Summary
- The UK evidence call on the impact and effectiveness of sections 1–13 of the Telecommunications (Security) Act closes at 23:59 on Monday 12 October 2026.
- Section 14 requires a report to Parliament within five years of Royal Assent on 17 November 2021; the first review’s statutory scope is narrower than the whole Act, whose section 15 begins a separate designated-vendor regime.
A statutory boundary matters
UK telecoms providers and other interested parties have two days left to submit evidence to the Government’s first review under the Telecommunications (Security) Act 2021. The call closes at 23:59 on Monday 12 October. It is an evidence deadline, not a finding that the security framework has succeeded or failed.
The review has a fixed legal perimeter. Section 14 directs the Secretary of State to assess the impact and effectiveness of sections 1–13, publish a report and lay it before Parliament. Reports must be no more than five years apart, and the first must be published within the five-year period that began when the Act was passed. Royal Assent came on 17 November 2021, putting the first report on a November 2026 clock. The official text of the Act makes the boundary explicit.
That matters because “the Telecommunications (Security) Act” can sound like one undivided review subject. The Government describes the framework as a combination of provider security duties, regulations, a code of practice and Ofcom monitoring and enforcement. The 2026 call focuses on sections 1–13 and welcomes evidence about the regulations and code. Section 15, by contrast, begins the Act’s designated-vendor directions. The required report therefore has a defined statutory subject; it should not be read automatically as a review of every later power in the Act.
Evidence needs a counterfactual
The call includes an unusually useful instruction for evaluating impact: respondents should not count security activity that would have happened anyway as business-as-usual, under existing obligations or through wider commercial decisions. That is a counterfactual test. It asks what the framework changed, rather than inviting a tally of everything providers have spent on security since 2021.
The distinction is difficult in a sector where systems, threats and investment plans keep changing. Higher security spending could reflect new legal duties, but it could also reflect equipment replacement, threat intelligence, ordinary risk management or commercial priorities. A rising number of controls is not by itself proof that the Act caused them; the absence of a publicly reported incident would not, by itself, prove that the duties were ineffective. The Government’s own policy objectives include making compromise harder, improving detection and limiting harm, as well as protecting availability, confidentiality and integrity.
The evidence request supports the Secretary of State’s review; it does not transfer the legal judgment to the companies that submit responses. The Government says it will also engage Ofcom and the National Cyber Security Centre, analyse the submissions and publish and lay the resulting report before Parliament. Readers will need to see how that report attributes observed changes to the statutory framework and how it keeps its sections 1–13 scope visible.
Guidance is part of the setting, not the result
The framework has continued to evolve during the period under review. Regulations took effect in October 2022, and the first code of practice followed in December 2022. Version 1.1 of the revised code was issued on 14 July 2026 after a draft had been laid before Parliament in June. It provides detailed guidance for large and medium-sized public telecoms providers on complying with the duties and regulations. That update is relevant context, but its publication is not the finding of the section 14 review.
The Government invites evidence from all stakeholders, with particular attention to public telecoms providers. It also warns that responses may be shared with government departments, Ofcom and agencies, and may be published in full or summary; confidentiality cannot be guaranteed in every circumstance. That disclosure rule is part of the evidence channel’s design and may shape how organisations document sensitive examples.
By 12 October, respondents can still add operational evidence. After that, the test moves to the statutory report: a clear account of what was reviewed, which changes can be attributed to the framework, and where the legal perimeter ends. The Act assigns the assessment to the Secretary of State and gives Parliament the report. Participation can improve the evidence base; publication and parliamentary scrutiny complete the accountability chain.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
