European Sovereignty Monitor

Policy and law

UK finalises rules on reporting incidents at critical tech suppliers

The Bank of England, PRA and FCA published final rules requiring UK financial firms to report operational incidents and register material third party arrangements, including cloud and tech suppliers, with compliance due by 18 March 2027.

Verified Financial Conduct Authority, Policy Statement PS26/2, 18 March 2026 (issued alongside the Bank of England and PRA's PS7/26)

What it does not test. Does not establish that any specific cloud or tech supplier has been designated critical, since the duty falls on firms rather than naming providers.

How this item counts. No movement: no answer to who owns, who operates, whose law governs or who made the parts changes. Weight 0. Reporting duty on UK firms only, doesn't change supplier own/operate/law/parts. European Sovereignty Index

Previously in Policy and law

Verified ANSSI leads G7 call for urgent shift to post-quantum cryptography Reported EU Commission sends AI Act information requests to over 30 companies Reported EU antitrust officials seek information on Oracle's cloud licensing practices

All Policy and law news →