top of page

New FCA Cryptoasset Regime 2027: Rules, Authorisation and How to Apply

7 days ago
11 min read
New FCA Cryptoasset Regime 2027: Rules, Authorisation and How to Apply

New FCA Cryptoasset Regime 2027: Rules, Authorisation and How to Apply

The Financial Conduct Authority’s (FCA) new cryptoasset regime is expected to take effect on 25 October 2027. It will bring specified UK cryptoasset activities within authorisation under the Financial Services and Markets Act 2000 (FSMA), alongside new conduct, prudential and activity-specific rules. Applications for the new permissions open on 30 September 2026, with the main application window closing on 28 February 2027. FCA: new cryptoasset regime | FCA: application gateway


For a new entrant, an established crypto provider or an already authorised financial services firm, the starting question is which activities its legal entity will perform and which permissions it needs. This guide explains the rules that shape that decision, the FCA application, the evidence required and what happens after submission. It applies to new and existing firms. Our separate guide to transition for existing firms examines continuity, late applications and contractual run-off. The position below is as at 28 September 2026; further FCA policy publications are expected before commencement.


Who needs FCA cryptoasset authorisation under the new regime?

Applicant

Likely route for a new in-scope activity

Immediate decision

New business without FSMA authorisation

Apply for FCA authorisation under the Financial Services and Markets Act 2000 (FSMA).

Which entity, activities and customer types will the application cover?

Firm registered only under the Money Laundering Regulations (MLRs)

Make a new FSMA authorisation application.

Which existing services cross into the new perimeter, and which additional permissions are needed?

Firm already authorised by the FCA under FSMA

Apply for a variation of permission for the relevant cryptoasset activities.

Can its current governance, resources and controls support the expanded model?

Payment or electronic money firm without the relevant FSMA authorisation

Assess the precise status of its entity; a new FSMA application may be required.

Which payment and cryptoasset functions sit in each legal entity?

Overseas business with UK-facing activity

Analyse the UK perimeter and the appropriate applicant structure.

How will the FCA supervise the business, including any UK branch and outsourced functions?


MLR registration is not FSMA authorisation. Nor does a payment, electronic money or unrelated FSMA permission automatically confer a cryptoasset permission. An existing FSMA-authorised firm uses the variation route; other firms need to establish whether a fresh FSMA application is required. The FCA’s gateway explanation makes these distinctions explicit.


1. Define the regulated activity before building the application

The application starts with an activity map, not a description of the product as an “exchange”, “wallet” or “platform”. The new perimeter includes issuing qualifying stablecoins in the UK; safeguarding qualifying cryptoassets or relevant specified investment cryptoassets, including certain arrangements for another person to safeguard them; operating a qualifying cryptoasset trading platform; dealing as principal or agent; arranging deals; and qualifying cryptoasset staking. More than one permission may be needed for one customer journey. FCA: regulated activities | FCA Handbook: PERG 18


For every service, record the asset type, customer, contracting entity, transaction flow, location of each activity, proposed permission and any limitation or exclusion. Test the operational facts: who holds or controls private keys, chooses a venue, receives and transmits instructions, settles transactions, or appoints a custodian? A third-party custody contract, offshore affiliate or software label does not decide the perimeter by itself. The FCA’s final PERG 18 guidance addresses the activity definitions, business test and territorial reach. The FSMA perimeter also differs from both MLR registration and the financial promotions regime.


An overseas firm should settle its UK structure early. The FCA’s threshold conditions include effective supervision and appropriate resources; its application preview contains a specific question for an overseas firm seeking to operate through a UK branch. Incorporation, branch arrangements and the location of decision-makers should follow the actual operating model, rather than be chosen solely for the application. FCA: minimum standards | FCA: application form preview


2. Work backwards from the FCA’s application form

The FCA has published a 73-page information preview, dated 17 September 2026. It is a planning aid, not a paper application to complete. The live, tailored form becomes available through the FCA’s online system when the gateway opens. Its questions depend on the firm’s permissions and business model, and the FCA has also published an updated financial data template for applicants. FCA: gateway and form


The form first builds the permission set, including investment types, limitations and requirements. It then seeks the conventional FSMA information on the entity, controllers, close links, senior managers, organisation, regulatory business plan, fees, financial forecasts, IT, governance, financial crime and complaints. Cryptoasset questions are added according to the proposed services and customer base. Prepare the underlying documents before entering answers: a polished form cannot resolve inconsistencies between the permission selection, customer terms, transaction diagrams and financial model.

Evidence area

What a credible application should demonstrate

Regulatory business plan

The services, customer segments, distribution, revenue model, group structure and day-one operating model match the permissions requested.

People and control

Senior manager applications, controller and close-link information, reporting lines, decision rights and adequate compliance and risk capacity are coherent.

Finance and prudential resources

Entity-level forecasts, funding evidence, regulatory capital calculations and stress assumptions support the intended scale and relevant prudential rules.

Financial crime and conduct

The firm can explain onboarding, sanctions and transaction controls, monitoring, complaints, promotions and, where relevant, retail appropriateness and Consumer Duty outcomes.

Technology and operations

IT controls, incident response, records, operational resilience and material outsourcing arrangements are specified and capable of being overseen.

Activity-specific safeguards

Custody, stablecoin, trading, intermediary or staking procedures address the risks actually created by the service.


The FCA assesses the threshold conditions, including the suitability of the business model, effective supervision, resources and the fitness and propriety of the firm and its people. Its final rule package includes general Handbook standards, prudential requirements, conduct rules, custody, stablecoin issuance, admissions and disclosures, and market abuse provisions. Which modules apply turns on the actual activity and customers. An application should trace each material rule to a responsible owner, an operational control and the evidence that the control can work. FCA: standards | FCA: final policy statement overview


Financial forecasts need to describe the applicant, not only the crypto product

Prepare the required financial data template and reconcile it with the regulatory business plan. The assumptions should explain customer volumes, transaction values, revenue, operating costs, capital, liquidity, outsourcing costs and downside cases. For an existing firm adding cryptoasset permissions, the forecast must make sense for the whole applicant legal entity, including its current regulated business. A group forecast alone does not show that the applicant has its own appropriate resources. The FCA points applicants to its financial information guidance and the updated template from its gateway page.


Make the activity-specific evidence operational

The FCA’s form preview shows how sharply the questions branch. A custodian may need to evidence the safeguarding trust, client asset records and reconciliations, oversight of third-party custodians and controls over the means of access to assets. A stablecoin issuer must explain the coin, backing assets, redemption and disclosures. Intermediaries face questions on order handling, execution, settlement and conflicts; trading platforms on their venue arrangements, admission, surveillance and market integrity. A staking provider must address the assets, risks and retail client understanding. Lending and borrowing features can generate additional conduct questions, even though the permission analysis must still be performed under the actual regulated activity definitions. FCA: form preview | FCA: final rules


This is where generic policy packs fail. The reviewer should be able to follow a transaction from onboarding to execution, custody or settlement, complaint handling and exit, and identify the person and system responsible at each point. Where a group company or supplier performs a critical step, show the contract, oversight, data access and contingency arrangement that let the applicant remain accountable.


3. Decide whether to use pre-application support

The FCA offers an optional, free pre-application support service (PASS) meeting. It can help a firm explain its model and understand the process, but the FCA does not give legal advice or promise approval. A request must already contain meaningful information about products, services, customers and the regulated activities proposed. The FCA says it will reject an unsupported request and may ask for any legal advice supporting the perimeter analysis. FCA: PASS and gateway


Use PASS to test a well-developed application strategy, particularly where the permission combination, group structure or overseas arrangement is complex. It is not a substitute for deciding who conducts each activity, resolving material design gaps or preparing the board to stand behind the business plan.


4. Submit a complete file and manage the FCA review

The online gateway opens at 7am on 30 September 2026. Build enough time before submission for board approval, senior manager applications, controller information, financial forecasts, technology evidence and supplier documentation. A firm seeking several permissions should check that each one is supported by the same operating model and that any proposed limitations are deliberate. The FCA expects applications made in the main window to be determined before commencement, but it does not guarantee a decision by that date. FCA: gateway


After submission, treat the application as an active regulatory project. Maintain a controlled version of the business plan and policies, answer information requests with evidence, keep forecasts and personnel details current, and tell the FCA about material changes. Be ready to demonstrate a process or control rather than merely describe it. The FCA may challenge the permission scope, resources, governance or implementation readiness before deciding whether the threshold conditions are met.


There is no universal application fee or review period for every cryptoasset model. Check the FCA’s current application fee guidance against the specific FSMA permissions sought; do not mistake the fee for MLR registration for the fee for FSMA authorisation. Budget separately for implementation, specialist legal or compliance work and the resources needed to operate after approval. A target launch date should allow for FCA questions and remediation, not presume approval on submission.


Can a new firm start trading while its application is pending?

The position depends on the activity and the date. Before the new FSMA regime begins, a new firm proposing an activity that requires current MLR registration must be registered before starting that activity in the UK. An MLR application and an application under the incoming FSMA regime are separate, even where their assessments overlap. After the new regime starts, a firm cannot undertake an in-scope regulated activity merely because it has applied; it needs the relevant permission or a specific legal basis to operate. FCA: MLR registration ahead of FSMA | FCA: gateway


For a firm already providing in-scope services, the timing and validity of its application can affect whether a statutory saving provision permits continuity after commencement. A later application can leave only restricted contractual run-off, and an entrant without pre-existing UK business cannot assume that those provisions let it launch. Our existing-firms transition guide sets out those routes and their conditions.


Seven checks before the board approves submission


  1. Perimeter: Does a permission matrix cover every product, legal entity, asset, UK activity and customer type, with reasons for exclusions and limitations?

  2. Consistency: Do the regulatory business plan, application answers, customer terms, transaction diagrams and financial forecasts describe the same business?

  3. Resources: Are capital, liquidity, people and systems available to the applicant entity at the proposed scale, including under a plausible stress case?

  4. Accountability: Are senior managers, group functions and third parties assigned clear responsibilities that the applicant can supervise?

  5. Safeguards: Can the firm demonstrate the controls for custody, stablecoins, trading, staking and financial crime that its actual services require?

  6. Customers: Are promotions, risk disclosures, appropriateness where relevant, complaints and the applicable Consumer Duty assessment built into the journey?

  7. Readiness: Has the firm resolved material gaps, approved a realistic launch plan and identified who will own FCA queries and changes during assessment?


Frequently asked questions


1. When can we apply for FCA cryptoasset authorisation?

The gateway opens on 30 September 2026. The main window is expected to close on 28 February 2027. The window is open to new applicants and firms needing to add cryptoasset permissions; its significance for an existing provider’s continuity is different from its significance for a first-time entrant. FCA: gateway


2. Does an FCA MLR cryptoasset registration count as authorisation?

No. MLR registration addresses the current anti-money laundering supervisory regime and does not convert into FSMA permission. A firm registered only under the MLRs must apply for the relevant new FSMA authorisation if its activity falls inside the new perimeter. FCA: gateway


3. Can an existing FSMA-authorised firm add cryptoasset activities?

Yes, through a variation of permission for the activities it proposes. Its existing authorisation does not cover the new activities automatically. The application still needs to show that its business model, governance and resources meet the standards for the enlarged permission. FCA: gateway


4. Can a payment institution or electronic money institution simply vary its existing permission?

Not on the strength of a payment or electronic money status alone. First establish whether the applicant entity is already FSMA-authorised and exactly which cryptoasset activities it proposes. The FCA expressly warns that payment and electronic money permissions do not automatically confer the new FSMA permissions. FCA: gateway


5. What documents should we prepare first?

Begin with the permission matrix, transaction and entity diagrams, regulatory business plan, organisation and control charts, senior manager and controller information, entity-level forecasts and financial data template. Then assemble risk, financial crime, compliance, complaints, IT and service-specific policies. The exact form branches according to the permissions and customers selected. FCA: form preview


6. Is a PASS meeting required?

No. It is optional and free. A useful request contains a developed business model, customer and product information, and a reasoned analysis of the permissions sought. The FCA can reject a request without meaningful supporting information and does not give legal advice or pre-approve the application. FCA: PASS


7. How long will FCA approval take?

There is no reliable single duration for every application. The FCA expects to determine applications made in the main window before the regime begins, but does not guarantee that outcome. Completeness, complexity, questions and remediation affect the timetable. Do not build a commercial launch around an assumed decision date. FCA: gateway


8. What fees and capital will we need?

The application fee depends on the permissions sought, so check the current FCA fee guidance for the FSMA application rather than relying on the separate MLR registration fee. Capital depends on the firm’s activities and applicable prudential requirements. Model the relevant FCA prudential rules, funding and stress needs for the applicant entity. A figure borrowed from another crypto business is not an adequate calculation.


9. Can we outsource custody, compliance or technology?

Outsourcing does not remove the applicant’s responsibility. The permission analysis must consider whether arranging third-party safeguarding is itself in scope; the application must then explain selection, oversight, access, security and contingency. The FCA’s form expressly asks for evidence of third-party custodian arrangements where relevant. FCA: form preview


10. Does the Consumer Duty apply to cryptoasset firms?

The FCA’s final rules and guidance explain how the Duty applies to relevant retail cryptoasset activity. An applicant serving retail customers should examine its target market, communications, support and consumer outcomes alongside the activity-specific conduct rules. A wholly institutional model still needs a correct customer classification and applicable conduct analysis. FCA: minimum standards | FCA: final rules


11. Can an overseas company apply through a UK branch?

The FCA’s form anticipates an overseas firm applying to conduct regulated activities from a UK branch and asks how it will meet the minimum standards. Whether that is the right structure depends on the firm’s activities, UK connection, governance and ability to be supervised effectively. A UK customer-facing website or offshore group entity is not itself a perimeter answer. FCA: standards


12. Does approval of a crypto financial promotion authorise the service?

No. Approval or lawful communication of a promotion and permission to conduct an underlying regulated activity are separate questions. Check the financial promotions route alongside the activity and entity analysis, particularly where an existing third-party approver is involved. FCA: s.21 approvers | FCA: gateway


How we can help

Buckingham Capital Consulting can support new entrants and established firms from initial scoping through submission and FCA questions. We can map activities and entities to permissions, test the proposed UK structure, perform an application readiness review, develop the regulatory business plan and financial model, and prepare governance, AML, conduct, safeguarding and operational evidence. We can also coordinate specialist input and help the board resolve gaps before it approves the file.


For a focused discussion of your proposed services and application route, contact Buckingham Capital Consulting. Firms already active in the market can also read our detailed guide to the transition for existing providers.


About Buckingham Capital Consulting

Buckingham Capital Consulting is a specialist regulatory consultancy supporting payment, electronic money, money services and cryptoasset businesses. Since 2013, it has worked with founders, boards and senior teams on licensing, registration, compliance, financial crime, safeguarding and regulator engagement in the UK and other markets. Its work includes UK FCA authorisation and European MiCA projects.


 
 
bottom of page