Telecoms | UK Regulatory Outlook September 2026
Published on 28 September 2026
Ofcom publishes call for input on UK preparations for the World Radiocommunication Conference 2027 | Ofcom publishes guidance on combatting scam mobile messages | Government publishes Call for Evidence on the Telecommunications (Security) Act 2021
Ofcom publishes call for input on UK preparations for the World Radiocommunication Conference 2027
On 1 September 2026, Ofcom published a call for input on UK provisional views and positions for the World Radiocommunication Conference 2027 (WRC-27), with a closing date for responses of 24 November 2026. The WRC-27 will take place in Shanghai, China from 18 October to 12 November 2027; Ofcom is leading the UK delegation at the WRC and in all preparatory work.
Ofcom is gathering industry views before it confirms the UK's negotiating positions. The WRC-27 agenda covers approximately 30 agenda items, grouped by Ofcom into broad subject areas:
- Satellites and earth station connectivity
- Mobile connectivity
- Environmental monitoring
- Space exploration and science
- Other subjects and standing agenda items
Issues include satellite matters (such as a regulatory framework for direct-to-direct satellite services to mobile phones) and future mobile broadband spectrum for increased network capacity.
The following agenda items are rated high UK priorities:
Agenda item 1.13 (direct-to-direct (D2D) services): This addresses direct connectivity between satellites and standard smartphones (so-called D2D services) in mobile spectrum bands between 694 MHz and 2.7 GHz. While the UK has already enabled D2D services domestically following Ofcom's 2025 decision, WRC-27 aims to develop a global regulatory framework to provide a proper international legal basis (removing reliance on the interim RR No. 4.4 mechanism) and harmonised technical conditions. Ofcom's preliminary position is to support new international allocations to the mobile-satellite service in IMT-identified bands, while ensuring terrestrial mobile networks are protected.
Agenda item 1.7 (potential identification of additional frequency ranges for International Mobile Telecommunications (IMT)): The frequency ranges being considered are:
- 4400-4800 MHz (Region 1 and Region 3)
- 7125-7250 MHz
- 7250-8400 MHz (excluding the portion from 7250 to 7750 MHz in Region 1)
- 8-15.35 GHz
Ofcom did not support this agenda item being included for WRC-27 but is currently minded to support the identification in the 7125-7250 MHz frequency range. With regard to the other frequency ranges, Ofcom has concerns regarding protection of military systems as well as coexistence challenges with satellite earth station receivers and high-resolution data downlinks.
Deadline for responses to Ofcom's call for input: 24 November 2026 at 5pm
Ofcom publishes guidance on combatting scam mobile messages
On 15 July 2026, Ofcom published its guidance on protecting people and businesses from scam mobile messages. The guidance applies in two stages: from 18 January 2027 in respect of person-to-person (P2P) messages, and from 15 July 2027 in respect of application-to-person (A2P) messages.
Under the Communications Act 2003, Ofcom has powers to prevent misuse of telecoms services (including mobile messaging) for fraud and scams.
To reduce the risk of people and businesses receiving scam P2P and A2P messages, Ofcom has introduced rules set out in General Condition (GC) C9 and Non-Provider Condition 3. The guidance applies to a range of providers, including: mobile network operators (MNOs); thick MVNOs (which use their own short message service centres); thin MVNOs (which rely on their host MNO); tier 1 aggregators (which have a direct contractual relationship with a mobile operator); and lower-tier aggregators (which do not contract directly with a mobile operator for termination). The rules each provider must comply with are specific to its role in the delivery of mobile messages, the channels over which messages are sent, and whether the provider assigns mobile numbers to customers.
Although the guidance is not legally binding, Ofcom has indicated that it will take it into account both when deciding whether to open a compliance investigation and when determining the appropriate enforcement response.
The guidance addresses three main areas of requirements:
P2P messaging
Providers must:
- receive and act on scam reports from customers and third parties (including via the 7726 database and the Cyber Defence Alliance);
- block numbers and messages, including where there are reasonable grounds to believe they have been used to scam recipients; and
- apply volume limits to Pay As You Go customers, with automated blocking where limits are exceeded.
A2P messaging
Providers must:
- receive and act on scam reports from end-users and appropriate third parties;
- block A2P messages that contain URLs or Telephone Numbers which they reasonably believe were used as part of a scam
- conduct robust Know Your Customer (KYC) checks on business senders at onboarding;
- verify and control the use of alphanumeric Sender IDs, including by restricting access to "Protected" IDs associated with high-risk brands;
- carry out ongoing Know Your Traffic (KYT) monitoring;
- impose equivalent obligations on third parties by contract; and manage incidents (including Significant Scams Incidents) within defined timeframes (one to five working days depending on the complexity of the supply chain involved).
Obligations applying to both P2P and A2P
All providers must:
- maintain a publicised right to challenge process for blocked numbers or messages;
- regularly review the effectiveness of their policies;
- train all relevant staff; keep records for defined retention periods (ranging from 12 months to five years depending on the category);
- monitor and address false positives; and ensure compliance with UK GDPR, the Data Protection Act 2018 and Privacy and Electronic Communications Regulations (PECR) in implementing any blocking or intelligence-sharing measures.
Non-compliance can result in financial penalties of up to 10% of annual turnover, directions to remediate, suspension of the right to provide networks or services, and withdrawal of number allocations.
GC C9 and Non-Provider Condition 3 obligations take effect for P2P mobile messages: 18 January 2027
GC C9 and Non-Provider Condition 3 obligations take effect for A2P mobile messages: 15 July 2027
Government publishes Call for Evidence on the Telecommunications (Security) Act 2021
On 17 August 2026, the Department for Digital, Culture, Media and Sport and the Department for Science, Innovation and Technology published a call for evidence on the impact and effectiveness of sections 1 to 13 of the Telecommunications (Security) Act 2021. This forms part of the secretary of state's statutory duty under section 14 of the 2021 Act to review the framework and lay a report before Parliament.
The 2021 Act framework, which emerged from the 2019 Telecoms Supply Chain Review, comprises three elements:
- Telecoms Security Act 2021: Overarching security duties on public telecoms providers to identify and reduce the risk of security compromises, prepare for their occurrence, prevent adverse effects, and remedy or mitigate such effects where they arise.
- The Electronic Communications (Security Measures) Regulations 2022: secondary legislation setting out specific security measures and the application to different tiers of provider.
- Telecommunications Code of Practice: guidance on the measures tier 1 and tier 2 providers should take to meet their legal obligations.
- Provisions to ensure Ofcom can effectively monitor and enforce providers' compliance with their legal obligations.
The call for evidence seeks views from all stakeholders who have engaged with the framework, with a particular focus on public telecoms providers. Respondents are asked to address the framework's effectiveness against its policy objectives, which include achieving higher security standards, protecting network availability, confidentiality, integrity and authenticity, and enabling effective enforcement — but should not comment on pre-existing obligations or business-as-usual security improvements.
Responses must be submitted via an online survey, with supplementary material sent by email in Word format.
The secretary of state is under a statutory duty under section 14 of the 2021 Act to carry out this review and lay a report before Parliament. Responses to the questions will support the government's assessment of "how effectively the 2021 Act is operating in line with its intended policy objectives".
Information provided in response to the call for evidence, including personal information, may be disclosed in accordance with UK legislation including the Freedom of Information Act 2000, the Data Protection Act 2018 and the Environmental Information Regulations 2004. Confidentiality cannot be guaranteed in all circumstances; providers wishing to protect commercially sensitive information should consider carefully what they submit.
Public telecoms providers should consider responding to the call for evidence to provide support to the framework or constructive comments if there have been challenges in implementing the framework in their business. In particular, managed service providers who may also be caught by the Cyber Security Resilience Bill might want to comment on how the government expects these two pieces of security legislation to operate together.
Deadline for responses: 12 October 2026 at 11:59pm