Telecommunications Cyber Security and Resilience Bill Compliance Guide
Complete guide to Cyber Security and Resilience Bill compliance for telecommunications providers and ISPs. Understand regulatory obligations under HL Bill 32.
Sector Overview
Telecommunications networks are the foundation of national connectivity - powering everything from emergency calls and broadband to cloud services and digital business. As enablers of nearly every other regulated sector, telecoms and ISPs are critical to the UK's digital resilience. Under the Cyber Security and Resilience Bill (HL Bill 32), telecommunications providers may be regulated in multiple ways depending on their activities.
Core Telecom Services Exclusion
Under Part 2, Section 3 of HL Bill 32, Regulation 8(1A) provides:
"Paragraph (1) does not apply to a person in relation to the provision by the person of a public electronic communications network or a public electronic communications service (in each case as defined by section 151(1) of the Communications Act 2003)."
- HL Bill 32, Part 2, Section 3, Regulation 8(1A)
Important:
Core public electronic communications networks and services are excluded from being operators of essential services. However, telecommunications providers may still be regulated through other means under the Cyber Security and Resilience Bill.
Why Telecommunications Providers Are In Scope
While core telecom services are excluded from OES status, telecommunications providers may still be in scope if they:
You're in scope if your organisation:
- Provides managed services - ongoing IT management, not just connectivity (regulated as RMSP under Part 2, Section 9)
- Provides cloud computing services - separate from core telecom services (regulated as RDSP under Part 2, Section 7)
- Carries on essential activities or provides activity-critical supplies (subject to Part 3 regulations)
- May be subject to directions for national security purposes (Part 4)
- Delivers broadband or mobile services to the public or critical organisations
- Manages backbone or last-mile telecom infrastructure
- Supports emergency services, government networks, or public communications
- Provides managed voice, video, or data services at scale (as managed services, not core telecom)
Digital Services Exclusion:
Under Part 2, Section 7 of HL Bill 32, Regulation 1(3A) excludes public electronic communications networks/services from being relevant digital services. However, if you provide cloud computing services separate from core telecom services, you may be regulated as an RDSP.
As Managed Service Providers (RMSP)
Under Part 2, Section 9 of HL Bill 32, telecommunications providers offering managed services (ongoing IT management, not just connectivity) may be regulated as Relevant Managed Service Providers (RMSPs):
- Register with the Information Commission within 3 months (Regulation 14C)
- Comply with security duties under Regulation 14B
- Report incidents within 24 hours (initial) and 72 hours (full) under Regulation 14E
- Notify affected customers as soon as reasonably practicable under Regulation 14G
- Comply with information requests and inspections
As Cloud Service Providers (RDSP)
Under Part 2, Section 7 of HL Bill 32, telecommunications providers offering cloud computing services separate from core telecom services may be regulated as Relevant Digital Service Providers (RDSPs):
- Register with the Information Commission within 3 months (Regulation 14)
- Comply with security duties under Regulation 12
- Report incidents within 24 hours (initial) and 72 hours (full) under Regulation 12A
- Notify affected customers as soon as reasonably practicable under Regulation 12C
- Comply with information requests and inspections
Essential Activities & Activity-Critical Supplies
Under Part 3, Section 24 of HL Bill 32, telecommunications providers may carry on essential activities or provide activity-critical supplies, subjecting them to additional security and resilience requirements:
- May be subject to regulations under Section 29 relating to security and resilience of network and information systems
- May be subject to requirements imposed under Section 30
- May be subject to enforcement, sanctions, and appeals under Section 31
- May become subject to financial penalties under future Part 3 regulations, which Section 32(3) caps at the greater of £17,000,000 and 10% of turnover; no such regulations have been made yet
- Must have regard to codes of practice issued under Section 36
National Security Directions - Part 4
Under Part 4, Section 43 of HL Bill 32, telecommunications providers may be subject to directions for national security purposes:
- The Secretary of State may give directions if threats relating to network and information systems pose a risk to national security
- Directions may impose requirements relating to management of systems, provision of information, or prohibitions on use of goods/services
- You must comply with directions and may be subject to monitoring, information gathering, and inspections under Sections 45-47
- Penalties for contravening a direction: up to £17,000,000, rising to the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, with daily penalties of up to £100,000 while the contravention continues
- HL Bill 32, Part 4, Sections 43-52
Penalties for Non-Compliance
Telecommunications providers face penalties depending on how they're regulated:
Part 2 Penalties (RMSP/RDSP):
Higher Maximum: the greater of £17,000,000 and 4% of turnover for serious failures
Standard Maximum: the greater of £10,000,000 and 2% of turnover for administrative failures
Part 3 Penalties (Essential Activities):
Cap on future regulations: the greater of £17,000,000 and 10% of turnover. Part 3 penalties only come into being once regulations under Section 29(1) are made, and none have been.
Part 4 Penalties (National Security Directions):
Maximum: £17,000,000 for contravening a direction, becoming the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, plus up to £100,000 per day while the contravention continues
- HL Bill 32, Part 2, Section 21; Part 3, Section 32; Part 4, Section 49
Benefits of Cyber Security and Resilience Bill Compliance
Infrastructure Trust
- Demonstrates infrastructure trustworthiness to clients and government
- Improves preparedness for cyber incidents and outages
- Strengthens positioning in public and enterprise procurement
Strategic Benefits
- Supports long-term investment in fibre rollout and 5G expansion
- Better alignment with existing Ofcom requirements
- Access to guidance from regulatory authorities
Direct References from HL Bill 32
Part 2, Section 3 - Exclusion of Core Public Electronic Communications
Regulation 8(1A) excludes core public electronic communications networks and services from being operators of essential services, but telecoms providers may still be regulated through other means.
HL Bill 32, Part 2, Section 3, Regulation 8(1A)
Part 2, Section 7 - Digital Services Exclusion
Regulation 1(3A) excludes public electronic communications networks/services from being relevant digital services, but telecoms providers offering cloud computing services separate from core telecom services may be regulated as RDSPs.
HL Bill 32, Part 2, Section 7, Regulation 1(3A)
Part 2, Section 9 - Managed Service Providers
Telecoms providers offering managed services (ongoing IT management, not just connectivity) may be regulated as relevant managed service providers (RMSPs).
HL Bill 32, Part 2, Section 9
Part 4, Section 43 - Directions for National Security
Telecommunications providers may be subject to directions for national security purposes if threats relating to network and information systems pose a risk to national security.
HL Bill 32, Part 4, Section 43
Frequently Asked Questions
Are telecommunications providers regulated under the CSRB?
Core public electronic communications networks and services are excluded from Operator of Essential Services status under the Cyber Security and Resilience Bill by Regulation 8(1A). Telecommunications providers may still be in scope if they provide managed services, provide cloud computing services separate from core telecom services, carry on essential activities under Part 3, or are subject to directions for national security purposes under Part 4.
Are ISPs excluded from the CSRB altogether?
ISPs are not excluded from the Cyber Security and Resilience Bill altogether, because Regulation 8(1A) only removes public electronic communications networks and services from Operator of Essential Services status. Regulation 1(3A) similarly excludes them from being relevant digital services. A provider that also offers managed services, or cloud computing services separate from its core telecom services, can still be regulated as an RMSP or an RDSP.
When is a telecoms provider a Relevant Managed Service Provider?
A telecoms provider is a Relevant Managed Service Provider under Part 2, Section 9 of HL Bill 32 where it provides managed services, meaning ongoing IT management rather than connectivity alone. RMSPs must register with the Information Commission within 3 months under Regulation 14C, comply with security duties under Regulation 14B, report incidents within 24 hours and 72 hours under Regulation 14E, and notify affected customers as soon as reasonably practicable under Regulation 14G.
Can telecoms providers be given national security directions?
The Secretary of State may give telecommunications providers directions for national security purposes under Part 4, Section 43 of HL Bill 32 where threats relating to network and information systems pose a risk to national security. Directions may impose requirements about the management of systems, require the provision of information, or prohibit the use of particular goods or services. Providers subject to a direction may also face monitoring, information gathering and inspections under Sections 45 to 47.
What penalties do telecoms providers face under the CSRB?
Telecommunications providers face a higher maximum penalty of the greater of £17,000,000 and 4% of turnover for serious Part 2 failures as an RMSP or RDSP, and a standard maximum of the greater of £10,000,000 and 2% of turnover for administrative failures. Part 3 penalties do not exist yet; when regulations are made, Section 32(3) caps them at the greater of £17,000,000 and 10% of turnover. Contravening a Part 4 national security direction carries a maximum of £17,000,000, rising to the greater of £17,000,000 and 10% of turnover only once regulations under Section 49(5) are in force, plus up to £100,000 per day while the contravention continues.
Need Help with Telecommunications Cyber Security and Resilience Bill Compliance?
Our expert team helps telecommunications providers navigate Cyber Security and Resilience Bill requirements alongside existing Ofcom regulations.