top of page

FCA Cryptoasset Regulation 2026–27: Authorisation, Rules and Transition for Existing Firms

Sep 28
14 min read
FCA Cryptoasset Regulation 2026–27: Authorisation, Rules and Transition for Existing Firms

FCA Cryptoasset Regulation 2026–27: Authorisation, Rules and Transition for Existing Firms

The UK’s new cryptoasset regime is no longer a distant policy proposal. The Financial Conduct Authority (FCA) has published the main body of its final rules and its guidance on which activities require authorisation. Applications for the new permissions open on 30 September 2026. The regime is expected to take effect on 25 October 2027.


For an existing firm, the immediate issue is whether its present business, legal entity and permissions will allow it to keep serving UK customers when the regime begins. Registration for anti-money laundering supervision does not convert into authorisation under the Financial Services and Markets Act 2000 (FSMA). Nor does an existing payment, electronic money or other financial services permission automatically cover a new cryptoasset activity. The route depends on the activity, the entity carrying it out and the permissions it already holds. FCA: new regime | FCA: application gateway


This guide sets out the rules as at 28 September 2026, the decisions firms need to make, the evidence an application will require and the different outcomes for firms that apply inside or outside the main window. It is written for boards, heads of legal and heads of compliance planning an actual UK operating model.


The dates that determine business continuity

Milestone

Date

Practical consequence

FCA application gateway opens

30 September 2026

Firms can seek a new FSMA authorisation or, where appropriate, a variation of an existing FSMA permission.

Main application window closes

28 February 2027

A valid application made in this window can qualify for the saving provision if it remains unresolved at commencement.

New regime expected to commence

25 October 2027

A firm needs the relevant permission or a lawful basis to continue the particular activity.


The FCA expects to determine applications submitted in the main window before commencement, but that is an objective, not a guaranteed decision date. The regulator urges firms to apply early with a complete and credible file. A submission rejected because it lacks the minimum information is not a valid application on which a firm can rely for continuity. FCA: gateway | FCA: preparation


Which activities require FCA authorisation?

The 2026 Cryptoassets Regulations amend the Regulated Activities Order to bring specified cryptoasset businesses within the FSMA authorisation perimeter. The activities include issuing a qualifying stablecoin in the UK; safeguarding qualifying cryptoassets or relevant specified investment cryptoassets, including arranging for another person to safeguard them; operating a qualifying cryptoasset trading platform; dealing in qualifying cryptoassets as principal or as agent; arranging deals, including arrangements with a view to transactions; and qualifying cryptoasset staking. An individual firm may need more than one permission. FCA: regulated activities


The legal analysis cannot stop at a product label such as “wallet”, “exchange”, “broker”, “payments” or “staking”. It must follow who contracts with the customer, who controls the asset or its means of access, who executes or arranges the transaction, which entity operates the platform and where each step occurs. A group that uses a third-party custodian may still be arranging safeguarding. A firm that calls itself a software provider may be arranging transactions if its role goes beyond supplying a passive tool. Conversely, buying or holding cryptoassets for a firm’s own account does not, by itself, make the firm a regulated cryptoasset service provider. The FCA’s new PERG 18 guidance gives activity-specific examples. FCA Handbook: PERG 18


The test also requires an assessment of whether the firm carries on the business of engaging in the activity, whether the activity is carried on or treated as carried on in the UK, and whether a relevant exclusion or exemption applies. These questions must be considered for each activity separately. The perimeter under FSMA is not identical to the perimeter for registration under the Money Laundering Regulations or to the rules on financial promotions. FCA Handbook: PERG 18


What changes for an existing regulated firm?

Current position

Route to consider for an in-scope cryptoasset activity

Point to check now

FCA registered cryptoasset exchange or custodian wallet provider under the Money Laundering Regulations

Apply for FSMA authorisation for the relevant cryptoasset activities, unless another existing FSMA authorisation changes the route.

Existing registration does not convert. Map every product and group entity to the new permissions.

Already FCA authorised under FSMA for other regulated activities

Apply to vary the existing permission to add the specific cryptoasset activities.

An existing FSMA licence does not authorise the new activities by implication.

Payment institution or electronic money institution without a relevant FSMA authorisation

Determine whether a new FSMA authorisation is required for its cryptoasset activity.

Payment or electronic money permissions do not automatically become cryptoasset permissions.

Overseas firm serving UK users

Assess whether its activities are carried on, or treated as carried on, in the UK, then determine the appropriate entity and authorisation route.

Customer location, the activity and the firm’s operational substance all matter.

Firm relying on an approved financial promotion

Assess the underlying business activity and its ability to market lawfully under the incoming framework.

Promotion approval is not permission to conduct a regulated cryptoasset activity.


For a firm already authorised under FSMA, the FCA describes the route as a variation of permission. For a firm registered only under the Money Laundering Regulations, a new FSMA application will ordinarily be needed for an in-scope activity. Payment and electronic money firms must check their precise legal status rather than assume that every case can use a variation. The FCA expressly includes those firms in its warning that existing registrations and permissions do not convert automatically. FCA: gateway | FCA Handbook: PERG 18.1


The exercise should produce a permission matrix, not a generic opinion that the firm is “in scope”. For each service, identify the asset, customer, contracting entity, regulated activity, territorial connection, proposed permission and any exclusion relied on. Record the legal and operational evidence behind each conclusion. That matrix should reconcile with the regulatory business plan, customer terms, technology flows, outsourcing arrangements and financial projections submitted to the FCA.


The transition rules: three materially different outcomes

Application made during the main window. If an existing firm makes a valid application between 30 September 2026 and 28 February 2027 and the FCA has not finally determined it when the regime begins, the statutory saving provision can permit continued provision of the relevant cryptoasset services while the application is decided. It can also operate where a refusal remains open to review. Conditions apply, and the FCA can in certain circumstances direct a firm into the more restrictive transitional provision. The firm must notify the FCA when it starts and stops using the saving provision. FCA: gateway


Application made after 28 February 2027 but before commencement. An application remains possible, but the FCA will not accelerate its assessment to make up for late submission. If the firm lacks the required permission on 25 October 2027, it enters the transitional provision while the application is considered. That is a restricted run-off position: the firm can perform only what is necessary for contracts entered into before it entered the provision. It cannot enter new contracts with either existing or new UK customers. The transitional provision can also apply following specified refusals or withdrawals, and has a maximum duration of two years. FCA: gateway | FCA: transitional provision


No valid application before commencement. A firm that does not apply before the regime starts cannot assume that either provision will protect it. It must complete the run-off of its in-scope UK business before commencement or obtain the necessary authorisation. Continuing without permission may breach the FSMA general prohibition or, for an already authorised firm, the prohibition on acting outside its permission. A rejected application that was never replaced with a valid one is treated as no application for these purposes. FCA: transitional provision


This distinction is commercially decisive. The saving provision protects continuity while a timely application is unresolved. The transitional provision is a controlled way to meet pre-existing obligations and leave or await a decision; it does not support ordinary customer acquisition. Firms should model the revenue, contractual and customer consequences of both outcomes before choosing a submission date.


What the final FCA rules require

The FCA published five principal policy statements on 30 June 2026, covering the application of its Handbook, prudential standards, stablecoin issuance, regulated cryptoasset services, and admissions, disclosures and market abuse. It published final perimeter guidance on 16 September 2026. Not every rule applies to every firm: the package is structured around the activities and customers in each business model. FCA: policy statement overview | FCA: perimeter guidance


Governance and conduct. Applicants must meet the FSMA Threshold Conditions, including suitability, appropriate resources, a viable business model and the ability to be supervised effectively. The FCA will apply relevant Handbook requirements, including its Principles for Businesses, the Senior Managers and Certification Regime, Consumer Duty and conduct rules according to their scope. A firm must show who owns each risk, how management information reaches the board, how customer outcomes are tested and what happens when controls fail. An existing anti-money laundering registration is no substitute for that wider operating framework.


Capital, liquidity and wind-down. COREPRU and CRYPTOPRU establish the new prudential framework. The amount a firm must hold depends on its activities and the applicable calculations, so a single headline minimum is rarely a complete answer. Management should test its forecast against capital and liquid asset requirements, stress scenarios, operating losses, group dependencies and a credible wind-down plan. The prudential policies were finalised in June; the FCA has separately consulted on additional guidance for firms’ overall risk assessments. FCA: prudential policy


Custody and stablecoins. The new CASS 17 rules address the safeguarding of client cryptoassets, including ownership arrangements, records, reconciliation, controls over private keys or other means of access and third-party custodians. CASS 16 governs the safeguarding of backing assets for qualifying stablecoin issuers, alongside rules on backing and redemption. A firm that uses a group company or external provider should be able to explain the legal custody chain, reconcile client entitlements to assets, manage incidents and demonstrate effective oversight of the provider. FCA: regulated activities policy


Trading and market integrity. Trading platforms and intermediaries must examine their dealing, execution, conflicts, disclosures and surveillance arrangements against the activity-specific rules. The admissions and disclosures regime and the market abuse regime place additional demands on firms involved in public offers, admissions and trading. Relevant controls must work with the actual order flow, listing process and data available to the firm. A generic market abuse policy will not explain how suspicious activity is identified and escalated. FCA: policy statements


Financial crime and resilience. Firms must continue to meet current anti-money laundering and financial promotion obligations while preparing for the new framework. Applications also need credible arrangements for sanctions, fraud, transaction monitoring, outsourcing, technology failure, cyber incidents, complaints and operational resilience where applicable. Where a firm already operates across payments, electronic money and cryptoassets, it should identify which controls are genuinely shared and where different legal duties require distinct records, safeguarding methods or reporting. FCA: current registration | FCA: policy statements


Stablecoin payments need a separate perimeter assessment

Stablecoin issuance, safeguarding, dealing, arranging and payment services do not collapse into one permission. The existing 2026 Regulations create a regulated activity for issuing a qualifying stablecoin in the UK. HM Treasury has also developed amendments intended to prevent certain payment uses of UK-issued qualifying stablecoins from requiring additional cryptoasset dealing or arranging permissions ahead of wider payments reform. Final amending legislation was laid in Parliament on 15 September 2026. The FCA has said it expects to consult on consequential perimeter guidance later in 2026 and publish further guidance in early 2027. HM Treasury: amendment update | FCA: PS26/18


The planned treatment is not a blanket exemption for every stablecoin payment model. Custody or arranging custody can still require a separate permission; overseas-issued stablecoins, lending and borrowing, and the precise structure of a cross-border flow require their own analysis. Firms should document the position under the legislation in force when they apply and monitor the amending instrument and later FCA guidance. They should also distinguish the FCA’s regime for non-systemic issuers from the Bank of England’s framework for stablecoins designated as systemic. HM Treasury: policy note | FCA and Bank of England: joint approach


Overseas firms and UK customers

An overseas incorporation does not, by itself, take a business outside the regime. The FCA says the ordinary test of whether an activity is carried on in the UK must be considered first, followed by the cryptoasset-specific provisions that treat certain activities involving UK consumers as carried on here. The answer differs by activity and transaction structure. The FCA also states expressly that reverse solicitation is not, in itself, an exclusion or exemption. A customer’s decision to approach a firm first does not settle the authorisation question. FCA Handbook: PERG 18.3


Territorial scope and the form of a satisfactory authorisation application are separate questions. An overseas group should assess which entity actually serves the customer, how UK-facing decisions and controls operate, and whether the FCA can supervise the proposed structure effectively. The FCA’s application information specifically asks an overseas firm applying through a UK branch to explain how it will meet its standards for international cryptoasset firms. FCA: application information | FCA: policy statements and international guidance


What should be in the application file?

The FCA’s 17 September 2026 information document describes the questions expected in the new online application. The form is tailored to the permissions and business model selected; the published document is for preparation and should not be completed as if it were the live form. It also indicates the crypto-specific information relevant to a variation of permission by an already authorised FSMA firm. FCA: application information


An effective preparation programme should assemble the following as one coherent account of the business:


  1. Perimeter and permissions. An activity-by-activity legal analysis, customer and asset types, legal entities, territorial position, exclusions and proposed permission limitations.

  2. Business model and governance. A regulatory business plan, organisational chart, ownership and controllers, senior management applications, decision rights, outsourcing map and evidence that the FCA can supervise the firm.

  3. Financial case. Forecasts, the FCA’s financial data template, prudential calculations, funding assumptions, stress testing, liquidity, group support and wind-down planning.

  4. Control framework. Financial crime risk assessment and procedures, compliance monitoring, conflicts, promotions, complaints, conduct, records, security, incident response and operational resilience as applicable.

  5. Activity-specific evidence. For example, custody trust and reconciliation arrangements; stablecoin backing, redemption and disclosures; trading platform admission and surveillance; or staking and lending customer protections.


The published form identifies a regulatory business plan, financial forecasts, senior manager and controller information, financial crime framework, compliance monitoring plan and complaints policy. It then asks detailed questions tailored to cryptoasset custody, stablecoin issuance, staking, lending and borrowing, trading and other activities. Policies must describe the actual system, people, third parties and evidence the firm will have at launch. A collection of templates that conflicts with the customer journey or financial model is unlikely to answer the FCA’s questions. FCA: application information


The practical sequence is to settle the perimeter and entity structure first, agree a board-owned gap analysis and delivery plan, build the operating evidence, and then submit a complete application early enough to answer FCA questions before October 2027. The FCA’s free pre-application support service can help a firm discuss its model and the process, but it requires meaningful information in advance and does not give legal advice or guarantee approval. FCA: preparation | FCA: gateway


Frequently asked questions


1. When does the new FCA cryptoasset regime start?

The regime is expected to commence on 25 October 2027. Firms can begin applications for the new permissions on 30 September 2026, and the main window closes on 28 February 2027. Current anti-money laundering registration and financial promotion requirements continue to matter before commencement. Firms should plan against both the submission window and the date on which they must hold permission or qualify for a lawful continuation arrangement.


2. Does an existing FCA cryptoasset registration become a full authorisation?

No. Registration under the Money Laundering Regulations is a different regulatory status. An exchange or custodian wallet provider that will conduct an in-scope activity under the new regime must determine the necessary FSMA permissions and apply for them. The existing registration should be maintained as required in the meantime. The FCA’s September perimeter guidance also describes notification obligations for firms that continue exchange or custody activity once the new regime begins. FCA Handbook: PERG 18.1 and 18.12


3. Can a payment institution or electronic money institution add cryptoassets under its present licence?

Its payment or electronic money permission does not automatically cover the new cryptoasset activities. The firm must map its actual services and legal status to the FSMA perimeter. If it is already an authorised person under FSMA, a variation of permission may be the route. If it is authorised or registered only under the payments or electronic money legislation, it may need a new FSMA authorisation. The analysis is particularly important where customer funds, cryptoasset custody and stablecoin payment flows intersect. FCA: gateway


4. What if our firm is already authorised under FSMA?

It must apply to vary its permission for each new regulated cryptoasset activity it intends to carry on. Existing authorisation for investment or other financial services does not confer cryptoasset permissions automatically. The firm should also identify which existing prudential, client asset and conduct rules continue to apply alongside the new cryptoasset-specific requirements. FCA Handbook: PERG 18.1


5. Can a non-UK firm continue serving UK customers from overseas?

Possibly, but it must first test whether its specific activities are carried on, or treated as carried on, in the UK and whether any relevant exclusion applies. Certain overseas activities involving UK consumers are expressly brought into the perimeter. The location of incorporation alone is not conclusive, and reverse solicitation is not an automatic escape route. A firm that needs authorisation must also show an operating structure the FCA can supervise effectively. FCA Handbook: PERG 18.3


6. Does using an external custodian remove the need for a custody permission?

Not necessarily. Safeguarding and arranging for another person to safeguard are both within the new activity framework. The answer turns on the firm’s role, contractual commitments and control of the assets or their means of access. An applicant relying on a third party should expect to evidence the arrangement, oversight, records, reconciliation and customer ownership position. FCA: regulated activities | FCA: application information


7. Can we continue taking on UK customers if our timely application is still pending in October 2027?

An existing firm that made a valid application during the main window can, subject to the statutory conditions and any FCA direction, use the saving provision if the application has not been finally determined. It should confirm the precise scope of the provision against the services it already provides and comply with the required FCA notifications. It should not describe a pending application as FCA authorisation. FCA: gateway


8. What happens if we apply after 28 February 2027?

The FCA can still receive an application before commencement, but it will not expedite the assessment because the firm applied late. If authorisation has not been granted by 25 October 2027, the firm enters the restricted transitional provision while the application is considered. It may perform only what is necessary under pre-existing contracts and cannot make new contracts with UK customers. That is a serious constraint on a business whose revenue depends on new accounts or repeat transactions under new contracts. FCA: gateway


9. Does the transitional provision give us two more years to trade normally?

No. Its maximum two-year duration is a ceiling for orderly run-off, not a general grace period. The exemption is limited to activities necessary to perform contracts made before entry into the provision. The firm must notify the FCA and relevant contractual parties and faces restrictions on financial promotions. It cannot enter new UK contracts merely because the provision remains available. FCA: transitional provision


10. What if an application is refused, withdrawn or rejected as incomplete?

The consequences depend on timing and whether the refusal remains open to review. An eligible firm may move from the saving provision into the restricted transitional provision after a final refusal, or use the transitional provision following a withdrawal in specified circumstances. A submission rejected for missing minimum information, with no later valid application, is treated as though the firm had not applied. It should not be used as a business continuity strategy. FCA: gateway | FCA: transitional provision


11. Are stablecoin payments exempt from cryptoasset authorisation?

There is no universal exemption. The position depends on whether the stablecoin is UK-issued, what the firm does with it and whether it issues, safeguards, deals, arranges, lends or borrows. HM Treasury has laid amendments intended to remove certain UK-issued qualifying stablecoin payment activity from dealing and arranging permissions ahead of wider payment services reform, but safeguarding and other activities require separate analysis. Firms should check the legislation and FCA guidance applicable to their precise flow. HM Treasury: amendment update | FCA: PS26/18


12. Does authorisation mean customers have deposit-style protection?

No. FCA authorisation should not be described as a guarantee against cryptoasset losses or as equivalent to a bank deposit. The availability of a complaint route or compensation scheme depends on the activity, the customer, the particular claim and the scheme rules. Firms should explain the protections that actually apply to their product and avoid implying that every cryptoasset holding or investment is covered by the Financial Services Compensation Scheme. FCA: cryptoassets


How Buckingham Capital Consulting can help

Buckingham Capital Consulting helps firms turn the new regime into a defined authorisation and implementation programme. We can assess the business model and territorial perimeter, map activities to permissions, review the legal entity and group structure, and identify the gap between present controls and the FCA’s requirements. For an existing authorised firm, that includes scoping a variation of permission; for a firm with only anti-money laundering registration, it includes preparing for a new FSMA application.


We support the regulatory business plan, governance and senior management evidence, financial and prudential forecasts, financial crime framework, customer and custody arrangements, compliance monitoring and the activity-specific materials relevant to the application. We can also help management organise responses to FCA questions and plan the operational changes needed before launch. The starting point is a candid assessment of the permissions, resources and timetable the business actually requires. Learn more about our FCA authorisation support and cryptoasset services, or contact the team.


About Buckingham Capital Consulting

Buckingham Capital Consulting is a UK regulatory consultancy founded in 2013. We advise financial services businesses on authorisation and ongoing compliance, with particular experience across payments, electronic money and cryptoasset activities. Our work combines regulatory analysis with the practical policies, governance and operating evidence firms need to present to the FCA. About Buckingham Capital Consulting

 
 
bottom of page