FCA Incident Reporting Rules: What UK CISOs Must Build Now
UK CISOs have 12 months to build the capability to report operational incidents within 24 hours, or four hours for payment firms. The FCA’s Policy Statement PS26/2, published alongside the Bank of England and PRA’s companion statement PS7/26 on 18 March 2026, creates a new UK incident and third-party reporting framework that comes into force on 18 March 2027.
This is not a paperwork update. It requires real-time detection, classification and escalation capability that most incident response processes were not built to deliver within the new thresholds. Firms that treat this as a compliance filing exercise, rather than an operational engineering problem, will struggle to meet the deadline comfortably.
What Exactly Do PS26/2 and PS7/26 Require?
The rules, developed jointly by the FCA, PRA and Bank of England, define what qualifies as a reportable operational incident and set firm reporting thresholds. All authorised firms must report basic incident information promptly — within 24 hours for most firms, tightened to four hours for payment services providers — in a structured format, followed by more detailed reporting as the incident develops.
Separately, the rules introduce material third-party reporting obligations covering both outsourcing and non-outsourcing arrangements. Firms must maintain and submit an annual register of material third-party relationships, giving regulators visibility into concentration risk across the sector.
Executive Action:
- Map current incident detection-to-escalation timelines against the new 24-hour and 4-hour thresholds
- Identify every third-party arrangement that would qualify as “material” under the new definition
- Assign a named owner for the annual material third-party register before it becomes mandatory
Why Does the Four-Hour Threshold Matter So Much?
Four hours is not enough time for most organisations to complete a manual triage process, brief senior stakeholders and produce a structured regulatory submission — which means the process has to be substantially automated and pre-rehearsed before an incident occurs. CISOs who wait until closer to the March 2027 deadline to test this end-to-end will discover gaps only when a live incident exposes them.
According to the FCA’s own framing of the reforms, the goal is to give regulators better visibility of operational disruption and third-party dependencies across the financial sector — meaning firms should expect the bar for “prompt and complete” reporting to rise over time, not soften.
Executive Action:
- Run a live-fire exercise simulating a four-hour reporting deadline within the next two quarters
- Pre-build structured reporting templates so classification, not formatting, is the bottleneck
- Use INFORMD’s project review checklist to track PS26/2 readiness milestones
How Should CISOs Approach the Third-Party Register?
Many firms already hold fragments of a third-party inventory across procurement, IT asset management and vendor risk systems, but rarely in a single register that meets a regulatory reporting standard. Building the PS26/2 register from scratch under time pressure is far riskier than consolidating existing data sources now, while the deadline still allows for iteration.
The register needs to distinguish outsourcing from non-outsourcing material arrangements, since both are now reportable — a distinction many existing vendor risk frameworks do not currently make explicit.
Executive Action:
- Consolidate procurement, IT asset and vendor risk data into a single third-party inventory now
- Classify each arrangement as outsourcing or non-outsourcing under the PS26/2 definitions
- Assign materiality thresholds jointly with the CFO and Chief Risk Officer, not CISO alone
What Should CISOs Brief the Board on Now?
Boards need to understand that PS26/2 readiness is a twelve-month build, not a compliance checkbox to tick closer to the deadline. The most useful CISO briefing sets out a phased readiness plan with named milestones, so the board can track progress and intervene early if a milestone slips. Vague reassurance that “we are on track” without supporting evidence should not satisfy a well-run Risk Committee.
This also intersects with DORA obligations for firms with EU operations and existing UK operational resilience impact tolerances — CISOs should present PS26/2 as one coordinated resilience programme, not a separate regulatory stream competing for the same engineering resource. Treating each regime as a distinct project multiplies cost and creates gaps at the seams between them.
Executive Action:
- Present a phased PS26/2 readiness roadmap to the Risk Committee within the next quarter
- Align PS26/2 workstreams with existing DORA and operational resilience programmes to avoid duplicated effort
- Request board sign-off on the resourcing needed to hit the March 2027 deadline comfortably, not at the last minute
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.
PS26/2 is the FCA’s operational incident and third-party reporting framework, published 18 March 2026 alongside the Bank of England and PRA’s PS7/26. It requires firms to report serious operational incidents within set timeframes and maintain a material third-party register.
The rules come into force on 18 March 2027, giving firms 12 months from publication to build the required detection, classification and reporting capability.
Most authorised firms must report basic incident information within 24 hours. Payment services providers face a tighter four-hour threshold, followed by more detailed structured reporting as the incident develops.
The rules cover both outsourcing and non-outsourcing arrangements judged material to the firm’s operations. Firms must maintain and submit an annual register distinguishing these two categories for regulatory visibility into concentration risk.
