FCA expands UK cryptoasset regime – Law Firm
Estimated reading time: 9 minutes
Headlines
On 30 June 2026, the Financial Conduct Authority (FCA) published the core final rules and guidance for the UK’s new cryptoasset regime. The timing is important: the publications arrived three months before the FCA’s authorisation gateway opens on 30 September 2026, and less than sixteen months before the new regime is expected to come into force on 25 October 2027.
The package marks a turning point. After several years of consultations and policy development, UK crypto regulation has moved from design to implementation. Firms now have a large body of final rules and guidance to digest, and a relatively short window in which to assess their business models, determine required permissions, and prepare authorisation applications.
The new regime will move the UK beyond the current limited framework of anti-money laundering registration and cryptoasset financial promotions. In-scope firms will be brought into a broader regime under the Financial Services and Markets Act 2000 (FSMA) covering authorisation, conduct, prudential standards, safeguarding, market integrity, Consumer Duty, operational resilience and senior management accountability.
This article does not attempt to summarise every rule. Instead, it focuses on what has landed, where the key pressure points are and what firms should be doing now.
What has landed?
The publications include final rules, final guidance, new consultations and supporting material. The distinction matters because not every document has the same legal status or practical significance.
| Category | Documents | Key area |
| Final Rules | PS26/9 | Admissions & Disclosures and the Market Abuse Regime for Cryptoassets |
| PS26/10 | Stablecoin Issuance | |
| PS26/11 | Regulated Cryptoasset Activities | |
| PS26/12 | A prudential regime for cryptoasset firms | |
| PS26/13 | Application of the FCA Handbook | |
| Final Guidance | FG26/5 | Application of the Consumer Duty to cryptoasset firms |
| FG26/6 | Guidance on cryptoasset operational resilience | |
| FG26/7 | Approach to international cryptoasset firms | |
| Outstanding Consultations | GC26/4 | These remain open for feedback and relate principally to prudential risk assessment guidance and systemic stablecoin regulation. |
| GC26/5 | Non-Handbook guidance on CRYPTOPRU 7: overall risk assessment for CRYPTOPRU firms | |
| BoE/FCA joint paper | Approach to joint regulation of systemic stablecoin issuers | |
| Supporting Material | Information about the authorisation application form for cryptoasset firms | Previews application forms for FCA authorisation and variations of permission |
The regime is not contained in a single instrument. The activity-specific rules in the FCA’s new Cryptoassets sourcebook (CRYPTO) are divided across PS26/9, PS26/10 and PS26/11. PS26/12 introduces the Core Prudential sourcebook (COREPRU) and the Cryptoassets Prudential sourcebook (CRYPTOPRU), while PS26/13 adds cross-cutting Handbook requirements. Firms will therefore need to build an activity-by-activity rules map for each legal entity and service, rather than treating any one Policy Statement as a complete compliance manual.
Timeline


Key developments
On 8 July 2026, the FCA published a preview of the form for firms seeking authorisation, or a variation of permission, for the new cryptoasset regulated activities. The form will combine the standard information required from most FSMA applicants with activity-specific modules for stablecoin issuance, safeguarding, staking, lending and borrowing, intermediation and operating a qualifying cryptoasset trading platform.
The preview confirms that even a relatively narrow application will require substantial supporting evidence, analogous to that for FSMA-regulated activities. Applicants seeking to safeguard cryptoassets, for example, will need to provide documentation covering trust arrangements and policies and procedures covering records and reconciliations, private-key controls and third-party custody. Other modules require evidence tailored to the relevant activity, including stablecoin backing and redemption, collateral management, order execution and market-abuse controls.
Registration under the Money Laundering Regulations (MLRs) will not convert automatically into FSMA authorisation, and firms already authorised under FSMA who undertake these activities will need to vary their permissions. A firm that submits a valid application during the 30 September 2026 to 28 February 2027 application period may continue the relevant activities under the saving provision if its application remains undetermined when the regime commences. This allows existing firms to continue operating while the FCA completes its assessment. Firms applying after the gateway window will not receive the same benefit: the FCA will not expedite their applications and, if still unauthorised at commencement of the regime, will be restricted to performing pre-existing contracts.
Firms should therefore complete their perimeter and permissions analysis, identify the relevant application modules and begin preparing the required policies, systems and supporting evidence before the gateway opens on 30 September 2026.
PS26/10 brings the issuance of UK qualifying stablecoins within direct FCA regulation for the first time. Non-systemic issuers will require FCA authorisation and will be regulated across the lifecycle of the token, while issuers recognised as systemic by HM Treasury will become jointly regulated by the FCA and the Bank of England (BoE).
The FCA’s regulatory model rests on three core requirements:
- Backing and safeguarding: the issuer must hold permitted backing assets and protect the backing pool from its own creditors.
- Redemption: holders must be able to redeem at par, generally by the end of the next business day after the issuer receives the stablecoin.
- Conduct and prudential standards: issuers will also be subject to disclosures, Consumer Duty, governance, capital and liquidity requirements.
The FCA has nevertheless made the final package more workable compared with previous drafts. It has removed forward-looking redemption forecasts from the backing asset calculation, permitted an excess of up to 5% in the backing pool, allowed limited intragroup custody and moved the start of the redemption period to after know-your-customer (KYC) checks and receipt of the stablecoin. PS26/12 also reduces the stablecoin issuance operational-risk K-factor from 2% to 1%, while PS26/13 removes UK-issued qualifying stablecoins from the restricted mass market investment category, although the Consumer Duty continues to apply.
These changes may reduce operational, capital and distribution friction, but do not alter the underlying model: the FCA is treating stablecoin issuers as operators of money-like infrastructure, for whom reserve management, redemption capacity and safeguarding are core regulatory functions.
Issuers whose stablecoins achieve significant use in payments should also plan for the possibility of systemic recognition. HM Treasury will assess this case by case, rather than by reference to a fixed market-value or market-share threshold, taking into account factors such as transaction volumes and values, substitutability and interconnectedness. Once recognised, the issuer will move into joint FCA and BoE regulation, with the BoE expecting a typical transition period of 12 to 36 months, depending on the circumstances.
PS26/11 deals with the core crypto-native activities: operating a qualifying cryptoasset trading platform, dealing, arranging, lending and borrowing, staking, safeguarding and the FCA’s current approach to decentralised finance (DeFi). The framework is intended to provide a conduct baseline for core cryptoasset business models.
For trading platforms and intermediaries, the FCA has made some refinements. Principal dealers have been removed from pre-trade transparency requirements. The FCA has also clarified that firms should check prices from at least three reliable UK authorised execution venues where possible but are not required to execute on those venues or undertake mechanical transaction-by-transaction checks, provided they maintain effective overall arrangements supported by periodic post-trade analysis.
For lending, borrowing and staking, the FCA has retained retail protections while making targeted refinements. PS26/11 confirms retail protections for cryptoasset lending, borrowing and staking, targeted refinements to collateral and auto-staking rules, and the application of safeguarding requirements under the FCA’s Client Assets sourcebook (CASS) 17 requirements with adjustments to reflect cryptoasset custody.
Custody will be a major implementation area. Firms will need to focus on ownership rights, segregation, reconciliation, trust arrangements, private key management, third-party custody arrangements and client communications.
PS26/9 introduces the final Admissions and Disclosures (A&D) regime and the Market Abuse Regime for Cryptoassets (MARC). Together, these regimes are intended to promote market integrity, improve transparency and strengthen consumer protection, while reflecting the structure and risks of cryptoasset markets.
The A&D regime gives UK qualifying cryptoasset trading platforms an important gatekeeper role. Before a qualifying cryptoasset, other than a UK-issued qualifying stablecoin, is admitted to trading, retail UK qualifying cryptoasset trading platforms (QCATPs) will be required to undertake due diligence and ensure that a qualifying cryptoasset disclosure document is published and uploaded to the FCA-owned centralised repository, subject to limited exceptions.
MARC will prohibit insider dealing, unlawful disclosure of inside information and market manipulation. It will be supported by systems and controls requirements for UK QCATPs and intermediaries, with additional obligations for large UK QCATPs, including on-chain monitoring and cross-platform information sharing.
Platforms, issuers, offerors and intermediaries should review PS26/9 and consider their proposed disclosure governance, token admission procedures, due diligence processes, surveillance tooling, inside information controls and information-sharing arrangements.
PS26/13 integrates cryptoasset firms into the FCA’s existing conduct and firm standards framework. Depending on their activities, firms will be subject to requirements including the Consumer Duty, the Conduct of Business Sourcebook (COBS), Dispute Resolution: Complaints (DISP) and the Financial Ombudsman Service, Senior Management Arrangements, Systems and Controls sourcebook (SYSC), the Senior Managers and Certification Regime (SM&CR), CASS and regulatory reporting, subject to targeted adaptations and disapplications. Firms will therefore need governance, accountability, customer-protection and reporting frameworks comparable to those of other FSMA-authorised firms.
There are, however, important limits to consumer protection. The FCA states that it does not plan to extend Financial Services Compensation Scheme (FSCS) cover to new regulated cryptoasset activities. It also confirms that, for the time being, firms safeguarding relevant specified investment cryptoassets will be subject to CASS 6 but not FSCS protection for those assets.
This creates a critical customer communications point. Firms will need to avoid a “regulatory halo” effect where customers assume that FCA authorisation protects them against cryptoasset price falls, market volatility or all custody-related losses. The FCA itself emphasises that cryptoassets remain high risk investments and that consumers could lose the entire value of their investment.
FG26/7 sets out the FCA’s approach to international cryptoasset firms seeking UK authorisation. Its baseline expectation is that solo-regulated international firms will carry on regulated cryptoasset activities through a UK legal entity. A UK branch may be accepted for QCATP activity where access to global liquidity supports better execution outcomes, while other regulated activities—particularly safeguarding—will generally be expected to sit in a UK legal entity. Dual-regulated firms may be permitted to carry on cryptoasset activities through a branch on a case-by-case basis, subject to the FCA’s and Prudential Regulation Authority’s assessment.
International cryptoasset firms will therefore need to consider the UK legal entity and branch requirements carefully when determining whether, and through what structure, to conduct UK operations.
What remains open?
Although the core regime is now final, updates to the regime will be continuing. The FCA has confirmed that further components of the cryptoasset regime remain to be progressed through policy development and consultation, including work on DeFi, distributed ledger technology, cryptoasset derivatives, stablecoin-related policy, audit requirements, resolution and financial crime guidance.
Two FCA prudential guidance consultations remain part of the implementation picture: GC26/4 on COREPRU 7 overall risk assessment and GC26/5 on CRYPTOPRU 7 overall risk assessment. Both close on 30 July 2026.
What should firms do now?
Firms should now move from regulatory monitoring to a structured authorisation and implementation programme. Firms that may fall into the new cryptoasset regime should:
- complete a perimeter analysis, mapping each product and service, legal entity, customer type and jurisdiction against the new regulated activities and available exclusions;
- settle the permissions and structure, including whether a new Part 4A authorisation, variation of permission, UK legal entity or branch model is required;
- prepare the application evidence, including the regulatory business plan, governance and SM&CR arrangements, financial forecasts, prudential assessments, financial crime framework, compliance monitoring plan and relevant activity-specific policies;
- identify operating-model changes, particularly in relation to custody and trusts, third-party arrangements, customer journeys, disclosures, market-abuse surveillance, operational resilience and regulatory reporting; and
- establish a delivery plan through to 25 October 2027, with clear ownership, dependencies, board oversight and evidence that the firm will be ready to comply from commencement.