By EJN Labs · 9 Sep 2026 · 7 min read
The Telecoms Security Code of Practice groups public telecoms providers into three tiers by scale. Tier 1 and Tier 2 providers are expected to evidence the Code’s technical security measures, including testing, on tier-specific timeframes; Tier 3 providers are not expected to follow the Code. Suppliers to any tier, including MSPs, increasingly need to show equivalent evidence through vendor assessment, commonly independent penetration testing.
Why does a Code of Practice for telecoms providers reach MSPs and IT providers?
MSPs and IT providers feel the Code through contracts, not direct regulation. Telecoms providers pass security expectations down their supply chain, so managed service providers and network integrators are increasingly asked to evidence controls mirroring what the Code sets out for their telecoms customers.
The mechanism is Annex B of the Code, its vendor security assessment criteria for suppliers of equipment, managed services and remote access. One criterion, covering vulnerability and issue management, expects a security declaration describing how quickly a supplier resolves reported issues, backed by spot-checks or lab testing where a customer wants more than paperwork. For an MSP managing a telecoms customer’s network estate or provisioning systems, that assessment surfaces at procurement or renewal, and a recent, independent penetration test report answers it faster than a lengthy back-and-forth.
What actually creates the legal duty behind the Code of Practice?
The Telecommunications (Security) Act 2021 creates the legal duty, not the Code. The Act gave Ofcom powers to enforce security duties on providers; the Electronic Communications (Security Measures) Regulations 2022 set out specific duties, and the Code recommends how providers meet them, tiered by scale.
Ofcom regulates compliance with the Act’s security duties rather than running a certification scheme, so there is no pass or fail certificate at the end of it. That is part of why a telecoms customer asking about the Code is not asking whether you hold a certificate; they want evidence that specific controls exist and work, which is exactly what a scoped penetration test is built to produce.
What is Tier 1, Tier 2 and Tier 3 expected to demonstrate?
Tier 1 covers the largest, national-scale providers, expected to implement the Code’s measures fastest. Tier 2 covers medium-sized providers, given longer to implement some of the same measures. Tier 3 covers smaller providers, not expected to follow the Code, though they may adopt its measures voluntarily.
The measures span governance, network architecture and monitoring, and testing sits inside a good number of them. The Code describes testing, including red team exercises, as how a provider verifies its defences and finds weaknesses before an attacker does, with guidance that testing should simulate real-world attacks so far as possible.
| Tier | What the Code expects | Where MSPs and suppliers fit in |
|---|---|---|
| Tier 1 | Full set of technical measures on the fastest implementation timeframes, testing included | Vendor contracts routinely reference Annex B assessment criteria |
| Tier 2 | Same measures, longer to implement some of them | Supplier assurance expectations follow, often on a similar timetable |
| Tier 3 | Not expected to follow the Code’s measures | May still request assurance evidence voluntarily, particularly where a Tier 1 or Tier 2 customer sits downstream |
For an MSP, your own tier under the Code, if you hold a public telecoms licence at all, matters less than the tier of the customers you supply. A Tier 3 customer may never raise a security question; a Tier 1 customer almost always will, and increasingly earlier in the sales cycle.
How does a penetration testing programme map onto the Code’s evidence expectations?
A penetration testing programme maps onto the Code through the evidence it produces, not because the Code names it as a mandatory step. Testing generates the dated findings, retest confirmation and vendor declarations that Tier 1 and Tier 2 providers, and their suppliers, use to show the measures are working.
- Scoping. We map what is relevant to the customer’s Code obligations: network edge, management plane, customer-facing systems, or the remote-access route your tooling uses to reach their estate.
- External and internal infrastructure testing. Covers the network edge and, where relevant, segregation between corporate IT and any management-plane systems in use.
- Application and API testing. In scope where portals, provisioning systems or OSS/BSS interfaces sit between your platform and the customer’s network.
- Red team or objective-based testing. Used where the tier and risk profile call for it, measuring detection and response rather than prevention alone.
- Retest and reporting. Dated evidence and a fix status that feeds straight into a vendor declaration or an Annex B assessment, not a generic summary.
The output is written to survive a security team’s follow-up questions, not just an initial submission. Findings map to the systems and access routes a telecoms customer cares about, so the report gets reused across renewals rather than recommissioned every time a questionnaire lands.
What does penetration testing scoped to the Code of Practice cost in the UK?
Typical UK day rates for CREST-accredited testing fall between £1,100 and £1,400. A supplier-facing scope covering external infrastructure and remote-access routes typically runs 4 to 6 days: £4,400 to £8,400. A fuller scope adding application and management-plane testing typically runs 7 to 10 days: £7,700 to £14,000.
| Scope | Typical effort | Typical UK cost |
|---|---|---|
| Supplier remote-access and external infrastructure review | 4 to 6 days | £4,400 to £8,400 |
| Customer portal, OSS/BSS or API testing | 5 to 7 days | £5,500 to £9,800 |
| Management-plane segregation and internal network test | 6 to 9 days | £6,600 to £12,600 |
| Red team or objective-based exercise, Tier 1 scale | 15 to 20 days | £16,500 to £28,000 |
| Retest after remediation | 1 to 2 days | £1,100 to £2,800 |
These are typical UK ranges rather than quotes; the figure that matters is the one built around your actual scope. Our guide to penetration testing costs in the UK covers the wider drivers. Where a customer sets a deadline, the quote form below gets a fixed scope and price back quickly.
How EJN Labs approaches telecoms security testing for MSPs and IT providers
EJN Labs is a CREST-accredited penetration testing firm, certified to ISO 27001 and ISO 9001, with engagements delivered by UK-based testers. For MSPs supplying telecoms customers, that detail can matter as much as the accreditation, since questionnaires ask where testing happened and findings are stored.
When we scope work against the Code, we start from the questionnaire or vendor declaration the client needs to complete, then map its questions to the testing that answers them directly, rather than running a generic external test and hoping it fits. In our experience this avoids a second, more expensive round of testing once a security team asks a follow-up the first report never anticipated.
Where an engagement spans network edge, management systems and customer-facing applications, that usually means combining our external infrastructure testing with API testing in one scope and report. Our CREST penetration testing page sets out the methodology in full.
Frequently Asked Questions
Does the Telecoms Security Code of Practice apply to MSPs directly?
No, not directly. The Code is guidance for public telecoms providers, tiered by scale, and MSPs are not regulated under it. MSPs feel its effect through contracts and vendor assessments, particularly Annex B, when they supply managed services, remote access or network equipment into a telecoms provider’s estate.
What is the difference between Tier 1, Tier 2 and Tier 3 providers?
Tier 1 covers the largest, national-scale providers, expected to implement the Code’s measures on the fastest timeframes. Tier 2 covers medium-sized providers, given longer to implement some of the same measures. Tier 3 covers smaller providers, who are not expected to follow the Code’s measures at all.
Does the Code of Practice require penetration testing?
The Code does not name penetration testing as a mandatory step for any tier. What it sets out is a set of technical security measures, and testing, including red team exercises, is the guidance’s own example of how a provider verifies those measures are actually working rather than just documented on paper.
How much does penetration testing for telecoms security cost in the UK?
Typical UK day rates for CREST-accredited testing fall between £1,100 and £1,400. A supplier-facing scope covering external infrastructure and remote-access routes typically runs 4 to 6 days: £4,400 to £8,400; a fuller scope adding application and management-plane testing typically runs 7 to 10 days: £7,700 to £14,000.
How long does a telecoms security testing programme take to complete?
Engagements typically run two to four weeks from kick-off to final report, depending on scope and how many systems are involved. Add time for retesting after remediation, and start scoping at least a month before a procurement deadline or Annex B assessment, since findings that need fixing can extend the timeline.
Get a scoped quote for telecoms security testing
If you need penetration testing evidence for a telecoms security questionnaire, an Annex B vendor assessment, or your own Tier 2 obligations, we can scope it around the exact evidence you have been asked for. Get a CREST pentesting quote and we will map the scope and confirm a price.
Related research
For the regulatory detail behind this post, see our guide to Ofcom’s telecoms security audits and our guide to penetration testing under the NIS Regulations. If you are choosing a supplier for the testing itself, our checklist for choosing a CREST-accredited provider covers the questions worth asking.




Leave a Reply