David Macphail | Senior Information Security Consultant, Xcina Consulting | 10 September 2026
The revised Telecommunications Security Code of Practice introduces more than editorial clarification. It has practical implications for control mapping, supplier assurance, privileged administration, evidence management and implementation planning. This article explains the principal changes and the actions public telecoms providers should consider now.
This article is primarily intended for leaders responsible for security, technology, network operations, regulatory compliance, risk, internal assurance and supplier management within large and medium-sized UK public telecoms providers. It may also be relevant to smaller providers and organisations supporting public telecoms networks where the Code provides a useful benchmark for proportionate security.
On 14 July 2026, the government issued version 1.1 of the Telecommunications Security Act (TSA) Code of Practice. The Code provides detailed guidance on how public telecoms providers can comply with duties under the Telecommunications (Security) Act 2021 and the Electronic Communications (Security Measures) Regulations 2022.
The revision refines the language of the Code, incorporates updates intended to address new threats and technological developments, and reinforces the expectation that providers take a comprehensive, risk-based approach to security.
At Xcina Consulting, we support organisations in interpreting complex regulatory requirements, assessing control and evidence gaps, prioritising remediation and establishing proportionate assurance arrangements. Our practical experience of TSA compliance work shows that the challenge is translating requirements into clear ownership, defensible decisions, reliable evidence and sustainable governance across technical, operational and supplier environments.
References to “telecoms providers” are tightened to “public telecoms providers”, creating greater consistency about the organisations addressed by the detailed guidance.
The revised Code stresses that providers should consider the whole Code when assessing risk, including physical and personnel security and technological change.
The NCSC provides technical advice but does not determine regulatory compliance. Ofcom retains responsibility for regulatory determinations, while each provider remains responsible for interpreting and acting on its obligations.
The mapping to the NCSC Cyber Assessment Framework is updated to CAF version 4.0, increasing the prominence of threat understanding, device management, identity and access management, data security and lessons learned.
The Vendor Security Assessment annex includes further Business Continuity and Disaster Recovery considerations, increasing the importance of meaningful evidence of supplier resilience.
Several CAF-aligned and management-plane or signalling-plane measures are associated with the 31 March 2028 timeframe. Providers should confirm applicable measures directly against the current Code and maintain an implementation plan reflecting dependencies, platform lifecycles and evidence requirements.
Version 1.1 sharpens and consolidates supporting guidance on Privileged Access Workstations (PAWs), reinforcing their role in protecting sensitive administrative activity through the management plane. A PAW is an appropriately secured device used to make changes to Security Critical Functions and/or Network Oversight Functions through a management plane.
Identity controls alone do not protect a privileged operation if the endpoint initiating it is untrusted or inadequately controlled. Providers should assess PAW design, deployment, operating procedures, third-party use and supporting evidence as an integrated control system.
Providers should be able to explain how their approach is appropriate and proportionate, how it addresses identified risks and what evidence demonstrates effective operation.
Supplier assurance should examine recovery capabilities, testing, dependencies and operational coordination, supported by evidence and informed challenge.
Providers using CAF-based assessments may reuse relevant control descriptions and evidence where these genuinely address the telecoms context and applicable measures.
Providers need a repeatable method for monitoring revisions, assessing applicability, recording decisions and updating controls, evidence and implementation plans.
Compare current TSA mappings, plans and evidence with the official Code and change log. Record applicability, rationale, ownership and resulting actions.
Connect relevant measures to current threat scenarios, network architecture, Security Critical Functions, Network Oversight Functions and risk treatment decisions.
Identify evidence that can be retained, evidence that should be updated and new evidence required.
Assess relevant contractual requirements, resilience evidence, recovery testing, privileged access and assurance rights.
Review the PAW and PAM operating model, including internal and third-party administration, monitoring, exception handling and evidence.
Prioritise actions according to risk, regulatory timeframe, technical dependency, platform lifecycle, resource and evidence lead time.
Give leadership a concise view of assessed changes, material risks, dependencies, decisions and progress.
A provider should demonstrate that the impact was assessed rather than merely replacing the reference version in documents.
The NCSC provides technical advice; Ofcom is responsible for regulatory compliance determinations.
Technical controls may fail where ownership, procedures, suppliers, competency, monitoring and evidence are weak.
Critical supplier claims should be supported by proportionate evidence, challenge, testing and remediation follow-up.
The impact assessment should feed into risk management, implementation, assurance and routine governance.
Code revisions should not be treated as document updates alone. Providers need a repeatable process for identifying change, assessing applicability, agreeing interpretations, assigning ownership and retaining evidence of decisions. A well-governed response supports regulatory readiness while reducing duplicated effort and clarifying accountability.
Understanding the changes is only the first step. Providers must determine which changes affect their environment, how existing arrangements align with the revised guidance, where evidence needs to be refreshed and how resulting actions should be prioritised.
Our approach is practical and proportionate. We help clients translate detailed regulatory and technical requirements into clear decisions, prioritised actions and defensible evidence.
Speak with Xcina Consulting about a focused impact discussion covering applicability, control mapping, evidence, supplier assurance, privileged administration and implementation planning. Visit Xcina Consulting or contact Lindsey Domingo to arrange an initial discussion with David Macphail.
This article provides general information and does not constitute legal advice or a determination of regulatory compliance. The relevance and proportionality of individual measures depend on each provider’s circumstances. Ofcom retains responsibility for regulatory compliance determinations.
Receive regular updates from our expert consultants as they provide clarification and guidance on issues impacting your organisation.
Subscribe >>