The March 2027 wave of the telecoms security act 2027 requires Tier 1 and Tier 2 operators to deliver implemented controls and testable evidence to Ofcom, as set out in the draft revised Telecommunications Security Code of Practice (draft revised Code of Practice, gov.uk).
At CyPro, we recommend a staged build plan that sequences quick wins, supplier assurance and evidence collection so operators can demonstrate compliance with the revised Code of Practice, informed by telecoms incident reporting from the European Union Agency for Cybersecurity (ENISA, 2024) and the Ofcom security report (Ofcom, 2025).
- What it is: The telecoms security act 2027 March 2027 wave requires implemented technical controls and testable evidence for Tier 1 and Tier 2 operators (draft revised Code of Practice, gov.uk).
- Approach: Use a staged build plan that starts with high-impact fixes, then moves to supplier assurance and formal evidence collection for board reporting.
- Key controls: Prioritise privileged access protections, dedicated administration workstations, central logging into a SIEM (Security Information and Event Management) and SOC (Security Operations Centre) monitoring for detections.
- Regulator focus: Ofcom expects demonstrable change, supplier oversight and clear evidence aligned to the revised Code of Practice (Ofcom, 2025).
What is the March 2027 Telecoms Security Act 2027 wave?
The March 2027 wave is the set of duties under the Telecommunications (Security) Act 2021 that activate for Tier 1 and Tier 2 operators in March 2027, requiring evidence against the revised Code of Practice and new reporting to Ofcom.
In the March 2027 wave the telecoms security act 2027 means firms must show implemented controls on network architecture, access management, supply chain and monitoring, including evidence aligned to the 2026 revised Code of Practice.
Which duties switch on in March 2027?
Tier 1 operators must demonstrate mature technical controls and continuous monitoring, while Tier 2 operators face a lighter but still mandatory set of measures focused on governance, basic hardening and patching. The March 2027 duties emphasise practical evidence, not theoretical policies, and Ofcom expects demonstrable change in operations and supplier oversight.
Ofcom's security report for October 2024 to October 2025 shows how regulator reporting is tightening, and that trend explains Ofcom's stricter evidence expectations in 2027 (Ofcom, 2025).
What does this mean practically for operators?
Operators must map which Code clauses apply, produce testable evidence, and fix high-risk gaps within 12 months. The March 2027 wave makes supply chain justification and incident detection capabilities mandatory for many providers, reflecting patterns seen in European telecom incidents (ENISA, 2024).
At CyPro, we recommend a twelve month build plan that sequences quick wins (patching, MFA, logging) in months 1 to 3, supplier audits and architecture reviews in months 4 to 8, and full evidence collection, testing and board reporting in months 9 to 12. Our suggested timeline aligns with the published March 2027 deadlines and practical evidence Ofcom will expect.
For a ready checklist and dates, see our Telecoms Security Act timeline for the March 2027 wave and the revised Code guidance on our resources page.
How does the March 2027 TSA wave work in practice?
The March 2027 wave gives Tier 1 and Tier 2 operators 12 months to show they have implemented the Code of Practice measures that apply to them, including strengthened access controls, protected administrative workstations, central logging and demonstrable monitoring and response arrangements.
Technical controls, clarified
The Code of Practice sets outcomes rather than a single mandatory product list: operators must show functioning Privileged Access Management (PAM), Privileged Access Workstations (PAWs) where appropriate, centralised logging and monitoring that supports detection and investigation, and secure integrations with cloud and third-party services. The Code does not prescribe a single log retention duration for every operator, it requires retention to be “appropriate” to the service and risks identified in an operator's risk assessment; operators should map their chosen retention to the Code clauses when preparing evidence.
Evidence and SIEM design priorities
Operators are expected to provide testable evidence tied to Code clauses, for example configuration snapshots, access review records, detection rules and exercise logs. SIEM and central logging design should therefore prioritise reliable ingestion, tamper-evidence and searchable storage so teams can reproduce detection timelines during assessment. Ofcom's reporting highlights the importance of timely reporting and accurate incident categorisation when assessing telecoms resilience, see the Ofcom security report for the period October 2024 to October 2025.
Sequencing and dependencies
Practical sequencing usually starts with discovery and identity controls, because PAM and PAWs reduce the highest-risk human access paths and simplify later evidence collection. Central logging and monitoring come next, so detections and playbooks can be validated within the 12-month window. ENISA's telecoms review shows operators that prioritise identity and logging reduce investigation overheads, which is useful context when planning resource and vendor lead times; see ENISA Telecom Security Incidents 2024.
At CyPro, we advise operators to map Code clauses to specific deliverables early, and to use our TSA requirements and TSA timeline pages when sequencing projects and preparing evidence.
Who needs to meet the March 2027 requirements, Tier 1 or Tier 2?
Tier 1 operators must meet the March 2027 requirements; some Tier 2 providers also must meet them when they provide key services to Tier 1s, such as signalling, core hosting or roaming support.
The Draft revised Telecommunications Security Code of Practice (GOV.UK) sets out how Ofcom will allocate duties by scale, network role and risk, and makes clear that obligations attach to the operator role as well as to supply‑chain services Draft revised Telecommunications Security Code of Practice (GOV.UK).
How to tell which tier applies
The draft Code lists indicators Ofcom will use to assign tiers, including user numbers, geographic reach and interconnection roles, so start by mapping those attributes against your services. Ofcom's redacted December 2025 report explains inspectors and auditors will check supplier evidence and service‑level controls during the 2026 and 2027 assurance cycles Ofcom, 2025.
Practical tests that often draw Tier 1 duties
- Do other operators rely on your signalling, roaming or interconnect services for national coverage? If yes, you may be treated as Tier 1 for those services.
- Do you host core network functions for multiple operators in the UK? Shared core hosting can pull a supplier into the March 2027 wave.
- Are you a managed‑service provider with contractual responsibility for resilience or incident response for a Tier 1 operator? Contractual roles and evidence obligations matter to Ofcom.
At CyPro, we recommend documenting these three tests, mapping contracts and producing a short evidence pack for Ofcom and the Department for Science, Innovation and Technology (DSIT). Our checklist on what the Telecoms Security Act actually requires and the timeline summary Telecoms Security Act Timeline help teams decide whether to plan for the March 2027 wave.
How much does implementing the March 2027 TSA wave cost in the UK? ££
Expect Tier 1 builds to cost roughly £1.2m to £4.0m in the first 12 months, and Tier 2 builds to cost roughly £250k to £900k, depending on scope, tooling and whether you use an in‑house or managed SOC; these figures reflect our telecoms security act 2027 modelling.
Cost breakdown by component
PAM, Privileged Access Workstations (PAWs) and identity gating commonly take the largest slice: licences, professional services to rationalise service accounts and ITSM changes often total £150k to £600k for mid-market firms. SIEM and Security Operations Centre setup (log ingestion, retention, detection engineering) is typically £200k to £1.5m, with recurring monitoring from £3k to £60k per month depending on 24x7 coverage. Hardware, network changes and signalling controls add £50k to £400k.
Tool licensing tends to be capital or committed OPEX for the first year, while managed detection and response or managed SOC sits as ongoing OPEX. The telecoms security act 2027 places emphasis on testable evidence and retention windows, which pushes SIEM retention and storage costs up relative to typical IT projects.
Signposting to primary guidance and practical materials is useful when sizing budgets: see the Telecoms Security Act explained page and the UK government cyber survey for behaviours and incident rates in 2025/2026 (Cyber security breaches survey 2025/2026).
| Organisation size / tier | One‑off build (year 1, £) | Annual run (year 2+, £) | What this includes |
|---|---|---|---|
| Tier 1 large operator | £1,200,000 to £4,000,000 | £360,000 to £1,200,000 | PAM, PAWs, SIEM, 24x7 SOC, retention, supply‑chain evidence |
| Mid‑market Tier 2 | £250,000 to £900,000 | £72,000 to £360,000 | PAM baseline, SIEM onboarding, detection rules, quarterly evidence packs |
| Small Tier 2 / critical supplier | £80,000 to £250,000 | £24,000 to £90,000 | Selective PAM, log centralisation, outsourced monitoring |
Budget phasing across 12 months
Phase 1 (months 0 to 4): discovery, identity gating and PAM pilot, 35, 45% of year‑one budget. Phase 2 (months 4 to 8): PAWs, service account clean‑up and tool procurement, 25, 35%. Phase 3 (months 8 to 12): SIEM ingestion, detection tuning and evidence collection for Ofcom, remaining 20, 30%. ENISA and consolidated regulator reporting show increased evidence demands that tend to push phasing toward earlier identity controls (ENISA consolidated report 2025).
At CyPro, we model total cost of ownership across three scenarios: build in‑house, hybrid build with managed run, and fully managed delivery, because the split between capital and operating budgets materially changes procurement and board approvals.
What is the difference between PAM/PAWs/SOC and adjacent security capabilities?
PAM, PAWs and a SOC each solve different problems: Privileged Access Management (PAM) controls high‑risk accounts, Privileged Access Workstations (PAWs) isolate sensitive admin tasks, and a Security Operations Centre (SOC) detects and responds to incidents. The telecoms security act 2027 expects evidence across all three for core network functions.
PAM focuses on who can do what and when, PAWs focus on where sensitive actions occur, and a SOC focuses on monitoring, detection and response. For organisations subject to the Telecoms Security Code of Practice, these controls are complementary, not interchangeable, and each has distinct evidence requirements for Ofcom and the Department for Science, Innovation and Technology (DSIT).
Where PAM fits versus Identity and Access Management
Privileged Access Management is a specialised subset of Identity and Access Management (IAM) that governs highly privileged accounts such as root, service accounts and network element administrators. PAM enforces session control, just‑in‑time access and credential vaulting; IAM covers lifecycle, federation and single sign‑on. Under the Telecoms Security Code of Practice, operators must show controls over both IAM and PAM for sensitive assets. For practical guidance see the TSA Code of Practice summary.
PAWs versus hardened endpoints
Privileged Access Workstations are dedicated, locked‑down devices for administrative tasks, often hosted on separate networks or via secure bastions. A hardened endpoint reduces attack surface across general users; a PAW prevents credential theft during admin sessions. Ofcom evidence requests in 2025 emphasised separation of admin workspaces for signalling and core functions, so deploying PAWs speeds compliance with the telecoms security act 2027 where administrative segregation is required (Financial Times notice).
SOC versus EDR and MDR
A SOC is an organisational capability that uses tools, people and processes to detect and respond. Endpoint Detection and Response (EDR) is a tool class that feeds telemetry into a SOC. Managed Detection and Response (MDR) is a service model that outsources parts of that SOC function. The Telecoms Security Code expects operators to demonstrate detection coverage and incident handling, which can be delivered by an in‑house SOC or by an MDR provider.
Choosing between building and buying depends on scale, evidence needs and supplier risk. For suppliers and operators preparing for the telecoms security act 2027, map each requirement to PAM, PAWs or SOC outputs during the first four months of a remediation plan to avoid last‑minute gaps (IBM, 2025).
When should you implement the March 2027 TSA wave and in what order?
Start immediately and follow a staged 12 month sequence: months 0 to 4 focus on Privileged Access Management (PAM), months 4 to 8 deliver Privileged Access Workstations (PAWs) and service‑account hygiene, months 8 to 12 bring SIEM/SOC ingestion and evidence capture for Ofcom. This order maps to the Telecoms Security Act 2027 requirements for identity-first controls and timely evidence.
A 12 month, risk‑prioritised plan that puts PAM first, PAWs second and SIEM/SOC last minimises rework, meets Ofcom evidence needs and aligns with the Telecoms Security Act 2027 March wave.
Why start with PAM?
PAM reduces the blast radius from compromised credentials, and it is quick to pilot so it should be month 0 to 4. Under the Telecoms Security Code of Practice, identity and access controls are foundational, and starting with PAM captures high‑risk accounts early. ENISA analysis of telecom incidents shows that credential misuse and privileged abuse remain material contributors to outages and compromise, so tackling privileged credentials first shortens the road to demonstrable compliance (ENISA, 2024).
Why deliver PAWs next?
Privileged Access Workstations isolate administrative tasks and remove lateral movement opportunities, making them a natural month 4 to 8 activity once PAM rules exist. PAWs require desktop build standards, secure imaging and ITSM automation, so delivering them after PAM reduces policy friction and avoids repeating account provisioning work. The Code expects PAW evidence alongside PAM logs for a complete audit trail, which helps with Ofcom submissions and inspections.
Why finish with SIEM, SOC and evidence capture?
SIEM ingestion, detection tuning and Security Operations Centre (SOC) workflows belong in months 8 to 12, once identity telemetry and PAW logs are feeding the pipeline. A later SIEM cutover reduces false positives and speeds meaningful detection tuning. Industry data shows credential abuse and exploitation remain common causes of breaches, underlining why identity telemetry is the best telemetry to feed a SOC (Verizon DBIR, 2025).
At CyPro, we sequence the March 2027 TSA wave to deliver evidence continuously, not only at the 12 month milestone. That means build PAM and PAW artefacts with collection and retention requirements in mind, so SIEM and SOC work is largely tuning and verification rather than rework. For technical guidance on signalling or protocol controls during the SIEM phase, see our signalling security guidance for practical checks and evidence expectations (Signalling security).
How to choose a provider for the March 2027 TSA wave?
Pick a provider that can deliver Privileged Access Management, Privileged Access Workstations and SIEM evidence end-to-end within 12 months, and that understands how the telecoms security act 2027 evidence model works.
When you evaluate suppliers, insist on three priced scenarios: advisory only, co-delivery and fully managed delivery, each mapped to the March 2027 TSA wave milestones. The telecoms security act 2027 requires documented evidence for controls, so suppliers must show sample evidence artefacts and an ingestion plan for logging and retention.
Must-have capabilities
Choose suppliers who can demonstrate technical delivery across these areas: Privileged Access Management (PAM) implementation, Privileged Access Workstation (PAW) deployment, SIEM or Security Operations Centre ingestion and retention, and secure supply chain checks. Ask for a worked scenario showing how they will capture, normalise and retain logs for Ofcom audit, and for a runbook of how they will prove control ownership during Ofcom spot checks. Demand references that map directly to the Telecoms Security Code of Practice and the March 2027 deadlines.
Procurement checklist and pricing scenarios
Request three scenarios priced separately: (1) advisory and gap analysis, (2) advisory plus delivery of PAM and PAWs, (3) fully managed SIEM ingestion and evidence retention. Ask suppliers to show UK-based support options, response SLAs for evidence requests, and a clear conflict of interest statement. Our preferred procurement anchors are timelines and examples that mirror the March 2027 TSA wave so you can compare like for like. For practical templates, see the Telecoms Security Act FAQs for typical evidence asks.
Finally, test suppliers with a short-list technical interview and a scenario test: ask them to price the March 2027 TSA wave with 13-month retention and 5-minute ingestion SLAs, and to provide the exact evidence artefact they would hand to Ofcom within 48 hours. Choosing a supplier who can both advise and deliver reduces rework and speeds your March 2027 readiness.
Evidence references: review the IBM Report: UK Sees Drop in Breach Costs as AI Speeds Detection and the Verizon 2025 Data Breach Investigations Report when assessing third-party risk interaction models for the telecoms security act 2027.
Frequently asked questions
Do I need PAM if I already have enterprise IAM?
Key fact: Privileged Access Management (PAM) covers privileged accounts and workflows that enterprise Identity and Access Management (IAM) often does not. PAM is required by the Code where access touches network elements, signalling systems or high-risk admin paths. Use a short checklist: count privileged identities, map critical system exposure, confirm audit and session-recording evidence, and check segregation from standard IAM workflows.
How long does implementation take for a mid-market Tier 2 operator?
Key fact: Typical delivery is phased, with PAM taking 4 to 6 months, Privileged Access Workstations (PAWs) 2 to 4 months and SIEM/SOC 4 to 8 months when run in parallel. PAM usually takes longest because of identity and ITSM integrations. Plan a phased go-live and align minimum evidence milestones for Ofcom at each phase, including configuration baselines and audit logs.
Can we outsource TSA compliance rather than build in-house?
Key fact: Outsourcing is common for SIEM, SOC and managed threat hunting, but PAM and PAWs need close internal identity work. Expect suppliers to provide SLAs, audit evidence packs, UK data residency options and local support. Include contract clauses requiring demonstrable Ofcom-ready evidence, defined acceptance criteria, incident response playbooks and clear responsibilities for identity integrations.
What is the minimum log retention and ingestion performance required in March 2027?
Key fact: The March 2027 wave expects 13 months of log retention and near-real-time ingestion targets such as five-minute ingestion. Use those figures to size storage, indexing and cost forecasts. For cloud versus on-premises SIEM architectures, model egress, hot versus cold storage tiers, retention costs and indexing performance against the five-minute ingestion SLA.
What ROI can we expect from investing in PAM, PAWs and a SOC for TSA compliance?
Key fact: ROI is mainly risk reduction, shown as fewer privileged misuse incidents, faster detection and reduced breach impact. Track practical metrics: mean time to detect, mean time to contain, and number of privileged incidents avoided. Build a business case by estimating cost avoidance from quicker containment, lower incident remediation costs and reduced regulatory penalties.