UK Telecommunications (Security) Act → GSMA FS.11 / FS.19 / FS.21
The UK TSA and its Ofcom Code of Practice are prescriptive: each measure must be evidenced. This crosswalk shows how the signalling-plane measures in the Code map onto the GSMA interconnect security baselines mobile operators already implement.
Scope: TSA measures M4.01–M4.08 (signalling, roaming, and interconnect security).
| Category | UK Telecommunications (Security) Act | GSMA FS.11 / FS.19 / FS.21 | Notes |
|---|---|---|---|
| Signalling firewall | TSA CoP M4.01 | FS.11 §4 / FS.19 §4 | Filter Cat-1 messages at all interconnect borders. |
| Interconnect monitoring | TSA CoP M4.02 | FS.11 §7 / FS.19 §7 | Retain SS7/Diameter telemetry per NCSC guidance (12 months typical). |
| Roaming partner vetting | TSA CoP M4.03 | FS.11 §5 / IR.77 | Formal risk classification of roaming counterparties. |
| 5G interconnect | TSA CoP M4.05 | FS.21 §4 | SEPP required for all N32 traffic; PRINS or TLS. |
| Testing | TSA CoP M4.07 | FS.11 §6 / FS.19 §6 | Annual signalling penetration test by independent party. |
| Incident notification | TSA §105K | FS.11 §7 / FS.19 §7 | Report significant compromises to Ofcom without undue delay. |
Gaps
- TSA requires supply-chain designation (HRV vendors) beyond GSMA scope.
- TSA Tier-1 operators (>1M users) face stricter timelines than the FS.11 baseline recommends.
Key takeaways
- GSMA FS.11 / FS.19 / FS.21 provide the technical evidence base for TSA CoP compliance.
- Independent annual signalling pentest is explicit in both regimes.
- HRV supply-chain designation is TSA-specific — no GSMA equivalent.