UK Critical Third Parties Regime: 13 July 2026 Go-Live
On 13 July 2026 the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority begin overseeing the first firms brought inside the UK Critical Third Parties regime. HM Treasury announced the designations three days earlier, on 10 July 2026, but the designations themselves take legal effect only from 13 July 2026, the same day oversight begins: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd, and Oracle Corporation UK Limited become Critical Third Parties (CTPs) that day. Under the new regime, the three financial regulators directly oversee designated providers for the resilience of their systemic third-party services, but designation is not authorisation.
This matters on two sides of the same contract. For the four designated providers, a new set of resilience, assurance and incident-reporting obligations now applies to the systemic services they supply to UK finance. For the banks, insurers, payment firms and market infrastructures that depend on those services, the temptation is to assume the regulators have taken the third-party problem off their plate. They have not. The designation changes who the regulators can talk to directly. It leaves every existing obligation exactly where it was, on the regulated firm.
The regime rests on powers added to the Financial Services and Markets Act 2000 by FSMA 2023, with the operative rules finalised in November 2024 and in force from 1 January 2025. What happened this month is operationalisation: the first designations, and the switch from a dormant rulebook to a live supervisory relationship.
Related reading: our guide to PRA Supervisory Statement SS2/21 on outsourcing and third-party risk management, which sets out the notification and register duties that continue to sit with UK firms regardless of any CTP designation.
The dates that decide your workload
The CTP regime has a long runway behind it and one firm-side deadline still ahead. Keeping the calendar straight is the difference between a resilience programme that anticipates the change and one that reacts to it.
- 21 March 2024: HM Treasury publishes its approach to designating Critical Third Parties.
- 12 November 2024: the Bank, PRA and FCA publish the final CTP rules and policy (PRA PS16/24 and FCA PS24/16).
- 1 January 2025: the CTP rules come into effect. They apply to a provider immediately once Treasury designates it.
- January 2026: the European Supervisory Authorities and the UK financial authorities sign a Memorandum of Understanding on cross-border coordination and information sharing over critical ICT third parties.
- 10 July 2026: HM Treasury announces the first four CTP designations, taking legal effect from 13 July 2026.
- 13 July 2026: the designation regulations take effect, the four providers formally become CTPs, and joint oversight by the three regulators begins.
- 18 March 2027: separate FCA rules on operational incident and material third-party reporting (PS26/2) come into force for firms.
For regulated-firm reporting teams, 18 March 2027 is the principal new firm-side build date in this timeline. The four CTPs have separate implementation milestones after designation: an interim self-assessment within three months, annual self-assessments, regular scenario testing (the CTP rules set no fixed minimum frequency for this, unlike the incident-management playbook exercise), and a first incident-management playbook exercise within 12 months followed by exercises at least biennially. These CTP deadlines do not remove any existing firm-level obligation.
Who Treasury designated under the UK Critical Third Parties regime
Treasury named four legal entities: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd, and Oracle Corporation UK Limited. Rachel Blake MP, Economic Secretary to the Treasury and City Minister, framed the designations as protecting the resilience of services financial firms rely on while supporting growth.
Read the scope carefully. The legal entity is designated, but regulatory oversight is confined to the systemic third-party services it provides to UK financial firms and financial market infrastructures. Treasury expressly states that the regime does not extend to the provider’s wider operations. The public designation does not, by itself, mean that every product or service offered by the designated legal entity is a systemic third-party service.
The second distinction is designation versus authorisation. The CTP regime brings a designated provider under resilience-focused oversight for the systemic services it supplies to UK finance, without conferring authorisation or any regulated permission. A CTP may nevertheless be subject to the FCA Handbook in another capacity, including as an authorised person. The designation must not be presented as regulatory approval or endorsement.
The list is open-ended. The regime is rolling, and there is no statutory ceiling on the number of CTPs. Further designations or revocations may follow under the statutory process. Regulatory recommendations are expected to be the usual route to designation, but Treasury’s published approach states that it may designate without a recommendation.
The statutory plumbing: FSMA 2023 and the section 312L test
The powers live in Part 18, Chapter 3C of FSMA 2000, inserted by FSMA 2023. Under section 312L, Treasury may designate a person providing services to authorised persons, relevant service providers or financial market infrastructure entities where, in Treasury’s opinion, failure or disruption of those services could threaten the stability of, or confidence in, the UK financial system. Treasury must have regard to the materiality of the services to essential activities, services or operations and to the number and type of financial entities receiving them. The test is therefore systemic and concentration-sensitive.
The division of labour is worth committing to memory because three bodies plus a government department are involved. Treasury decides who is designated, and any future designation or de-designation. The regulators do the supervising, periodically review whether a CTP still meets the designation criteria, make recommendations to Treasury, and evaluate whether the oversight approach is working. So the decision to bring a provider in, or let one out, is a Treasury call informed by regulatory advice, while the day-to-day oversight is the regulators’. Firms that want to understand why a particular provider was or was not designated should look to Treasury’s published approach, which sets out the designation criteria.
What a designated CTP has to do from now
The obligations sit in the FCA CTP sourcebook and substantively aligned PRA and Bank rules, supported by joint supervisory material. They are broader than three ongoing reporting tasks: a designated CTP must comply with six Fundamental Rules, eight Operational Risk and Resilience Requirements, information and notification duties, self-assessment, testing and exercise requirements, record-keeping, and a UK address-for-service requirement. The following three items are reporting-team touchpoints, not an exhaustive statement of the regime.
First, provide regular assurance, information and notifications to the regulators about the systemic services it supplies. This is a standing relationship, not a one-off filing. The regulators expect a repeatable flow of evidence about how the service is run and how its resilience is maintained.
Second, a CTP must carry out regular scenario testing of each systemic third-party service; the CTP rules set no fixed minimum frequency for this, unlike the incident-management playbook exercise. Separately, the CTP must run its first incident-management playbook exercise within 12 months of designation and at least biennially thereafter, using a representative sample of firms receiving systemic third-party services. Participation must be open to all such firms, but the regulators have not made firm participation mandatory. Scenario testing and playbook exercises are distinct requirements; only the playbook exercise involves direct participation by dependent firms.
Third, notify the regulators and affected firms of a CTP operational incident. The final CTP rules use an actual-impact test rather than defining reportability solely by reference to event types. This provider-level reporting channel sits alongside any incident-reporting duty that applies separately to an affected regulated firm. DORA’s major ICT-incident reporting duty is imposed on EU financial entities, not on critical ICT third-party providers, so it is not a direct equivalent of the UK CTP reporting rule.
Where this leaves the firms that rely on the cloud
The FCA put the point in one sentence in its go-live statement: the regime complements existing outsourcing and operational resilience rules, and does not replace them. Regulated firms remain responsible for managing their own third-party arrangements, including due diligence, risk management and contingency planning. Designation of a provider discharges none of that.
This is where I see teams reach for the wrong conclusion. The reasoning goes: the regulator now supervises AWS directly, so my own assurance work over AWS can shrink. That inverts the regime. A CTP designation gives the regulators a lever over systemic resilience at the provider; it says nothing about whether your particular workloads, your configuration, your exit plan and your contingency arrangements are sound. Your operational resilience obligations are measured against your own important business services, not against the provider’s designation status.
Those firm-level obligations already bite hard. Under SYSC 15A of the FCA Handbook, delivered through PS21/3, firms in scope must identify their important business services, set impact tolerances for each, and map and test to find and fix vulnerabilities. Those rules came into force on 31 March 2022, and the transitional period during which firms had to reach the point of being able to stay within their impact tolerances in severe but plausible scenarios ran to 31 March 2025. That transitional runway has closed. The expectation now is steady-state: a firm demonstrating, and continuing to invest to maintain, the ability to remain within tolerance even when a key third party fails.
The outsourcing and third-party risk management framework runs alongside operational resilience as a separate discipline. Before 18 March 2027, SS2/21 expects banks to maintain a register of outsourcing arrangements, while PRA notification requirements apply to material outsourcing arrangements. From 18 March 2027, PS7/26 and the updated SS2/21 introduce notification and annual-register requirements for material third-party arrangements. CTP designation does not displace either the current or the incoming firm-level requirements, though it is a prompt to revisit where the provider supports important business services.
The firm-side reporting that lands in March 2027
The forward deadline that belongs on a UK reporting calendar is PS26/2, the FCA’s policy statement on operational incident and third-party reporting, published on 18 March 2026 with rules coming into force on 18 March 2027. It is a distinct regime from the CTP rules, and it is the one that generates new returns for firms.
PS26/2 does two things. It defines an operational incident and sets thresholds for when a firm must report one, and it requires firms to notify the regulator of new or significantly changed material third-party arrangements and to maintain a register of those arrangements that is submitted to the FCA annually. The operational incident reporting reaches broadly, covering firms with Part 4A permissions, payment service providers, UK recognised investment exchanges, registered trade repositories and registered credit rating agencies. The material third-party reporting is narrower, aimed at enhanced-scope Senior Managers and Certification Regime firms, banks and building societies, designated investment firms, Solvency II firms, large CASS firms, UK recognised investment exchanges, authorised e-money and payment institutions, and consolidated tape providers.
The annual material third-party register is the artefact to plan for. If that structure sounds familiar to anyone tracking Europe, it should: our walkthrough of the DORA register of information covers the EU equivalent, and firms operating on both sides of the Channel will be maintaining two registers to two different specifications. One cannot simply be repurposed wholesale as the other.
How the UK regime lines up against DORA
The UK CTP regime is a domestic framework under FSMA, and it is a Brexit-era divergence point worth stating plainly: it is not the UK’s implementation of the EU’s Digital Operational Resilience Act. DORA, Regulation (EU) 2022/2554, gives the European Supervisory Authorities an oversight role over ICT third-party providers designated as critical to the EU financial sector, with one ESA acting as Lead Overseer for each critical provider. The UK built a corresponding but separate regime, with Treasury as the designating body in place of the ESAs.
The mechanics differ in ways that matter for a group operating in both jurisdictions. Under DORA Article 31(12), an EU financial entity may use the services of a critical ICT third-party provider established in a third country only if the provider establishes an EU subsidiary within 12 months of designation. DORA also permits the Lead Overseer to exercise oversight powers at third-country premises, under Article 36, where the statutory conditions for an inspection outside the Union are met. The UK regime does not require a UK subsidiary, although every CTP must provide a UK address for service. A provider may be designated under DORA, under the UK regime, under both, or under neither; the obligations remain separate.
The two systems are stitched together at the supervisory level. In January 2026 the ESAs and the UK financial authorities signed a Memorandum of Understanding on cooperation, exchange of information and coordination of oversight for critical ICT third parties operating across the EU and the UK. It is a coordination instrument, not a mutual-recognition one. It helps the authorities avoid working at cross purposes over the same global provider; it does not let a provider or a firm treat compliance in one bloc as compliance in the other.
Three regulators, one provider: the coordination question
A single cloud provider now answers to the Bank, the PRA and the FCA at once. FSMA requires the three to coordinate their CTP functions, and a Memorandum of Understanding between them, dated November 2024, sets out how. Under it, the authorities may jointly agree that one of them acts as lead regulator for a given designated CTP, which gives the provider, and the firms watching the relationship, a single primary point of contact instead of three parallel supervisory conversations.
The multi-regulator design is familiar UK territory. The Bank and the FCA already run coordinated oversight of financial market infrastructures through their own arrangements, as covered in our piece on the Bank of England and FCA FMI Memorandum of Understanding. The CTP lead-regulator model borrows the same instinct: concentrate a shared responsibility so the supervised entity is pulled in one direction. For a firm, the practical takeaway is not to assume that one regulator will lead. The MoU states that most CTPs are expected to be overseen on a shared basis; the regulators may use a lead-regulator model in some cases and will notify the CTP of that decision.
Frequently Asked Questions
Does the CTP designation mean our firm can reduce its own due diligence on AWS, Microsoft, Google Cloud or Oracle?
No. The FCA stated at go-live that the regime complements but does not replace existing outsourcing and operational resilience rules, and that firms remain responsible for their own third-party arrangements, including due diligence, risk management and contingency planning. Designation gives the regulators oversight of systemic resilience at the provider level; it does not validate your specific workloads, contracts or exit plans.
Is a designated CTP now an authorised or regulated firm?
Not by virtue of the designation. The CTP regime brings the provider under resilience-focused oversight for the systemic services it supplies to UK finance, without conferring authorisation or regulated permissions. A CTP may separately be subject to the FCA Handbook in another capacity, including as an authorised person.
Which services of the four providers are actually in scope?
Only the systemic services the provider supplies to the UK financial sector. Treasury confirmed that oversight is limited to those services and does not extend to the provider’s wider operations. The designation attaches to the legal entity, while the regulators’ reach is bounded by the systemic-service perimeter.
What must a designated CTP report, and does that replace our incident reporting?
A CTP must submit an interim self-assessment within three months of designation and annual self-assessments thereafter, carry out regular scenario testing (no fixed minimum frequency under the CTP rules), run its first incident-management playbook exercise within 12 months and exercises at least biennially thereafter, and report CTP operational incidents to the regulators and affected firms. Firm participation in playbook exercises is not mandatory under the CTP rules. A CTP’s reporting channel does not replace any incident-reporting duty that applies separately to an affected regulated firm.
How does this interact with DORA if we operate in the EU as well?
The UK CTP regime and DORA are separate frameworks. A provider can be a critical provider under DORA, a CTP in the UK, both or neither, and each designation carries its own obligations. The ESAs and UK authorities signed a coordination Memorandum of Understanding in January 2026, but it does not make compliance in one bloc count as compliance in the other.
Is there a new return we have to build because of the CTP regime?
The CTP rules themselves apply to designated providers; your firm is not directly in their scope. The firm-side change to plan for is PS26/2, which comes into force on 18 March 2027 and requires in-scope firms to report operational incidents against defined thresholds and to maintain and submit an annual register of material third-party arrangements.
Will more providers be designated?
Further designations are possible. The regime is rolling, there is no statutory limit on the number of CTPs, and further designations or revocations may follow under the statutory process. Regulatory recommendations are expected to be the usual route to designation, but Treasury may designate without one. The regulators also periodically review whether existing CTPs continue to meet the designation criteria.
Related Articles
- PRA SS2/21: Outsourcing and Third-Party Risk Management – the register and notification duties that continue to sit with UK firms.
- DORA Register of Information – the EU register of ICT third-party arrangements and how it is structured and submitted.
- DORA ICT Incident Reporting – the EU major-incident reporting duty that parallels the UK approach.
- DORA Resilience Testing for Smaller Firms – proportionality in DORA’s testing expectations.
- Bank of England and FCA FMI Memorandum of Understanding – how UK regulators coordinate oversight of shared infrastructure.
- The ESAs’ DORA ICT Incident Annual Report – what aggregate EU incident data reveals about third-party concentration.
Key Takeaways
- From 13 July 2026 the Bank of England, PRA and FCA jointly oversee four designated Critical Third Parties: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd, and Oracle Corporation UK Limited.
- The regime sits in Part 18, Chapter 3C of FSMA 2000 (added by FSMA 2023); Treasury designates under the section 312L systemic-risk test, weighing service materiality and the number and type of financial entities affected, and the regulators supervise.
- Designation is not authorisation, and oversight reaches only the provider’s systemic services to UK finance and stops short of its wider business.
- Designated CTPs face six Fundamental Rules and eight Operational Risk and Resilience Requirements, including self-assessment (interim then annual), scenario testing, incident-management playbook exercises with a representative sample of dependent firms, and CTP operational-incident notification.
- The regime shifts no obligation off regulated firms, who still own due diligence, outsourcing registers, operational resilience under SYSC 15A, and their own incident reporting.
- The firm-side build deadline is PS26/2 (PRA equivalent: PS7/26): operational incident reporting and an annual material third-party register, in force 18 March 2027.
- The UK CTP regime is distinct from DORA; a provider can be designated under one, both or neither, and the January 2026 EU-UK Memorandum of Understanding coordinates oversight without creating mutual recognition.
Sources and References
- FCA statement, “UK financial regulators to begin overseeing Critical Third Parties announced by Treasury” (10 July 2026): fca.org.uk
- HM Treasury / GOV.UK, “UK financial system strengthened with new safeguards for major technology providers”: gov.uk
- FCA PS24/16, “Operational resilience: Critical third parties to the UK financial sector” (12 November 2024): fca.org.uk
- Bank of England / PRA PS16/24, “Operational resilience: Critical third parties to the UK financial sector”: bankofengland.co.uk
- FCA statement, “New rules to strengthen resilience of UK’s financial sector” (12 November 2024): fca.org.uk
- FCA Handbook, Critical Third Parties sourcebook (CTPS) – Fundamental Rules, Operational Risk and Resilience Requirements, self-assessment and testing/exercise chapters: handbook.fca.org.uk
- Memorandum of Understanding between the FCA and the Bank of England (including as PRA) on the CTP regime: gov.uk (PDF)
- Memorandum of Understanding between the ESAs and the UK Financial Authorities on oversight of critical ICT third-party service providers: fca.org.uk (PDF)
- HM Treasury, “Critical Third Parties – HM Treasury’s Approach to Designation” (21 March 2024): gov.uk
- FCA PS26/2, “Operational incident and third party reporting” (18 March 2026): fca.org.uk
- PRA PS7/26, “Operational resilience: Operational incident and third-party reporting” (18 March 2026): bankofengland.co.uk
- FCA, “Operational resilience” (SYSC 15A / PS21/3, in force 31 March 2022, transitional period to 31 March 2025): fca.org.uk
- Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA), Articles 31 and 36: eur-lex.europa.eu
- Financial Services and Markets Act 2000, section 312L (Critical third parties), as inserted by FSMA 2023: legislation.gov.uk
- FCA 2024/41, Critical Third Parties Instrument 2024 (the CTPS rulemaking instrument): api-handbook.fca.org.uk (PDF)
What to put on the resilience team’s desk this quarter
The CTP go-live is a supervisory milestone for four providers, and a discipline check for everyone who uses them. Keep third-party assurance exactly where it is, then re-map where each designated provider sits inside your important business services and confirm your impact tolerances still hold if that provider’s systemic service degrades. After that, put the one real firm-side deadline on the calendar: PS26/2 on 18 March 2027, with an annual material third-party register to build and an operational-incident reporting process to define. The regulators now have a direct line to the cloud. The obligation to know your own dependency stays with you.
Last updated: July 2026
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.