The FCA has set out the shape of the UK's incoming cryptoasset regime, giving firms enough of a framework to begin preparing for authorisation, even though a number of important details remain to be finalised.

In a recent introductory webinar, the regulator presented the policy package published on 30 June 2026 and set out its expectations of firms ahead of the authorisations gateway. This article provides an overview of the regime's objectives, the practical implications for firms and the actions firms should be taking now.

Objectives and scope of the regime

The regime brings cryptoasset activities within the FCA's perimeter for the first time, moving firms beyond the current anti-money laundering registration into full regulation under the Financial Services and Markets Act. It is built from five core policy statements. The first covers admissions and disclosures together with the market abuse regime, and the remaining four address stablecoin issuance (PS26/10), regulated cryptoasset activities (PS26/11), the prudential framework, and the application of existing FCA rules to cryptoasset firms.

Three dates anchor the timeline. The authorisations gateway opens on 30 September 2026, the application window closes on 28 February 2027 and the full regime comes into force on 25 October 2027. While that final date may appear distant, the time required to prepare a credible application makes the window considerably tighter than it first appears.

Key areas the FCA addressed

Obligations are determined by activity. The regime regulates specific activities: operating a trading platform, dealing and arranging as an intermediary, safeguarding, staking (committing cryptoassets to help operate a blockchain network in return for rewards), and lending and borrowing. Certain requirements apply broadly, but many are activity-specific, thus a firm's obligations depend on precisely what activities they carry out. Trading platforms must demonstrate fair, orderly, and transparent markets, with controls over conflicts of interest, market making, algorithms, and settlement. Intermediaries must evidence fair order handling, execution, and reporting.

Consumer understanding underpins the retail-facing rules. Across admissions, lending and borrowing, and staking, a consistent expectation applies: retail clients must be given clear information, and for lending, borrowing, and staking, firms must obtain express prior consent on each occasion and assess appropriateness before providing a service. Admitting an asset for retail trading is framed as a deliberate decision, supported by due diligence and a clear disclosure document.

Safeguarding is a central pillar of the regime. The rules build on existing custody principles but add cryptoasset-specific expectations regarding private keys, access control, daily reconciliations and the ability to identify and return client assets. A notable feature is the 2% float that permits qualifying trading platforms to access global liquidity and netting. Firms must also apply the correct client asset regime to each asset type, with tokenised securities remaining under the existing CASS framework, cryptoassets falling under the new regime and fiat client money under CASS 7.

Stablecoin issuers face the most stringent requirements. UK issuers must provide holders with a legally enforceable right to redeem at par value, process redemptions by the next working day, hold backing assets in a statutory trust separate from their own, and keep tokens fully backed at all times. Interest to holders is prohibited, although non-time-based rewards, such as transaction-based rewards, are permitted. The FCA regulates non-systemic stablecoins while the Bank of England assumes responsibility for systemic ones, and the two regimes are designed to operate together.

The prudential framework mirrors MIFIDPRU, adapted for cryptoassets. Firms must hold the higher of a permanent minimum requirement, a fixed overhead requirement (25% of the preceding year's relevant expenditure), or K-factor requirements linked to activity risk. Underpinning the framework is an overall risk assessment that firms must maintain as a live document and review at least annually, supported by new guidance now out for consultation.

Existing FCA requirements apply in full. Firms new to the perimeter must comply with the consumer duty, conduct rules, complaints handling, financial crime controls, operational resilience, the senior managers and certification regime and regulatory reporting. International firms are generally expected to operate through a UK legal entity, although trading platforms may in certain cases be able to operate through a UK branch.

What firms are telling us

The framework is now sufficiently developed to act on, but our conversations with firms preparing for the gateway point to a consistent set of concerns. Three themes stand out.

First, firms do not yet have full clarity. Several important elements remain in consultation or are still to be finalised, including the perimeter guidance, financial crime guidance, and transition and deferral arrangements, with further guidance expected on decentralised finance and distributed ledger technology. Firms are being asked to prepare against a picture that is not yet complete.

Second, the timeframe to bring operations up to standard is short. For many firms, particularly those new to the FCA's perimeter, the scale of change to governance, safeguarding, prudential, and conduct arrangements is significant, and the application window leaves limited room to design, implement, and evidence those changes.

Third, and most practically, firms for whom the UK is a strategic market are asking a straightforward question: what do we actually need to do, and in what order. With guidance still emerging and the window fixed, the priority is separating the decisions that can be taken now from those that must wait and sequencing the work accordingly.

Practical implications for firms

The regime rewards firms that understand their own business model precisely. As obligations flow from activities, the first task is not compliance drafting but an accurate assessment of what the firm does and how that maps to the perimeter. Firms that omit this step risk preparing for the wrong requirements.

Timing is a strategic decision rather than an administrative one. A firm already active in the UK that misses the application window will fall into a transitional, and effectively no-new-business, regime and will forgo the benefit of the savings arrangements. For those firms, a late or rushed application carries direct commercial consequences.

For firms moving from anti-money laundering registration to full authorisation, a particular risk is managing both processes concurrently. The FCA noted that maintaining existing obligations while standing up a substantial readiness programme is where firms most often struggle. Applications are expected to run in parallel, ideally under a single case officer.

Proportionality is genuine but conditional. The framework is designed to scale with the size and complexity of a firm, which assists smaller entrants, but the overall risk assessment and safeguarding expectations still require substantive, ongoing evidence rather than paper compliance. The consistent test the FCA set was whether arrangements operate effectively in practice and under stress.

Recommended actions

  • Map your activities against the perimeter: begin with the cryptoasset legislation approved in February 2026 and the FCA's perimeter guidance as it is finalised. This determines which rules and permissions apply.
  • Test the fundamentals relevant to your model: safeguarding and client asset segregation, stablecoin backing and redemption arrangements for issuers, and order handling and disclosures for intermediaries.
  • Commence the overall risk assessment early: it will take time to gather evidence and engage senior management, and the supporting guidance is open for input now.
  • Engage the FCA's pre-application support service: review the published, activity-specific application forms so you can assess readiness before submitting.
  • Plan around the window: if you are already active in the UK, treat 28 February 2027 as a firm commercial deadline rather than a target.

Further detail is still to come, including final perimeter guidance, financial crime and transition arrangements, and dedicated deep-dive sessions on each policy statement. The direction of travel, however, is settled, and the firms that arrive at the gateway well prepared will be best positioned in the market that follows.

Prepare for the gateway with confidence

The window is short, the assessment is detailed and important guidance is still emerging. If the UK is a strategic market for your business, the priority is understanding what to do now and sequencing the work sensibly against the deadline.

We speak with firms across the sector as they prepare for authorisation, which gives us a clear view of where firms are encountering difficulty. Contact our team to discuss what the new regime means for your business and how we can help you prepare.