Regime news, maintained
The CTP regime is live: what the first designations mean
Who are the designated Critical Third Parties? On 10 July 2026 HM Treasury designated the first four: AWS EMEA, Google Cloud EMEA, Microsoft Ireland and Oracle UK, all hyperscale cloud providers. Regulator oversight began on 13 July 2026 under PS16/24. Here is what the designations change for the firms that depend on them.
The first cohort
Four designations, all hyperscale cloud
The Critical Third Parties regime lets HM Treasury designate providers whose failure could threaten the stability of the UK financial system, and puts the designated providers under direct regulatory oversight. The rules were finalised in PS16/24 and took effect on 1 January 2025; the first designations arrived on 10 July 2026.
Reviewed July 2026. This page is maintained as the regime develops.
| Designated Critical Third Party | What it provides |
|---|---|
| Amazon Web Services EMEA | Hyperscale cloud infrastructure and platform services |
| Google Cloud EMEA | Hyperscale cloud infrastructure and platform services |
| Microsoft Ireland | Hyperscale cloud infrastructure and platform services |
| Oracle UK | Hyperscale cloud infrastructure and platform services |
The composition of the first cohort is the message. The regulators went straight to the concentration risk that has worried them longest: a handful of cloud providers underpinning most of the UK financial sector at once.
How the regime runs
Designation, self-assessment, annual cycle
The regime moves in phases. Each designated provider works through the same sequence, so the first cohort's dates give you the shape of every cohort to come.
| Phase | When | What happens |
|---|---|---|
| Designation | 10 July 2026 for the first cohort | HM Treasury designates a provider as a Critical Third Party. Regulator oversight of the first four began on 13 July 2026, under rules the regulators finalised in PS16/24, in force since 1 January 2025. |
| Initial self-assessment | Within three months of designation | Each designated CTP submits its first self-assessment against the regime's fundamental rules and operational risk requirements. For the July 2026 cohort that lands around mid-October 2026. |
| Annual cycle | Every year thereafter | The self-assessment is refreshed annually, alongside the regime's ongoing testing, information-sharing and incident-reporting duties. Oversight is continuous, not a one-off gateway. |
Read the regime correctly
The obligations sit on the providers, not on you
This is the point most early commentary buries. The CTP regime regulates the designated providers themselves: it is AWS, Google, Microsoft and Oracle that owe the self-assessments, the testing and the incident reporting. Your firm gains something it has never had, supervisory visibility of a provider you could never meaningfully audit, but it is not handed any new compliance checklist by the designations.
Nor is it relieved of an old one. Your duties under the FCA's operational resilience rules and PS21/3 are untouched: mapping your dependencies, setting impact tolerances, maintaining exit and contingency plans and testing severe but plausible scenarios all remain yours. The regime adds oversight of the provider. It is not a substitute for your own third-party resilience work, and supervisors will read it as exactly that.
If you depend on a designated CTP
Three things to update now
Almost every UK financial services firm depends on at least one of the first four, directly or through its software supply chain. The designations do not create new duties for you, but they do change what a credible resilience programme looks like.
Re-read your third-party mapping
Your resource mapping should already show which important business services depend on AWS, Google Cloud, Microsoft or Oracle, directly or through a SaaS provider built on them. If it cannot answer that question quickly, that is the first gap to close, because supervisors can now see the dependency from both ends.
Update the self-assessment narrative
Your own self-assessment should acknowledge the designations: which of your providers are designated, what the regime does and does not give you, and how your exit and contingency planning reflects that. A self-assessment written before July 2026 is now describing an outdated landscape.
Test a designated-CTP outage
A severe but plausible scenario in which a designated CTP suffers a prolonged outage is now the most defensible test you can run. The FCA has already criticised testing that is not severe enough; a hyperscaler failure scenario answers that finding directly.
Both of these are priced and published here. Our scenario testing exercise includes a designated-CTP outage scenario in its library, at £8,550 to £13,200 fixed by scope. And the third-party mapping review sits inside the self-assessment review, from £8,990, with every fee on the pricing page.
The EU parallel
DORA runs the same play for the EU
If your group has EU entities or EU clients, the CTP regime will feel familiar, because DORA built its mirror image first. The European Supervisory Authorities designated 19 critical ICT third-party providers in November 2025, and the first oversight inspections are running through 2026. Same logic, same concentration concern, a different rulebook and a different set of designations.
For dual-scoped firms the practical task is reconciliation: one dependency map that knows which providers are designated under which regime, and scenario testing that satisfies both. Our DORA for UK firms guide covers where the two regimes meet and where they part.
Quick answers
CTP regime questions, answered
Who are the designated Critical Third Parties?
HM Treasury designated the first four Critical Third Parties on 10 July 2026: AWS EMEA, Google Cloud EMEA, Microsoft Ireland and Oracle UK. All four are hyperscale cloud providers. Regulator oversight of the four began on 13 July 2026, and their first self-assessments are due within three months of designation, around mid-October 2026.
Does the CTP regime apply to my firm?
Not directly. The regime's obligations sit on the designated providers themselves, not on the firms that use them. Your own duties are unchanged: PS21/3 and SS1/21 still require you to map your dependencies, set impact tolerances, plan exits and test severe but plausible scenarios, including the failure of a designated provider.
What should we do about the designations?
Three things. Check that your resource mapping shows every dependency on a designated CTP, including indirect dependencies through SaaS providers. Update your self-assessment so it reflects the designations and what they change. And put a designated-CTP outage into your next scenario testing round, because it is now the obvious severe but plausible scenario for most firms.
Concentration risk, evidenced
Put the designations into your evidence base
A free 45 minute call covers where your mapping, self-assessment and scenario testing stand against the new landscape, and whether a CTP-outage exercise or a self-assessment review is the right next step.