Ofcom's Telecommunications Security Code of Practice 2026 (version 1.1), gov.uk formalises scheduled assessments and recurring Section 135 notices, so Tier 2 telecoms providers in the UK must be audit-ready on a predictable timetable. At CyPro, we see ofcom telecoms security enforcement moving from ad hoc checks to routine oversight, with clearer evidence expectations in Ofcom's reporting (Ofcom security report for the period October 2024 to October 2025, gov.uk) and the National Cyber Security Centre's operational notes (NCSC Annual Review 2025, ncsc.gov.uk).
- What changed: Ofcom now runs scheduled assessments and recurring Section 135 notices, increasing predictability for Tier 2 providers (Telecommunications Security Code of Practice 2026, gov.uk).
- Who this affects: Tier 2 telecoms providers in the UK must keep labelled incident logs and retrievable evidence for routine reviews and be ready to respond to formal notices (Ofcom security report, gov.uk).
- What to expect: Expect clearer evidence standards and closer operational liaison with the National Cyber Security Centre during assessments (NCSC Annual Review 2025, ncsc.gov.uk).
- Practical steps: Prepare playbooks, timestamped audit trails and a named contact for notices under ofcom telecoms security enforcement.
What is Ofcom's new supervision playbook and how does it change enforcement?
Ofcom's 2026 supervision playbook formalises routine, scheduled assessments and yearly Section 135 notices, moving enforcement from ad hoc checks to predictable oversight that expects Tier 2 providers to produce repeatable evidence and labelled incident reporting.
Expect scheduled evidence requests and annual Section 135 notices, clearer incident categories and a lower "critical" threshold; Tier 2 compliance leads must be audit-ready every year.
What specifically changed in the playbook?
The playbook renames incident categories to critical, major and moderate and lowers the critical threshold from 3 million user-hours to 1.5 million user-hours, making more incidents qualify as "critical" for reporting and escalation. The Telecommunications (Security) Act 2021 is still the legal basis, but Ofcom now sets clearer procedural expectations in the Telecommunications Security Code of Practice 2026.
Why this matters for Tier 2 providers
Tier 2 providers will face routine assessments rather than ad hoc checks, so evidence that used to be pulled for a single review must now be repeatable and readily retrievable. Ofcom's December 2025 reporting cycle also signals that supervision is now continuous rather than episodic, as shown in Ofcom's security reporting for October 2024 to October 2025 (Ofcom security report).
In our experience, this change shortens timelines for evidence requests and increases the frequency of consequence management conversations, so technical teams should prioritise playbooks, audit trails and labelled incident logs. The move also aligns with the National Cyber Security Centre's emphasis on operational readiness and repeatable controls in its 2025 review (NCSC Annual Review 2025), which increases enforcement pressure on providers that cannot demonstrate consistent controls.
Practical implication: expect an annual or near-annual Section 135 notice, planned audits and more incidents crossing the "critical" threshold under the new definitions. If you want a concise guide to how Ofcom uses its assessment powers and penalties, see our plain-English explainer on How Ofcom enforces the Telecoms Security Act, which maps the evidence types Ofcom typically requests.
How do Ofcom's routine assessments and yearly s135 notices work in practice?
At CyPro, we view a routine assessment as a formal information-gathering exercise, not an informal query: a Section 135 notice starts the process and requires a provider to supply the documents and answers specified in the notice within the deadline set by Ofcom.
Ofcom's process then moves through evidence submission, remote validation and, where needed, on-site inspection, followed by findings and a remediation window aligned to the Telecommunications Security Code of Practice. The Code sets expectations on monitoring, architecture, supply-chain controls and incident records, and Ofcom explains how assessments map to those sections in its public reporting (Telecommunications Security Code of Practice 2026).
What evidence does Ofcom commonly ask for?
Ofcom routinely requests mapped evidence such as network and service diagrams with versioning and owners, monitoring or Security Information and Event Management (SIEM) extracts showing detections, patch and change logs, supplier security attestations, and incident response timelines. Ofcom's December 2025 reporting on its supervisory work shows assessments focus on monitoring maturity and supply-chain controls, which is why those artefacts recur in notices (Ofcom security report for the period October 2024 to October 2025).
Practical steps for a fast, low-friction response
Keep evidence searchable and explainable: timestamped exports, change tickets with links, named owners on diagrams and supplier attestations that explicitly reference the component or contract in scope. Nominate a single accountable contact for regulatory notices, and keep a short notice pack template mapped to Code sections ready to hand. That approach reduces follow-up questions and the need for repeated clarifications during remote checks or site visits.
For teams that need immediate help, our Telecoms Security Act compliance page explains typical packs and timelines in detail, and our Ofcom enforcement primer covers how notices and penalty processes operate. See our TSA compliance support from CyPro (TSA compliance support from CyPro) and How Ofcom enforces the Telecoms Security Act (How Ofcom enforces the Telecoms Security Act).
Who within a Tier 2 provider needs to prepare for Ofcom's changes?
Direct answer: compliance leads, the Head of Security or CISO, the Director of IT, Data Protection Officers (DPOs) and network operations must coordinate preparation, with procurement and legal supporting supplier evidence and the board owning governance and escalation.
Roles and primary responsibilities
Compliance leads should own the runbook for Section 135 notices and routine assessments under ofcom telecoms security enforcement, gathering retained evidence, timestamps and supplier attestations. The Head of Security or CISO must translate the Telecommunications (Security) Act 2021 duties into technical controls, and the Director of IT should provide change logs, network diagrams and SIEM exports on request.
Network operations and the Network Operations Centre (NOC) should be ready to export monitoring data and show incident timelines, because Ofcom will expect operational proof rather than high-level claims. Data Protection Officers must verify any personal data in logs and ensure UK GDPR controls are documented when sharing evidence.
Where legal, procurement and the board come in
Legal and procurement must update supplier contracts and Service Level Agreements (SLA) to mandate security attestations and evidence retention, or risk blocking timely proof during assessments. The board needs to evidence oversight and a named accountable contact for notices, because ofcom telecoms security enforcement actions often begin with information requests that require executive sign-off.
Ofcom's approach is operational: expect requests mapped to the Telecommunications Security Code of Practice and follow-up questions. For examples of the evidence sets Ofcom typically requests, see our guide to Telecoms Security Act requirements.
Practical implication: assemble a cross-functional team now, document roles in a runbook, and practise a Section 135 response once a year to reduce friction during Ofcom routine assessments. Recent reporting shows Ofcom’s assessment activity and reporting have increased, so preparation matters.
Sources: Information Commissioner’s Office (ICO) and Ofcom.
How much does preparing for routine Ofcom assessments cost in the UK?
Expect one-off preparation costs from about £8,000 to £120,000 and ongoing annual overheads from about £3,000 to £60,000, depending on size and maturity. These figures cover gap analysis, evidence packaging, monitoring upgrades and a retained contact for notices under ofcom telecoms security enforcement.
Cost components
Gap analysis and evidence packaging typically cost £3,000 to £25,000 for a Tier 2 provider, because Ofcom expects timestamped artefacts, SIEM exports and supplier attestations. Monitoring and logging improvements, including SIEM tuning or additional log retention, usually cost £5,000 to £40,000. A modest retained compliance resource or vCISO costs £1,500 to £6,000 per month.
Pricing table: typical 2026 UK ranges
The table below shows pragmatic bands we see in the market for 2026, based on CyPro engagements and publicly reported enforcement activity.
| Organisation size / maturity | One-off preparation (2026, £) | Annual readiness overhead (2026, £) | Includes |
|---|---|---|---|
| Small Tier 2 (50 to 200 staff) | £8,000 to £25,000 | £3,000 to £12,000 | Gap analysis, evidence pack, basic monitoring |
| Mid-market Tier 2 (200 to 1,000 staff) | £25,000 to £60,000 | £12,000 to £30,000 | SIEM tuning, supplier attestations, retained adviser |
| Large Tier 2 / borderline Tier 1 (>1,000 staff) | £60,000 to £120,000+ | £30,000 to £60,000+ | Architecture changes, extended logging, tabletop exercises |
Evidence and assumptions
These ranges assume an existing baseline of enterprise logging and an ISMS mapped to the Telecommunications Security Code of Practice. Ofcom’s public reporting and the National Cyber Security Centre’s 2025 review show increased assessment activity and expectations for demonstrable logs and runbooks, which raise the cost of last-minute remediation (NCSC, 2025). Ofcom’s own materials and guidance also underline that retained, explainable evidence shortens assessment time and therefore reduces cost (NCSC speech, 2025).
At CyPro, we price for transparency: our engagements include a one-off readiness sprint and an annual retainer option. For practical help, see our Resources page for templates and example evidence artefacts.
How does Ofcom's routine supervision compare with previous Ofcom enforcement and other regulators?
Ofcom's routine supervision shifts from episodic investigations to scheduled, evidence-led assessments that expect continuous compliance records and proactive remediation. This change means Tier 2 teams must keep audit-ready logs, runbooks and supplier evidence at hand rather than preparing for occasional spot checks.
Ofcom's routine supervision requires continuous evidence and regular reporting, so Tier 2 teams should treat assessments as operational tasks not one-off compliance exercises.
Scope and cadence
Routine supervision is scheduled and recurring, while previous Ofcom enforcement focused on incident-driven probes and ad hoc spot checks. The Telecommunications (Security) Act 2021 gives Ofcom powers for ongoing assessments and information notices, so the regulator can request evidence on a timetable rather than only after incidents. For Tier 2 providers this means ongoing evidence collection is the default, not an exception.
How Ofcom compares with the ICO and NCSC
The Information Commissioner’s Office (ICO) under UK GDPR has historically used incident-driven investigations and fines for data breaches, emphasising personal data handling. The National Cyber Security Centre (NCSC) provides guidance and operational support but does not run routine statutory supervision. Ofcom's routine supervision therefore sits between the ICO's enforcement model and the NCSC's advisory role, combining statutory powers with technical expectations.
What this means for evidence and escalation
Ofcom's routine supervision expects demonstrable controls, logs and supplier assurance at short notice, so Tier 2 teams should map what Ofcom, the ICO and NCSC would each want to see. Mapping prevents duplicated work and reduces the risk of inconsistent responses when multiple regulators ask for overlapping evidence during the same security episode.
Practical steps include centralising runbooks, keeping six months of searchable logs, and documenting third-party attestations. In our experience, preparing this evidence reduces friction during inspections and lowers the chance that routine supervision turns into a formal enforcement action under the Telecoms (Security) Act.
For technical guidance and signposting on signalling-specific evidence requirements, see our Signalling security: SS7, Diameter and 5G duties service page. For regulator detail and the formal expectations behind routine supervision, read Ofcom's public reporting and the NCSC Annual Review 2025 for context and operational implications (Ofcom security report, NCSC Annual Review 2025).
When should a Tier 2 provider act and what should they prioritise now?
Act now: Tier 2 providers must start immediate evidence and monitoring work to meet Ofcom's routine supervision expectations and to reduce follow-up remediation. Prioritise incident categorisation, searchable logging, supplier assurance and a Section 135 mock within 30 days.
Immediate priorities
Start by updating incident categorisation to the new thresholds so internal reports match what Ofcom expects. Ofcom's supervisory model focuses on evidence that can be requested at short notice, so ensure your incident categorisation aligns with the Telecommunications Security Code of Practice and Ofcom guidance. Runbooks for at least the most likely incidents should be consolidated, and six months of searchable logs retained to answer information notices quickly.
Ofcom telecoms security enforcement increasingly targets process failings rather than single technical bugs, so prioritise documentation of monitoring coverage, alert thresholds and escalation paths. Centralising these artefacts reduces duplicated evidence requests from other bodies such as the Information Commissioner’s Office and the National Cyber Security Centre.
30-day checklist and tactical steps
In the first 30 days, update incident categories, map monitoring sources, run a Section 135 mock assessment and validate supplier attestations for critical services. The Section 135 mock helps practise the mechanics of evidence production under the Telecommunications (Security) Act 2021, and it reveals gaps in runbooks and log retention. Finish tactical remediation within 90 days and move to an annual maintenance cadence thereafter.
Why this matters now
Ofcom telecoms security enforcement now includes regular assessments and the ability to demand evidence without notice, so early action reduces rework and response delay when an assessor arrives. The National Cyber Security Centre's Annual Review highlights increased operational demand on providers to demonstrate continuous readiness, and Ofcom's public reporting shows routine supervision is becoming the norm for Tier 2 providers (NCSC Annual Review 2025) and (Ofcom security report for the period October 2024 to October 2025).
At CyPro, we recommend a 30/90/365 plan: the first 30 days to prove evidence readiness, 90 days to remediate gaps uncovered, then an annual cadence to keep artefacts current. For practical support, see our plain-English guide to the Telecoms Security Act and the Code of Practice, which lays out the exact evidence items assessors request (Telecommunications Security Act: The UK TSA Explained).
How to choose whether to handle Ofcom assessments in-house or hire a specialist?
Do it in-house when you already have compliant evidence, a named owner and ongoing monitoring; hire a specialist when you lack staff, searchable logs or repeatable Section 135 runs. Ofcom telecoms security enforcement expects prompt, structured evidence and realistic, repeatable responses.
Build versus buy, short answer
Build if you have an established security assurance function, clear responsibilities and tooling that stores six months of indexed logs. Buy if you do not have a mature evidence pipeline, experienced telecoms security practitioners, or the bandwidth to run mock Section 135 assessments on schedule. Ofcom telecoms security enforcement treats weak or ad hoc evidence as a trigger for deeper supervision.
Practical selection criteria
Choose providers who show telecoms-specific experience, published evidence templates and a clear plan for handing back capability. Look for: telecoms Code of Practice alignment, Section 135 mock runs, supplier assurance packs, and searchable logging playbooks. Assessors must reference the Telecommunications Security Code of Practice; the primary Code file is publicly available from the Department for Science, Innovation and Technology and Ofcom's publications UK Government, 2026.
Check also for cross-regulator readiness: the Information Commissioner’s Office and the National Cyber Security Centre increasingly coordinate where data or national security concerns overlap. The NCSC Annual Review describes the operational pressure on responders and why assessors should be able to map evidence to NCSC expectations NCSC, 2025.
At CyPro, we recommend a two-stage approach: a rapid gap analysis, then a priced remediation and handback plan. If you choose a specialist, require a clear transfer plan so your team owns the evidence after the engagement. If you build in-house, budget for tooling, one dedicated full-time equivalent and annual external mock Section 135 exercises.
Frequently asked questions
Will Ofcom issue Section 135 notices to every Tier 2 provider every year?
Ofcom's May 2026 guidance proposes that yearly Section 135 notices become routine for supervision, but that does not automatically mean every Tier 2 provider will get one annually. Ofcom is more likely to target providers with large user bases, previous findings or higher risk profiles. Maintain engagement records, treat the risk as real and be prepared to demonstrate controls quickly if contacted.
What does the new critical incident threshold of 1.5 million user-hours mean for reporting?
The consultation lowers the critical threshold from 3 million to 1.5 million user-hours, so more incidents will qualify as critical and face faster oversight. That change increases the likelihood of evidence requests, interim measures and escalation by Ofcom. Update incident playbooks to capture user-hours metrics and timestamped logs so you can classify and evidence incidents to Ofcom quickly.
How long do we have to respond to a Section 135 notice?
The guidance formalises shorter response windows, so expect tight deadlines for initial evidence, often 48 to 72 hours, with fuller submissions on a 30-day remediation schedule. Practical reality is that Ofcom will press for rapid answers. Nominate a single point of contact, pre-compile common evidence sets and run a rapid collation plan to meet those timelines reliably.
Do we need ISO 27001 or Cyber Essentials to satisfy Ofcom assessments?
Legal duties come from the Telecoms (Security) Act and the Ofcom Code of Practice, so ISO 27001 and Cyber Essentials help but are not a legal substitute. Certifications evidence control maturity, but Ofcom will want mapped, operational evidence against the Code measures. Keep certifications current, and ensure you can present mapped artefacts and logs when Ofcom asks under a Section 135 notice.
Can a third party prepare and submit evidence on our behalf?
Third parties can prepare evidence and act as advisers, but the provider remains accountable under the Telecoms (Security) Act and to Ofcom. Ofcom will expect contractual authorisation, clear provenance and audit trails for submitted material. Use written mandates, preserve originals and retain ultimate sign-off internally; do not treat delegation as a transfer of legal responsibility.