The regulatory instruments, sector terms, corridor regimes and framework concepts used across Direct Intelligence, defined once and grouped by section.
UK-India Comprehensive Economic and Trade Agreement; signed 24 July 2025; NOT in force; CRaG ratification in progress; first half of 2026 entry into force expected.
UK domestic mechanism mirroring the EU CBAM; established in primary law by the Finance Act 2026 (Royal Assent 18 March 2026); commencement date 1 January 2027; first accounting period 2027; first filing and payment 31 May 2028.
EU legislative package provisionally agreed 7 May 2026 to defer EU AI Act high-risk obligations; not yet formally adopted; until adoption, original 2 August 2026 high-risk date remains active law.
World's first comprehensive AI law; prohibited practices from February 2025; GPAI obligations from August 2025; Article 50 transparency obligations from 2 August 2026; high-risk obligations provisionally deferred subject to Digital Omnibus formal adoption.
AI models capable of performing a wide range of distinct tasks; subject to specific EU AI Act obligations (in force August 2025); GPAI models with systemic risk carry additional requirements.
International AI management system standard (published December 2023); third-party certifiable; increasingly procurement-relevant in GCC, Singapore, and South Korea corridors.
The Cyber Security and Resilience Bill uses a 1 MW rated IT load threshold (10 MW for enterprise-only centres) to determine whether a data centre is in scope.
Secondary legislation defining the scope of mandatory-notification obligations under the NSI Act 2021; currently specify 17 sectors; expansion to 19 sectors (Critical Minerals, Semiconductors as standalones) confirmed 12 March 2026, secondary legislation pending.
Critical National Infrastructure. The regulated, high-scrutiny sectors and operators Direct Intelligence serves. DI operates across 24 CNI sectors across three tiers.
Doran Integrated Rational-Emotional Cognitive Theory. The intellectual framework underlying all Direct Intelligence services, expressed through six service pillars: NEXUS, VECTOR, SENTINEL, BEACON, STRATA, and FORGE. Intellectual property of Gary Daniel Doran; administered through Direct Intelligence Ltd with academic governance through ICDM.
Institute of Critical Infrastructure Decision Making. The research arm of Direct Intelligence Ltd. Conducts original primary research, governs the DIRECT framework intellectual programme, and is the publishing governance body for The Signal and for FORGE commissioned research. Canonical name: Institute of Critical Infrastructure Decision Making. No variance permitted.
Incoming statute; key Tier 2 sectors in scope: data centres (1 MW threshold), space and satellite operators, emergency services. Royal Assent expected H2 2026.
Trilateral security partnership between Australia, the United Kingdom and the United States. Pillar I covers the nuclear-powered submarine programme; Pillar II covers advanced capabilities. Directly enables the ITAR §126.7 licence-free defence-trade exemption for Authorised Users.
Intelligence-sharing alliance comprising Australia, Canada, New Zealand, the United Kingdom and the United States. Underpins cyber-threat intelligence sharing and supply-chain posture alignment.
Australia's first standalone Cyber Security Act; in force late November 2024; ransomware-payment reporting (72 hours) from 30 May 2025; smart IoT device standards from March 2026.
Australian Signals Directorate's eight baseline cybersecurity mitigation strategies; widely applied as a procurement and assurance standard for Australian government and critical-infrastructure suppliers.
New Zealand's data-protection regime; mandatory notifiable-privacy-breach scheme; extraterritorial reach to overseas agencies carrying on business in New Zealand.
The proposed Digital Charter Implementation Act 2022; contained the Consumer Privacy Protection Act and the Artificial Intelligence and Data Act; died on the Order Paper January 2025 on prorogation. Not delayed; gone.
Canada's federal critical-infrastructure cyber statute, mid-passage as of June 2026; enacts the Critical Cyber Systems Protection Act (CCSPA); passed Third Reading in the House of Commons 26 March 2026; before Senate.
Will establish mandatory cybersecurity duties for designated operators in federally regulated vital sectors; penalties up to CAD 15 million per day; 90-day programme obligation on designation.
Personal Information Protection and Electronic Documents Act (2000); Canada's federal private-sector privacy baseline; unmodernised; remains the operative federal floor.
Act to modernise legislative provisions as regards the protection of personal information (Quebec); three-stage rollout completed September 2024; GDPR-adjacent obligations; de facto operative privacy standard.
Control of Major Accident Hazards Regulations 2015; active, fully enforced regime governing upper-tier and lower-tier hazardous sites; joint Competent Authority of HSE and environmental regulators.
Post-Brexit GB chemicals registration and evaluation regime; HSE acts as the GB agency; registration deadlines extended multiple times since 2021; Northern Ireland follows EU REACH under the Windsor Framework.
Statutory delivery body for the UK's new-nuclear capital programme; direct restructured successor to Great British Nuclear; tasked with directing the SMR programme and identifying further sites.
Rolls-Royce SMR preferred bidder selected 10 June 2025; Wylfa confirmed as site 13 November 2025; delivery contract signed 13 April 2026; FID expected approximately 2029.
Policy programme following the Grenfell Tower Inquiry Phase 2; Construction Products Reform White Paper published 25 February 2026; legislative response expected.
Statutory hard stops under the Building Safety Act 2022 for higher-risk buildings; Gateways 2 and 3 are legal hard stops; operative from 1 October 2023.
A building at least 18 metres in height or at least 7 storeys, with at least two residential units; subject to the full Gateway regime and dutyholder obligations under the Building Safety Act 2022.
Large-scale infrastructure projects requiring Development Consent Orders rather than planning permission; cross-referenced across energy, water, transport, construction sectors.
In-force UK statute; three-gateway regime for higher-risk buildings (at least 18m or 7 storeys, at least 2 residential units) operative from 1 October 2023; dutyholder obligations throughout design and construction lifecycle.
Designation granted via UK ECJU coordinated with US DDTC; prerequisite for licence-free trilateral defence trade under ITAR §126.7; Final Rule effective 30 December 2025.
US DoD supply-chain cybersecurity certification regime; Phase 1 live from 10 November 2025; Phase 2 (mandatory Level 2 C3PAO) from 10 November 2026; gates US federal contract eligibility.
2025 strategy restructuring MOD acquisition; establishes National Armaments Director; three-tier procurement segmentation; +£2.5bn SME spend target by 2028.
AUKUS defence-trade exemption under US International Traffic in Arms Regulations; Final Rule effective 30 December 2025; enables licence-free transfers between designated Authorised Users.
US ITAR provision enabling licence-free defence trade between AUKUS Authorised Users; applies to UK, US and Australia only; Final Rule effective 30 December 2025.
The next iteration of the periodic assessment of UK university research quality; formally reinstated 10 December 2025 with revised 55/25/20 weighting; submission criteria finalised late 2026; institutional submissions due autumn 2028; results published December 2029.
Government action plan targeting at least 95% clean electricity generation by 2030; sets specific capacity targets including 43 to 50 GW offshore wind.
Reformed grid-connection regime; application window closed 26 August 2025; projects must meet readiness and strategic-alignment criteria for a confirmed connection date.
Requirement under the Environment Act 2021 to deliver at least 10% BNG for most TCPA development; mandatory since 12 February 2024; mandatory for NSIPs from 2 November 2026.
EU carbon border tax; definitive period began 1 January 2026; financial liability for embedded emissions in cement, steel, aluminium, fertilisers, electricity, hydrogen now applies; first certificate surrender 30 September 2027.
International Sustainability Standards Board baseline standards for climate-related and broader sustainability disclosures; the foundation of the UK SRS.
Published 25 February 2026 on a voluntary basis only; NOT mandatory; FCA expected to mandate for in-scope listed entities from 1 January 2027 via listing rules, subject to final rules.
Non-EU technology providers brought into direct supervisory scope by the European Supervisory Authorities under DORA; designations rolling through 2026.
EU package provisionally agreed 7 May 2026 deferring AI Act high-risk obligations. Not yet formally adopted; not yet in EU Official Journal. Until adoption, original 2 August 2026 dates remain law.
Digital Operational Resilience Act. EU binding ICT risk-management framework for the financial sector. Directly applicable, no transposition. Fully applicable since 17 January 2025, no grace period. Lex specialis to NIS2 for financial entities.
The principle that more specific law prevails over more general law where both apply to the same matter; DORA is lex specialis to NIS2 for financial entities.
EU expanded cyber-resilience framework. Transposition deadline 17 October 2024; obligations apply country-by-country through national law; transposition uneven.
European Commission decisions confirming the UK provides an essentially equivalent level of data protection. Renewed 19 December 2025; valid until 27 December 2031.
UK regime (FCA PS24/16; PRA PS16/24) taking legal effect 1 January 2025; HM Treasury designates CTPs; regime going live as designations roll out through 2026.
Digital Operational Resilience Act (Regulation (EU) 2022/2554); fully applicable 17 January 2025; lex specialis to NIS2 for financial sector; applies extraterritorially to UK firms and ICT providers serving EU financial entities.
Single regulatory platform for operational incident reporting under PRA PS7/26; 24-hour window for authorised firms; 4-hour window for payment service providers; mandatory from 18 March 2027.
International information-security management standard; procurement floor across UK CNI; substantially evidences DORA ICT risk-management requirements; 2013-to-2022 transition closed October 2025.
Regime under FCA PS21/3 and PRA SS1/21; transition ended 31 March 2025; firms must continuously operate important business services within impact tolerances.
Sanitary and Phytosanitary agreement; Common Understanding signed 19 May 2025; under active negotiation; NOT in force; non-binding mid-2027 implementation target.
UAE In-Country Value programme; scores suppliers on local spend, workforce and investment; ICV certificates weighted in major tenders; 14-month validity.
Saudi Arabia's Personal Data Protection Law; administered by SDAIA; in force with extraterritorial reach; data-residency and transfer conditions apply.
Prospective free trade agreement between the United Kingdom and the six GCC member states; negotiations began June 2022; ongoing as of May 2026; not signed, not concluded, not in force.
Mandatory publication and registration service under the Procurement Act 2023; live from 24 February 2025; suppliers must register for a unique identifier; without it, contract award is legally prohibited.
Replaces lowest-price evaluation under the Procurement Act 2023; SME inclusion, social value, prompt payment, supply-chain resilience, and decarbonisation are core evaluation criteria.
Cabinet Office policy lens for MAT evaluation; periodically reweighted; current version formalises decarbonisation and supply-chain resilience as core pricing criteria.
Post-Brexit replacement for the Public Contracts Regulations 2015; in force 24 February 2025; covers England, Wales, and Northern Ireland; Scotland retains its own regime.
Medicines and Healthcare products Regulatory Agency; UK regulator for medicines and medical devices; Post-Market Surveillance regime in force from June 2025; pre-market SI and International Reliance Framework expected 2026.
Introduced King's Speech 13 May 2026; second reading completed 1 June 2026; abolishes NHS England and transfers functions to DHSC; legal abolition targeted April 2027; not yet law.
India's Digital Personal Data Protection Act; operationalised by DPDP Rules notified 13 November 2025; three-phase commencement: Phase 1 (November 2025), Phase 2 (November 2026), Phase 3 substantive obligations (13 May 2027, no grace period).
FCA announced 21 October 2025 as future single AML supervisor for professional services; consultation outcome and migration timetable expected Autumn 2026.
Cryptographic algorithms designed to be secure against quantum-computer attacks; NIST PQC standards finalised 2024; migration timeline being set across CNI sectors.
Cryptographic protocol using quantum mechanics to distribute encryption keys; secure against quantum-computer attacks; UK government investment programme.
The common standard governing all ICDM and Direct Intelligence outputs: a claim is either sourced (source stated) or labelled as an assessment (basis and confidence level stated). The in-force / announced / under-negotiation distinction is applied to every regulatory reference.
The editorial publication of ICDM. Publishes original analysis on emergent risk, governance and institutional behaviour across critical national infrastructure. Not a newsletter or aggregator. Published when analysis warrants it. Open access, no registration required.
ICDM research formats that require verified-access request rather than open download: Position Papers, Monographs, Applied Research series and the Dossier Series. Access via /briefing-gate.
The landing page at /research. Describes the three-part research architecture: ICDM (the institute), The Signal (the channel) and FORGE (the service). Not a content page; a navigation and orientation page.
Annual cross-sector benchmark measuring where the UK CNI supply chain sits against incoming regulatory obligations; formalised through RP-07; annual cadence from H1 2027.
First structured maturity model for institutional intelligence capability in UK CNI; formalised through RP-10; annual benchmarking tool; annual cadence from Q3 2027.
The formal discipline established through the DIRECT framework and the Decision Architecture Series. The systematic study of how individuals, groups, organisations and societies structure, sequence and execute decisions.
National Security and Investment Act 2021. The UK's mandatory-notification screening regime for acquisitions in sensitive sectors. Currently covers 17 sensitive sectors; expansion to 19 sectors confirmed 12 March 2026; secondary legislation not yet enacted.
The structured reconstruction of an institutional decision: what is actually being decided, who holds it and who can block it, the sequence of moves required, and the dependency between them.
The process of entering or expanding in a UK market governed by statutory screening regimes, procurement frameworks, and sector-specific regulatory perimeters.
The Decision-Architecture Engine; the decision-architecture pillar of the DIRECT framework. Translates institutional friction into defensible, sequenced advisory positions.
A structured analysis of how a specific institutional buyer makes a given decision: who decides, who can veto, what the institution is optimising for behind its stated criteria, and where in its real process the outcome is determined.
The opening stage of an Intelligence engagement: fixing the specific institutional decision, the live timeframe, and the confidence threshold needed to act.
The Intelligence Engine; the decision-intelligence pillar of the DIRECT framework. Sector signal, buyer behaviour and regulatory data fused into a single decision view.
Original research conducted under ICDM governance and scoped to a specific institutional question on behalf of a verified client, delivered with a defensibility review.
The Research pillar of the DIRECT framework; the commissioned research service. The route by which a verified institution commissions Direct Intelligence to conduct original research on a specific question, under ICDM governance. Distinct from the institute's published research, available through The Signal.
The ongoing management of a certification and compliance architecture as a live, demonstrable state between surveillance assessments and recertification cycles.
The UK government-backed baseline cybersecurity certification scheme, independently assessed. Layered under the multi-standard management system architecture.
Digital Operational Resilience Act (EU). In force for financial-sector entities; ICT-risk-management requirements substantively evidenced by an operational ISO 27001 management system.
ISO 14001 is the international standard for Environmental Management Systems (EMS). It provides a framework for organisations to manage their environmental responsibilities in a systematic way that contributes to the environmental pillar of sustainability.
ISO 22301 is the international standard for Business Continuity Management Systems (BCMS). It specifies requirements to plan, establish, implement, operate, monitor, review, maintain and continually improve a documented management system to protect against, reduce the likelihood of occurrence, prepare for, respond to, and recover from disruptive incidents.
ISO 45001 is the international standard for Occupational Health and Safety Management Systems (OH&S). It provides a framework for organisations to improve employee safety, reduce workplace risks and create better, safer working conditions.
ISO 9001 is the internationally recognised standard for Quality Management Systems (QMS), published by the International Organization for Standardization. It specifies requirements for a QMS that organisations can use to demonstrate the ability to consistently provide products and services that meet customer and regulatory requirements.
The international standard for information security management systems; procurement-prerequisite across UK CNI; 2013-to-2022 transition closed 31 October 2025.
ISO/IEC 27701 is an international standard that extends ISO/IEC 27001 to include requirements and guidance for establishing, implementing, maintaining and continually improving a Privacy Information Management System (PIMS).
The Assurance Engine; the governance-and-standards pillar of the DIRECT framework. One platform, multiple standards, continuous compliance governed end to end.
The Execution Engine; the applied-AI pillar of the DIRECT framework. AI built to human-in-the-loop and EU AI Act risk-management standards from inception.
The DI methodology for building human-governed AI systems: train humans first, codify their knowledge into the AI, feed AI outputs back into human understanding, then build the AI to augment humans while humans govern it.
An AI system design pattern in which defined human control points, reviewable decision records and named accountability roles are structural properties of the system, not nominal sign-off steps.
The network security controls within ISO/IEC 27001:2022 (A.8.20 network security, A.8.21 security of network services, A.8.22 segregation of networks); the architectural basis for sovereign private AI deployments.
A DI Systems service delivery model in which hardware and software are installed within the client's physical perimeter, running a private large-language model closed from public networks.
The evidence standard STRATA is designed to produce: proof that a named role holds the competencies its operating environment requires, produced to a standard that survives scrutiny.
The Workforce Engine; the workforce pillar of the DIRECT ecosystem. Applies the DIRECT framework at the individual register (senior decision advisory) and the organisational register (capability mapping). Not externally accredited.
Act 19 of 2024; key provisions commenced 31 October 2025; third-party CII responsibility, STCC, expanded incident reporting including supply-chain incidents. Parts 3C and 3D (ESCI and foundational digital infrastructure) enacted but not commenced.
Singapore's financial regulator; sets technology-risk-management and outsourcing requirements that function as de facto entry conditions for financial-sector technology suppliers.
Singapore's non-statutory AI governance framework; increasingly treated as a procurement and assurance expectation by institutional buyers; not binding legislation.
Personal Data Protection Act 2012 (as amended 2020); breach notification threshold: significant harm or 500 or more individuals; extraterritorial effect.
Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trust; promulgated 21 January 2025; in force with Enforcement Decree from 22 January 2026; obligations live; penalty provisions deferred approximately one year.
Korea Information Security Management System; administered through KISA; mandatory for certain ICT service providers; increasingly treated as a de facto procurement precondition.
Personal Information Protection Act; one of the more stringent data-protection regimes in Asia; extraterritorial reach; enforced by PIPC; amendment commencement 11 September 2026 raises penalty ceiling.
Legally binding directions under the TSA 2021 issued to approximately 35 operators requiring removal of Huawei equipment from UK 5G networks by end of 2027.
Designation under the Telecommunications (Security) Act 2021; currently applies to Huawei; national security powers vested in the Secretary of State can extend the designation.
In-force UK statute; commenced 1 October 2022; codifies Telecoms Security Requirements; enforced by Ofcom with penalties up to 10% turnover or £100k per day; Tier 1 deadline 31 March 2024; Tier 2 31 March 2025; full Code 31 March 2028.
National Security and Investment Act 2021; 17 mandatory-notification sectors currently; expansion to 19 sectors confirmed 12 March 2026; secondary legislation not yet enacted.
Committee on Foreign Investment in the United States; reviews foreign acquisitions of US businesses in critical technologies, critical infrastructure or sensitive personal data for national security risk.
Federal Risk and Authorization Management Program; authorisation programme for cloud services sold to US federal agencies; impact levels Low, Moderate, High.
US federal information-security standard for protecting Controlled Unclassified Information on non-federal systems; baseline for CMMC 2.0 Level 2; 110 detailed controls.
Anticipated legislation (2026 to 2027 session, expected but not guaranteed) to abolish Ofwat and establish the single integrated regulator; no confirmed timeline.