Thursday, 1 October 2026

Where technology leaders come to think out loud

ColumnInfrastructure & Telecoms

Telecoms security review should end the limbo for smaller providers

The government has opened its statutory review of the Telecommunications (Security) Act 2021. But the smallest providers it covers, those under £50m turnover, still have legal duties and no specific guidance of their own

VETTDD infrastructure telecoms section card
Image: VETTDD
In brief
  • The statutory review of the Telecommunications (Security) Act is taking evidence until 12 October 2026.
  • Nearly four years after the security regulations took effect, the code of practice still says only that guidance for Tier 3 providers ‘may’ follow.
  • Business buyers should ask providers which tier they are in and how they meet the duties, and the review should set a short baseline for the smallest providers.

The government opened a call for evidence on 17 August 2026 into the impact and effectiveness of sections 1 to 13 of the Telecommunications (Security) Act 2021, the law that put security duties on public telecoms providers and gave Ofcom the powers to enforce them. Section 14 of the act requires the secretary of state to review those sections and lay a report before Parliament. The call runs for eight weeks, to 12 October, and the government says it particularly wants to hear from companies that provide public electronic communications networks and services.

The framework has three layers. The act sets overarching duties. The Electronic Communications (Security Measures) Regulations 2022, in force since 1 October 2022, set out specific measures. The Telecommunications Security Code of Practice, first published in December 2022 and reissued as version 1.1 on 14 July 2026, explains how providers are expected to comply, with dated milestones that run to 31 March 2028.

The code sorts providers by relevant turnover. Tier 1 is £1bn or more; Tier 2 is £50m up to £1bn; Tier 3 is everyone below £50m except micro-entities, to which the regulations do not apply. Tier 3 providers “are not expected to follow the measures in the Code of Practice”, the code says, but they “must continue to take appropriate and proportionate measures” to meet their duties. Then comes a line still present in version 1.1: “The government may choose to issue specific guidance for Tier 3 providers in the future.”

Nearly four years after the regulations took effect, on the code’s own wording, that future has not arrived. The review is the moment to end the wait. Below £50m is likely to sit much of the UK’s smaller provider base, from regional full-fiber builders to business internet and hosted voice providers. For the small and mid-sized organizations that buy from them, the security of a connection currently rests on what each provider decides ‘proportionate’ means.

Proportionate is doing a lot of work

Even the providers that do have a code find the line hard to draw. The government’s response to its consultation on the 2026 revision, published on 1 June, records respondents asking for more detail and others calling the guidance too prescriptive, sometimes on the same area of guidance. Some argued that Ofcom’s compliance monitoring pushed providers toward a checklist approach rather than the risk-based one the code asks for.

If Tier 1 and Tier 2 providers, with a code that runs to more than 170 pages and a regulator monitoring their compliance, still argue over where proportionate ends, Tier 3 providers are drawing the line alone. The threat does not shrink with turnover. The government’s case for revising the code cites the GSMA, the mobile industry body, as saying the number of cyberattacks has risen by about 75% over five years.

There is a fair argument for light touch at the small end. A provider with a few thousand business lines is unlikely to fund the security operations of a national network, and a code written for Tier 1 could push some out of the market. But the choice is not between the full code and nothing. A short Tier 3 baseline – patching windows, privileged access, supplier contracts, monitoring – would give smaller providers a standard to work to and their customers a standard to ask about.

Buyers should ask which tier

For a CIO at a mid-sized firm, a provider’s tier rarely appears on the order form. It should come up before the contract is signed.

A Tier 1 or Tier 2 provider should be able to say where it stands against the code’s milestones. That includes the supply chain measures that, under the code, should be in all its contracts by 31 March 2027, among them a break clause allowing it to exit a contract without penalty where a third-party supplier does not fix security failings within a reasonable time. A buyer can reasonably ask whether its own provider has done the same with the suppliers behind it.

A Tier 3 provider should be able to explain what it treats as appropriate and proportionate, and whether it has adopted any of the code’s measures voluntarily, as the code allows. A provider that cannot answer either question has answered a different one.

The review should pick a side

Smaller providers have their own reason to respond before 12 October. Written guidance would cost them effort, but it would also give them something they lack: a recognized benchmark to cite when a business customer, an insurer or a public sector buyer asks how secure their network is. Without it, the honest answer is ‘as secure as we judged proportionate’, and that is a hard thing to put in a tender.

The government has two credible options. It can write the Tier 3 guidance the code holds out, scaled to what small providers can afford. Or it can say plainly that the duties alone are the standard, and that Ofcom will judge proportionality case by case. Either would be better than another review cycle of “may choose to”.

A security duty without a standard is a promise each provider writes for itself.

AdvertisementZoomInfo

Get The VETTDD BriefingThe week in the technology channel, every week.

Subscribe free
Sources
  1. DCMS and DSIT, “Call for evidence on the impact and effectiveness of Sections 1 to 13 of the Telecommunications (Security) Act 2021”, 17 August 2026. https://www.gov.uk/government/calls-for-evidence/call-for-evidence-on-the-impact-and-effectiveness-of-sections-1-to-13-of-the-telecommunications-security-act-2021/call-for-evidence-on-the-impact-and-effectiveness-of-sections-1-to-13-of-the-telecommunications-security-act-2021
  2. DCMS and DSIT, “Telecommunications Security Code of Practice 2026 (version 1.1)”, issued 14 July 2026. https://www.gov.uk/government/publications/revised-telecommunications-security-code-of-practice-2026-version-11/telecommunications-security-code-of-practice-2026-version-11
  3. DSIT, “Proposals to update the Telecommunications Security Code of Practice 2022: government response”, 1 June 2026. https://www.gov.uk/government/consultations/proposals-to-update-the-telecommunications-security-code-of-practice-2022/outcome/proposals-to-update-the-telecommunications-security-code-of-practice-2022-government-response
About the author

Editor

The VETTDD editorial desk. Interviews, analysis, columns and news on the decisions shaping UK B2B technology.

More from Editor →