ININCA
Supply Chain Knowledge Base & Attestation Builder Prototype

The third-party supplier shared responsibility model, made clickable

The full model is on the left tab: the Provider is responsible for security and reliant on its suppliers, across four phases from scoping to resilience. Click any action to see where it sits in the regulatory framework and to record your own position against it.

Tier 1 operators cascade their Telecommunications (Security) Act requirements to suppliers one by one, so smaller suppliers face the prospect of multiple, inconsistent interpretations of what they must do to keep supplying.[5] The right tab turns your position into a single, sourced attestation, scaled to your size and role, that any Tier 1 can accept.

The regulatory basis, and how proportionality works
  • Public telecoms providers hold security duties under the Communications Act 2003, ss 105A to 105D, inserted by the Telecommunications (Security) Act 2021.[1]
  • The specific measures sit in the Electronic Communications (Security Measures) Regulations 2022. Supply chain is regulation 7: the provider takes "appropriate and proportionate" measures to require its third-party suppliers to identify, disclose and reduce security risks, with reg 7(4)(a)(ii) where a supplier is itself a network provider with access to sensitive data or equipment.[2]
  • Micro-entities are exempt from the specific measures under regulation 16.[2]
  • The Telecommunications Security Code of Practice is tiered by relevant turnover: Tier 1 (£1bn+), Tier 2 (£50m to under £1bn), Tier 3 (under £50m, not a micro-entity). Tier 3 providers are not expected to follow the Code's detailed measures but may adopt them where appropriate and proportionate.[3]
  • The Code contains 78 Third Party Supplier Measures the in-scope provider works through with each supplier.[4]

Green is the responsible Provider. Slate are the parties it is reliant on. Click any action for detail and to record a status.

Model structure: Business Secure, third-party supplier shared responsibility model (supplied by member). Actions reproduced as given; framework mapping and citations added.

1. Profile your organisation

This sets which actions apply, scales the model on the other tab, and frames the attestation.

Yes if you operate a public network or service of your own, for example a wholesale altnet. This decides whether you hold direct duties or are assured purely through contract.
Used to scale the attestation. Tier 3 and micro-entities are treated proportionately.
Select all that apply. These are the columns of the model that apply to you.
Add an organisation name, your provider status, scale and at least one role to continue.