The government has opened a statutory review of the UK’s telecoms-security framework, asking network and communications providers for evidence on whether rules introduced after the 2019 Telecoms Supply Chain Review are working effectively.
The eight-week call for evidence covers sections 1 to 13 of the Telecommunications (Security) Act 2021, the Electronic Communications (Security Measures) Regulations 2022, and the Telecommunications Security Code of Practice.
Submissions are open until 11.59pm on 12 October. The government will assess the responses alongside input from the National Cyber Security Centre and Ofcom before publishing a review and laying it before Parliament.
The framework strengthened legal obligations on public telecoms providers following concerns over the resilience of communications networks and their dependence on technology suppliers.
Providers are required to identify and reduce the risks of security compromises, prepare for incidents, prevent or limit adverse effects when compromises occur, and remedy or mitigate the consequences.
The legislation also gives ministers powers to specify security measures through regulation and allows detailed technical guidance to be set through a code of practice. Ofcom is responsible for monitoring and enforcing compliance.
The review therefore reaches into network architecture, supply chains, operational processes, incident management, governance, and capital investment across the telecommunications sector.
The code applies detailed expectations to larger and medium-sized providers with relevant turnover of at least £50m, while the underlying statutory duties have wider significance across public electronic communications networks and services.
The government revised the Telecommunications Security Code of Practice in July to respond to emerging threats and technological change. The statutory review is broader, examining the impact and effectiveness of the framework itself rather than updating individual pieces of guidance.
Operators will be able to submit evidence on the cost and practicality of compliance. Security requirements can drive spending on network monitoring, access controls, software management, supplier oversight, incident response, staffing, and replacement infrastructure.
The review also gives government and regulators an opportunity to assess whether those obligations are delivering the resilience improvements envisaged when Parliament strengthened the law.
Ofcom recently opened a compliance investigation into Zayo Group UK over information provided in response to a statutory request connected with telecoms-security obligations.
That investigation concerns one provider and does not establish a breach. The new review is sector-wide, but the two developments show the framework moving simultaneously through enforcement and evaluation several years after the regulations came into effect.
Telecoms security has wider commercial consequences because communications infrastructure supports banking, logistics, cloud computing, manufacturing, public services, and everyday digital operations. A significant disruption at a major provider can propagate quickly into organisations that depend on its network.
Operators are also balancing security investment against spending on fibre, mobile infrastructure, cloud connectivity, automation, and next-generation network services. Those commitments compete for capital at a time when network businesses are under pressure to improve resilience without losing pace on infrastructure upgrades.
Supply chain management remains central to the regime. Telecoms companies rely on hardware, software, managed services, and specialist technology from third parties, creating vulnerabilities that cannot always be managed solely within the operator’s own organisation.
The framework is designed partly to make those dependencies more visible and ensure providers retain sufficient control over critical functions. That can require more detailed supplier due diligence, contractual protections, access restrictions, testing, and contingency planning.
The review is not itself a proposal to weaken or strengthen a particular requirement. Its stated purpose is to establish how effectively the existing regime is operating and gather evidence that will inform the Secretary of State’s statutory assessment.
Providers have specifically been asked to distinguish the effects of the legislation from security work that would have happened anyway through business-as-usual improvements, existing obligations, or commercial decisions.
That distinction should give government a clearer view of the incremental cost and benefit attributable to the regime itself.
The findings will be published after the evidence has been analysed and laid before Parliament, providing the basis for any subsequent changes to a security framework that has become part of the operating environment for the UK’s largest communications providers.





You must be logged in to post a comment.