TSA 2021 and Penetration Testing: What Ofcom Checks When It Audits Telecoms Providers

TSA 2021 and Penetration Testing: What Ofcom Checks When It Audits Telecoms Providers

By EJN Labs · 19 Aug 2026 · 8 min read

TSA 2021 penetration testing is not a single named exercise in the Act itself, but the security duties it created, and the regulations and Code of Practice that sit under it, expect public telecoms providers to test their networks and services against realistic attack. Ofcom‘s oversight covers evidence of that testing. Typical focused engagements run 4 to 6 days, around £4,400 to £8,400.

Why TSA 2021 penetration testing matters for telecoms providers

TSA 2021 penetration testing matters because the Telecommunications (Security) Act 2021 rewrote the security obligations of every public telecoms provider in the UK, and the penalties for falling short are serious: fines of up to ten per cent of relevant turnover, with daily penalties for continuing contraventions.

The Act inserted new security duties into the Communications Act 2003, backed them with the Electronic Communications (Security Measures) Regulations 2022, and gave Ofcom the job of monitoring and enforcement.

For a CTO or network security lead, the practical question is not whether the Act applies. If you provide a public electronic communications network or service in the UK, it does. The question is what evidence to have ready for Ofcom. The Act does not contain the words “penetration test”, but it does impose a duty to identify and reduce the risk of security compromises, backed by a framework that expects providers to prove, through testing, that their measures work.

The regulatory driver: the Act, the Regulations and the Code of Practice

The framework has three layers, each closer to explicit testing expectations.

  • The Act (TSA 2021). Places overarching duties on providers to take appropriate and proportionate measures to identify and reduce the risks of security compromises. Passed by the UK Parliament, with policy owned by DSIT and enforcement by Ofcom.
  • The Electronic Communications (Security Measures) Regulations 2022. Turn the duties into specific measures, including a duty to test networks and services for anything that could compromise security.
  • The Telecommunications Security Code of Practice. Sets out how the duties can be met, with tiered implementation dates. Tier 1 providers (the largest, by relevant turnover) face the earliest deadlines and closest scrutiny; Tier 2 follows; Tier 3 is expected to comply proportionately.

On top of this sits TBEST, the threat-intelligence-led penetration testing scheme for the telecoms sector, run with Ofcom oversight. Its existence tells you how the regulator thinks: realistic testing of live defences is the standard the sector is measured against. Because the testing duty is risk-based, a provider without recent, independent test results is in a weak position in any Ofcom conversation, whatever its tier.

What Ofcom looks for when it audits a provider

Ofcom monitors compliance through information requests, structured assessments and formal enforcement. The evidence themes it probes map closely to what a well-scoped penetration test produces:

What Ofcom probesEvidence a pen test programme provides
Exposure of the network edge and management planeExternal infrastructure testing of internet-facing services, signalling gateways and remote access
Segregation of the management plane from exposed systemsInternal testing that attempts to pivot from corporate IT into network management
Security of customer-facing platforms and APIsWeb application and API testing of portals, provisioning systems and OSS/BSS interfaces
Supply chain and third-party access riskTesting of vendor remote-access routes and MSP connections into the estate
Ability to detect and respond to compromiseRed team or TBEST-style exercises that measure detection, not just prevention

The common thread: Ofcom is not satisfied by policy documents. It wants controls that survive contact with an attacker, and independent test reports with findings, retest evidence and dates are the cleanest way to show that.

What to test in a telecoms estate

Telecoms estates are broader than typical corporate networks, and scoping is where most programmes go wrong. When we scope TSA-driven work at EJN Labs, we split the estate into four zones and test the boundaries.

  • The exposed edge. Internet-facing infrastructure, VPN concentrators, SIP and signalling gateways, DNS and customer portals. This is standard external infrastructure penetration testing, the minimum credible starting point.
  • Customer platforms and APIs. Self-service portals, provisioning APIs, billing integrations and partner interfaces. API penetration testing matters because provisioning APIs often hold privileged paths into the network itself.
  • The management plane. The systems your engineers use to configure network equipment. The Telecommunications Security Code of Practice (version 1.1, issued 14 July 2026) is explicit here: paragraph 2.15 says securing the management plane should be treated as a priority, and paragraphs 2.16 and 2.17 say providers shall architect and operate that infrastructure to inhibit network compromise through administrative access, with office productivity workstations kept logically or physically separate from anything holding management plane access. Testing should attempt to reach the plane from less trusted zones.
  • Cloud and virtualised functions. As network functions move into the cloud, cloud penetration testing of accounts, identities and workload isolation joins the TSA evidence picture.

For Tier 1 and 2 providers, a periodic red team exercise is the closest commercial equivalent to TBEST and produces the detection-and-response evidence Ofcom values most.

How a TSA-driven engagement runs

A typical engagement follows five stages, adapted to networks that carry live customer traffic and cannot tolerate careless testing.

  1. Scoping. We map your estate against the four zones above, agree which boundaries matter most for your tier, and define safe testing windows for anything touching production signalling or provisioning paths.
  2. Rules of engagement. Written authorisation, emergency contacts, and explicit exclusions for systems where an outage would itself be a reportable compromise.
  3. Testing. UK-based testers work through the agreed scope, chaining findings the way a real attacker would.
  4. Reporting. Findings are rated by real-world exploitability and mapped to the security duty themes in the Code of Practice, so the report drops straight into your evidence pack.
  5. Retest. Once fixes land, we verify them and issue updated evidence showing closure, not just discovery.

To prepare before a test starts, our penetration testing checklist walks through the questions to settle in advance, from asset lists to access arrangements.

What it costs and how scope drives the price

Testing is priced by effort, and effort is driven by scope: the number of external hosts, the complexity of APIs and portals, and how deep into the management plane testers go. UK day rates for CREST-accredited work typically run £1,100 to £1,400, and the ranges below reflect that.

EngagementTypical effortTypical UK price
External infrastructure test (network edge)3 to 5 days£3,300 to £7,000
Customer portal and API test4 to 6 days£4,400 to £8,400
Internal and management-plane segregation test5 to 8 days£5,500 to £11,200
Cloud estate review and test5 to 8 days£5,500 to £11,200
Red team / TBEST-style exercise15 to 25 days£16,500 to £35,000

These are typical UK ranges rather than quotes; an exact price needs a short scoping conversation. For what moves prices across the market, see our guide to penetration testing costs in the UK.

How EJN Labs approaches TSA 2021 testing

EJN Labs is a UK firm delivering CREST-accredited penetration testing, and we hold Cyber Essentials Plus, ISO 27001 and ISO 9001 ourselves, so we know what building and defending a regulator-facing evidence pack involves. All work is carried out by UK-based testers, which matters in a sector where DSIT and Ofcom pay close attention to who touches network infrastructure.

Two things distinguish TSA-driven work from a generic test. First, scoping is boundary-led: we identify the trust boundaries the Regulations care about, particularly between corporate IT, customer platforms and the management plane, and test whether they hold. Second, reporting is regulator-aware: findings are grouped by security duty theme, not just by host, so a compliance owner can trace each result to the obligation it evidences. Regulated sectors elsewhere face similar dynamics; our work on cyber security for financial services follows the same evidence-first approach.

Frequently Asked Questions

Does TSA 2021 explicitly require penetration testing?

No. The Act itself does not name penetration testing. However, the Electronic Communications (Security Measures) Regulations 2022 include a duty to test networks and services for security weaknesses, and the Code of Practice sets the testing expectations Ofcom checks against.

Independent penetration testing is, in our experience, the most common way to evidence that duty.

Who does TSA 2021 apply to?

TSA 2021 applies to providers of public electronic communications networks and services in the UK. Obligations are tiered by relevant turnover, with Tier 1 covering the largest national providers, Tier 2 covering mid-sized providers and Tier 3 covering smaller ones.

Suppliers such as equipment vendors, MSPs and data centres feel the requirements through contracts and supply chain assurance.

What does TSA-driven penetration testing cost?

Typical UK ranges at a CREST-accredited firm run from £3,300 to £7,000 for an external infrastructure test, £4,400 to £8,400 for a portal and API test, and £5,500 to £11,200 for management-plane or cloud testing, at day rates of £1,100 to £1,400.

In day terms that is 3 to 5 days for the external infrastructure test, 4 to 6 days for the portal and API work, and 5 to 8 days for the management-plane or cloud testing. Exact pricing depends on scope.

What is TBEST and do we need it?

TBEST is the threat-intelligence-led penetration testing scheme for the UK telecoms sector, overseen with Ofcom involvement and aimed primarily at the largest providers. Most providers are not required to join it, so for the majority of the sector the answer is no.

Outside the scheme, a well-scoped red team exercise delivers similar assurance and produces detection-and-response evidence Ofcom recognises.

How often should a telecoms provider test under TSA 2021?

The duties are risk-based, so there is no fixed statutory interval. In practice, most in-scope providers test the network edge and key customer platforms at least annually, retest after significant changes such as new provisioning APIs or cloud migrations, and exercise the management plane on a one to two year cycle.

Build your Ofcom evidence pack before you need it

The providers that handle TSA scrutiny well hold recent, independent test evidence before the information request lands. Tell us what your estate looks like and we will return a fixed scope and price. Get a CREST penetration testing quote from UK-based testers who understand the telecoms security framework.

Leave a Reply

Your email address will not be published. Required fields are marked *