Revised Telecommunications Security Code of Practice: what has changed and what does it mean for providers?

Posted on: 19th August 2026, by Magrathea

What has happened?

The long-awaited revised Telecoms Security Requirements (TSR) Code of Practice is now published, almost 4 years after the original was introduced in December 2022, which is music to our collective ears!

A lot has changed since then. New technologies such as eSIMs are more widely used, Application Programming Interfaces (APIs) have been further identified as a potential weak area, network automation has increased, and the cyber threat landscape has continued to evolve. Following an eight-week consultation in late 2025, the Government published its response in June 2026, with the final revised Code, version 1.1, issued on 14 July 2026.

The Code provides detailed guidance for large and medium-sized companies, known as Tier 1 and Tier 2 providers. Tier 3 providers, such as Magrathea, are not expected to follow the individual measures within the Code, but must still take appropriate and proportionate measures to meet their duties under the Act and Regulations and may choose to adopt relevant elements of the Code as good practice.

As a supplier to Tier 1 and Tier 2 providers, and as part of our own approach to security and resilience, Magrathea also looks to the Code when considering appropriate and proportionate security measures.

The revised Code has four main aims:

  • Reflect evolving technology: including the increased use of eSIMs, automation and APIs.
  • Respond to emerging security threats: including the growing sophistication of cyber-attacks against telecommunications infrastructure.
  • Provide greater clarity: particularly in areas where providers found the original Code ambiguous or insufficiently detailed, including security testing and privileged access.
  • Reinforce a holistic, risk-based approach: encouraging providers to consider technical, physical and personnel security together rather than treating individual controls in isolation.

The consultation received 30 responses. While there was broad support for the aims of the revision, providers also raised concerns around cost, implementation timescales and the technical practicality of some proposals.

What has changed?

The revised Code contains a wide range of amendments, but some of the most significant areas include:

  • Network automation: new guidance aligned with existing NCSC guidance, including secure principles for machine learning.
  • Signalling security: additional guidance recognising the continued targeting of signalling systems by cyber threat actors.
  • Privileged Access Workstations (PAWs): expanded guidance around devices used to access and make changes to security-critical parts of a network, bringing the Code more closely into alignment with European Telecommunications Standards Institute (ETSI) standards.
  • API security: new guidance reflecting the increasing reliance on APIs and the security risks associated with their compromise. Providers are expected to ensure APIs are securely implemented and appropriately documented.
  • Patching, updates and security testing: additional guidance intended to reduce the threat posed by non-persistent malware, with greater emphasis on appropriate, risk-based testing and identifying vulnerabilities, missing patches and configuration changes.

The underlying principle is that providers are expected to take a risk-based approach to security and resilience, planning on the assumption that their worst credible scenario could happen and putting appropriate measures in place to reduce both the likelihood and impact.

What are the implications?

Implementing additional security controls inevitably has a cost.

Indicative estimates from Tier 1 and Tier 2 providers suggest potential one-off implementation costs could be approximately £1.9 million to £3.2 million per provider, with ongoing annual costs of approximately £285,000 to £445,000.

These figures are indicative and will vary significantly according to factors such as provider size, network architecture and existing security maturity.

The Government’s assessment is that, in the context of the scale and revenues of the UK telecommunications sector and the potential consequences of a major security incident, the overall financial impact is relatively low.

Consultation feedback did, however, result in some implementation periods being extended.

For example, some of the new measures relating to supporting business processes and the NCSC Cyber Assessment Framework now have an implementation date of 31 March 2028, while other new measures have later implementation dates.

For Tier 3 providers, the position is different. The detailed measures and implementation dates within the Code do not apply directly. However, Tier 3 providers still need to be able to demonstrate that they have taken appropriate and proportionate steps to comply with their security obligations.

That makes the revised Code a useful reference point even where following its individual measures is not mandatory.

What does this mean for clients?

The threat environment today is very different from the one organisations faced when the original Code was published in 2022.

Security and resilience therefore need to extend beyond traditional network protection.

The revised Code highlights areas that may sometimes receive less attention, including APIs, eSIMs, automation, privileged access, physical security and the people with access to critical systems.

There are several practical lessons that apply to providers of all sizes.

Understand your entire environment. Security does not stop at the edge of the network. Consider systems, APIs, physical locations, employees, contractors and third parties that could introduce risk.

Understand your suppliers. The security of a service increasingly depends on the organisations and technology supporting it. Knowing who provides critical elements, how access is controlled and where responsibilities sit is an important part of managing supply-chain risk.

At Magrathea, our network and core switching services are developed and maintained by our in-house team. This helps give our clients greater visibility of their supply chain.

Think beyond cyber security. Technical controls such as firewalls, authentication and patching matter, but so do staff training, access management and the physical security of operational sites.

Plan for failure, not just prevention. Effective risk management means planning on the assumption that even your worst credible scenarios could happen, rather than relying solely on preventative controls. Consider what the impact would be, how you can reduce the risk and, crucially, how you would respond and recover if it did happen.

Above all, security and resilience should not be viewed as a collection of individual compliance measures. They work best when they form part of an organisation-wide approach to understanding, managing and continually reviewing risk.

What should you do next?

We recommend that clients review both the revised Telecommunications Security Code of Practice and Ofcom’s updated Network and Service Resilience Guidance.

Even where the detailed Code does not apply directly, providers should be able to demonstrate that security and resilience risks have been considered and that appropriate and proportionate measures are in place.

Industry frameworks, such as the NIC Resilience Framework, can also provide a useful way to assess current arrangements, identify gaps and prioritise improvements.

Our own security guidance provides further practical information, including the measures available from Magrathea to help protect your services. Please refer to the Guide or contact support@magrathea-telecom.co.uk if you would like a copy.

Further Reading