top of page

Trinidad & Tobago TATT Cybersecurity Requirements

  • 1 day ago
  • 5 min read

Trinidad & Tobago: TATT Sets New Cybersecurity Requirements for Telecom and Broadcasting Operators


The Telecommunications Authority of Trinidad and Tobago (TATT) has significantly raised the cybersecurity bar for the country's licensed operators and it has done so through two separate instruments that are easy to conflate but sit at very different stages.

First, TATT has finalized its Cybersecurity Framework for Public Telecommunications Networks and Broadcasting Facilities (Final Version 1.0, published 30 January 2026, TATT Ref 2/3/68). This is an approved instrument, not a proposal it followed two rounds of public consultation and was retitled from "Guidelines" to "Framework" in its final form.


Second, and separately, TATT is consulting on a draft revision of the generic Concession the Concession for the operation of a Public Telecommunications Network and/or Provision of Public Telecommunications Service and/or Broadcasting service (Revised Draft Version 2.1, 7 January 2026, TATT Ref 2/3/73). This draft would hard wire binding cybersecurity and cybercrime conditions into the concession instrument that every operator signs.

Together, these actions move Trinidad and Tobago from voluntary guidance toward enforceable, concession level cybersecurity obligations for both telecommunications and broadcasting operators.


Regulatory context


TATT's mandate to protect consumers of telecommunications and broadcasting services flows from the Telecommunications Act, Chap. 47:31. Both instruments are anchored in that Act and in the existing concession regime, and both are explicitly tied to Trinidad and Tobago's National Cyber Security Strategy and the work of the Trinidad and Tobago Cyber Security Incident Response Team (TT-CSIRT).

The finalized Framework applies to public telecommunications networks that are based on Internet Protocol (IP) or that provide connectivity to the Internet, and to broadcasting facilities. It deliberately does not cover end user (subscriber side) security, nor redundancy against loss of facilities from natural disasters or other force majeure events. It classifies each measure as either Required (compulsory) or Recommended (voluntary). Most measures are recommended best practice, but a defined subset is compulsory.

The draft Concession revision takes a complementary path: rather than a standalone guidance document, it embeds cybersecurity and cybercrime as enforceable concession conditions (draft conditions A46–A48), alongside strengthened emergency telecommunications and disaster recovery conditions (draft conditions A35–A39).


Breaking down the TATT cybersecurity requirements


The most consequential obligations across the two instruments are:


  • 24-hour incident notification. Under the finalized Framework (Required Measure 17), operators must notify TATT within 24 hours of any meaningful cybersecurity incident. This is the source of the widely reported "24-hour" figure it lives in the finalized Framework, not in the draft Concession.

  • Full incident report on a 5/7 day clock. Under the Framework (Required Measure 18) and mirrored in the draft Concession (A47(e)): where an incident is resolved within five days, the full report is due no later than five days after resolution; where it runs longer than five days, the report is due within seven days of the incident's start. Reports use TATT's prescribed template and cover the nature, services affected, scope, customer notification plan, and resolution timeframe.

  • Cybersecurity plan within one year. Operators must prepare and submit a cybersecurity plan or independent certification of its existence within one year of being directed to do so by TATT (Framework Required Measure 14), and must review that plan at least annually or when a major threat emerges (Required Measure 15).

  • Annual conformance reporting potentially public. Operators must file an annual conformance report indicating whether they are fully, partially, or non conformant with each measure (Framework Required Measure 27). Notably, TATT does not treat an operator's overall conformance level as confidential and may publish it.

  • Five year data preservation (cybercrime). The draft Concession (A48) requires operators, on actual knowledge of content giving rise to criminal liability, to preserve the relevant data message and associated traffic data for no less than five years for law enforcement purposes, in addition to content takedown and law enforcement cooperation duties.

  • Risk based, secure by design obligations. The draft Concession (A47(a)–(b)) requires proportionate measures to identify, monitor, reduce, and mitigate network security risks, and to design, redevelop, and maintain networks so as to reduce the risk of security compromises.

  • Strengthened resilience and emergency conditions. The draft Concession (A39) requires disaster resilient facilities plus up to date disaster recovery and business continuity plans, and (A35–A38) modernizes emergency communications obligations.


Enforcement has real teeth. Failure to submit the conformance report, or to comply with a Required measure, may be deemed a breach of concession, exposing the operator to suspension or termination of the concession under condition A25. A breach of the Act itself can also trigger an offence provision. A widely cited figure places the maximum fine under section 71 of the Act at TT$25,000 this comes from secondary reporting and should be checked against the Act text before publication.


Infographic summarizing Trinidad & Tobago's TATT cybersecurity regulatory updates and their impact on equipment manufacturers.

What this means for manufacturers


An important clarification for equipment makers, importers, and test labs: these instruments impose obligations on network operators and broadcasters (concessionaires) not directly on device manufacturers. Neither the finalized Framework nor the draft Concession revision creates a new device type approval or equipment certification requirement. Trinidad and Tobago's equipment certification and type approval regime (under sections 32, 45, and 48 of the Telecommunications Act) is untouched by these cybersecurity measures.

That said, the commercial impact on the equipment supply chain is real and flows downstream through operator procurement:


  • Vendor security becomes a purchasing condition. Framework Required Measure 21 obliges operators to ensure that their significant vendors and the equipment, software, and systems those vendors supply are secure and monitored, in accordance with standards TATT may establish. The Framework's supporting 10 point vendor management guidance expects operators to define security standards in procurement documents and RFPs, require third party testing/verification, embed security hardening in SLAs, and run vendor risk reviews and security assessments at least every three years.

  • Named schemes become de facto commercial expectations. The Framework references the GSMA Network Equipment Security Assessment Scheme (NESAS), TIA SCS 9001 (Cyber and Supply Chain Security), the GSMA Baseline Security Controls, and for media/broadcast vendors EBU Recommendation R 143. Vendors that already hold or map to these are better positioned in TT tenders.

  • ISO/IEC alignment matters. TATT recommends operators adopt ISO/IEC 27001 under the controls in ITU-T X.1051 (ISO/IEC 27011). The Trinidad and Tobago Bureau of Standards (TTBS) has adopted these as national standards (TTS/ISO/IEC 27001:2024 and 27002:2024), so supplier evidence framed against these standards will be recognized locally.


Certification impact summary


Area

Impact on equipment vendors / test labs

Status

Device type approval / equipment certification

No change. Existing TATT type approval regime (Act ss. 32, 45, 48) is not altered by either instrument.

Unchanged

Vendor security assurance

Operators must ensure vendor supplied equipment, software, and systems are secure and monitored (Framework Required Measure 21). Expect security requirements in RFPs, SLAs, and periodic (≥3-yearly) vendor assessments.

Finalized (Framework v1.0)

Recognized assurance schemes

NESAS, SCS 9001, GSMA Baseline Security Controls, EBU R 143 (media vendors) referenced; holding/mapping to these strengthens tender positioning.

Finalized

National standards alignment

ISO/IEC 27001 + ITU-T X.1051 recommended; adopted locally as TTS/ISO/IEC 27001:2024 / 27002:2024 via TTBS.

Finalized

Operator level obligations that shape demand

24-hour notification, 5-/7-day incident reports, annual conformance reporting, cybersecurity plans, 5 year data preservation.

Framework final; concession conditions in draft


Timeline and required actions


Date / trigger

Event or required action

Instrument

29 Oct 2024 – 13 Dec 2024

First consultation round (as "Guidelines" v0.1)

Framework (Ref 2/3/68)

21 May 2025 – 14 Jul 2025

Second consultation round (v0.2)

Framework (Ref 2/3/68)

14 Nov 2025

Revised draft Concession issued (Version 2.0)

Concession (Ref 2/3/73)

7 Jan 2026

Revised draft Concession adjusted after targeted stakeholder consultation (Version 2.1)

Concession (Ref 2/3/73)

30 Jan 2026

Cybersecurity Framework finalized (Version 1.0) in effect as TATT's framework

Framework (Ref 2/3/68)

Consultation close for draft Concession revision

closing date not confirmed against a primary TATT source

Concession (Ref 2/3/73)

Within 1 year of TATT direction

Operators submit cybersecurity plan or independent certification

Framework Required Measure 14

Annually thereafter

Review cybersecurity plan; file conformance report (may be published)

Framework Required Measures 15, 27

Per incident

Notify TATT within 24 hours; file full report on 5/7 day clock

Framework Required Measures 17–18; Concession A47(d)–(e)


bottom of page