ArmourIQ LogoArmourIQ
Cyber News

FCA Operational Incident and Third-Party Reporting: What Firms Must Do Before March 2027

By ArmourIQ Security TeamSeptember 28, 20268 min read
Cyber News

The FCA has published PS26/2, a new set of rules on operational incident and third-party reporting that come into force on 18 March 2027. They add two standing obligations for UK financial firms: reporting significant operational incidents to the regulator, and maintaining and submitting a register of the third parties they most depend on. Firms have until March 2027 to prepare, and for most this is a higher reporting standard than they currently meet.

What PS26/2 introduces

PS26/2 builds on the operational resilience regime that has applied since 2022, but it is about reporting rather than internal resilience. It creates two separate requirements. The first is operational incident reporting: firms must tell the FCA, in a standard format, when they suffer an operational incident that crosses defined thresholds. The second is material third-party reporting: certain firms must keep a register of their material third-party arrangements and submit it to the FCA each year (source: FCA).

Both requirements take effect on 18 March 2027. The rules were finalised in March 2026, which gives firms roughly twelve months to put the processes, judgement and record-keeping in place. That window is the point of this post: the work is straightforward, but it is not something to start the week the rules go live.

Operational incident reporting

Under the new rules, a reportable operational incident is one that risks causing intolerable harm to consumers from which they cannot easily recover, risks the safety and soundness of the firm or other market participants, or risks market stability, market integrity or confidence in the UK financial system. This is a broader, outcome-based test than the current focus on important business services, and firms have to make a judgement about whether an incident is likely to meet it (source: FCA).

Once a firm determines that an incident meets the threshold, it must submit a report to the FCA within 24 hours. Most FCA solo-regulated firms will file a single short standard report. A smaller group of enhanced-reporting firms must do more: an initial report within the same 24 hours, updates as the situation changes materially, and a final report once the incident is resolved. Payment service providers face a faster clock, and must report within four hours of first detection under their existing obligations. The aim is a single, standardised submission rather than the fragmented reporting firms deal with today (source: FCA).

Material third-party reporting

The second requirement asks in-scope firms to maintain a register of their material third-party arrangements and submit it to the FCA annually. The register captures the detail regulators need to understand supply-chain concentration: the contracts, legal entity identifiers, materiality assessments, most recent audit dates and whether a provider could realistically be substituted. Firms also have to notify the FCA of new material third-party arrangements, or significant changes to existing ones (source: FCA).

The annual submission works on a fixed cycle. The register reflects a firm's position as at 31 December, and firms have a 90-day window to submit once the FCA opens it. In practice this means the quality of the register depends on records that are kept current through the year, not assembled in the weeks before the deadline.

How this fits with the rules already in place

PS26/2 sits on top of two regimes firms should already know. The operational resilience rules, in force since 2022 with a transitional period that ended on 31 March 2025, require firms to identify their important business services, set impact tolerances and test that they can stay within them. Separately, PS24/16 created the Critical Third Parties regime, which lets HM Treasury designate a small number of systemically important suppliers, typically major cloud or technology providers, for direct oversight by the Bank of England, PRA and FCA (source: FCA).

The new reporting rules are the piece that makes the rest visible to the regulator. Resilience testing tells a firm where it stands; incident reporting tells the FCA when something goes wrong; the third-party register tells the FCA who the firm depends on. A firm that has done the resilience work already holds most of the raw material the reporting rules ask for.

Who this affects

The two requirements have different scopes. Operational incident reporting applies broadly, reaching firms with Part 4A permission, payment service providers, UK recognised investment exchanges, registered trade repositories and registered credit rating agencies. Material third-party reporting is narrower, covering enhanced-scope firms under the Senior Managers and Certification Regime, banks, designated investment firms, building societies, Solvency II insurers, large CASS firms, UK RIEs, authorised e-money and payment institutions, and consolidated tape providers (source: FCA).

The rules also reach suppliers, indirectly but firmly. A SaaS platform, managed service provider or consultancy anywhere in the world that supports a UK-regulated firm may now appear on that firm's material third-party register and be drawn into its incident reporting when something goes wrong on the supplier's side. Being ready to evidence your own resilience and to move quickly during an incident is increasingly a condition of serving UK financial clients.

What we recommend

With the deadline set for 18 March 2027, the sensible approach is to treat the next year as preparation time rather than waiting for the rules to bite. None of this depends on buying new technology; most of it is about judgement, ownership and records. We would advise firms and their suppliers to focus on the following.

1. Decide now how you will judge a reportable incident. The threshold is a judgement call made under pressure, often at unsocial hours. Agree in advance who makes the call, against what criteria, and how the 24-hour clock (or four hours for payment firms) is tracked from the moment an incident is confirmed. Write it down before you need it.

2. Rehearse the reporting path, not just the response. Most firms exercise their incident response; far fewer rehearse notifying the regulator within a fixed window while the incident is still live. Build the FCA submission into your tabletop exercises so the reporting step is muscle memory rather than a scramble.

3. Build the material third-party register as a living record. The register is only as good as the data behind it: contracts, materiality assessments, audit dates and substitutability all have to be current. Stand it up now and keep it maintained through the year, rather than reconstructing it against a 31 December snapshot each cycle.

4. Map incidents to third parties before one happens. Many reportable incidents will originate with a supplier. Knowing which third parties support which services, and what access they hold, lets you assess and report an incident quickly instead of chasing the facts mid-crisis. This is the same mapping the resilience rules already expect, put to a second use.

5. Give the programme clear ownership. Incident reporting and third-party oversight sit across technology, risk, compliance and the business. Someone at leadership level should own the judgement calls, keep the register current and make sure the reporting processes are tested. Where there is no dedicated security leader, this is a gap worth closing before March 2027, whether through an internal appointment or an external advisory arrangement.

Frequently asked questions

Frequently asked questions

When do the FCA's operational incident and third-party reporting rules take effect?

The rules in PS26/2 come into force on 18 March 2027. They were finalised in March 2026, giving firms about twelve months to prepare their incident-reporting and third-party register processes.

What counts as a reportable operational incident?

An incident is reportable if it risks intolerable harm to consumers, risks the safety and soundness of the firm or other market participants, or risks market stability, integrity or confidence in the UK financial system. It is a broad, outcome-based test, and the firm has to judge whether an incident is likely to meet it.

How quickly do we have to report an incident?

Once a firm determines an incident meets the threshold, it must report to the FCA within 24 hours. Enhanced-reporting firms then provide updates and a final report as the incident develops and resolves. Payment service providers face a faster timeline of four hours from first detection.

What is the material third-party register?

In-scope firms must maintain a register of their material third-party arrangements, covering contracts, legal entity identifiers, materiality assessments, audit dates and substitutability, and submit it to the FCA each year. The register reflects the firm's position as at 31 December, with a 90-day window to submit once the FCA opens it. Firms must also notify the FCA of new or significantly changed material arrangements.

Does my firm fall in scope?

Incident reporting applies broadly, including firms with Part 4A permission, payment service providers, UK RIEs, trade repositories and credit rating agencies. Third-party reporting is narrower, covering enhanced-scope SM&CR firms, banks, designated investment firms, building societies, Solvency II insurers, large CASS firms and several others. If you are FCA-authorised, check both scopes, as many firms fall into at least one.

We are a supplier to a UK-regulated firm. Does this reach us?

Indirectly, yes. If you support a UK-regulated firm, you may appear on its material third-party register and be drawn into its incident reporting when something goes wrong on your side. You will increasingly be expected to evidence your own resilience and to respond quickly during an incident, wherever you are based.

Conclusion

PS26/2 turns operational resilience from something firms manage internally into something they must report on. From 18 March 2027, UK financial firms will need to notify the FCA of significant incidents within tight windows and account each year for the suppliers they depend on. The requirements are manageable, but they reward preparation: firms that decide their reporting judgements, rehearse the submission path and keep their third-party records current will handle the new regime as routine, while those that leave it until 2027 will be building the process during their first real incident.

Operational ResilienceFCAIncident ReportingThird-Party RiskFinancial Services
Share