The Signal · A-08 · Series A

The Telecoms Security Act's Tier 2 Deadline Is a Test the Sector Is Failing Quietly

24 August 2026·5 min read

The Telecommunications (Security) Act and its associated Electronic Communications (Security Measures) Regulations imposed one of the most prescriptive security regimes in UK critical national infrastructure. The framework sets out detailed, specific security requirements for public telecoms providers, backed by the Telecoms Security Code of Practice, and it is enforced by Ofcom with substantial penalty powers. The regime is tiered by provider size, with the largest Tier 1 providers facing the earliest and most demanding compliance timelines and the mid-sized Tier 2 providers following on a later schedule.

The Tier 1 deadlines drew most of the attention, because they applied to the largest and most visible providers and arrived first. The Tier 2 deadlines have drawn far less, and that is where the more instructive story now sits. A significant part of the Tier 2 population is approaching, or has reached, its compliance obligations without the security maturity the regime assumes, and the sector is failing this test quietly, in a way that the regulatory framework is structured to eventually make loud.

What the Regime Actually Demands

The Telecoms Security regime is unusual in UK CNI regulation for its specificity. Where most security regulation sets out principles and outcomes and leaves the implementation to the regulated entity, the Telecoms Security Code of Practice sets out detailed, prescriptive measures: specific controls, specific architectural requirements, specific operational practices. The regime tells providers, in considerable detail, what they must actually do.

This specificity is deliberate. The framework was designed in response to concerns about the security of telecoms networks that the previous, more principles-based approach had failed to address. The prescriptive measures exist because the sector, left to interpret security principles for itself, had produced security postures the government judged inadequate. The Code of Practice removes the interpretive latitude and replaces it with specific requirements, on the reasoning that the sector needed to be told precisely what to do rather than asked to work it out.

For providers with mature security capabilities, the prescriptive regime is demanding but achievable. They have the architecture, the operational practices, and the security expertise to implement the specific measures, and the regime largely formalises and extends what they were already doing. For providers without mature security capabilities, the prescriptive regime is a different proposition. It requires them to implement specific, detailed security measures that assume an underlying maturity they do not possess, and implementing the measures without the maturity produces compliance that is formal rather than real.

The Tier 2 Problem

The Tier 2 population, broadly the mid-sized providers below the largest national operators, includes organisations with widely varying security maturity, and the variation is the source of the problem. Some Tier 2 providers have invested in genuine security capability and approach the regime from a position of strength. Others have grown rapidly, operate on thin margins, and have historically invested in security to the minimum the market required, which was, before this regime, not very much.

The quiet failure occurs because the path of least resistance for an under-mature provider facing a prescriptive regime is to implement the measures formally without building the underlying capability. The Code of Practice specifies what must be done; a provider can do those things, document that it has done them, and present a compliant posture, without the measures being supported by the operational maturity that would make them genuinely effective. The controls are implemented but not genuinely operated. The architecture is changed but not genuinely secured. The practices are adopted on paper but not embedded in the organisation's actual operation.

This is the documentary-maturity problem in a specific regulatory setting, sharpened by the regime's prescriptiveness. Because the Code of Practice is so specific, a provider can demonstrate compliance with each measure individually while the measures, implemented without underlying maturity, do not add up to the security posture the regime intends. The specificity that was designed to prevent inadequate security can, for an under-mature provider, become a checklist that produces the appearance of security without the substance.

Why Ofcom Enforcement Changes the Picture

The reason the quiet failure will eventually become loud is the nature of Ofcom's enforcement role and powers. Ofcom is resourced and empowered to assess actual telecoms security, not merely documentary compliance. Unlike enforcement frameworks that assess documentation, Ofcom's role is built to assess the actual security posture of the networks it regulates, and its penalty powers are substantial. When Ofcom's enforcement scrutiny reaches the Tier 2 population, it will be able to distinguish providers with genuine security maturity from providers with documentary compliance, in the same way that the Cyber Bill's enforcement will distinguish them across the broader CNI population.

The quietness of the current failure is a function of timing. The Tier 2 obligations are recent enough, and Ofcom's enforcement attention is distributed enough, that the gap between formal and real compliance has not yet been systematically exposed. This is a window, not a reprieve. The enforcement scrutiny is coming, the regulator is equipped to apply it, and the providers relying on formal compliance are relying on the scrutiny not arriving rather than on their compliance withstanding it.

The Strategic Reading

For Tier 2 providers, the strategic choice is whether to use the current window to build genuine security capability or to continue relying on formal compliance until enforcement forces the issue. Building genuine capability now, deliberately, is less expensive and less disruptive than building it later, reactively, under enforcement scrutiny after a finding has established the inadequacy of the current posture. The providers that understand the enforcement trajectory are doing so. The providers that are treating the recent passing of their compliance deadline as the end of the work are positioning themselves for the more expensive path.

For CNI operators and customers that depend on Tier 2 providers, the situation is intelligence about supply chain risk. A CNI operator whose telecoms supply chain includes under-mature Tier 2 providers has a security exposure in that supply chain, regardless of the providers' formal compliance, and the NIS2-style supply chain security obligations increasingly require operators to understand and manage exactly this kind of exposure. The Telecoms Security regime's tiered structure, and the variable maturity within the Tier 2 population, is therefore not only a telecoms-sector compliance matter. It is a supply chain security consideration for everyone who depends on telecoms infrastructure, which, in a digitally dependent economy, is effectively every CNI operator.

The Telecoms Security Act's Tier 2 deadline is a test of whether the regime's prescriptive approach actually produces security in providers that lacked it, or merely produces documentation of security in providers that still lack it. For a significant part of the Tier 2 population, the current answer is the latter, and the sector is failing the test quietly because the enforcement that would make the failure loud has not yet arrived. It will. The providers and the operators that depend on them would be wise to read the quiet as a warning rather than an absence of one.