SIP Trunking
Provides flexible, cost-effective and reliable voice SIP connections between your PBX and our network, replacing traditional lines. SIP Trunks can be carried over new or existing IP connectivity and support existing phone numbers. Benefits include increased flexibility, resilience, and reduced costs. SIP Trunking is suitable for businesses of all sizes.
Features
- Voice connectivity
- Operates across new or existing internet connectivity
- New co-termed channels can be added at any time
- UK-based 24/7 customer service and technical professionals
- Available on SIP enabled and ready PBXs
- End-to-end Quality of Service (QoS)
- Spend management and auto suspend tools
- Multiple resilience options available
- Optional call manager portal
- International SIP trunks
Benefits
- Extends the life of your PBX
- Removes reliance on outdated technology such as ISDN
- Increased flexibility by quickly adding new channels
- Ensures issues are resolved effectively
- Supports a wide range of PBX systems
- Ensures voice quality is maintained
- Reduced, controllable and manageable costs through channel subscription model
- Increased resilience, aiding business continuity
- Increased control of inbound and resilience options
- Support overseas offices
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 1 5 9 5 4 7 0 4 0 3 5 0 7 4
Contact
TALKTALK BUSINESS DIRECT LIMITED
Andrew Stokes
Telephone: 07976911843
Email: andrew.stokes@talktalk.business
About your service
- Service categories
-
Systems Infrastructure Software
System and service management
- IT operations management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
-
Service levels apply for TalkTalk Business connectivity only.
Recommended minimum bandwidth is 126.4 kbps.
Deployment across circuits will be subject to upstream/downstream bandwidth limits and the primary PBX codec being used.
SIP compatible PBXs only using either G. 711 or G. 729a codec standard (G.711 preferred for better voice quality). - System requirements
-
- Existing SIP compatible and ready PBX – conformance list available
- TalkTalk Business connectivity circuit of adequate bandwidth size
- Compatible SBC – conformance list available
- Authenticated IP address
- PBX must have appropriate SIP licence
User support
- Email or online ticketing support
- Yes
- Support response times
-
Incident reporting and support requests should be raised by telephone: 0333 003 4333 or via email ttbenterpriseassurance@talktalk.business. Our Assurance team aims to diagnose faults within 30 minutes. Support requests which are less time sensitive should be raised by email.
Support is available 24/7/365. All questions and queries will be acknowledged immediately upon receipt by our support teams, and we will endeavour to respond as quickly as possible during the working day.
Response Service Levels
P1: Critical Fault loss of service. Restoration 9 hours
P2: Partial loss of service. Restoration 3 working days
P3: Degradation of service. Restoration 7 working days - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- No
- Support levels
-
The service offers the following support, which is included as standard:
• P1: Critical Fault. Loss of service - 9 clock-hours’ resolution, 24/7
• P2: Partial loss of service - 3 working days’ resolution
• P3: Degradation of service - 7 working days’ resolution
Faults can be raised 24x7, 365. Each case will be allocated to a cloud support engineer who will investigate the issue and either resolve the fault directly or raise a ticket and track the support case with our suppliers. Tickets will be prioritised according to the severity of the fault reported and tracked and managed through our published fault management process.
Customers are kept regularly informed through this process.
We can be contacted via:
In hours – Monday - Friday (excl. Bank Holiday) 8:30 to 17:15
Email: systemsupport@talktalkbusiness.co.uk
Phone: 0191 493 1120, option 1 or
0800 4661234, option 1 then 3
Out of hours:
Email: b2booh@talktalkbusiness.co.uk
Phone: 0800 5426753
All customers will be allocated a named Account Manager who will have a team of dedicated technical specialists that will support on any customer requirements. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
We appoint a dedicated project coordinator, responsible for the delivery of the service.
The coordinator determines project stakeholders, contact details, design document and delivery steps.
The SIP product provides an inbound and outbound number translation but, if additional services such as SIP Trunk Call Manager or inbound services are provided, then we can offer training material[Impart1.1][AS1.2]. This will be in the form of a handbook with full details on how to start using the service, how to fully access, and all functionality through which a user can manage their own inbound numbers. We also offer an online service manual that describes how to access and all relevant material to enable to user to access the service and configure. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
The system only holds Calling Line Identification (CLI[I2.1][AS2.2]) details and IP addressing. These are never required by the customer as they are not relevant if the service is ceased.
Former customers can initiate a right-to-be-forgotten request to remove their data that is held on our customer database. This will mean all service-related data will be deleted via existing internal data cleanse processes, documented on TalkTalk’s online support centre (https://supportcentre.talktalkbusiness.co.uk/). We will also raise a data deletion request with our supplier. - End-of-contract process
-
Once out of fixed-term contract, all services [Impart3.1][AS3.2]will revert to a rolling monthly contract unless re-signed to a new fixed term. The customer will be given the option to renew. If they choose not to renew, then the service will be decommissioned.
If a service is ceased, decommissioning is not chargeable and will involve the closure of any billing activity and removal of any service-specific data on our commissioning and billing systems. We also raise a data deletion request with our supplier. Customers can initiate a right-to-be-forgotten request to remove data held on our customer database.
Current processes are documented on TalkTalk’s online support centre (https://supportcentre.talktalkbusiness.co.uk/).
The Standard SIP service and voice tariffs are included as standard however for additional cost would be any of the following:
• Call recording
• Often an add‑on with its own pricing.
• Caller ID management / reputation tools
• Can be billed separately for compliance and branding. [rockydialer.com]
• Compliance features (Do Not Call scrubbing, fraud blocking)
• Listed as add‑on cost factors by providers. [rockydialer.com]
• d. Advanced routing, failover, or QoS (premium SLAs) - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- This documentation can also be accessed via PDF which allows users with disabilities or sensory impairment to access information through functions such as text to speech and font settings.
Using the service
- Web browser interface
- No
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The optional SIP Trunk Call Manager offers a suite of inbound call handling tools, including full and direct control of your inbound numbers and implementation of routing features such as call diverts, system announcements and network-based queuing. These tools are suited to businesses that want to offer a high level of customer service, organisations looking to deal with incoming sales enquiries effectively without missing a call or organisations making a step change in the way they handle business continuity. These tools can be tailored to every individual’s needs and can be adapted instantly via web and app control.
- Accessibility standards
- None or don’t know
- Description of accessibility
-
Users access SIP through apps that hide the protocol behind a user-friendly interface. Examples include:
• VoIP softphones
• Unified communication apps (e.g., Microsoft Teams (when configured with SIP gateways))
• SIP-based messaging or video apps
Users simply:
• Log in with a SIP username/password
• Make calls, send messages, or join video sessions
• The app handles SIP signalling in the background
SIP does not carry media. It only handles:
• Call setup
• Call teardown
• Session negotiation
Actual voice/video is carried by RTP (Real-Time Transport Protocol), not SIP. - Accessibility testing
-
Although the SIP protocol itself doesn’t include accessibility criteria, any SIP‑powered communication system must follow accessibility standards if it's user‑facing. That includes User Interface Accessibility (WCAG, EN 301 549, Section 508)
For SIP softphones, VoIP clients, mobile apps, and web clients:
Tests you would run:
• Screen reader support (JAWS, NVDA, VoiceOver)
• Keyboard‑only navigation
• Clear focus indicators
• Color contrast compliance
• Resizable text / zoom compatibility
• Accessible error messages and status announcements (call failure, mute state, etc.)
Audio Accessibility
Since SIP systems are primarily voice‑driven:
Tests include:
• Volume control range
• Clear audio output without distortion
• Compatibility with assistive devices (hearing aids, TTY/TDD gateways)
• Real‑time text (RTT) interoperability
• (Many modern SIP systems support RTT over SIP/RTP.) - API
- No
- Customisation available
- No
Scaling
- Independence of resources
- Each customer will have their own PBX and a dedicated connectivity service, therefore they won’t be affected by the demands of other users. The service uses dedicated internet-based connectivity, ensuring no other (data) traffic will impede the SIP service. Deployment to existing services will be subject to upstream/downstream bandwidth limits and the primary codec of the PBX.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Service metrics and statistics can be provided via the SIP Trunk Call Manager platform. Users can sign up for daily, weekly or monthly emails containing either a CSV file of all the advanced statistics for the specified period, or a summary csv file with high-level statistics for each number within the account. Three email addresses can be designated to receive reports.
Service metrics will include:
• Call handling performance in real time
• Monitor vital key call metrics
• Call routing
• Received call statistics
• Call answer waiting times
• Volume of calls answered by set times of day. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Gamma Telecom
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Other
- Other data at rest protection approach
- Data at rest is encrypted. There is an access control policy. We also have a data security standard that details the requirements for classification, storage, use, processing and destruction of all data. The access control policy and data security standard are both internal documents, so we are unable to share them.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- The only data that will be held are contact details, endpoint locations, DDIs and IP addresses. These cannot be exported.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- Other
- Other protection within supplier network
- Call data records are transferred to TalkTalk Business from its supplier using Secure File Transfer Protocol (SFTP). SFTP ensures secure file transfers by providing a variety of alternatives for strong authentication during digital communication and data transfer. SFTP uses the Advanced Encryption Standard (AES) to encrypt data, using a mathematical process involving prime numbers to encrypt data with a specific key. Users will require both the key and login rights to access data transferred in this way.
Availability and resilience
- Guaranteed availability
-
Across the core service we report a target availability of 99.99%.
Delivered availability will be dependent on the availability of the underlying connectivity service.
Service Credits are provided in the event of not meeting the listed SLA:
• 0-12 hours – 1% of monthly recurring charges
• 12-24 hours – 2%
• 24-72 hours – 15%
• 72-120 hours – 50% - Approach to resilience
-
Data centre: Our supplier holds ISO 22301:2012 Business Continuity Management accreditation, further information on request.
By default, SIP Trunking offers a single site connection to a single Session Border Controller (SBC) High Availability cluster in the core. Customers can choose optional active/active or active/standby configurations.
Active/Active offers dual endpoints in loadshare mode working off geographically diverse, highly available connection resilience. For this configuration, all traffic will be split between two load-balanced primary SIP trunks and, in the event of failure of one of the trunks, all calls will automatically route to the second, active, trunk to ensure resilience.
Active/Standby offers dual endpoints in active/standby mode working off geographically diverse, highly available connection resilience. For this configuration, all traffic will route via a primary SIP trunk and, in the event of failure of the primary trunk, all calls will automatically route via a secondary SIP trunk. - Outage reporting
-
Incident reporting and support requests should be raised by telephone on 0333 003 4333 or via email ttbenterpriseassurance@talktalk.business. Our team aims to diagnose faults within 30 minutes. Support requests which are less time sensitive should be raised by email.
TTB will prioritise the incident according to the criteria and record the appropriate value for each of the following categories:
· Service
· Incident Type
· Work Type
· Reported Source
· Product Categorisation Tier
Our Internal and/or External Communications teams will send an email to all recipients in the Major Incident Communications Content & Distribution Lists document, describing:
· Impact
· Symptoms
· Manual workaround (if available)
· Instructions or additional information for customers and/or agents (if available)
· Provide a progress update
Email alerts will be provided in the event of a major service outage (MSO).
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- SIP Trunk Call Manager is accessed by account name and password, and management ports are managed by the supplier on their portal. This will ensure that only relevant users are able to access management interfaces and support channels, in line with the supplier’s management ports.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials
- Information security policies and processes
-
TTB has a Master Security Policy in place and operates an Information Security Management System via its Security Operations Centre (SOC) for the reporting of all potential security breaches. The system is based on industry good practice (NIST CSF, PCI DSS) and is externally certified to ISO 27001. This covers a range of policies and procedures to ensure the confidentiality, integrity and availability of information, e.g., Master Security Policy, the Privacy Policy and the GDPR Policy.
We have in place a named DPO – Adam Rogers with the responsibility for GDPR/ISO27001 policies and processes.
The reporting of any security incidents is done directly to the Security team security@talktalkplc.com via the phishing report message button in the email toolbar. All incidents logged will go into the Security Team to process and escalate into the Head of Security.
All colleagues attend mandatory annual security training, and GDPR training to ensure they meet audit standards around data handling requirements and encourage them to share the responsibility for protecting data at all times. All colleagues have set timescales for training completion and this is reported against to ensure compliance. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Service components are logged/tracked by the Gamma SIP Portal and managed by our Voice Operations team with online portal/database records kept. Current deployed services can be assessed at any time.
Our change management process is based on the ITIL Framework to assess priority class.
Our change lifecycle phases are Initiate/Review, Authorise/Plan, Schedule/Implement and Closure. Dependent on the change class, these will move through these phases throughout their lifecycle.
Raising a change generates tasks in Remedy 9 which will be allocated for approval/ rejection. Our Impact Assessment document captures the change details, with questions around security requirements/impact. - Vulnerability management type
- Undisclosed
- Vulnerability management approach
-
We scan both our on-premises and cloud infrastructure for vulnerabilities every week. Security patches will be deployed at the next available patching window (usually monthly) to address potential threats and we have a monthly governance meeting to discuss vulnerabilities remediation activities.
Our Vulnerability Manager/Threat Intel Specialist and SOC team proactively monitor security intelligence feeds and vendor announcements to gain information about potential threats. On detection, we work with Operational teams to ensure that remediation is completed. If a security advisory is deemed Critical to our infrastructure, we manage it via security incident management processes. - Protective monitoring type
- Undisclosed
- Protective monitoring approach
-
TTB operates a security incident management program for the alerting of potential compromises and deploys endpoint protection technology. The security team logs PAll potential compromises, registered on the action plan tracker and updated with notes/associated actions to mitigate risk.
Users can report Priority level 1/2 incidents by telephone, with a response given within 1 hour. Incidents can also be reported by email/web portal.
Incident reports are provided upon request. For network incidents, reports are distributed to impacted customers via email. Reason for Outage reports for priority 1 faults are provided by email within 10 working days from root cause. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Incident reporting and support requests should be raised by telephone on 0333 003 4333 or via email ttbenterpriseassurance@talktalk.business. Our team aims to diagnose faults within 30 minutes. Support requests which are less time sensitive should be raised by email.
Following incident resolution, the customer will be notified part of the logged ticket fault. Reports will be provided upon request for network incidents, and these reports distributed to impacted customers via email. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 3%
- Between £2,500,001 and £5,000,000
- 4%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- ISOQAR
- ISO/IEC 27001 accreditation date
- Tuesday 27 January 2026
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Alcumus ISOQAR
- ISO 9001 accreditation date
- Monday 26 May 2025
- What the ISO 9001 doesn’t cover
-
Exclusions:
8.3 Design and Development of products and services
7.1.5.2 Measurement traceability
Location: Gateshead - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Viking Cloud
- PCI DSS accreditation date
- Monday 3 November 2025
- What the PCI DSS doesn’t cover
- None - The Non PCI is not covered by our certification, all PCI is covered under this certification.
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 41015739-ac20-4a9f-a558-edbab61126e0
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-