TSA Code of Practice v1.1
 

What public telecoms providers should do now

David Macphail | Senior Information Security Consultant, Xcina Consulting | 10 September 2026

The revised Telecommunications Security Code of Practice introduces more than editorial clarification. It has practical implications for control mapping, supplier assurance, privileged administration, evidence management and implementation planning. This article explains the principal changes and the actions public telecoms providers should consider now.

 

At a glance

  • Version 1.1 reinforces a comprehensive, risk-based approach across public electronic communications networks and services, including physical and personnel security.
  • The revision updates alignment with the NCSC Cyber Assessment Framework ‘CAF’ and increases the prominence of device management, identity and access management, data security and threat understanding.
  • Supplier assurance expectations are strengthened through additional Business Continuity and Disaster Recovery considerations in the Vendor Security Assessment annex.
  • Privileged Access Workstations remain central to protecting management-plane activity, including access performed by managed service providers and other third parties.
  • Providers should demonstrate that the revision was assessed, interpretations recorded, ownership assigned and evidence and remediation plans updated where required.

 

Who should read this?

This article is primarily intended for leaders responsible for security, technology, network operations, regulatory compliance, risk, internal assurance and supplier management within large and medium-sized UK public telecoms providers. It may also be relevant to smaller providers and organisations supporting public telecoms networks where the Code provides a useful benchmark for proportionate security.

 

A revision that requires a managed response

On 14 July 2026, the government issued version 1.1 of the Telecommunications Security Act (TSA) Code of Practice. The Code provides detailed guidance on how public telecoms providers can comply with duties under the Telecommunications (Security) Act 2021 and the Electronic Communications (Security Measures) Regulations 2022.

The revision refines the language of the Code, incorporates updates intended to address new threats and technological developments, and reinforces the expectation that providers take a comprehensive, risk-based approach to security.

At Xcina Consulting, we support organisations in interpreting complex regulatory requirements, assessing control and evidence gaps, prioritising remediation and establishing proportionate assurance arrangements. Our practical experience of TSA compliance work shows that the challenge is translating requirements into clear ownership, defensible decisions, reliable evidence and sustainable governance across technical, operational and supplier environments.

 

What changed in version 1.1?

Clearer audience and terminology

References to “telecoms providers” are tightened to “public telecoms providers”, creating greater consistency about the organisations addressed by the detailed guidance.

 

A stronger holistic and risk-based emphasis

The revised Code stresses that providers should consider the whole Code when assessing risk, including physical and personnel security and technological change.

 

Clarified roles for Ofcom and the NCSC

The NCSC provides technical advice but does not determine regulatory compliance. Ofcom retains responsibility for regulatory determinations, while each provider remains responsible for interpreting and acting on its obligations.

Updated alignment with CAF version 4.0

The mapping to the NCSC Cyber Assessment Framework is updated to CAF version 4.0, increasing the prominence of threat understanding, device management, identity and access management, data security and lessons learned.

Additional supplier resilience focus

The Vendor Security Assessment annex includes further Business Continuity and Disaster Recovery considerations, increasing the importance of meaningful evidence of supplier resilience.

Revised implementation planning

Several CAF-aligned and management-plane or signalling-plane measures are associated with the 31 March 2028 timeframe. Providers should confirm applicable measures directly against the current Code and maintain an implementation plan reflecting dependencies, platform lifecycles and evidence requirements.

 

Privileged Access Workstations in focus

Version 1.1 sharpens and consolidates supporting guidance on Privileged Access Workstations (PAWs), reinforcing their role in protecting sensitive administrative activity through the management plane. A PAW is an appropriately secured device used to make changes to Security Critical Functions and/or Network Oversight Functions through a management plane.

 

Key considerations for a PAW strategy

  • Use clean, known-good operating system images and control permitted software.
  • Apply full-disk encryption, hardware-backed protection and suitable boot authentication.
  • Restrict removable media and routes that could weaken segregation.
  • Integrate PAWs with central monitoring and investigation processes.
  • Apply least privilege and controlled elevation for administrative activity.
  • Integrate PAWs with Privileged Access Management controls where appropriate.
  • Ensure relevant third-party administrators use trusted PAWs, supported by segregation, contractual requirements and assurance rights.

Identity controls alone do not protect a privileged operation if the endpoint initiating it is untrusted or inadequately controlled. Providers should assess PAW design, deployment, operating procedures, third-party use and supporting evidence as an integrated control system.

Why the revision matters

Evidence of effectiveness matters

Providers should be able to explain how their approach is appropriate and proportionate, how it addresses identified risks and what evidence demonstrates effective operation.

Supplier resilience requires deeper assurance

Supplier assurance should examine recovery capabilities, testing, dependencies and operational coordination, supported by evidence and informed challenge.

CAF alignment may reduce duplication

Providers using CAF-based assessments may reuse relevant control descriptions and evidence where these genuinely address the telecoms context and applicable measures.

Governance must keep pace with technical change

Providers need a repeatable method for monitoring revisions, assessing applicability, recording decisions and updating controls, evidence and implementation plans.

Actions providers should begin now

1. Establish a controlled version 1.1 impact assessment

Compare current TSA mappings, plans and evidence with the official Code and change log. Record applicability, rationale, ownership and resulting actions.

2. Revalidate risk and control linkages

Connect relevant measures to current threat scenarios, network architecture, Security Critical Functions, Network Oversight Functions and risk treatment decisions.

3. Refresh the evidence strategy

Identify evidence that can be retained, evidence that should be updated and new evidence required.

4. Review supplier and managed service dependencies

Assess relevant contractual requirements, resilience evidence, recovery testing, privileged access and assurance rights.

5. Reassess privileged administration

Review the PAW and PAM operating model, including internal and third-party administration, monitoring, exception handling and evidence.

6. Update the implementation roadmap

Prioritise actions according to risk, regulatory timeframe, technical dependency, platform lifecycle, resource and evidence lead time.

7. Strengthen governance and executive reporting

Give leadership a concise view of assessed changes, material risks, dependencies, decisions and progress.

Questions for boards and accountable executives

  • Has the organisation completed and approved a documented assessment of version 1.1?
  • Can management explain which changes affect the organisation and where alternative approaches have been adopted?
  • Are accountable owners, funding, dependencies and implementation milestones clear?
  • Is the available evidence sufficient to demonstrate that key controls operate as intended?
  • Have supplier resilience and privileged third-party access been assessed?
  • Is there independent challenge over conclusions, evidence and reported progress?

What good evidence may look like

  • A threat-led risk assessment linking relevant measures to risks, treatment decisions and proportionate controls.
  • A controlled version 1.1 impact register showing applicability, interpretation, ownership, decisions and actions.
  • A crosswalk between the Code, applicable CAF version 4.0 areas, internal controls, owners, metrics and evidence.
  • Supplier records covering contractual obligations, assurance evidence, test outcomes, dependencies and remediation.
  • Evidence that physical, personnel, operational and cyber risks are considered together.
  • PAW and PAM documentation supported by build standards, access records, monitoring and third-party assurance.
  • Governance reporting that distinguishes implementation, open risk, evidence gaps, dependencies and escalations.

Common pitfalls to avoid

Treating version 1.1 as a cosmetic edit

A provider should demonstrate that the impact was assessed rather than merely replacing the reference version in documents.

Assuming the NCSC is the compliance decision-maker

The NCSC provides technical advice; Ofcom is responsible for regulatory compliance determinations.

Over-indexing on technology

Technical controls may fail where ownership, procedures, suppliers, competency, monitoring and evidence are weak.

Using questionnaires as the limit of supplier assurance

Critical supplier claims should be supported by proportionate evidence, challenge, testing and remediation follow-up.

Creating a one-off delta document

The impact assessment should feed into risk management, implementation, assurance and routine governance.

 

A final word on governance

Code revisions should not be treated as document updates alone. Providers need a repeatable process for identifying change, assessing applicability, agreeing interpretations, assigning ownership and retaining evidence of decisions. A well-governed response supports regulatory readiness while reducing duplicated effort and clarifying accountability.

 

How Xcina Consulting can help

Understanding the changes is only the first step. Providers must determine which changes affect their environment, how existing arrangements align with the revised guidance, where evidence needs to be refreshed and how resulting actions should be prioritised.

  • TSA Code version 1.1 impact assessments.
  • TSA gap and readiness reviews.
  • Control and evidence reviews.
  • Remediation planning and tracking.
  • Supplier assurance reviews.
  • Focused technical and governance workshops.
  • Independent assurance and internal audit support.

Our approach is practical and proportionate. We help clients translate detailed regulatory and technical requirements into clear decisions, prioritised actions and defensible evidence.

 

Has your organisation assessed the impact of Code version 1.1?

Speak with Xcina Consulting about a focused impact discussion covering applicability, control mapping, evidence, supplier assurance, privileged administration and implementation planning. Visit Xcina Consulting or contact Lindsey Domingo to arrange an initial discussion with David Macphail.

 

 

 

Important notice

This article provides general information and does not constitute legal advice or a determination of regulatory compliance. The relevance and proportionality of individual measures depend on each provider’s circumstances. Ofcom retains responsibility for regulatory compliance determinations.

 

Sources and further reading

  • Revised Telecommunications Security Code of Practice 2026 (version 1.1): GOV.UK publication page.
  • Telecommunications Security Code of Practice 2026 (version 1.1): official HTML version.
  • Telecommunications Security Code of Practice 2026 (version 1.1): official change log.
  • Xcina Consulting website.
 

David MacPhail

Information Security Senior Consultant
LinkedIn >>
T: +44 (0)20 3745 7820

David MacPhail

Xcina Management Team

David leads our Cyber Maturity practice.  During his 15+ years in cyber security practices, David has delivered information security consultancy for many high-profile clients, most notably as a PCI DSS QSA. 

He has assisted a wide variety of organisations in securing their information assets and applications and achieving and maintaining compliance with industry standards.  David has extensive international and UK-based experience delivering security consultancy assignments.

Prior to specialising in security consultancy and the PCI DSS, he was engaged with a Managed Security Services provider and has extensive experience in network architecture, SOC / SIEM, firewall design, implementation, rules reviews, vulnerability (including ASV) scanning and penetration testing delivery.  David is also a CISSP and ISO27001 Lead Auditor.

Subscribe to Updates

Receive regular updates from our expert consultants as they provide clarification and guidance on issues impacting your organisation.

Subscribe >>