Regime news, maintained

The CTP regime is live: what the first designations mean

Who are the designated Critical Third Parties? On 10 July 2026 HM Treasury designated the first four: AWS EMEA, Google Cloud EMEA, Microsoft Ireland and Oracle UK, all hyperscale cloud providers. Regulator oversight began on 13 July 2026 under PS16/24. Here is what the designations change for the firms that depend on them.

The first cohort

Four designations, all hyperscale cloud

The Critical Third Parties regime lets HM Treasury designate providers whose failure could threaten the stability of the UK financial system, and puts the designated providers under direct regulatory oversight. The rules were finalised in PS16/24 and took effect on 1 January 2025; the first designations arrived on 10 July 2026.

Reviewed July 2026. This page is maintained as the regime develops.

Designated Critical Third Party What it provides
Amazon Web Services EMEA Hyperscale cloud infrastructure and platform services
Google Cloud EMEA Hyperscale cloud infrastructure and platform services
Microsoft Ireland Hyperscale cloud infrastructure and platform services
Oracle UK Hyperscale cloud infrastructure and platform services

The composition of the first cohort is the message. The regulators went straight to the concentration risk that has worried them longest: a handful of cloud providers underpinning most of the UK financial sector at once.

How the regime runs

Designation, self-assessment, annual cycle

The regime moves in phases. Each designated provider works through the same sequence, so the first cohort's dates give you the shape of every cohort to come.

Phase When What happens
Designation 10 July 2026 for the first cohort HM Treasury designates a provider as a Critical Third Party. Regulator oversight of the first four began on 13 July 2026, under rules the regulators finalised in PS16/24, in force since 1 January 2025.
Initial self-assessment Within three months of designation Each designated CTP submits its first self-assessment against the regime's fundamental rules and operational risk requirements. For the July 2026 cohort that lands around mid-October 2026.
Annual cycle Every year thereafter The self-assessment is refreshed annually, alongside the regime's ongoing testing, information-sharing and incident-reporting duties. Oversight is continuous, not a one-off gateway.

Read the regime correctly

The obligations sit on the providers, not on you

This is the point most early commentary buries. The CTP regime regulates the designated providers themselves: it is AWS, Google, Microsoft and Oracle that owe the self-assessments, the testing and the incident reporting. Your firm gains something it has never had, supervisory visibility of a provider you could never meaningfully audit, but it is not handed any new compliance checklist by the designations.

Nor is it relieved of an old one. Your duties under the FCA's operational resilience rules and PS21/3 are untouched: mapping your dependencies, setting impact tolerances, maintaining exit and contingency plans and testing severe but plausible scenarios all remain yours. The regime adds oversight of the provider. It is not a substitute for your own third-party resilience work, and supervisors will read it as exactly that.

If you depend on a designated CTP

Three things to update now

Almost every UK financial services firm depends on at least one of the first four, directly or through its software supply chain. The designations do not create new duties for you, but they do change what a credible resilience programme looks like.

Re-read your third-party mapping

Your resource mapping should already show which important business services depend on AWS, Google Cloud, Microsoft or Oracle, directly or through a SaaS provider built on them. If it cannot answer that question quickly, that is the first gap to close, because supervisors can now see the dependency from both ends.

Update the self-assessment narrative

Your own self-assessment should acknowledge the designations: which of your providers are designated, what the regime does and does not give you, and how your exit and contingency planning reflects that. A self-assessment written before July 2026 is now describing an outdated landscape.

Test a designated-CTP outage

A severe but plausible scenario in which a designated CTP suffers a prolonged outage is now the most defensible test you can run. The FCA has already criticised testing that is not severe enough; a hyperscaler failure scenario answers that finding directly.

Both of these are priced and published here. Our scenario testing exercise includes a designated-CTP outage scenario in its library, at £8,550 to £13,200 fixed by scope. And the third-party mapping review sits inside the self-assessment review, from £8,990, with every fee on the pricing page.

The EU parallel

DORA runs the same play for the EU

If your group has EU entities or EU clients, the CTP regime will feel familiar, because DORA built its mirror image first. The European Supervisory Authorities designated 19 critical ICT third-party providers in November 2025, and the first oversight inspections are running through 2026. Same logic, same concentration concern, a different rulebook and a different set of designations.

For dual-scoped firms the practical task is reconciliation: one dependency map that knows which providers are designated under which regime, and scenario testing that satisfies both. Our DORA for UK firms guide covers where the two regimes meet and where they part.

Quick answers

CTP regime questions, answered

Who are the designated Critical Third Parties?

HM Treasury designated the first four Critical Third Parties on 10 July 2026: AWS EMEA, Google Cloud EMEA, Microsoft Ireland and Oracle UK. All four are hyperscale cloud providers. Regulator oversight of the four began on 13 July 2026, and their first self-assessments are due within three months of designation, around mid-October 2026.

Does the CTP regime apply to my firm?

Not directly. The regime's obligations sit on the designated providers themselves, not on the firms that use them. Your own duties are unchanged: PS21/3 and SS1/21 still require you to map your dependencies, set impact tolerances, plan exits and test severe but plausible scenarios, including the failure of a designated provider.

What should we do about the designations?

Three things. Check that your resource mapping shows every dependency on a designated CTP, including indirect dependencies through SaaS providers. Update your self-assessment so it reflects the designations and what they change. And put a designated-CTP outage into your next scenario testing round, because it is now the obvious severe but plausible scenario for most firms.

Scenario testing, as a fixed-fee exercise

Rocket above the Operational Resilience UK call to action

Concentration risk, evidenced

Put the designations into your evidence base

A free 45 minute call covers where your mapping, self-assessment and scenario testing stand against the new landscape, and whether a CTP-outage exercise or a self-assessment review is the right next step.