The Enhanced CIRMP Rules 2026 introduce a significant uplift in supply chain security requirements for affected critical infrastructure entities.

In this episode, Tim Slattery and Marina Shteinberg from Pentagram Advisory unpack section 10A and explore the shift from traditional supply chain risk management towards critical dependency assurance. We examine what organisations may need to map, the distinction between major suppliers and dependencies supporting critical components, how deeply supply chains should be mapped, and the challenges involved in determining Maximum Acceptable Outage (MAO).

We also explore major-supplier assessment and Foreign Ownership, Control or Influence (FOCI), the intersection between supply chain dependencies and critical worker obligations, and the practical implementation questions responsible entities should be considering as they prepare for the 10 June 2028 implementation deadline.

The central question is no longer simply: Who are our suppliers?

It is: What does our critical infrastructure asset depend upon, where do those dependencies sit, and do we have sufficient assurance and resilience to manage the resulting risk?

Podden och tillhörande omslagsbild på den här sidan tillhör Pentagram Advisory. Innehållet i podden är skapat av Pentagram Advisory och inte av, eller tillsammans med, Poddtoppen.