Twelve years ago, third-party risk management in financial services was a compliance footnote - a vendor questionnaire, an annual review, a box ticked ahead of an audit. Today it is a board-level discipline with statutory teeth, and the shift did not happen gradually. It happened in a series of defined regulatory moments: the EU's Digital Operational Resilience Act (DORA) entering into force on 17 January 2025, the UK's Critical Third Parties (CTP) regime taking effect from 1 January 2025 under joint PRA and FCA rules, and - as of 13th of July 2026 - the first designation regulations for critical third parties coming into force in the UK, formally bringing systemically important suppliers under direct regulatory oversight for the first time. The pattern is instructive, because the same structural shift is now visibly underway in the oil and energy sector - roughly two to three years behind financial services, but moving with comparable intent and speed.
On 28 May 2026, the UK Government published its Energy Sector Cyber Security Strategy, a four-year roadmap running to 2030 that was developed jointly by the Department for Energy Security and Net Zero (DESNZ), Ofgem, the National Cyber Security Centre and the National Energy System Operator. The strategy commits to developing legislation enabling direct regulation of critical suppliers by the end of 2027, and to identifying Designated Critical Suppliers (DCS) with defined maturity targets by 2030. This is, in substance, the same regulatory architecture financial services has already built: a formally designated tier of critical third parties, subject to direct oversight rather than oversight solely through the regulated entities that use them.
Ofgem has moved in parallel. Its Adapted Cyber Assessment Framework (CAF) Profile for the energy sector - built on the NCSC's foundational 14 CAF principles - now imposes explicit, prescriptive third-party risk requirements on Operators of Essential Services, including mandatory supplier inventories mapped across both OT and IT environments, contractual audit and penetration testing rights, and continuous rather than point-in-time risk assessment. Energy operators must now submit Assurance Program Plans and demonstrate compliance through documented Red-Amber-Green assessments available for regulatory scrutiny - a level of formality that would have been unfamiliar to most energy TPRM functions five years ago, but is now simply how the financial sector's Common Assurance frameworks have operated for some time.
The UK Cyber Security and Resilience Bill, introduced to Parliament in November 2025, completes the parallel. It introduces mandatory incident reporting within 24 hours for initial notification, extends regulatory scope to bring an estimated 900-plus additional managed service providers into direct regulation, and sets financial penalties of up to £17 million or 4% of global annual turnover - a penalty structure directly comparable to DORA's own enforcement regime.
What makes this convergence worth watching closely is not the specific instruments - DORA and the CSR Bill are different pieces of legislation solving for different sectors - but the underlying regulatory logic they share. Both regimes recognise that systemic risk in a critical sector no longer sits primarily within the regulated entity; it sits in the small number of suppliers, software providers and infrastructure operators on whom the entire sector depends. Financial services reached that conclusion after a series of high-profile third-party outages exposed how concentrated that dependency had become. Energy regulators appear to be reaching the same conclusion now, informed by a rising rate of third-party-originated cyber incidents across the sector and a growing awareness of how exposed OT environments have become through vendor connectivity.
For organisations in the energy sector building or maturing their third-party risk function, the direct implication of this convergence is timing. The Designated Critical Supplier framework will not arrive as a single deadline - it will arrive in stages, mirroring how the UK's own CTP regime for financial services took a full eighteen months from final rules to the first live designations. Organisations that begin building supplier-level assurance evidence, contractual audit rights and continuous monitoring capability now will be positioned when designation arrives, rather than reacting to it. The sector that watches banking's last decade closely has a genuine head start.