UK Telecommunications (Security) Act 2021
Evidence request list. 10 controls, 10 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Code of Practice
Per TSA + Telecommunications Security Code of Practice: Network Architecture Hierarchy and Security Layers + security measures per code + Ofcom Code of Practice compliance.
- TSA evidence for UKTSA-2
- tier + HRV + reporting partial
Monitoring, Notification and Enforcement
Implement continuous security monitoring of networks and services. Detect anomalous activity, unauthorized access attempts, and potential compromises in near real-time.
- Security monitoring policy with telemetry sources covering signalling, management, and bearer planes
- Incident response runbooks with Ofcom notification triggers and timelines
- SOC operating procedures and 24x7 staffing rosters
- Post incident review reports and corrective action tracking
- Threat intelligence ingestion records and indicator of compromise sweeps
- Notification timelines to Ofcom not tested through tabletop exercises
- Monitoring coverage gaps in virtualised network functions
- Incident classification thresholds inconsistent with Code of Practice severity tiers
- Lessons learned not fed back into security duties evidence
Notify Ofcom and affected users of security compromises. Tier 1 providers must report within 24 hours for significant incidents. Maintain incident response capabilities.
- Security monitoring policy with telemetry sources covering signalling, management, and bearer planes
- Incident response runbooks with Ofcom notification triggers and timelines
- SOC operating procedures and 24x7 staffing rosters
- Post incident review reports and corrective action tracking
- Threat intelligence ingestion records and indicator of compromise sweeps
- Notification timelines to Ofcom not tested through tabletop exercises
- Monitoring coverage gaps in virtualised network functions
- Incident classification thresholds inconsistent with Code of Practice severity tiers
- Lessons learned not fed back into security duties evidence
Ofcom monitors and enforces compliance. May issue assessment notices, contravention notices, and fines up to 10% of turnover or GBP 100,000 per day for continued contravention.
- Security monitoring policy with telemetry sources covering signalling, management, and bearer planes
- Incident response runbooks with Ofcom notification triggers and timelines
- SOC operating procedures and 24x7 staffing rosters
- Post incident review reports and corrective action tracking
- Threat intelligence ingestion records and indicator of compromise sweeps
- Notification timelines to Ofcom not tested through tabletop exercises
- Monitoring coverage gaps in virtualised network functions
- Incident classification thresholds inconsistent with Code of Practice severity tiers
- Lessons learned not fed back into security duties evidence
Network Security Duties
Implement secure network architecture with defined security zones, controlled access between zones, and protection of management plane traffic from user and control plane traffic.
- Network architecture diagrams showing security critical functions and exposure zones
- Network segmentation policy aligned to Code of Practice Tier 1 requirements
- Privileged access management records covering network oversight functions
- Cryptographic key management procedures and inventory of TLS and IPsec deployments
- Configuration baselines and hardening standards for network equipment
- Firmware integrity verification logs and trusted update process records
- Management plane not isolated from signalling and bearer planes
- Legacy SNMP v1 and v2 still active on production network elements
- Privileged access reviews not performed at the cadence required by Tier 1
- Cryptographic algorithm inventory incomplete or stale
Implement strong authentication for network access. Privileged access management for network functions. Multi-factor authentication for remote access and critical operations.
- Network architecture diagrams showing security critical functions and exposure zones
- Network segmentation policy aligned to Code of Practice Tier 1 requirements
- Privileged access management records covering network oversight functions
- Cryptographic key management procedures and inventory of TLS and IPsec deployments
- Configuration baselines and hardening standards for network equipment
- Firmware integrity verification logs and trusted update process records
- Management plane not isolated from signalling and bearer planes
- Legacy SNMP v1 and v2 still active on production network elements
- Privileged access reviews not performed at the cadence required by Tier 1
- Cryptographic algorithm inventory incomplete or stale
Assess and manage risks from equipment vendors and managed service providers. High-risk vendor restrictions apply. Must have contingency plans for vendor supply chain disruption.
- Supply chain risk register covering TSA designated vendors and high risk vendor restrictions
- Vendor security assurance reports and ISO 27001 or equivalent attestations
- Contractual security schedules with right to audit and Ofcom information sharing clauses
- Vendor diversification analysis and concentration risk reports per Tier 1 obligations
- Equipment removal plans for designated vendors with timetables submitted to DSIT
- Sub tier suppliers not mapped beyond Tier 1 vendors
- No documented timetable for designated vendor equipment removal
- Vendor security testing relies on self attestation without independent validation
- Concentration risk in core network functions not quantified
Reporting
Per TSA: incident reporting to Ofcom + cooperation + enforcement.
- TSA evidence for UKTSA-4
- tier + HRV + reporting partial
Security Duties
Per UK Telecommunications (Security) Act 2021 Sections 105A-D: General Duty to Identify and Reduce Security Risks + Duty to Prepare for the Occurrence of Compromises + Duty to Reduce Adverse Effects of Compromises + Tier Classification.
- TSA evidence for UKTSA-1
- tier + HRV + reporting partial
Supply Chain
Per TSA: supply chain risk + equipment security + designated vendors (high-risk vendor) restrictions.
- TSA evidence for UKTSA-3
- tier + HRV + reporting partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the UK Telecommunications (Security) Act 2021 framework page.