Trinidad & Tobago TATT Cybersecurity Requirements
- 1 day ago
- 5 min read
Trinidad & Tobago: TATT Sets New Cybersecurity Requirements for Telecom and Broadcasting Operators
The Telecommunications Authority of Trinidad and Tobago (TATT) has significantly raised the cybersecurity bar for the country's licensed operators and it has done so through two separate instruments that are easy to conflate but sit at very different stages.
First, TATT has finalized its Cybersecurity Framework for Public Telecommunications Networks and Broadcasting Facilities (Final Version 1.0, published 30 January 2026, TATT Ref 2/3/68). This is an approved instrument, not a proposal it followed two rounds of public consultation and was retitled from "Guidelines" to "Framework" in its final form.
Second, and separately, TATT is consulting on a draft revision of the generic Concession the Concession for the operation of a Public Telecommunications Network and/or Provision of Public Telecommunications Service and/or Broadcasting service (Revised Draft Version 2.1, 7 January 2026, TATT Ref 2/3/73). This draft would hard wire binding cybersecurity and cybercrime conditions into the concession instrument that every operator signs.
Together, these actions move Trinidad and Tobago from voluntary guidance toward enforceable, concession level cybersecurity obligations for both telecommunications and broadcasting operators.
Regulatory context
TATT's mandate to protect consumers of telecommunications and broadcasting services flows from the Telecommunications Act, Chap. 47:31. Both instruments are anchored in that Act and in the existing concession regime, and both are explicitly tied to Trinidad and Tobago's National Cyber Security Strategy and the work of the Trinidad and Tobago Cyber Security Incident Response Team (TT-CSIRT).
The finalized Framework applies to public telecommunications networks that are based on Internet Protocol (IP) or that provide connectivity to the Internet, and to broadcasting facilities. It deliberately does not cover end user (subscriber side) security, nor redundancy against loss of facilities from natural disasters or other force majeure events. It classifies each measure as either Required (compulsory) or Recommended (voluntary). Most measures are recommended best practice, but a defined subset is compulsory.
The draft Concession revision takes a complementary path: rather than a standalone guidance document, it embeds cybersecurity and cybercrime as enforceable concession conditions (draft conditions A46–A48), alongside strengthened emergency telecommunications and disaster recovery conditions (draft conditions A35–A39).
Breaking down the TATT cybersecurity requirements
The most consequential obligations across the two instruments are:
24-hour incident notification. Under the finalized Framework (Required Measure 17), operators must notify TATT within 24 hours of any meaningful cybersecurity incident. This is the source of the widely reported "24-hour" figure it lives in the finalized Framework, not in the draft Concession.
Full incident report on a 5/7 day clock. Under the Framework (Required Measure 18) and mirrored in the draft Concession (A47(e)): where an incident is resolved within five days, the full report is due no later than five days after resolution; where it runs longer than five days, the report is due within seven days of the incident's start. Reports use TATT's prescribed template and cover the nature, services affected, scope, customer notification plan, and resolution timeframe.
Cybersecurity plan within one year. Operators must prepare and submit a cybersecurity plan or independent certification of its existence within one year of being directed to do so by TATT (Framework Required Measure 14), and must review that plan at least annually or when a major threat emerges (Required Measure 15).
Annual conformance reporting potentially public. Operators must file an annual conformance report indicating whether they are fully, partially, or non conformant with each measure (Framework Required Measure 27). Notably, TATT does not treat an operator's overall conformance level as confidential and may publish it.
Five year data preservation (cybercrime). The draft Concession (A48) requires operators, on actual knowledge of content giving rise to criminal liability, to preserve the relevant data message and associated traffic data for no less than five years for law enforcement purposes, in addition to content takedown and law enforcement cooperation duties.
Risk based, secure by design obligations. The draft Concession (A47(a)–(b)) requires proportionate measures to identify, monitor, reduce, and mitigate network security risks, and to design, redevelop, and maintain networks so as to reduce the risk of security compromises.
Strengthened resilience and emergency conditions. The draft Concession (A39) requires disaster resilient facilities plus up to date disaster recovery and business continuity plans, and (A35–A38) modernizes emergency communications obligations.
Enforcement has real teeth. Failure to submit the conformance report, or to comply with a Required measure, may be deemed a breach of concession, exposing the operator to suspension or termination of the concession under condition A25. A breach of the Act itself can also trigger an offence provision. A widely cited figure places the maximum fine under section 71 of the Act at TT$25,000 this comes from secondary reporting and should be checked against the Act text before publication.

What this means for manufacturers
An important clarification for equipment makers, importers, and test labs: these instruments impose obligations on network operators and broadcasters (concessionaires) not directly on device manufacturers. Neither the finalized Framework nor the draft Concession revision creates a new device type approval or equipment certification requirement. Trinidad and Tobago's equipment certification and type approval regime (under sections 32, 45, and 48 of the Telecommunications Act) is untouched by these cybersecurity measures.
That said, the commercial impact on the equipment supply chain is real and flows downstream through operator procurement:
Vendor security becomes a purchasing condition. Framework Required Measure 21 obliges operators to ensure that their significant vendors and the equipment, software, and systems those vendors supply are secure and monitored, in accordance with standards TATT may establish. The Framework's supporting 10 point vendor management guidance expects operators to define security standards in procurement documents and RFPs, require third party testing/verification, embed security hardening in SLAs, and run vendor risk reviews and security assessments at least every three years.
Named schemes become de facto commercial expectations. The Framework references the GSMA Network Equipment Security Assessment Scheme (NESAS), TIA SCS 9001 (Cyber and Supply Chain Security), the GSMA Baseline Security Controls, and for media/broadcast vendors EBU Recommendation R 143. Vendors that already hold or map to these are better positioned in TT tenders.
ISO/IEC alignment matters. TATT recommends operators adopt ISO/IEC 27001 under the controls in ITU-T X.1051 (ISO/IEC 27011). The Trinidad and Tobago Bureau of Standards (TTBS) has adopted these as national standards (TTS/ISO/IEC 27001:2024 and 27002:2024), so supplier evidence framed against these standards will be recognized locally.
Certification impact summary
Area | Impact on equipment vendors / test labs | Status |
Device type approval / equipment certification | No change. Existing TATT type approval regime (Act ss. 32, 45, 48) is not altered by either instrument. | Unchanged |
Vendor security assurance | Operators must ensure vendor supplied equipment, software, and systems are secure and monitored (Framework Required Measure 21). Expect security requirements in RFPs, SLAs, and periodic (≥3-yearly) vendor assessments. | Finalized (Framework v1.0) |
Recognized assurance schemes | NESAS, SCS 9001, GSMA Baseline Security Controls, EBU R 143 (media vendors) referenced; holding/mapping to these strengthens tender positioning. | Finalized |
National standards alignment | ISO/IEC 27001 + ITU-T X.1051 recommended; adopted locally as TTS/ISO/IEC 27001:2024 / 27002:2024 via TTBS. | Finalized |
Operator level obligations that shape demand | 24-hour notification, 5-/7-day incident reports, annual conformance reporting, cybersecurity plans, 5 year data preservation. | Framework final; concession conditions in draft |
Timeline and required actions
Date / trigger | Event or required action | Instrument |
29 Oct 2024 – 13 Dec 2024 | First consultation round (as "Guidelines" v0.1) | Framework (Ref 2/3/68) |
21 May 2025 – 14 Jul 2025 | Second consultation round (v0.2) | Framework (Ref 2/3/68) |
14 Nov 2025 | Revised draft Concession issued (Version 2.0) | Concession (Ref 2/3/73) |
7 Jan 2026 | Revised draft Concession adjusted after targeted stakeholder consultation (Version 2.1) | Concession (Ref 2/3/73) |
30 Jan 2026 | Cybersecurity Framework finalized (Version 1.0) in effect as TATT's framework | Framework (Ref 2/3/68) |
Consultation close for draft Concession revision | closing date not confirmed against a primary TATT source | Concession (Ref 2/3/73) |
Within 1 year of TATT direction | Operators submit cybersecurity plan or independent certification | Framework Required Measure 14 |
Annually thereafter | Review cybersecurity plan; file conformance report (may be published) | Framework Required Measures 15, 27 |
Per incident | Notify TATT within 24 hours; file full report on 5/7 day clock | Framework Required Measures 17–18; Concession A47(d)–(e) |
