7 Days is a weekly round up of developments in pensions, normally published on Monday mornings. We collate this information from key industry sources, such as the DWP, HMRC and TPR.
In this 7 Days
- HMRC consults on NMPA draft regulations
- TPR publishes new and updated guidance to accompany the new CDC code
- Companies House updates timing for identity verification requirements
- SPP report on choosing an endgame strategy
- GAD blog on digital resilience for pension schemes
HMRC consults on NMPA draft regulations
On 6 August 2026, HMRC published a technical consultation on draft regulations to introduce transitional measures for the increase to NMPA from age 55 to age 57 from 6 April 2028.
Some individuals who are aged 55 or 56 immediately before the NMPA increase may already have become entitled to pension benefits or have taken steps to access those benefits. Without further provision, payments made after 5 April 2028 could be unauthorised, despite the member having satisfied the rules in force prior to the increase.
To address this issue, in specified circumstances, members who were aged 55 or 56 on 5 April 2028 will be treated as having reached age 57 so that the relevant pension and lump sum payments made on or after 6 April 2028 continue to qualify as authorised payments. The draft regulations cover certain pension income payments, stand-alone lump sums, pension commencement lump sums, pension commencement excess lump sums and trivial commutation lump sums.
The consultation closes on 28 September 2026.
TPR publishes new and updated guidance to accompany the new CDC code
TPR’s new code of practice for CDC schemes came into force on 31 July 2026, replacing the existing CDC code from that date. The new code has been expanded to cater for unconnected multi-employer CDC schemes.
On that same day, TPR published a set of new and updated guidance to accompany the code, including on the fit and proper persons requirement, promotion and marketing of multi-employer CDC schemes and meeting the systems and processes requirements.
Companies House updates timing for identity verification requirements
On 5 August 2026, Companies House updated its transition plan outlining the timing for reforms under the Economic Crime and Corporate Transparency Act 2023, which include the identity verification requirements being phased in from 18 November 2025. The introduction of identity verification for those submitting filings to Companies House (eg a company secretary) has been postponed until no earlier than November 2027.
SPP report on choosing an endgame strategy
The SPP has published a paper, “Choosing an Endgame: Timing, Trade-offs, and Trustee Decision-Making”, bringing together industry views on how the endgame landscape has changed, following a roundtable held in July 2026. The consensus from the roundtable highlights that future decision-making should balance long-term member security against the potential for economic upside, commercial realities, the timing of benefits, scheme size and the evolving tools available for risk management. The paper aims to provide a strategic framework to help trustees and sponsoring employers assess the trade-offs involved in choosing an endgame, and recommends moving to “objective-led” planning, supported by robust contingency plans and alignment of governance and surplus incentives.
GAD blog on digital resilience for pension schemes
On 3 August 2026, GAD published a blog highlighting “digital resilience” as a priority for pension schemes. Digital resilience is an organisation’s ability to prepare for, respond to and recover from IT disruptions, including cyber-attacks, data breaches, system outages and human error. For the pensions industry, “the stakes are high” because schemes hold sensitive personal and financial data, and digital failures can have serious consequences like delaying payment and putting members’ personal information at risk.
With digital resilience high on TPR’s agenda, the blog identifies practical steps schemes can take to reduce risk and better prepare for incidents, including planning for worst-case scenarios, carrying out due diligence on suppliers, providing appropriate training, and regularly testing response and continuity plans.