DSIT, the Department for Science, Innovation and Technology, and DCMS, the Department for Digital, Culture, Media and Sport, opened a call for evidence on 17 August covering sections 1 to 13 of the Telecommunications (Security) Act 2021, the Electronic Communications (Security Measures) Regulations 2022 and the Telecommunications Security Code of Practice 1. A call for evidence is the stage before a decision: government asks who is affected what the current rules cost and achieve, then decides whether to change them.
The three documents named form one regime rather than three. The Act carries the duties, the regulations made under it set out the specific measures, and the code of practice describes how a provider is expected to meet them. Reviewing all three at once means the question on the table is the shape of the regime, not the wording of a clause inside it.
The reason a telecoms security regime exists at all was put on the record in June, when the head of Britain's National Cyber Security Centre told an audience at RUSI that the agency had handled more than 200 incidents affecting UK critical national infrastructure, three quarters of them state-linked . Telecoms is the layer every other piece of that infrastructure runs across, which is why it got its own statute rather than a place inside a general one.
France published in a different register the same fortnight. ANSSI, its national cyber agency, released a Wi-Fi security guide on 31 August pitched as good practice for readers at any level rather than detailed technical recommendation 2. One government asks its industry whether the law is working; another hands out advice with no legal force behind it. Both are what the quiet end of cyber policy actually looks like between enforcement moments.
