artificial Intelligence schedule where the system identifies or tracks events, people or objects, or serves a cyber security purpose; a credit scoring model outside those purposes does not. A payments firm holding a government contract (for example, processing welfare payments or tax collections) may fall within Critical Suppliers to Government only where that contract involves SECRET or TOP SECRET material, List X accreditation or Security Check vetting.
Separately, an acquisition of a qualifying holding in an FCA-authorised firm, including a payments institution authorised under the Payment Services Regulations 2017 or an electronic money institution authorised under the Electronic Money Regulations 2011, requires prior FCA approval under section 178 Financial Services and Markets Act 2000. This is a separate regime from the NSIA 2021 and the two processes run in parallel. Where a target is both FCA-authorised and active in a mandatory NSIA sector, the acquirer will need to manage dual clearance workstreams with different timetables, decision-makers and information requirements.
| Clearance regime | Decision-maker | Trigger | Typical timetable |
|---|---|---|---|
| NSIA 2021 mandatory notification | Secretary of State (via ISU) | Acquisition crossing 25%, 50% or 75% threshold in entity active in specified sector | 6-8 weeks (initial review); 3-5 months if called in |
| FCA change in control | FCA | Acquiring control (10% or more, or significant influence) or increasing control through the 20%, 30% or 50% steps in an FCA-authorised firm | 60 working days (statutory assessment period) |
| CMA merger control | CMA | Turnover or share of supply thresholds met | Variable; Phase 1 typically 40 working days |
For PE investors and acquirers in the payments sector, understanding which of these regimes applies, and coordinating conditions precedent and timetables accordingly, is a core part of deal planning.
What is the notification and clearance process?
The notification process is administered by the Investment Security Unit, which currently sits within the Cabinet Office. The formal decision-maker is the Secretary of State (Chancellor of the Duchy of Lancaster).
Step 1: Assess whether notification is required. Determine whether the target is a qualifying entity active in one or more mandatory sectors. If so, the transaction must be notified before completion. If the target falls outside the mandatory sectors but the transaction is otherwise within scope (for example, an acquisition of material influence), the acquirer may choose to notify voluntarily for legal certainty.
Step 2: Submit the notification. Notifications are submitted through the NSI notification service online portal. The form requires details of the target’s activities, the transaction terms and the acquirer’s ownership structure. Each notifiable transaction must generally be notified separately, although the ISU accepts single notifications for related acquisitions from the same seller. The notification must be accompanied by a signed declaration confirming accuracy. The ISU’s market guidance notes recommend notifying only once there is a good faith intention to proceed, evidenced by agreed heads of terms, board approval or a firm intention announcement.
Step 3: Initial review period. Once the ISU accepts the notification, it has 30 working days to decide whether to clear the transaction or call it in for further assessment (NSIA 2021, section 14). In the 2025-26 reporting period, the median time from receipt to acceptance of a mandatory notification was 11 working days (7 in 2024-25), and 95.6% of reviewed acquisitions were cleared within the review period without being called in.
Step 4: Call-in and detailed assessment (if required). If the ISU identifies potential national security concerns, it issues a call-in notice. Following call-in, there is an initial 30 working day assessment period, extendable by a further 45 working days on notice, and by further periods with the acquirer’s agreement (NSIA 2021, section 23). Information notices and attendance notices issued during this period stop the clock. The Secretary of State may impose interim orders to prevent pre-emptive action during the review.
Step 5: Final order or clearance. If the Secretary of State concludes that, on the balance of probabilities, a transaction gives rise to a risk to national security, a final order may impose conditions (such as maintaining UK management or restricting information sharing) or prohibit the transaction. In 2025-26, 60 call-in notices were issued and nine final orders made: eight imposed conditions and one blocked the acquisition. In 2024-25 the figures were 56 call-ins and 17 final orders, 16 with conditions and one requiring the acquisition to be unwound.
What are the consequences of not obtaining clearance?
The penalties for non-compliance are severe. Under NSIA 2021, section 13(1), a notifiable acquisition completed without the Secretary of State’s approval is void. The transaction is treated in law as if it had never taken place.
Completing a notifiable transaction without approval is a criminal offence, punishable by up to five years’ imprisonment and an unlimited fine. Officers of a body corporate may be held personally liable if the offence was committed with their consent or connivance, or is attributable to their neglect (NSIA 2021, section 36). The Secretary of State may also impose civil monetary penalties of up to 5% of worldwide turnover or GBP 10 million, whichever is higher, without the need for criminal prosecution.
In the 2025-26 reporting period, the government identified 42 potential offences of completing a notifiable acquisition without approval (60 in 2024-25). No penalties were imposed and no criminal prosecutions were concluded in either year, but parties were required to give reassurance that steps had been taken to prevent any recurrence. Retrospective validation is available on application by any materially affected person under NSIA 2021, section 16, but it should not be relied upon as a substitute for proper notification.
What does the regime mean in practice for deal timetables?
For acquirers in the telecoms and digital infrastructure sectors, the practical implications are as follows.
Deal documentation. Transaction agreements should contain NSIA-specific conditions precedent. The completion mechanism must include suspensory provisions preventing closing until ISU clearance is received. This is distinct from any CMA merger control condition and must be drafted separately.
Timetable. A straightforward mandatory notification typically adds 6 to 8 weeks to the deal timetable: around two weeks for form acceptance (the 2025-26 median was 11 working days) and up to 30 working days for the initial review. If the transaction is called in, the assessment may take a further 3 to 5 months. Transaction timetables and funding arrangements must account for this.
Risk assessment. The risk of intervention depends on three factors set out in the Secretary of State’s section 3 statement (updated May 2024): target risk (whether the target operates in a sensitive sector), acquirer risk (the identity and affiliations of the acquirer), and control risk (the extent of control being acquired). In 2025-26, Defence (47%), Critical Suppliers to Government (33%) and Military and Dual-Use (33%) were the areas most often associated with call-ins, while Advanced Materials (five of nine) and Data Infrastructure (three of nine) accounted for most final orders. Acquirers associated with the United Kingdom made up the largest share of call-ins (52%) and of final orders (five of nine). Acquirers associated with China accounted for 30% of call-ins and three final orders, a far larger share than of notifications, where China is not among the four most common origins.
Engagement with the ISU. Where the risk profile is uncertain, early engagement with the ISU can help. The ISU provides informal guidance on whether a transaction falls within scope, although this guidance does not have legal force. In higher-risk cases, preparatory contact with stakeholders in the Ministry of Defence or other relevant departments can facilitate a smoother review.
How Bratby Law helps with NSIA clearances
We advise acquirers, targets and their professional advisers on all aspects of the NSIA 2021 regime as it applies to telecoms, data and digital infrastructure transactions. Our services include:
- Assessing whether a transaction triggers mandatory notification by analysing the target’s activities against the 17 specified sectors
- Preparing and submitting mandatory and voluntary notifications to the ISU
- Advising on deal structuring, conditions precedent and suspensory mechanisms specific to NSIA clearance
- Managing the ISU review process, including responding to information notices and preparing for call-in
- Advising on potential remedies and conditions to address national security concerns
- Coordinating NSIA clearance with parallel CMA merger control and FCA change in control processes where the target operates in a regulated financial services sector
- Advising on retrospective validation where a notifiable acquisition has been completed without approval
Our experience as General Counsel to operators in the telecoms and payments sectors means we understand the target’s business and regulatory position from the inside. This is particularly valuable when explaining the target’s activities to the ISU and assessing whether those activities fall within the mandatory notification sectors.
Need advice on NSIA clearances for a telecoms or digital infrastructure deal?
Related Transactions pages
See also our other Transactions pages:
- Mergers and Acquisitions (M&A)
- SaaS and Cloud Services
- Private equity
- Subsea cables
- MVNOs and MVNEs
- Interconnection, peering and access agreements
- Network sharing and co-location agreements
- Digital Infrastructure Projects
- Data Commercialisation and Licensing
- Transactions (pillar page)
Frequently asked questions about NSIA clearances
Do all telecoms transactions require NSIA notification?
No. Mandatory notification requires both a qualifying target activity within a specified sector and a section 8 trigger event. A public electronic communications network or service provider falls within paragraph 2 of the Communications schedule only where the £50 million relevant-UK-turnover condition is also met. Service contracts and MVNO arrangements that do not acquire control are not notifiable acquisitions. A sub-threshold share acquisition may still be called in if it confers material influence, but it is not mandatorily notifiable on that basis alone.
How long does NSIA clearance take?
Most transactions are cleared within the initial 30 working day review period. In 2025-26, the median time from receipt to acceptance of a mandatory notification was 11 working days, and 95.6% of reviewed acquisitions were cleared without being called in. If a transaction is called in, a final order took a median of 69 statutory working days from call-in in 2025-26 (97 working days once time with the clock stopped is counted), so 3 to 5 months remains a realistic planning assumption; a called-in deal cleared by final notification took a median of 24 statutory working days.
Can I complete the transaction before receiving clearance?
No. A notifiable acquisition completed without the Secretary of State’s approval is void under section 13(1) NSIA 2021. The transaction is treated as if it had never taken place. Completion without approval is also a criminal offence carrying up to five years’ imprisonment.
Does the NSIA apply to foreign-to-foreign transactions?
Yes. The regime applies to any acquisition of a qualifying entity that carries on activities in the UK or supplies goods or services to persons in the UK, regardless of where the acquirer or target is incorporated (NSIA 2021, section 7). A foreign-to-foreign acquisition of a company operating UK telecoms infrastructure or data centres is within scope.
What happens if we missed a mandatory notification?
The acquirer should apply for retrospective validation under section 16 NSIA 2021. The government identified 42 potential offences of completion without approval in 2025-26 and 60 in 2024-25. No penalties were imposed and no prosecutions were concluded in either year, but the parties were required to give assurances on future compliance. Retrospective validation does not guarantee clearance, and the Secretary of State retains the power to call in the transaction.
Is a voluntary notification advisable?
It depends on the risk profile. Voluntary notifications accounted for 11% of all notifications received in 2025-26 (147 of 1,324) and 12% in 2024-25. They are worth considering where the target’s activities are close to a mandatory sector boundary, where the acquirer’s identity or nationality may raise concerns, or where the acquirer wants legal certainty that the transaction will not be called in after completion. The government can call in an acquisition that was not notified for up to six months from the date it becomes aware of it, and in the ordinary case no later than five years after completion (NSIA 2021, section 2(2)). The five-year limit does not apply to a notifiable acquisition completed without approval: that acquisition is void and can be called in within six months of the government learning of it, however long after completion (section 2(3)).
How does NSIA clearance interact with CMA merger control?
The two regimes operate in parallel. A transaction may require both NSIA clearance and CMA merger control clearance. The timetables run independently: obtaining NSIA clearance does not affect the CMA process, and vice versa. Where both apply, deal documentation should include separate conditions precedent for each clearance. The NSIA 2021 replaced the previous public interest merger regime for national security cases under the Enterprise Act 2002.
Independent directory rankings
Our specialist expertise is recognised in major independent legal directories:
- Chambers & Partners: Rob Bratby is ranked as a Band 2 lawyer in the UK Guide 2026 in the “Telecommunications” category: Chambers
- The Legal 500: Rob Bratby is listed as a Leading Partner for Telecoms in London (TMT: IT and Telecoms). The Legal 500
- Lexology: Rob Bratby is recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection: Lexology



