Critical National Infrastructure
Technology and Regulatory Risk in Telecoms and Defence
By Stephen Hermanson
August 2026
Introduction
Summer recess is often a time for reflection and 2026 heatwaves in the UK provided ample opportunity to escape to an air-conditioned library or shaded deckchair to think more broadly about the security of critical national infrastructure (CNI). I found myself searching for perspective, and whilst stepping back to gauge the wider picture I came across a piece in The Telegraph about Germany’s support to the UK nuclear programme.
Further reading about the UK’s Defence Nuclear Enterprise (DNE), or what some might refer to as the Defence Industrial Complex, revealed some interesting parallels and differences to other critical sectors. I decided to explore the comparison to understand more about the technology risk and whether other CNI sectors such as Telecoms offered any insights for DNE.
For example, the UK’s replacement warhead programme (Astraea) is often discussed as a physics programme. That framing is incomplete as Astraea is also a technology-dependent programme in the same sense that telecoms, energy and data infrastructure are – reliant on semiconductors, high-performance computing, and increasingly AI-assisted tooling, all sourced through supply chains that are now openly contested ground in UK-EU-US technology policy and in State cyber campaigns.
Telecoms has already had a painful and public reckoning with technology-partner risk. If we conclude that DNE has equivalent Critical National Infrastructure status, then it’s worth asking how DNE can navigate inevitable public policy interventions that seek to respond to very similar technology and supply chain risks.
DNE as CNI – not a special case
The UK National Protective Security Authority’s current CNI sector list places DNE explicitly within the Defence sector, alongside the Ministry of Defence, the National Armaments Director Group, and the three Services. That designation is fairly intuitive and the Government’s own framing of DNE as a “National Endeavour” reinforces the point. The £15 billion committed to the sovereign warhead programme this Parliament firmly establishes Astraea as a critical national infrastructure programme as opposed to a niche defence project.
The point is not that DNE and Astraea are newly vulnerable. It’s that both also face state-linked supply chain compromise, concentration risk in a shrinking pool of trusted technology vendors, and dependency on compute and components whose provenance is increasingly a matter of public policy rather than private procurement. Telecoms, data infrastructure and energy have all had to build publicly regulated responses to these threats. DNE’s assurance architecture has historically been built around a different question (safety and proliferation).
Astraea’s digital pivot: why compute sovereignty is now a programme risk
Astraea will be the first British warhead certified without a live nuclear test, in line with the UK’s Comprehensive Test Ban Treaty commitments. In place of live testing, certification rests on the UK Atomic Weapons Establishment’s (AWE) digital and experimental infrastructure, which recreates the extreme temperatures and pressures found at detonation, and powerful compute, which underpins the modelling and simulation work behind the design. That is a structural change from earlier warhead generations. It means the compute and simulation layer isn’t a supporting IT function sitting behind the “real” programme. It’s directly part of the certification chain. A disruption, compromise or capability gap in that layer is a programme risk, not simply an IT risk.
This is terrain that the UK’s technology-sovereignty debate is wrestling with. On semiconductors, the EU’s own justification for its Chips Act 2.0 is blunt: dependency on a small number of overseas manufacturers and designers has become “a potential source of geopolitical leverage”. AWE’s procurement of advanced electronics and electromechanical devices (for arming, fuzing and firing systems and other non-nuclear components that sit outside treaty commitments) may draw on specialised, low-volume, high-assurance components from overseas manufacturers and designers. Supplier assurance systems such as the Defence Cyber Protection Partnership will have an increasingly essential and scrutinised role.
On AI and compute, the UK sovereignty debate has moved beyond theory. In mid-2025 (around London Tech Week) the UK government commitment to scale compute capacity twenty-fold by 2030. In September 2025 the UK-US Technology Prosperity Deal was framed around $30bn in US investment. In January 2026 a cross-party Early Day Motion signed by 45 MPs warned that government services and “critical infrastructure” have become dependent on a small number of hyperscale cloud providers. The AI-assisted design, simulation or manufacturing for Astraea or its successors will inherit that same dependency question, layered onto the existing export-control regime that governs the W93/Mk7 (US warhead programme) relationship with Astraea.
As for cybersecurity, AWE’s own risk profile changed materially when it was brought back under full Ministry of Defence control in 2021. The Future Materials Campus, Mensa and Pegasus builds are large, long-duration, digitally intensive capital programmes – precisely the profile that state-linked supply chain campaigns elsewhere in CNI have targeted during construction and commissioning.
The telecoms precedent: categorise, mandate, diversify
Telecoms has already run this playbook. The Telecommunications (Security) Act 2021 gave government a legal mechanism (“designation notices” and “designated vendor directions”) to formally categorise a supplier as high-risk and mandate its removal on a defined timeline. Crucially, that mandate was paired with funding to strengthen supply chain diversity in the telecommunications infrastructure market. Diversification was not left to market forces alone, and included a £250 million 5G Supply Chain Diversification Strategy, a Telecoms Diversification Taskforce, and sustained government backing for Open RAN as a route to a more competitive vendor base.
What stands out for DNE purposes is government’s own candour about the trade-off this created. In its own words at the time, removing high risk vendors “brings with it a resilience risk as we become more dependent on the remaining suppliers”. Diversification wasn’t treated as a one-off vendor ban; it was treated as a resourced, multi-year programme explicitly designed to stop one dependency risk from simply concentrating into another. The regulatory architecture reflected that: Ofcom was given an ongoing security-monitoring duty over the sector, informed by the National Cyber Security Centre’s (NCSC) technical risk assessments, rather than the security question being left inside general market regulation.
Where the analogy holds and where it breaks
The telecoms model transfers well to everything in Astraea’s technology stack that is not treaty-bound, such as semiconductor and electronics supply chains, other non-nuclear components, the compute and AI tooling for the certification pathway, and the cyber assurance of contractor and construction ecosystems.
However, the analogy breaks down at the core of the Astraea programme. Telecoms diversification worked because alternative vendors genuinely existed and new entrants would eventually appear. Astraea’s core dependency, the shared Mk7 aeroshell and its parallel development with the US W93 programme (governed by the 1958 Mutual Defence Agreement and the Polaris Sales Agreement), has no equivalent alternative. It is singular by treaty design, not by market failure, and it cannot be diversified.
Nonetheless, it’s still possible to apply the diversification logic in other layers that surround the treaty. This distinction is worth making because it changes the mitigation strategies for DNE technology resilience and for specific programmes such as Astraea.
Recommendations: old questions, new tools, and a role for ONR
This isn’t a new line of inquiry. Writing for RUSI in January 2021, Dr Matthew Harries set out five themes where Parliament should press for clarity about what would become the Astraea programme, and included these questions: “What are the implications of dependence on US decisions, especially those relating to the W93/Mk7 programme? What is the backup plan in case of any disruption?”
Since 2021, the technology sovereignty and cybersecurity debates offer DNE a template for technology assurance and hardening that sits outside the treaty relationship, even where the relationship itself remains structurally “unhedgeable”.
Harries’ broader recommendations for routine Defence Committee sessions (in private where appropriate) with the Nuclear Warhead Capability Sustainment Programme and scrutiny of AWE’s post-nationalisation governance can allow technology and supply-chain resilience to become an explicit and standing part of the agenda as opposed to building entirely new scrutiny mechanisms and architecture.
That instinct, to use what already exists rather than build something new, should guide the regulatory answer too. The obvious risk in reaching for a Telecoms Security Act-style regime for DNE is regulatory and assurance burden: a new designated-vendor apparatus, modelled on Ofcom’s role, stacked on top of an already complex safety and security architecture that DNE answers to. That architecture already has a natural home for this work. The Office for Nuclear Regulation regulates nuclear security, safety and the protection of sensitive nuclear information and industrial control systems at AWE sites, working in partnership with the National Cyber Security Centre. ONR does not regulate warhead design itself (that responsibility sits with the Defence Nuclear Safety Regulator) but, its site-level cyber and information assurance remit already reaches into relevant parts of AWE that technology-sovereignty risk actually touches.
Rather than layering a new Ofcom-style vendor-designation regime onto DNE, the more proportionate route is to extend ONR’s existing cyber security and information assurance function (in partnership with NCSC and the Ministry of Defence’s own Defence Cyber Protection Partnership) into a formal technology assurance role for programmes such as Astraea. That keeps the assurance function inside a body that already holds the necessary clearances, sector trust and working relationship with AWE, rather than asking a new structure to build all of it from scratch while duplicating work ONR is, in large part, already resourced to do. The question for Parliament, in Harries’ terms, shouldn’t only be whether Astraea is on schedule and on budget; it should be who is accountable for assuring the technology, compute and AI supply chains the programme now quietly depends on, and whether that accountability sits with a body equipped to exercise it without adding a second regulatory layer to an already heavily regulated enterprise.
References
- Germany in talks to help fund Britain’s Trident nuclear deterrent, The Telegraph
- National Protective Security Authority, “Critical National Infrastructure,” npsa.gov.uk
- GOV.UK, “A National Endeavour: Nuclear as part of the Defence engine for growth”
- AWE, “The UK’s Defence Nuclear Enterprise: Driving Growth, Security and Innovation,” awe.co.uk, May 2026
- Wikipedia, “Astraea (nuclear warhead)”
- European Commission, “Proposal for the Chips Act 2.0,” digital-strategy.ec.europa.eu
- Council of the European Union, Chips Act 2.0 documentation, 3 June 2026
- GOV.UK, “AWE – Advanced Electronics and Electromechanical Devices: Competition Document”
- Computer Weekly, “Breaking the stranglehold: Responses to data sovereignty risk,” April 2026
- GOV.UK, “Roadmap to remove high risk vendors from telecoms network,” November 2020
- UK Parliament, Written Statement HCWS610, 30 November 2020
- GOV.UK, “Ex-BT boss leads task force to attract new vendors to UK telecoms”
- Matthew Harries, “The UK’s New Nuclear Warhead: Issues for Parliament,” RUSI Commentary, 11 January 2021
- Office for Nuclear Regulation, “Cyber Security and Information Assurance specialism,” onr.org.uk
- Institute for Government, “Office for Nuclear Regulation,” explainer, accessed January 2026
Leave a comment