UK Telecommunications (Security) Act 2021
The UK Telecommunications (Security) Act 2021 amends the Communications Act 2003 to strengthen the security of the UK's telecommunications networks and services. It gives the Secretary of State power to issue security codes of practice and Ofcom powers to enforce compliance. The associated Electronic Communications (Security Measures) Regulations 2022 specify detailed security requirements. Applies to all public telecoms providers in the UK.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (24)
Authentication
| Code | Title |
|---|---|
| TSA-2.4 | Multi Factor Authentication for Sensitive Functions |
Codes of Practice
Ofcom codes of practice and technical guidance measures
| Code | Title |
|---|---|
| UKTSA-COP-01 | Electronic Communications Security Measures |
| UKTSA-COP-02 | Tiered Security Requirements |
| UKTSA-COP-03 | Security Competency Requirements |
Containment
| Code | Title |
|---|---|
| TSA-1.3 | Duty to Reduce Adverse Effects of Compromises |
Customer Communication
| Code | Title |
|---|---|
| TSA-3.4 | Customer Information After Compromises |
Enforcement and Penalties
CRTC enforcement, private right of action, and penalties
| Code | Title |
|---|---|
| BSA-ENF-1 | Anti-Structuring Prohibition |
| BSA-ENF-2 | Civil Money Penalties |
| BSA-ENF-3 | Criminal Penalties |
| CASL-ENF-01 | Administrative Monetary Penalties |
| CASL-ENF-02 | Compliance and Due Diligence |
| CASL-ENF-03 | Address Harvesting |
| ENF-1 | EPA Inspection Authority |
| ENF-2 | Civil Penalties |
| ENF-3 | Enforcement Actions |
| ENF-4 | Technical Assistance |
| RA10175-S10 | Law Enforcement Authority |
| RA10175-S21 | Jurisdiction |
| RA10175-S8 | Penalties |
| RIDTPPA-10 | Controller and Processor Contracts |
| RIDTPPA-11 | Data Minimisation and Purpose Limitation |
| RIDTPPA-9 | AG Enforcement |
| UKTSA-ENF-01 | Ofcom Information Powers |
| UKTSA-ENF-02 | Ofcom Inspection Powers |
| UKTSA-ENF-03 | Enforcement Notices |
| UKTSA-ENF-04 | Financial Penalties |
| UKTSA-ENF-05 | Security Breach Notification |
| ZMDPA-ENF-01 | Data Protection Commissioner Powers |
| ZMDPA-ENF-02 | Penalties for Non-Compliance |
| s.11 | Consent, Justification and Objection |
| s.5 | Notice to Data Principal |
| s.7 | Certain Legitimate Uses |
| s.8 | Accountability |
Governance
| Code | Title |
|---|---|
| TSA-3.3 | Annual Security Report and Board Sign Off |
| TSA-3.7 | Penalty Provisioning and Compliance Programme |
Incident Preparedness
| Code | Title |
|---|---|
| TSA-1.2 | Duty to Prepare for the Occurrence of Compromises |
Logging and Monitoring
| Code | Title |
|---|---|
| TSA-2.5 | Network Function Logging and Monitoring |
Monitoring and Compliance
Security monitoring, incident response, and Ofcom oversight
| Code | Title |
|---|---|
| UK-TSA-MON-01 | Security Monitoring |
| UK-TSA-MON-02 | Incident Notification |
| UK-TSA-MON-03 | Ofcom Enforcement |
Network Architecture
| Code | Title |
|---|---|
| TSA-2.2 | Network Architecture Hierarchy and Security Layers |
Network Security
Security requirements for telecoms networks and services
| Code | Title |
|---|---|
| ISM-0520 | Unauthorised Device Prevention |
| ISM-1028 | NIDS/NIPS Deployment |
| ISM-1181 | Network Segmentation |
| ISM-1182 | Wireless network security |
| ISM-1311 | SNMP v1/v2 Prohibition |
| ISM-1627 | Anonymity Network Inbound Blocking |
| ISM-1628 | Anonymity Network Outbound Blocking |
| ISM-1781 | Data Encryption in Transit |
| ISM-1782 | Protective DNS |
| ISM-1800 | Trusted Firmware |
| UK-TSA-NET-01 | Security Architecture |
| UK-TSA-NET-02 | Access Control and Authentication |
| UK-TSA-NET-03 | Supply Chain Security |
Operations
| Code | Title |
|---|---|
| TSA-3.1 | Network Oversight Function Operating Continuously |
Privileged Access
| Code | Title |
|---|---|
| TSA-2.3 | Privileged Access Workstation Use |
Regulatory Engagement
| Code | Title |
|---|---|
| TSA-3.6 | Ofcom Inspection and Information Notice Response |
Reporting
| Code | Title |
|---|---|
| TSA-3.2 | Incident Notification to Ofcom |
Resilience
| Code | Title |
|---|---|
| TSA-3.5 | Resilience and Redundancy of Sensitive Functions |
Scope
| Code | Title |
|---|---|
| TSA-2.1 | Tier Classification and Code of Practice Application |
Security Duties
Primary security duties for providers of public electronic communications networks and services
| Code | Title |
|---|---|
| UKTSA-SD-01 | General Security Duty |
| UKTSA-SD-02 | Network Architecture Security |
| UKTSA-SD-03 | Monitoring and Analysis |
| UKTSA-SD-04 | Security Incident Response |
| UKTSA-SD-05 | Governance and Accountability |
Security Governance
| Code | Title |
|---|---|
| TSA-1.1 | General Duty to Identify and Reduce Security Risks |
Security Testing
| Code | Title |
|---|---|
| TSA-2.9 | Testing of Security Measures |
Software Integrity
| Code | Title |
|---|---|
| TSA-2.8 | Software and Configuration Integrity |
Supply Chain Security
| Code | Title |
|---|---|
| AEO-SC-1 | Cargo Security |
| AEO-SC-2 | Conveyance Security |
| AEO-SC-3 | Premises Security |
| AEO-SC-4 | Trading Partner Security |
| CTPAT-SCS-01 | Physical Security |
| CTPAT-SCS-02 | Personnel Security |
| CTPAT-SCS-03 | Conveyance and Cargo Security |
| EU-CHIPS-SUP-01 | Supply Chain Monitoring |
| EU-CHIPS-SUP-02 | Crisis Assessment and Response |
| EU-CHIPS-SUP-03 | International Partnerships |
| EU-CRMA-SUP-01 | Strategic Benchmarks |
| EU-CRMA-SUP-02 | Strategic Projects Recognition |
| EU-CRMA-SUP-03 | Supply Chain Monitoring |
| NIS2-IA-7 | Supply Chain Security Policy |
| NIS2-IA-8 | Supplier Security Assessment |
| NRF-4 | Supply Chain Risk Identification |
| NRF-5 | Third-Party Partner Standards |
| NRF-6 | Vendor Risk Management |
| TSA-2.7 | Supplier Risk Management and High Risk Vendors |
| UKTSA-SC-01 | Supply Chain Risk Assessment |
| UKTSA-SC-02 | High-Risk Vendor Restrictions |
| UKTSA-SC-03 | Vendor Diversification |
| UKTSA-SC-04 | Third-Party Access Controls |
| WCO-SAFE-SCS-01 | Advance Electronic Information |
| WCO-SAFE-SCS-02 | Risk Management |
| WCO-SAFE-SCS-03 | Non-Intrusive Inspection |
Supply Chain Security
Customs security and risk management
| Code | Title |
|---|---|
| AEO-SC-1 | Cargo Security |
| AEO-SC-2 | Conveyance Security |
| AEO-SC-3 | Premises Security |
| AEO-SC-4 | Trading Partner Security |
| CTPAT-SCS-01 | Physical Security |
| CTPAT-SCS-02 | Personnel Security |
| CTPAT-SCS-03 | Conveyance and Cargo Security |
| EU-CHIPS-SUP-01 | Supply Chain Monitoring |
| EU-CHIPS-SUP-02 | Crisis Assessment and Response |
| EU-CHIPS-SUP-03 | International Partnerships |
| EU-CRMA-SUP-01 | Strategic Benchmarks |
| EU-CRMA-SUP-02 | Strategic Projects Recognition |
| EU-CRMA-SUP-03 | Supply Chain Monitoring |
| NIS2-IA-7 | Supply Chain Security Policy |
| NIS2-IA-8 | Supplier Security Assessment |
| NRF-4 | Supply Chain Risk Identification |
| NRF-5 | Third-Party Partner Standards |
| NRF-6 | Vendor Risk Management |
| TSA-2.7 | Supplier Risk Management and High Risk Vendors |
| UKTSA-SC-01 | Supply Chain Risk Assessment |
| UKTSA-SC-02 | High-Risk Vendor Restrictions |
| UKTSA-SC-03 | Vendor Diversification |
| UKTSA-SC-04 | Third-Party Access Controls |
| WCO-SAFE-SCS-01 | Advance Electronic Information |
| WCO-SAFE-SCS-02 | Risk Management |
| WCO-SAFE-SCS-03 | Non-Intrusive Inspection |
Vulnerability Management
| Code | Title |
|---|---|
| TSA-2.6 | Vulnerability Management Across Network Equipment |
Your Compliance Coverage
If you comply with UK Telecommunications (Security) Act 2021, you already cover:
TISAX - Trusted Information Security Assessment Exchange
26%
25 controls mapped
Compare →South Korea Cloud Security Assurance Program (CSAP)
25%
24 controls mapped
Compare →PAS 1192-5:2015 - Security-Minded Approach to BIM and Digital Built Environments
25%
24 controls mapped
Compare →+ 652 more: Canada ITSG-33 - IT Security Risk Management (25%), New Zealand Information Security Manual (NZISM) (25%)
See all 655 mapped frameworks ↓Maps to 655 other frameworks
Frequently Asked Questions
What is UK Telecommunications (Security) Act 2021?
UK Telecommunications (Security) Act 2021 is a compliance framework from United Kingdom with 24 domains and 95 controls. The UK Telecommunications (Security) Act 2021 amends the Communications Act 2003 to strengthen the security of the UK's telecommunications networks and services. It gives the Secretary of State power to issue security codes of practice and Ofcom powers to enforce compliance. The associated Electronic Communications (Security Measures) Regulations 2022 specify detailed security requirements. Applies to all public telecoms providers in the UK. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does UK Telecommunications (Security) Act 2021 have?
UK Telecommunications (Security) Act 2021 has 95 controls organised across 24 domains. The largest domains are Enforcement and Penalties (27 controls), Supply Chain Security (25 controls), Network Security (13 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does UK Telecommunications (Security) Act 2021 map to?
UK Telecommunications (Security) Act 2021 maps to 655 other compliance frameworks. The top mapping partners are TISAX - Trusted Information Security Assessment Exchange (26% coverage), South Korea Cloud Security Assurance Program (CSAP) (25% coverage), PAS 1192-5:2015 - Security-Minded Approach to BIM and Digital Built Environments (25% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with UK Telecommunications (Security) Act 2021 compliance?
Start your UK Telecommunications (Security) Act 2021 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about UK Telecommunications (Security) Act 2021 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 95 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required