UK Telecommunications (Security) Act → GSMA FS.11 / FS.19 / FS.21

The UK TSA and its Ofcom Code of Practice are prescriptive: each measure must be evidenced. This crosswalk shows how the signalling-plane measures in the Code map onto the GSMA interconnect security baselines mobile operators already implement.

Scope: TSA measures M4.01–M4.08 (signalling, roaming, and interconnect security).

CategoryUK Telecommunications (Security) ActGSMA FS.11 / FS.19 / FS.21Notes
Signalling firewallTSA CoP M4.01FS.11 §4 / FS.19 §4Filter Cat-1 messages at all interconnect borders.
Interconnect monitoringTSA CoP M4.02FS.11 §7 / FS.19 §7Retain SS7/Diameter telemetry per NCSC guidance (12 months typical).
Roaming partner vettingTSA CoP M4.03FS.11 §5 / IR.77Formal risk classification of roaming counterparties.
5G interconnectTSA CoP M4.05FS.21 §4SEPP required for all N32 traffic; PRINS or TLS.
TestingTSA CoP M4.07FS.11 §6 / FS.19 §6Annual signalling penetration test by independent party.
Incident notificationTSA §105KFS.11 §7 / FS.19 §7Report significant compromises to Ofcom without undue delay.

Gaps

  • TSA requires supply-chain designation (HRV vendors) beyond GSMA scope.
  • TSA Tier-1 operators (>1M users) face stricter timelines than the FS.11 baseline recommends.

Key takeaways

  • GSMA FS.11 / FS.19 / FS.21 provide the technical evidence base for TSA CoP compliance.
  • Independent annual signalling pentest is explicit in both regimes.
  • HRV supply-chain designation is TSA-specific — no GSMA equivalent.