← Sectors·CNI Designated - Tier 1LGD: OFCOM / DSIT·S05 - Sovereign Sector Intelligence

The New
CNI Mandate.

Navigating the proposed classification of Data Centres as Essential Services.

1MW / 10MWEssential Entity ThresholdsThe "Rated IT Load" thresholds proposed for Essential Entity designation under the forthcoming Cyber Bill, and for NSIP designation.
24 / 72 HoursIncident Reporting TimelinesThe incident-reporting timelines to Ofcom proposed under the forthcoming Cyber Bill.
Sector Context

In March 2026, the digital substrate of the UK economy has reached its definitive sovereign status. Following the 12 September 2024 CNI Designation, Data Centres now sit on an equal footing with Energy and Water. The Cyber Security & Resilience Bill, which completed Commons passage on 10 June 2026 and is now before the Lords, would categorise UK operators as Essential Entities once enacted (Royal Assent expected in the second half of 2026). Under the oversight of Ofcom, providers are preparing for the world's most rigorous operational resilience and incident reporting standards. Direct Intelligence provides the governance architecture required to secure this foundational infrastructure while navigating the DSIT National Research Cloud and the Telecommunications Security Act (TSA) mandates.

Institutional Friction Audit

Identify the Accountability Friction.

The Essential Entity Transition

Legacy operators struggling to complete the designation assessment before enforcement begins, creating compliance exposure.

The "Capable of Impact" Duty

Providers unprepared for the proposed duty, once the Cyber Bill is enacted, to report incidents "capable of having a significant impact" within the 24-hour window.

The Customer Notification Loop

Preparing for the proposed statutory duty to notify affected customers and the public of significant cyber incidents under the forthcoming Bill.

The Power & AI Bottleneck

Hyperscale developers requiring NSIP designation for data centres over 10MW, creating planning complexity with long timelines.

The High-Risk Vendor Filter

Comms providers facing immediate compliance requirements under the TSA to remove designated High-Risk Vendor equipment.

Ecosystem Matrix

The Sector Landscape.

Data Centres & Cloud

Readiness for Essential Entity designation under the forthcoming Cyber Bill, CNI designation, and the NSIP planning pathway for facilities over 10MW.

Telecommunications Networks

TSA compliance, High-Risk Vendor remediation, and 5G security architecture.

IoT & PSTI

Product Security and Telecommunications Infrastructure Act (PSTI) - IoT default password and support period mandates.

Satellite Communications

NSI Act satellite schedule, CNI designation for ground stations, and UK-US Data Bridge compliance.

Operational Overlay

DIRECT Pillar Deployment.

DIRECT
01

Decision architecture for Ofcom regulatory engagement and readiness for Essential Entity designation under the forthcoming Cyber Bill.

02

Cyber Bill readiness, TSA High-Risk Vendor management, and 24-hour incident reporting architecture.

03

Market entry for telecoms technology firms in the CNI-designated procurement environment.

04

AI-enabled network monitoring, incident detection, and PSTI compliance for IoT deployments.

05

Capital engineering for DSIT National Research Cloud and data infrastructure investment.

STRATA
01

Accrediting the cyber resilience and telecommunications security workforce.

Sector Record
ClassificationCNI Designated - Tier 1
SectorS05 - Sovereign Sector Intelligence
Lead Gov DeptOFCOM / DSIT
CoverageActive - PSTI Enforcement

Regulatory Triggers

Designation12 Sep 2024

CNI designation of Data Centres - brought within critical national infrastructure scope.

ForthcomingH2 2026

Cyber Security & Resilience Bill - completed Commons passage 10 June 2026; before the Lords; Royal Assent expected H2 2026.

ComplianceOngoing

TSA High-Risk Vendor - mandatory equipment removal deadline.

Restricted Intelligence

Dossier Access Required
Telecommunications Briefing

The Telecommunications dossier covers the sector's regulatory architecture, the institutions that govern it, and the decisions currently in play. Access is restricted to verified CNI operators and sovereign entities.

Request Access →