Call for evidence on the impact and effectiveness of Sections 1 to 13 of the Telecommunications (Security) Act 2021
Published 17 August 2026
1. Introduction
The UK Telecoms Supply Chain Review 2019 identified the need to establish an enhanced legislative framework for telecoms security, which was introduced through the Telecommunications (Security) Act 2021.
The Telecommunications (Security) Act 2021 (the ‘2021 Act’) amended the Communications Act 2003 (the ‘2003 Act’) to establish a new telecoms security framework to improve the security and resilience of public telecoms networks and services.
The 2003 Act, as amended, includes:
- Overarching security duties on public telecoms providers to identify and reduce the risk of security compromises occurring, prepare for the occurrence of security compromises, prevent adverse effects arising from a security compromise that has occurred, and to remedy or mitigate such adverse effects.
- Powers for the Secretary of State to make regulations setting out specific security measures to be taken by public telecoms providers.
- Powers for the Secretary of State to issue codes of practice giving guidance on the measures to be taken by public telecoms providers to meet their legal obligations.
- Provisions to ensure the telecoms regulator, Ofcom, can effectively monitor and enforce public telecoms providers’ compliance with their legal obligations under the 2003 Act (as amended).
The Electronic Communications (Security Measures) Regulations 2022 (the ‘Regulations’) and the Telecommunications Security Code of Practice (the ‘Code of Practice’) were established using these powers.
They are intended to address risks to the security of the UK’s public telecoms networks and services. They have been developed in conjunction with the National Cyber Security Centre (‘NCSC’), the UK’s national technical authority for cyber security, and Ofcom, the telecoms regulator.
The Regulations came into force on 1 October 2022. They set out specific security measures that public telecoms providers must take in addition to the overarching legal duties in sections 105A and 105C of the 2003 Act (as amended by the 2021 Act).
The Code of Practice was issued in December 2022. It provides detailed guidance to large and medium-sized public telecoms providers (i.e. those with a relevant turnover in the relevant period of more than or equal to £50 million) on the government’s preferred approach to demonstrating compliance with the duties in the 2003 Act and the requirements within the Regulations.
In July 2026, the Revised Telecommunications Security Code of Practice 2026 (version 1.1) was published. This document provides up to date guidance addressing risks posed by evolving security threats and new innovations in telecoms technology.
2. Purpose of this call for evidence
Under section 14 of the 2021 Act, the Secretary of State must “carry out reviews of the impact and effectiveness of sections 1–13” and, following each review, “publish a report and lay a copy before Parliament.”
This call for evidence forms a key part of the evidence-gathering process to inform that report. The government will also engage with the NCSC and Ofcom to assess the impact and effectiveness of the 2021 Act to date.
The call for evidence seeks views from all stakeholders who have engaged with the 2021 Act, the Regulations, and the Code of Practice (collectively, the ‘framework’). Responses to the questions, submitted via the online survey, will support the government’s assessment of how effectively the 2021 Act is operating in line with its intended policy objectives.
Its purpose is to gather evidence on the operation and effectiveness of the existing framework.
Further details on the call for evidence, and how to respond, are set out in the following sections.
3. Call for evidence details
This call for evidence will be open from Monday 17 August to Monday 12 October 2026. We encourage participants to provide feedback in line with the questions proposed, where possible.
Enquiries to:
Email: telecoms.security.consultation@dsit.gov.uk
Network Security Policy Team
Department for Digital, Culture, Media and Sport (DCMS)
2nd Floor
22 Whitehall
London
SW1A 2EG
Audiences:
This is a public call for evidence, but we are particularly seeking views from companies which provide public electronic communications networks and services.
Territorial extent:
The geographic scope of this call for information is the UK.
4. How to respond
You can complete the questions in the call for evidence via this online survey. This will support our assessment of your responses. This call for evidence will run until 11:59pm on Monday 12 October 2026.
The purpose of the call for evidence is to gather views on the impact and effectiveness of the 2021 Act. When responding to the survey, please do not consider activities that would have taken place as part of business-as-usual security improvements, pre-existing regulatory obligations, or wider commercial decisions.
If you would like to send additional evidence by email, Word format is preferred. This will support our assessment of your responses.
In exceptional circumstances, if you need to submit a hard copy or require another format (e.g. braille or large font) please contact: telecoms.security.consultation@dsit.gov.uk
5. Confidentiality and data protection
Information you provide in response to this call for information, including personal information, may be disclosed in accordance with UK legislation (the Freedom of Information Act 2000, the Data Protection Act 2018 and the Environmental Information Regulations 2004).
If you want the information that you provide to be treated as confidential, please tell us, but be aware that we cannot guarantee confidentiality in all circumstances. An automatic confidentiality disclaimer generated by your IT system will not be regarded by us as a confidentiality request.
We will process your personal data in accordance with all applicable data protection laws. See our privacy policy.
The information you provide may be shared between UK government departments, Ofcom and agencies for this purpose. Personal information will be removed in such instances. Copies of responses, in full or in summary, may be published after the call for evidence closing date on the department’s website.
6. The objectives of the Telecommunications (Security) Act 2021
The policy objectives for the 2021 Act are set out in the Impact Assessment for the primary legislation. The Regulations and Code of Practice, made under powers in the Act, provide further detail on how these overarching aims are delivered in practice.
In this call for evidence, we have focused on the objectives set out in the 2021 Act, however we also welcome evidence relating to the Regulations, and the Code of Practice.
These objectives are set out as follows:
- To have higher standards and practices of cyber security across the telecoms sector through a new, robust security framework.
- To ensure providers of Public Electronic Communications Networks (PECNs) or Public Electronic Communications Services (PECSs) take appropriate and proportionate measures to prevent, remove, or manage the risks posed to the security of networks and services, specifically to ensure:
- that networks and services are accessible and available to customers;
- the confidentiality of communications and data;
- the integrity and authenticity of networks, systems, communications, and sent, received or stored data; and
- the protection of networks and services from unauthorised access or interference.
- To create practical controls to make it hard for an attacker to compromise a UK network, and make it likely that any such compromise will be noticed quickly and the harm and impact limited, and make remediation as simple as possible.
- To provide a new duty for Ofcom to promote the security and resilience of PECN/PECS, and to enhance its existing powers in this area.
- To provide a delegated power to make secondary legislation and accompanying Codes of Practice, which set out specific security requirements and guidance on how relevant PECN/PECS might meet the security duties placed upon them.
Next steps and outcomes
This call for evidence will be live for 8 weeks, from Monday 17 August to Monday 12 October 2026.
Following the closure of the call of evidence, the responses will be analysed by the government and form part of the evidence base used by the Secretary of State to review the impact and effectiveness of sections 1-13 of the 2021 Act.
A report of the review’s findings will be published and laid before Parliament.