FCA Crypto Authorisation: Preparing for the September 2026 Gateway
FCA Crypto Authorisation: Final Rules and the Five-Month Application Window
The Financial Conduct Authority has finalised the principal rules for the United Kingdom’s new cryptoasset regulatory regime. Firms will be able to apply for authorisation between 30 September 2026 and 28 February 2027, ahead of the regime commencing on 25 October 2027.
This is not simply an extension of the existing anti-money laundering registration system. In-scope crypto firms will enter the wider framework under the Financial Services and Markets Act 2000, with requirements covering prudential resources, governance, customer treatment, market conduct, safeguarding, reporting and regulatory supervision.
Existing registrations and permissions will not convert automatically. Crypto exchanges, custodians, intermediaries, stablecoin issuers and other affected businesses should now determine their regulatory perimeter, identify the permissions they need and prepare an authorisation-ready operating model.
For readers’ convenience, we have placed the key official sources and regulatory materials at the end of this article.
Publish Date
07 Aug 2026
Reading Time
13 minutes
Category
Legal News
Jurisdiction
UK
The FCA has completed the main crypto rulemaking programme
On 30 June 2026, the FCA published its final crypto roadmap rules and guidance. The package brings together several policy statements covering the prudential regime, stablecoin issuance, custody, trading platforms, conduct, governance, consumer protection, market integrity and regulatory reporting.
The final rules are intended to apply to firms authorised to conduct regulated cryptoasset activities on or after 25 October 2027. That is the full commencement date specified in the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026.
The FCA has described the June package as the completion of its crypto roadmap. However, some secondary guidance remains outstanding.
In particular, the FCA expects to publish a further policy statement on the cryptoasset regulatory perimeter in September 2026. It also plans consultations on decentralised finance, operational resilience for businesses using distributed ledger technology and financial-crime guidance relevant to crypto firms.
Businesses should therefore treat the current rules as the main application framework, while continuing to monitor the remaining guidance.
When does the UK crypto authorisation gateway open?
The application period runs from:
| Milestone | Date |
|---|---|
| Authorisation gateway opens | 30 September 2026 |
| Application window closes | 28 February 2027 |
| New crypto regime commences | 25 October 2027 |
The FCA is encouraging firms to apply early during the five-month window. Applying within the prescribed period may allow an eligible firm to rely on statutory saving provisions if the FCA has not determined its application before the new regime begins.
The saving provisions are commercially important. Subject to the applicable conditions, a firm that applies within the window may continue specified activities while its application remains under consideration.
A firm that applies after 28 February 2027 will be in a materially weaker position. If it has not obtained the required permission by 25 October 2027, it may enter the transitional framework and be restricted to activities necessary to perform pre-existing contracts.
Such a firm may be unable to enter new contracts with existing UK customers or onboard new UK customers. The FCA has also said that it will not accelerate late applications to compensate for delayed submission.
Existing FCA registrations will not convert automatically
One of the most important points for the market is that an existing regulatory status does not automatically become a crypto authorisation.
The FCA has confirmed that the following businesses may still need to submit a new application or variation of permission:
- firms registered under the UK Money Laundering Regulations;
- firms already authorised under FSMA;
- payment institutions;
- electronic money institutions;
- and firms relying on an authorised approver for crypto financial promotions.
The relevant question is whether the business will conduct one or more regulated cryptoasset activities after the new regime begins. Existing status may help demonstrate regulatory experience, but it does not remove the need to obtain the correct crypto permissions.
For currently authorised firms, the appropriate route may be a variation of permission rather than a completely new authorisation. The business must still assess how its crypto activities affect its governance, financial resources, risk profile, systems and existing permissions.
For MLR-registered businesses, the change is more substantial. MLR registration focuses principally on financial-crime controls. FSMA authorisation introduces a much wider assessment of whether the firm meets the FCA’s Threshold Conditions and can comply with ongoing conduct and prudential requirements.
Which crypto businesses may require FCA authorisation?
The final perimeter will depend on the statutory activities and the FCA’s forthcoming guidance. Businesses should not assume that a familiar commercial label determines their status.
Depending on the precise business model and UK connection, authorisation may be relevant to firms involved in:
- operating a qualifying cryptoasset trading platform;
- dealing in qualifying cryptoassets as principal;
- dealing as agent;
- arranging transactions;
- safeguarding qualifying cryptoassets;
- operating qualifying cryptoasset staking arrangements;
- and issuing qualifying stablecoins.
The FCA has specifically referred to trading platforms, intermediaries, custodians, stablecoin issuers and businesses arranging staking as firms that may require authorisation.
A perimeter assessment should examine the actual contractual and operational arrangements. Relevant questions include:
- Which entity contracts with the UK customer?
- Where are orders received, transmitted and executed?
- Who controls customer assets or private keys?
- Does the business act as principal, agent or arranger?
- Is the platform operator legally separate from the custodian?
- Is staking provided directly or arranged through another entity?
- Does the firm issue, distribute or facilitate use of a qualifying stablecoin?
- Which activities are performed in or into the United Kingdom?
Overseas businesses should pay particular attention to territorial scope. The location of the group headquarters is not, by itself, decisive.
What do the final FCA crypto rules cover?
The final framework is broader than a licensing form or compliance-policy exercise. It requires applicants to demonstrate that their business model can operate under the FCA’s standards from authorisation onward.
Prudential capital and liquidity
The FCA has created a dedicated prudential framework for regulated cryptoasset firms. The framework covers:
- the composition of regulatory capital;
- permanent minimum capital requirements;
- fixed-overheads requirements;
- activity-based risk requirements;
- liquid assets;
- concentration risk;
- overall risk assessments;
- and public prudential disclosures.
The final permanent minimum requirements include £75,000 for dealing as agent and arranging deals, £150,000 for operating a cryptoasset trading platform and qualifying staking activities, and £750,000 for dealing as principal. The amount ultimately required may be higher where other prudential calculations produce a larger figure.
Firms must therefore prepare more than evidence of current cash balances. An application may require forward-looking financial projections, capital classification, liquidity planning, risk calculations and a credible assessment of the resources needed during stressed conditions and wind-down.
The FCA’s final prudential rules also address stablecoin issuance. Following consultation, the operational-risk capital factor for stablecoin issuance was reduced from 2% to 1%.
Governance and senior management
Most authorised crypto firms will be brought within established FCA Handbook requirements concerning governance and systems and controls.
The final package applies, where relevant:
- the Senior Management Arrangements, Systems and Controls Sourcebook;
- the Senior Managers and Certification Regime;
- conduct standards;
- regulatory reporting;
- client-asset requirements;
- complaints and dispute-resolution rules;
- and the Consumer Duty.
The FCA has confirmed that most crypto firms will be subject to requirements including the Consumer Duty, COBS, SYSC, SM&CR, CASS and access to the Financial Ombudsman Service.
Applicants should expect the FCA to examine whether senior managers understand the business and can exercise effective control over it. Governance arrangements should match the firm’s scale, complexity and risk rather than exist only as formal documentation.
Relevant evidence may include:
- a clear board and committee structure;
- allocated senior-management responsibilities;
- conflicts-of-interest controls;
- management information and escalation processes;
- risk ownership;
- compliance independence;
- internal-audit arrangements;
- and board-approved implementation and wind-down plans.
Consumer Duty and customer treatment
The application of the Consumer Duty is a significant change for many crypto businesses.
Firms serving retail customers will need to demonstrate that they can deliver good outcomes across:
- products and services;
- price and value;
- consumer understanding;
- and customer support.
This may require changes to product governance, fee disclosure, customer communications, complaints handling and the assessment of foreseeable harm.
A technically accurate risk warning will not necessarily be sufficient. Firms should consider whether customers can understand the product, its costs, its limitations and the principal risks of loss.
Custody and client assets
Crypto custodians will need to consider the interaction between the dedicated crypto rules and the FCA’s client-asset framework.
Application materials should explain:
- how legal and beneficial ownership is recorded;
- how customer assets are segregated;
- the firm’s wallet architecture;
- private-key management;
- access controls;
- reconciliation procedures;
- incident response;
- use of sub-custodians;
- insolvency treatment;
- and arrangements for returning assets during wind-down.
The FCA is unlikely to assess custody through cybersecurity documents alone. The legal structure, operational process and customer disclosures must be consistent.
Market integrity and trading platforms
Trading platforms and intermediaries will face requirements intended to support fair and orderly markets.
Depending on the activity, firms may need controls covering:
- token-admission standards;
- disclosure review;
- conflicts of interest;
- order handling;
- market surveillance;
- insider information;
- suspicious activity;
- wash trading and manipulation;
- and record keeping.
Platforms should assess whether existing surveillance tools and staffing can support the new requirements. A system built primarily for transaction monitoring under AML rules may not be sufficient for market-abuse monitoring.
Financial crime controls remain essential
The introduction of FSMA authorisation does not make AML/CFT controls less important. It places them within a wider supervisory framework.
Applicants should be able to demonstrate effective:
- business-wide and customer-risk assessments;
- customer due diligence;
- sanctions screening;
- blockchain analytics;
- transaction monitoring;
- source-of-funds controls;
- suspicious-activity escalation;
- governance;
- outsourcing oversight;
- and independent testing.
The FCA has already warned that poor-quality applications may be rejected, delayed or refused. Existing MLR-registered firms should not assume that prior registration proves readiness for the new regime.
Operational resilience and outsourcing
Operational resilience is particularly important for crypto firms relying on cloud infrastructure, wallet providers, blockchain analytics, liquidity venues or group technology.
An applicant should be able to identify:
- its important business services;
- critical dependencies;
- material outsourced providers;
- service and concentration risks;
- incident-management arrangements;
- data-recovery processes;
- and credible continuity plans.
Group-wide technology does not remove the authorised entity’s responsibility. The UK applicant should have sufficient oversight, contractual rights, management information and practical ability to intervene.
The FCA plans additional consultation on operational-resilience guidance for firms using distributed ledger technology. Businesses should monitor that work, but should not delay their underlying resilience assessment.
What should firms prepare before 30 September 2026?
The remaining period before the gateway opens should be used to assemble a coherent application rather than a collection of disconnected policies.
The FCA expects firms to determine the required activities and permissions, conduct a gap analysis, adopt a board-approved implementation plan and assess the resources and costs of authorisation and ongoing compliance.
A practical work programme should include the following stages.
1. Confirm the regulatory perimeter
Map every UK-facing product, service, contractual flow and group entity against the new regulated activities.
Any uncertainty should be recorded and resolved through legal analysis. Where assumptions remain dependent on the forthcoming perimeter policy statement, firms should identify them explicitly.
2. Select the applicant entity
The applicant should have the substance, people, governance, capital, contracts and systems necessary to conduct the regulated activity.
A newly incorporated shell with all meaningful functions located elsewhere is unlikely to provide a strong authorisation case without a credible implementation programme.
3. Define the permissions
The requested permissions must reflect the real business model.
Overly narrow permissions can prevent the firm from conducting planned activities. Overly broad permissions can increase scrutiny and require the applicant to evidence capabilities it does not need.
4. Complete a regulatory gap analysis
The gap analysis should cover, at minimum:
- Threshold Conditions;
- governance and SM&CR;
- prudential requirements;
- Consumer Duty;
- conduct of business;
- custody and safeguarding;
- financial crime;
- market integrity;
- operational resilience;
- outsourcing;
- complaints;
- regulatory reporting;
- and wind-down.
Each gap should have an accountable owner, remediation action, budget and delivery date.
5. Prepare financial and prudential materials
Applicants should develop:
- regulatory-capital calculations;
- liquidity forecasts;
- base and stress scenarios;
- operating forecasts;
- group-funding arrangements;
- an overall risk assessment;
- and a wind-down financial model.
The FCA has published an updated financial-data template that applicants will be required to complete. The application form itself is still being finalised, although the FCA does not expect its overall structure and content to change materially.
6. Strengthen governance and accountability
Senior managers should be involved before submission.
The board should understand the regulatory perimeter, principal risks, implementation gaps, resource requirements and assumptions underlying the application. Policies approved shortly before submission, without evidence of practical implementation, may receive greater scrutiny.
7. Align documentation with actual operations
The regulatory business plan, policies, contracts, organisation chart, financial projections and technology descriptions should tell the same story.
Inconsistencies can raise questions about whether the applicant understands or controls its own business.
8. Plan for remediation and regulatory questions
A good application should be complete, but firms should still prepare for follow-up questions.
Key personnel should be available to explain the business model, governance, financial assumptions, customer journey, custody model and principal risks.
What happens if a firm does not obtain authorisation?
A business carrying on an in-scope regulated cryptoasset activity without the required permission after the regime commences may breach the UK’s general prohibition.
The consequences may include:
- restrictions on continuing UK business;
- inability to onboard customers;
- enforcement exposure;
- contractual disruption;
- reputational damage;
- and the need for an orderly wind-down.
The transitional provisions should not be treated as a substitute for preparation. Their purpose is to manage the consequences of firms leaving or completing existing contractual obligations, not to provide an unrestricted extension of normal business.
Firms that decide not to apply should prepare a controlled UK exit plan. This should cover customer communications, return or transfer of assets, contract termination, complaints, records, staffing, outsourcing and regulatory notifications.
The September gateway changes the UK market-entry timetable
The new regime creates a clear decision point for international crypto groups.
Businesses planning to enter the UK must determine whether to:
- submit during the 2026–2027 application window;
- acquire or invest in an appropriately authorised business;
- restructure their UK product offering;
- delay market entry until permission is obtained;
- or withdraw particular services from the UK perimeter.
Transaction structures involving an existing MLR-registered company require careful analysis. MLR registration does not guarantee future FSMA authorisation, and a transaction does not remove the need for change-in-control, governance and applicant-readiness work.
Buyers should therefore assess the target’s regulatory status, compliance history, technology, customer liabilities, financial resources, senior management and readiness for the new regime.
How Legasset can assist
The UK crypto authorisation process will require coordinated legal, regulatory, financial and operational preparation.
Legasset advises crypto and fintech businesses on regulatory-perimeter analysis, legal-entity structuring, authorisation strategy, AML/CFT, governance, prudential readiness, regulatory business plans, operational arrangements and wind-down planning.
We also support overseas groups entering the UK and investors assessing regulated or registered crypto businesses. Sensitive transaction information is considered only after appropriate KYC, NDA and Proof of Funds procedures where applicable.
FAQ: UK crypto authorisation dates and application requirements
When does the FCA crypto authorisation gateway open?
The gateway opens on 30 September 2026. The prescribed application window closes on 28 February 2027
When does the new UK crypto regime begin?
The main regime commences on 25 October 2027, when the relevant provisions of the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 take effect.
Does an existing MLR registration become an FCA crypto authorisation?
No. Existing MLR registrations do not convert automatically. An in-scope business must submit the appropriate FSMA authorisation application.
Does an authorised payment institution or EMI need a separate crypto permission?
Potentially, yes. A PI or EMI conducting a new regulated cryptoasset activity may need a variation of permission or additional authorisation. Its existing payments or electronic-money permission does not automatically cover crypto activities.
What happens when a firm applies before 28 February 2027?
Subject to the statutory conditions, a firm that applies during the prescribed period may be able to rely on saving provisions if the FCA has not completed its assessment before the new regime begins.
Can a business apply after 28 February 2027?
It can submit an application outside the window, but it may not benefit from the same saving provisions. If it is not authorised by 25 October 2027, its ability to continue UK activities may be severely restricted.
What capital will a crypto firm need?
The answer depends on the activities and the wider prudential calculation. The final permanent minimum requirements include £75,000 for certain agency and arranging activities, £150,000 for trading platforms and qualifying staking activities, and £750,000 for dealing as principal.
Is AML registration enough for the application?
No. AML systems are one part of the assessment. Applicants must also address governance, customer treatment, prudential resources, conduct, resilience, reporting, custody and other applicable FCA requirements.
Should overseas crypto firms apply?
An overseas firm should assess whether its activities fall within the UK regulatory perimeter. Offering services from another jurisdiction does not automatically place the firm outside UK requirements.
Topic-Specific Official Resources and Regulatory Materials
This FCA hub brings together the final policy statements and explains how the application window, saving provisions and ongoing authorisation requirements will operate.
II. Financial Conduct Authority — FCA sets final UK crypto rules
The announcement summarises the final regulatory package, the September 2026 gateway and the remaining guidance expected from the FCA.
III. Financial Conduct Authority — How the crypto authorisation gateway will operate
This resource explains the application period, saving provisions, late applications, transitional arrangements and the information expected in an application.
IV. Financial Conduct Authority — Preparing for the new cryptoasset regime
The FCA sets out the perimeter, permissions, gap-analysis, implementation-planning and resourcing work expected from prospective applicants.
V. UK Legislation — Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026
The statutory instrument establishes the UK cryptoasset regulatory regime and confirms the full commencement date of 25 October 2027.
VI. Financial Conduct Authority — PS26/12: A Prudential Regime for Cryptoasset Firms
This policy statement contains the final rules on capital, liquidity, concentration risk, risk assessment and prudential disclosures.
VII. Financial Conduct Authority — PS26/13: Application of the FCA Handbook to Regulated Cryptoasset Activities
This statement explains how conduct, governance, Consumer Duty, SM&CR, CASS, complaints and reporting rules apply to authorised crypto firms.
How do I get other licenses?
How Crypto and Payment Firms Should Prepare for the EU AML Regulation
Which Financial and Crypto Groups Could Face Direct AMLA Supervision?
European Commission Reviews MiCA Rules for Stablecoins and Crypto Services
BVI Gains Ground in Tokenised Treasuries and RWA Finance
Hong Kong Broadens Tax Relief for Funds and Family Offices
Supreme Court Tightens UK LLP Salaried Member Rules
MiCA Reshapes USDT Access on European Crypto Platforms
No CASP Licence, no EU Business: MiCA Transitional Period Ends Across the EU
Europe’s MiCA CASP Register After March and April 2026












