Skip to content

Evidence request lists

UK Telecommunications (Security) Act 2021

Evidence request list. 10 controls, 10 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Code of Practice

UKTSA-2
Code of Practice and Network Architecture

Per TSA + Telecommunications Security Code of Practice: Network Architecture Hierarchy and Security Layers + security measures per code + Ofcom Code of Practice compliance.

Artefacts an auditor will ask for
  • TSA evidence for UKTSA-2
Where this commonly fails
  • tier + HRV + reporting partial

Monitoring, Notification and Enforcement

UK-TSA-MON-01
Security Monitoring

Implement continuous security monitoring of networks and services. Detect anomalous activity, unauthorized access attempts, and potential compromises in near real-time.

Artefacts an auditor will ask for
  • Security monitoring policy with telemetry sources covering signalling, management, and bearer planes
  • Incident response runbooks with Ofcom notification triggers and timelines
  • SOC operating procedures and 24x7 staffing rosters
  • Post incident review reports and corrective action tracking
  • Threat intelligence ingestion records and indicator of compromise sweeps
Where this commonly fails
  • Notification timelines to Ofcom not tested through tabletop exercises
  • Monitoring coverage gaps in virtualised network functions
  • Incident classification thresholds inconsistent with Code of Practice severity tiers
  • Lessons learned not fed back into security duties evidence
UK-TSA-MON-02
Incident Notification

Notify Ofcom and affected users of security compromises. Tier 1 providers must report within 24 hours for significant incidents. Maintain incident response capabilities.

Artefacts an auditor will ask for
  • Security monitoring policy with telemetry sources covering signalling, management, and bearer planes
  • Incident response runbooks with Ofcom notification triggers and timelines
  • SOC operating procedures and 24x7 staffing rosters
  • Post incident review reports and corrective action tracking
  • Threat intelligence ingestion records and indicator of compromise sweeps
Where this commonly fails
  • Notification timelines to Ofcom not tested through tabletop exercises
  • Monitoring coverage gaps in virtualised network functions
  • Incident classification thresholds inconsistent with Code of Practice severity tiers
  • Lessons learned not fed back into security duties evidence
UK-TSA-MON-03
Ofcom Enforcement

Ofcom monitors and enforces compliance. May issue assessment notices, contravention notices, and fines up to 10% of turnover or GBP 100,000 per day for continued contravention.

Artefacts an auditor will ask for
  • Security monitoring policy with telemetry sources covering signalling, management, and bearer planes
  • Incident response runbooks with Ofcom notification triggers and timelines
  • SOC operating procedures and 24x7 staffing rosters
  • Post incident review reports and corrective action tracking
  • Threat intelligence ingestion records and indicator of compromise sweeps
Where this commonly fails
  • Notification timelines to Ofcom not tested through tabletop exercises
  • Monitoring coverage gaps in virtualised network functions
  • Incident classification thresholds inconsistent with Code of Practice severity tiers
  • Lessons learned not fed back into security duties evidence

Network Security Duties

UK-TSA-NET-01
Security Architecture

Implement secure network architecture with defined security zones, controlled access between zones, and protection of management plane traffic from user and control plane traffic.

Artefacts an auditor will ask for
  • Network architecture diagrams showing security critical functions and exposure zones
  • Network segmentation policy aligned to Code of Practice Tier 1 requirements
  • Privileged access management records covering network oversight functions
  • Cryptographic key management procedures and inventory of TLS and IPsec deployments
  • Configuration baselines and hardening standards for network equipment
  • Firmware integrity verification logs and trusted update process records
Where this commonly fails
  • Management plane not isolated from signalling and bearer planes
  • Legacy SNMP v1 and v2 still active on production network elements
  • Privileged access reviews not performed at the cadence required by Tier 1
  • Cryptographic algorithm inventory incomplete or stale
UK-TSA-NET-02
Access Control and Authentication

Implement strong authentication for network access. Privileged access management for network functions. Multi-factor authentication for remote access and critical operations.

Artefacts an auditor will ask for
  • Network architecture diagrams showing security critical functions and exposure zones
  • Network segmentation policy aligned to Code of Practice Tier 1 requirements
  • Privileged access management records covering network oversight functions
  • Cryptographic key management procedures and inventory of TLS and IPsec deployments
  • Configuration baselines and hardening standards for network equipment
  • Firmware integrity verification logs and trusted update process records
Where this commonly fails
  • Management plane not isolated from signalling and bearer planes
  • Legacy SNMP v1 and v2 still active on production network elements
  • Privileged access reviews not performed at the cadence required by Tier 1
  • Cryptographic algorithm inventory incomplete or stale
UK-TSA-NET-03
Supply Chain Security

Assess and manage risks from equipment vendors and managed service providers. High-risk vendor restrictions apply. Must have contingency plans for vendor supply chain disruption.

Artefacts an auditor will ask for
  • Supply chain risk register covering TSA designated vendors and high risk vendor restrictions
  • Vendor security assurance reports and ISO 27001 or equivalent attestations
  • Contractual security schedules with right to audit and Ofcom information sharing clauses
  • Vendor diversification analysis and concentration risk reports per Tier 1 obligations
  • Equipment removal plans for designated vendors with timetables submitted to DSIT
Where this commonly fails
  • Sub tier suppliers not mapped beyond Tier 1 vendors
  • No documented timetable for designated vendor equipment removal
  • Vendor security testing relies on self attestation without independent validation
  • Concentration risk in core network functions not quantified

Reporting

UKTSA-4
Incident Reporting and Ofcom Cooperation

Per TSA: incident reporting to Ofcom + cooperation + enforcement.

Artefacts an auditor will ask for
  • TSA evidence for UKTSA-4
Where this commonly fails
  • tier + HRV + reporting partial

Security Duties

UKTSA-1
Security Duties (Sections 105A-D)

Per UK Telecommunications (Security) Act 2021 Sections 105A-D: General Duty to Identify and Reduce Security Risks + Duty to Prepare for the Occurrence of Compromises + Duty to Reduce Adverse Effects of Compromises + Tier Classification.

Artefacts an auditor will ask for
  • TSA evidence for UKTSA-1
Where this commonly fails
  • tier + HRV + reporting partial

Supply Chain

UKTSA-3
Supply Chain and Equipment Security

Per TSA: supply chain risk + equipment security + designated vendors (high-risk vendor) restrictions.

Artefacts an auditor will ask for
  • TSA evidence for UKTSA-3
Where this commonly fails
  • tier + HRV + reporting partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the UK Telecommunications (Security) Act 2021 framework page.