No Significant Impact On Other Businesses
Version 1.1 of the Telecommunications Security Code of Practice was issued on 14 July 2026. Its explanatory memorandum makes two statements that sit oddly together. The first, at paragraph 6.1, is "The law has not changed." The second, at paragraph 9.5, is that there is "no, or no significant, impact on other business, charities or voluntary bodies because the revised code only applies to Tier 1 and Tier 2 public telecoms providers." The first is straightforwardly true. The second is true of the Code and misleading about its consequence, and if your business supplies anything to a large telecoms operator, the difference is going to reach you through a contract.
What actually happened
The Telecommunications (Security) Act 2021 amended the Communications Act 2003 and created the duties. The Electronic Communications (Security Measures) Regulations 2022 set the requirements. The Code of Practice, first issued in 2022, is neither of those. It is the government's stated preferred approach to demonstrating compliance with them, and Ofcom alone determines whether a provider has complied.
That distinction is why paragraph 6.1 can say the law has not changed while the document still matters. The duty was always there. What moved is the standard against which a provider will be judged to have met it.
The revisions followed NCSC advice and an eight week consultation that closed in October 2025, with thirty responses. A separate cost survey ran to January 2026 and drew seven. Respondents broadly supported the intent and objected to the costs, the timelines and the technical feasibility of some proposals. The government moved on all three, and the new measures now phase in across March 2028, December 2028 and December 2029.
Five areas gained new guidance. Network automation, aligned to the NCSC's machine learning principles. Signalling, because the signalling plane continues to be targeted. Privileged access workstations, now aligned to an ETSI standard. Application programming interfaces, which the memorandum notes have been "linked to significant data losses". And patching and updates, aimed at non-persistent malware.
Why the deferral is not the story
The obvious read of a 2028 and 2029 timetable is that nothing needs doing until 2027. That reading survives about as long as it takes to think about procurement.
A Tier 1 operator buying network equipment, managed services or software today is buying something that must still satisfy this Code in March 2028. Nobody replaces core infrastructure on a twelve month cycle. So the requirements do not wait for the deadline: they enter the tender documents in the cycle before it, which is the one running now.
The deferral did not remove the pressure. It moved the pressure from a compliance department into a procurement department, which is a considerably worse place for a supplier to meet it for the first time.
Paragraph 9.5, and why it is the most consequential sentence in the document
The memorandum is clear that the Code binds only Tier 1 and Tier 2 providers, that it does not affect small or micro businesses, and that there is no significant impact on other organisations. As a statement about the legal reach of the instrument, every word of that is correct.
Now consider how each of the five revised areas is actually implemented.
Privileged access workstations are used by whoever holds privileged access. In a large telecoms operator that population is not confined to employees. It includes managed service providers, equipment vendors doing remote maintenance, and integrators with standing access from a project years ago. Aligning the operator to an ETSI standard means aligning everyone who touches the network to it.
API guidance governs interfaces, and an interface has two ends. The operator can only secure its own side. The rest arrives as a requirement on whoever is on the other end.
Patching and updates guidance is about how quickly known flaws are removed. An operator cannot patch what a vendor has not shipped, so the obligation converts almost immediately into supplier commitments on release timelines and notification.
None of that is a legal duty on the supplier. All of it becomes a contractual one. The organisations that will feel this first are companies with no tier, no Code, no Ofcom relationship and no seat at the consultation, receiving a clause they did not negotiate from a customer they cannot afford to lose.
The number worth writing down
DSIT's indicative estimate is £1.9m to £3.2m in one off implementation cost per provider, with ongoing annual costs of roughly £285,000 to £445,000. The memorandum describes these as minor when set against the scale and revenues of the sector, and against those revenues they are.
Read it from the other direction. That money is not spent inside the operator. It is spent on equipment, on integration work, on managed services and on assurance, which means it is spent with suppliers. A cost the memorandum calls minor for a handful of large providers is, for the firms serving them, a defined multi-year programme of demand arriving in tender documents.
That is the commercial case for getting in front of it rather than waiting to be asked.
What leaders should do now
- Establish whether a large telecoms provider is in your customer base, and say so out loud. Many firms supply one without regarding themselves as a telecoms supplier: software, integration, professional services, facilities, hardware. If one of your customers is above £50m of relevant turnover in public telecoms, this reaches you.
- Find out who holds privileged access into a customer network, and on what device. If your engineers connect to an operator's environment, the ETSI aligned workstation standard is coming to you through their contract. Knowing whether your current build would pass is a week of work now and a lost renewal later.
- Get your patch and disclosure commitments written down before you are asked for them. Time from awareness to fix, time from fix to customer notification, and how you handle a flaw you cannot fix quickly. Operators will ask. The ones who answer from a document win.
- Read the five revised areas against your own product. Automation, signalling, privileged access, APIs and patching. Most suppliers touch two or three. The exercise takes an afternoon and tells you which tender questions are coming.
- Treat the 2028 date as a procurement date, not a compliance date. Whatever is bought in 2027 must satisfy it. Whoever cannot demonstrate it in 2027 is not on the list.
Three questions for the board
- Do we supply, directly or through a partner, any public telecoms provider large enough to be Tier 1 or Tier 2, and does anyone here know that for certain?
- Does anyone in this business hold privileged access into a customer's network, and would the device they use meet a standard our customer is about to be judged against?
- If an operator sent us their revised security schedule next month, would we be negotiating it or reading it for the first time?
The strategic takeaway
Regulation aimed at a small number of large organisations does not stay with them. It is implemented through their supply chains, because that is where most of the attack surface and most of the work actually sits. The Cyber Resilience Act is doing it in software, DORA is doing it in financial services, and the revised Code is doing it in telecoms.
The memorandum is not wrong that this instrument does not bind other businesses. It simply describes the document rather than the market. The firms that read it as an all clear will meet it anyway, eighteen months from now, in a tender they do not win.
Confidence note
Confirmed. That the Telecommunications (Security) Act 2021 amended the Communications Act 2003, that the Electronic Communications (Security Measures) Regulations 2022 set the requirements, and that the Code of Practice is guidance on the government's preferred approach to demonstrating compliance rather than law. That version 1.1 of the revised Code was issued on 14 July 2026 following NCSC advice and an eight week public consultation held between 28 August and 22 October 2025, which drew thirty responses, plus a cost survey that drew seven. That the memorandum states at paragraph 6.1 that the law has not changed, and at paragraph 9.5 that there is no significant impact on other businesses because the Code applies only to Tier 1 and Tier 2 providers. That Tier 1 means relevant turnover of £1bn or more and Tier 2 means £50m or more but less than £1bn. That new guidance covers network automation, signalling, privileged access workstations aligned to ETSI, application programming interfaces, and patching and updates. That indicative costs are £1.9m to £3.2m one off per provider and £285,000 to £445,000 annually, described in the memorandum as minor relative to sector revenues. That Ofcom alone determines compliance. All of the above is from the explanatory memorandum published on GOV.UK and updated 14 July 2026.
Assessed. That the new measures phase in across March 2028, December 2028 and December 2029 is drawn from secondary reporting of the government's consultation response rather than read directly in the response itself, so treat the specific dates as reported rather than verified. That requirements will reach suppliers through contracts ahead of those dates is our assessment, based on the observed pattern under the Cyber Resilience Act and DORA. The memorandum makes no statement about supply chain effects in either direction, and none of the operators has published a revised supplier schedule that we have seen.
Not known. How many providers sit in each tier. Whether any operator has yet issued revised supplier terms referencing version 1.1. What Ofcom's enforcement posture will be during the transition, given the memorandum records that the 2022 Code remains the current benchmark. Whether the cost estimates, which DSIT itself calls indicative, will prove close.
If an operator sent you their revised security schedule next month, would you be negotiating it or reading it?
Garzon Cyber Solutions is built to put questions like this on the risk register with an owner, map the controls to what regulators, customers and insurers actually ask for, and place the people who keep the answer current. Cybersecurity, compliance and talent, delivered in that order, as one capability.
Start the Conversation →DSIT, "Explanatory memorandum to the revised Telecommunications Security Code of Practice 2026", updated 14 July 2026 · DSIT, "Revised Telecommunications Security Code of Practice 2026 (version 1.1)" · DSIT, "Proposals to update the Telecommunications Security Code of Practice 2022: government response" · NCSC, Machine learning principles · Osborne Clarke, UK Regulatory Outlook, telecoms, June 2026