Global fintech and funding innovation ecosystem

UK Cryptoasset Regulations And FCA Final Rules

NCFA Regulatory Intelligence - UK FCA Final Cryptoasset Rules
NCFA Canada | Regulatory Intelligence | Digital Assets, Cryptoassets and Blockchain | Last updated July 19, 2026 | Status final FCA rules
NCFA Regulatory Intelligence
This guide explains UK cryptoasset regulations and the FCA final rules for authorisation, market access, implementation, compliance and opportunity analysis. Sources include FCA policy statements PS26/9 to PS26/13, finalised guidance FG26/5 to FG26/7 and the aggregate cost benefit analysis.
FCA Cryptoasset Regime Final rules for UK regulated cryptoasset activities

UK Cryptoasset Regulations And FCA Final Rules

The FCA published its final cryptoasset rules and guidance on 30 June 2026. The application period runs from 30 September 2026 to 28 February 2027, and the new regime starts on 25 October 2027. Use this guide to understand what the final rules require, what firms need to build, how the consultation outcome changed the design and where regulation creates market opportunities. Coverage includes admissions, disclosures, market abuse, stablecoin issuance, trading platforms, intermediaries, lending, borrowing, staking, safeguarding and custody, prudential requirements, Consumer Duty, governance, operational resilience, financial crime, reporting, redress, international firms and DeFi.

What Are The UK Cryptoasset Regulations?

The UK cryptoasset regulations bring specified cryptoasset activities into Financial Conduct Authority supervision under the Financial Services and Markets Act. The FCA final rules cover authorisation, trading platforms, intermediaries, stablecoin issuance, custody, lending, staking, disclosures, market abuse, prudential requirements, Consumer Duty, governance and operational resilience. The regime starts on 25 October 2027.

Final Rules Published30 June 2026
Applications Open30 September 2026
Application Deadline28 February 2027
Regime Starts25 October 2027
RegulatorFinancial Conduct Authority
Existing RegistrationMLR registration does not automatically convert to FSMA authorisation

UK Cryptoasset Regulation Journey

The UK has completed perimeter design, consultation and final FCA rulemaking. Firms now have an implementation period to prepare authorisation, governance, capital, custody, trading, stablecoin, market abuse and conduct systems before the regime starts.
Policy and consultation
Final rules and buildout
Implementation and supervision
Perimeter2023 to 2024 Cryptoasset activities brought into scope
Consultations2025 to 2026 CP25 and CP26 industry feedback
Final Rules30 June 2026 PS26/9 to PS26/13
Applications And Buildout30 Sep 2026 to 28 Feb 2027 Authorisation and systems preparation
Regime Starts25 October 2027 Handbook instruments commence
Supervision2027 onward Market conduct and resilience

Impact Analysis

Selected figures from the FCA aggregate cost benefit analysis and policy statements.
8%UK adults with cryptoasset holdings in 2025
£2,250Estimated average UK consumer crypto holding
£1.315BEstimated quantified firm costs over 10 years
£735MEstimated value of improved regulatory protections
£25MExample trading platform 10 year PV costs
£10MExample FSMA custodian entering crypto custody
£8MExample stablecoin issuer 10 year PV costs
£285MEstimated prudential requirement PV costs

What Firms Should Do Now

Firms that carry out or plan to carry out regulated cryptoasset activities should prepare their authorisation and implementation evidence before the application deadline.

  1. Map every UK activity against the regulated activity perimeter and identify any exclusions or special treatment.
  2. Determine whether the firm needs a new FCA authorisation or a variation of permission.
  3. Prepare a complete application for the period from 30 September 2026 to 28 February 2027 and apply as early as practical.
  4. Assign accountable owners across CRYPTO, CASS, CRYPTOPRU, Consumer Duty, SYSC, SM&CR, financial crime and reporting.
  5. Build evidence for governance, financial resources, custody, resilience, outsourcing, consumer outcomes and operational controls.
  6. Test systems and remediation plans before the regime starts on 25 October 2027.

Regulatory Intelligence Explorer

Navigate the FCA final cryptoasset regime by rule area. Each section separates requirements, implementation work, consultation outcome and NCFA’s strategic perspective.

Overview

Requirements The FCA package creates a full UK cryptoasset regime rather than a single rule. It combines designated activity rules for admissions and market abuse, regulated activity rules for trading platforms, intermediaries, lending, borrowing, staking and safeguarding, stablecoin issuance rules, prudential requirements and cross cutting FCA Handbook standards. The Handbook instruments commence on 25 October 2027.
  • The regime covers UK qualifying cryptoasset trading platforms, cryptoasset intermediaries, qualifying stablecoin issuers, custodians, lending and borrowing services, staking services and firms carrying on regulated cryptoasset activities in or into the UK
  • The final package includes CRYPTO sourcebook rules, CASS 16 for stablecoin backing assets, CASS 17 for safeguarding qualifying cryptoassets, CRYPTOPRU and COREPRU prudential rules, Consumer Duty, COBS, SYSC, SM&CR, DISP, FOS access, reporting and operational resilience requirements
  • The commencement sequence includes stablecoins, admissions, market abuse, intermediaries, trading platforms, lending, borrowing and staking, safeguarding, client asset consequentials, conduct and firm standards, and prudential instruments
  • The FCA kept the broad policy architecture but made targeted changes for proportionality, including stablecoin backing asset simplification, best execution clarification, removal of principal dealers from pre trade transparency, and operational resilience guidance
Implementation Firms should build a regime map by activity, not by document title. A single firm may need authorisation, admissions controls, disclosures, surveillance, custody arrangements, CASS controls, prudential calculations, Consumer Duty evidence, financial crime controls, operational resilience testing and regulatory reporting. The implementation plan should assign accountable owners for each CRYPTO, CASS, SYSC, COBS, SM&CR, DISP and CRYPTOPRU dependency.
Consultation Outcome
  • The FCA moved from consultation to final rules while preserving the regime design
  • Respondents generally supported a comprehensive regime, but pushed for proportionality, international competitiveness and operational clarity
  • The FCA responded with targeted refinements rather than a lighter perimeter
  • Remaining open items include further guidance on DeFi decentralisation and separate DLT operational resilience guidance
NCFA Perspective This is a regulatory market structure event. The UK is setting a supervised operating model for crypto as financial infrastructure. The strategic question is which firms can turn authorisation, custody, stablecoin operations, market surveillance, prudential analytics and conduct evidence into repeatable operating capability before the regime goes live.

Scope and Authorisation

Requirements The regime applies to regulated cryptoasset activities brought into scope by the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 and implemented through FCA Handbook instruments. Activities include operating a qualifying cryptoasset trading platform, dealing, arranging, qualifying cryptoasset lending and borrowing, staking, safeguarding and qualifying stablecoin issuance. Firms conducting those activities will need FCA authorisation unless an exclusion or specific treatment applies.
  • UK QCATP operators require authorisation where they operate in the UK or serve UK consumers from overseas
  • International firms are assessed against threshold conditions including location of offices, effective supervision, appropriate resources, suitability and business model
  • Dual regulated firms may operate in the UK through a branch where the PRA is satisfied threshold conditions and ongoing requirements are met
  • The FCA expects an authorisation gateway before the regime goes live, with firms preparing systems, controls and evidence in advance
  • Existing cryptoasset MLR registration does not replace FSMA authorisation for regulated cryptoasset activities
Implementation Firms should map every UK facing activity to the regulated activity perimeter and authorisation pathway. The implementation file should include corporate structure, UK presence, branch or subsidiary analysis, overseas service model, governance, financial resources, systems and controls, operational resilience, outsourcing, financial crime and Consumer Duty evidence.
Consultation Outcome
  • The FCA clarified its approach to international firms and branches following feedback
  • The final approach remains cautious about cross border firms serving UK consumers without clear UK accountability
  • The FCA did not create a broad equivalence shortcut in the final package
  • The authorisation runway becomes a key commercial dependency for firms seeking UK market access
NCFA Perspective Scope is the competitive gate. The UK is giving global crypto firms a route into a regulated market, but the route depends on authorisation evidence, supervision, governance and operational substance. That is different from simply allowing offshore activity to reach UK users.

Admissions and Disclosures

Requirements The admissions and disclosure framework governs admission of qualifying cryptoassets to trading on UK QCATPs and offers to the public of qualifying cryptoassets admitted to trading. It uses qualifying cryptoasset disclosure documents, admission criteria, due diligence, responsibility allocation and disclosure obligations to create a baseline for market entry.
  • UK QCATP operators must establish admission criteria and assess whether a qualifying cryptoasset should be admitted to trading
  • Offerors and relevant issuers must produce qualifying cryptoasset disclosure documents where required
  • Disclosure documents must support informed decisions and include material information about the cryptoasset, rights, risks, technology, governance and project context
  • Trading platforms need procedures for disclosure review, admission decisions, record keeping and ongoing monitoring
  • Relevant issuers and offerors face responsibility for statements and omissions in disclosure documents
  • Protected forward looking statements have specific treatment under the regime
  • Firms must manage the link between admissions, disclosures, market abuse controls and post admission monitoring
Implementation Implementation requires an admissions committee or equivalent control function, written admission criteria, due diligence checklists, disclosure templates, issuer and offeror attestations, legal review, technology risk review, conflict checks, decision records and post admission triggers. Platforms should prepare a repository for disclosure documents, versions, approvals, rejection reasons and ongoing updates.
Consultation Outcome
  • The FCA retained the admissions and disclosure framework after consultation
  • The final rules are designed to support market integrity without importing traditional securities listing rules wholesale
  • Firms will need to show how disclosures are complete, fair and understandable for the relevant market
  • The burden falls heavily on platforms because admission decisions become a regulated control point
NCFA Perspective Admissions are where market access becomes a regulated quality filter. The practical opportunity is not only listing more tokens. It is building repeatable disclosure, due diligence, legal review and issuer data infrastructure that can support credible cryptoasset markets.

Market Abuse

Requirements The market abuse regime addresses insider dealing, unlawful disclosure of inside information and market manipulation in qualifying cryptoassets and related instruments. The FCA rules and guidance set out concepts, prohibited behaviours and systems requirements for UK QCATP operators and cryptoasset intermediaries.
  • CRYPTO 4 provides guidance on inside information, insider dealing, unlawful disclosure and market manipulation
  • UK QCATP operators and cryptoasset intermediaries must prevent, detect and disrupt cryptoasset market abuse
  • Operators need systems and procedures for monitoring orders, transactions, communications, suspicious behaviour and abusive patterns
  • Firms must receive and store notifications securely with completeness, integrity and confidentiality
  • Market abuse arrangements must address crypto specific risks such as cross venue trading, on chain activity, token issuance events, concentrated holdings and information asymmetry
  • Outsourcing or delegation does not remove responsibility for compliance
  • Firms need records that can support investigation, escalation and regulator engagement
Implementation Firms should build surveillance scenarios for insider dealing, pump and dump activity, spoofing, wash trading, manipulation around token admissions, misuse of issuer information, coordinated social activity and suspicious on chain transfers. Platforms should integrate order book data, trade data, wallet data where available, issuer announcements, disclosure documents and escalation logs.
Consultation Outcome
  • The final package applies a market abuse model tailored to cryptoasset markets while drawing on familiar FCA concepts
  • The FCA expects trading venues and intermediaries to operate proactive controls rather than relying only on post event enforcement
  • Secure notification and evidence handling are explicit operational requirements
  • The regime creates a compliance technology need across surveillance, data integrity and case management
NCFA Perspective Market abuse is the credibility test for regulated crypto trading. The UK framework will only support institutional adoption if market surveillance, disclosure timing and manipulation controls are strong enough to distinguish regulated markets from speculative venues.

Stablecoin Issuance

Requirements PS26/10 sets final rules for non systemic UK issued qualifying stablecoins, covering issuance, backing assets, redemption, safeguarding and disclosures. CASS 16 governs management and safeguarding of backing asset pools. The FCA’s approach treats stablecoins as money like instruments where trust depends on backing, segregation, redemption, reconciliation and clear disclosures.
  • Issuers must maintain a backing asset pool for each qualifying stablecoin product and segregate it from the firm’s own assets and from other backing pools
  • Backing pools must be held in backing funds accounts or backing assets accounts meeting CASS conditions
  • Issuers using expanded backing assets must calculate the backing asset composition requirement every redemption day
  • The core backing asset requirement is the higher of 5% and the highest redemption percentage over the previous 180 redemption days or shorter operating history
  • Issuers must promptly notify the FCA if they cease to comply with specified backing asset requirements, with a limited exception for rebalancing after a daily calculation
  • Backing assets are held on statutory trust for holders of the qualifying stablecoin
  • Backing asset pools for different stablecoin products must be separate, distinct, independently managed and held in different accounts
  • Stablecoin funds must be promptly paid into a backing funds account or invested in assets held in a backing assets account
  • Issuers must conduct internal and external safeguarding reconciliations, identify and resolve discrepancies and maintain records
  • Redemption requirements include T+1 expectations, with KYC checks completed before the redemption period begins
  • Issuers must provide disclosures and make holders aware of withdrawal rights
  • The FCA allows limited intragroup custody subject to safeguards and allows a 5% excess in the backing asset pool
Implementation Stablecoin issuers need a dedicated operating model for backing assets, liquidity, reconciliation, redemption, disclosures, trust accounting, custodian oversight and holder communications. Implementation should include product level backing pool ledgers, daily BACR calculations where expanded assets are used, reconciliation workflows, FCA notification triggers, redemption queue logic, KYC timing controls, disclosure history and governance over tokenized versions of backing assets.
Consultation Outcome
  • The FCA simplified the backing asset composition requirement after feedback that forward looking redemption estimates were complex and burdensome
  • The FCA kept the range of permissible backing assets and rejected broader LVNAV and non UK UCITS MMF expansion because of stability concerns
  • Tokenized versions of permissible backing assets are not prohibited if they comply with CASS 16 and custody requirements
  • Redemption timelines were adjusted so KYC checks are completed before the redemption period begins
  • The FCA confirmed statutory trust arrangements and made refinements to third party and intragroup custody treatment
NCFA Perspective Stablecoin issuance is where compliance becomes product architecture. The winners will not be the firms that simply issue tokens. They will be the firms that can evidence backing, redemption, liquidity, disclosure and custody controls well enough for consumers, institutions and regulators to treat stablecoins as usable financial infrastructure.

Trading Platforms

Requirements PS26/11 sets rules for UK qualifying cryptoasset trading platforms. The framework covers location and authorisation, platform access, operating rules, conflicts, settlement arrangements, transparency, record keeping and reporting. The FCA expects platforms serving UK consumers to operate through an authorised UK model or an acceptable international firm structure.
  • UK QCATP operators require FCA authorisation if operating in the UK or serving UK consumers from overseas
  • Platforms must have operating rules, admission processes, access standards and controls for orderly trading
  • Retail customer focused requirements apply where platforms serve retail clients
  • Platforms must manage conflicts of interest, including risks around affiliated activities, proprietary activity, token admissions and market data
  • Settlement arrangements must be clear, reliable and consistent with safeguarding and operational resilience requirements
  • Transparency, record keeping and reporting obligations apply to orders, transactions and platform operation
  • Best execution expectations interact with authorised execution venues and periodic post trade analysis
  • Principal dealers were removed from pre trade transparency requirements in the final approach
  • Platforms need market abuse prevention, detection and disruption arrangements under PS26/9
Implementation Platform implementation should include authorisation planning, operating rulebook, access policy, admission governance, conflicts register, surveillance tooling, settlement design, order and trade records, client reporting, market data controls, resilience mapping and incident response. Firms should evidence why venue access, matching, settlement, custody and conflict controls protect consumers and market integrity.
Consultation Outcome
  • The FCA clarified location, incorporation and international firm expectations after feedback
  • Principal dealers were removed from pre trade transparency requirements
  • Best execution was clarified so firms should check prices from at least three reliable UK authorised execution venues where possible but do not need mechanical transaction by transaction checks or execution on those venues
  • The FCA retained the broader platform framework and added guidance rather than reducing the venue perimeter
NCFA Perspective Trading platforms are the centre of the regulated market. The commercial question is whether UK authorised venues can offer credible liquidity, transparent execution and institutional controls without losing users to offshore platforms that do not meet the same standard.

Intermediaries

Requirements The intermediary rules cover firms dealing in qualifying cryptoassets as principal, arranging deals and providing related intermediation services. They connect execution quality, client communication, conflicts, payments for order flow, authorised venue interaction, conduct obligations and prudential requirements.
  • Intermediaries must understand which regulated activity they perform and whether they deal, arrange, route, introduce or support client execution
  • Execution arrangements must be effective and supported by periodic post trade analysis
  • Firms should check prices from at least three reliable UK authorised execution venues where possible
  • The FCA clarified that firms are not required to execute on those venues or perform mechanical transaction by transaction checks if effective arrangements are in place
  • Conflicts, remuneration, inducements and payments for order flow require controls
  • Client communications and conduct obligations apply through COBS and Consumer Duty where relevant
  • Intermediaries may be subject to prudential requirements, financial crime controls, operational resilience and reporting
Implementation Intermediaries should build an execution policy, venue assessment framework, periodic price review, conflicts assessment, client disclosure process, order routing records, remuneration review and evidence that client outcomes are monitored. Firms with global routing models need controls showing how UK clients receive fair treatment under the UK regime.
Consultation Outcome
  • The FCA responded to feedback by clarifying best execution rather than imposing venue execution mandates
  • The final rules seek to balance execution quality with the reality of fragmented global crypto liquidity
  • Concerns about the arranging perimeter and international firms were addressed through guidance and refinements
  • Intermediaries remain a high implementation burden because conduct, execution, financial crime and prudential requirements overlap
NCFA Perspective Intermediation is where user experience meets regulatory discipline. Firms that can route orders well, evidence execution quality and manage conflicts may turn compliance into trust. Firms that treat execution as a black box will struggle under the new model.

Lending and Borrowing

Requirements The lending and borrowing chapter applies to authorised cryptoasset firms providing qualifying cryptoasset lending or borrowing services to retail clients who are not overseas retail clients, with certain requirements also applying to clients who are not overseas clients. Firms remain responsible where they comply through third parties such as custodians or service providers.
  • Firms must provide retail clients with information about the firm and the qualifying cryptoasset lending or borrowing service before the client is bound or before service provision
  • Information must be provided in a durable medium or through a qualifying website, mobile application or digital medium
  • Where clients give express prior consent for yield to be used in further lending, firms may not need to repeat the information requirement for that yield use
  • Retail protections apply to lending and borrowing service design, client information and risk communication
  • Firms remain responsible for compliance when using third party custodians or service providers
  • Rules and controls must address collateral, yield, client reporting, service risk, counterparty risk and return of assets
  • Lending and borrowing firms will also need prudential, safeguarding, operational resilience, financial crime and Consumer Duty evidence
Implementation Implementation should include client information templates, durable medium controls, express consent capture, yield treatment logic, collateral policy, counterparty due diligence, risk disclosures, client reporting, third party contracts, custody links, withdrawal and return processes, and complaint handling. Firms should stress test whether clients understand rehypothecation, loss, yield, liquidity and counterparty risk.
Consultation Outcome
  • The FCA confirmed retail protections for lending and borrowing as part of the final PS26/11 package
  • The rules preserve firm accountability even where service delivery uses third parties
  • Final refinements address collateral and service design issues but keep lending and borrowing inside a regulated conduct baseline
  • This is one of the areas where Consumer Duty evidence will matter because product risk can be hard for retail clients to understand
NCFA Perspective Crypto lending is no longer being treated as a purely private yield product. The UK regime pushes it toward regulated product governance, clear client information and controlled service design. That could reduce high risk models but may also create room for safer institutional and collateral services.

Staking

Requirements The staking framework in PS26/11 confirms retail protections and targeted refinements to staking rules, including treatment of auto staking. Staking services create operational, validator, custody, disclosure and client outcome risks that connect to safeguarding, operational resilience and Consumer Duty.
  • Firms providing staking services must identify whether the service is within the regulated perimeter and which client protections apply
  • Client information should explain staking arrangements, validator risk, lockups, slashing, rewards, fees, liquidity, tax or reporting context where relevant and operational dependencies
  • Auto staking treatment was refined in the final rules
  • Where staking uses validators, node operators, custodians or other service providers, the authorised firm remains accountable for regulated obligations
  • Operational resilience guidance identifies validator risk and validator outages as crypto specific risks
  • Firms need records showing staking instructions, rewards, fees, losses, slashing events, service disruptions and client communications
Implementation Implementation should include validator due diligence, staking policy, client consent flows, reward calculation controls, fee disclosure, slashing incident workflow, exit queue process, asset segregation, outsourcing or third party arrangements and resilience testing for validator outages. Firms should connect staking risk to Consumer Duty outcomes and complaint handling.
Consultation Outcome
  • The FCA retained staking inside the final activity framework while making targeted refinements
  • Operational resilience guidance specifically highlights validator risks and outages
  • The final approach does not remove staking risk but requires firms to evidence controls and client understanding
  • Further market practice will likely shape supervisory expectations after go live
NCFA Perspective Staking is a good example of regulation translating crypto native activity into financial services controls. The opportunity is not simply offering yield. It is making staking understandable, monitored, resilient and institutionally acceptable.

Safeguarding and Custody

Requirements The FCA applies safeguarding requirements through CASS 17 for qualifying cryptoassets and related CASS amendments. Custody and safeguarding are central to the regime because many cryptoasset failures come from weak asset control, poor segregation, private key compromise, unclear client ownership or inadequate third party oversight.
  • Firms safeguarding qualifying cryptoassets must comply with CASS 17 requirements tailored to cryptoasset custody
  • Safeguarding requirements interact with CASS 16 where tokenized stablecoin backing assets or qualifying stablecoin custody is involved
  • Firms need arrangements for holding, recording, reconciling and protecting client cryptoassets
  • Private key management, wallet infrastructure, access controls, signing authority and recovery procedures are core operational controls
  • Third party custody or infrastructure arrangements require due diligence, contractual protections and ongoing oversight
  • Client reporting must ensure clients can access information, including where information is available on chain
  • Custody controls link to operational resilience, financial crime, Consumer Duty, dispute resolution, complaints and prudential requirements
Implementation Custodians and firms using custodians should document wallet architecture, key ceremony, MPC or HSM controls, cold and warm wallet policies, access roles, transaction approval, reconciliation, incident response, third party oversight, bankruptcy analysis, client asset records, insurance or financial resources and client reporting. Firms should test private key loss, unauthorized signing, chain outage, custodian failure and reconciliation breaks.
Consultation Outcome
  • The FCA confirmed application of safeguarding requirements under CASS 17 with cryptoasset specific adjustments
  • The FCA did not create a separate SM&CR prescribed responsibility for digital asset custody because existing custody PRs cover custody of a broad range of assets
  • Limited intragroup custody is permitted for stablecoin backing arrangements subject to safeguards
  • The final regime gives custody a central role in institutional trust and consumer protection
NCFA Perspective Custody is likely to be the most important infrastructure layer in the regime. Regulated crypto markets cannot scale without credible asset control, private key governance, reconciliation and failure recovery. This is where specialist infrastructure providers may gain durable advantage.

Prudential Requirements

Requirements PS26/12 creates a prudential framework for regulated cryptoasset firms covering capital, own funds, concentration risk, liquid assets, overall risk assessment and public disclosure. It uses CRYPTOPRU and COREPRU amendments to establish a baseline that reflects cryptoasset risks without simply importing bank prudential rules.
  • Firms must meet own funds definition and composition requirements
  • Own funds requirements include fixed overhead and K factor based components where applicable
  • The operational risk K factor for stablecoin issuance was reduced from 2% to 1% in the final rules
  • The revised market risk framework applies a single 40% net cryptoasset position requirement for K NCP where assets can be prudently valued and are admitted to a UK QCATP
  • Cryptoassets that do not meet the conditions are deducted from regulatory capital and subject to a 100% volatility adjustment for K CCD
  • Concentration risk and liquid asset requirements apply to support resilience
  • Firms must conduct overall risk assessments and maintain adequate financial resources
  • Public disclosure obligations are included with proportionality refinements
  • Prudential obligations apply alongside activity specific conduct, custody, stablecoin and Handbook requirements
Implementation Firms should build prudential models by activity and balance sheet exposure. Required work includes own funds classification, K factor calculation, stablecoin issuance exposure, custody and platform activity mapping, cryptoasset valuation policy, capital deduction logic, liquid asset monitoring, concentration risk limits, stress testing, management information, public disclosure process and board sign off.
Consultation Outcome
  • The FCA largely maintained the prudential architecture but recalibrated key areas for proportionality
  • Stablecoin operational risk capital was reduced from 2% to 1%
  • The market risk framework was simplified to a 40% treatment for qualifying prudently valued assets admitted to a UK QCATP and deduction or 100% volatility adjustment for others
  • The public disclosure regime was made more proportionate
  • Respondents supported prudential clarity but raised concerns about calibration, competitiveness and operational burden
NCFA Perspective Prudential rules turn crypto firms into regulated financial businesses with capital and liquidity discipline. The effect may be fewer casual entrants, but stronger survivors. The commercial opportunity is prudential analytics, treasury management, disclosure tooling and capital efficient operating models.

Consumer Duty and Conduct

Requirements PS26/13 applies key FCA Handbook standards to regulated cryptoasset activities, including Consumer Duty, COBS, conduct rules, dispute resolution, compensation treatment and reporting. Most firms carrying on regulated cryptoasset activities will be subject to these cross cutting obligations, with specific exceptions for certain professional client platform activity and platform member transactions.
  • Consumer Duty applies to relevant cryptoasset activity subject to defined scope and exclusions
  • Principles 6 and 9 and Consumer Duty do not apply when operating a qualifying CATP for professional clients
  • Certain Principles and Consumer Duty do not apply to transactions concluded between members or participants under the rules of a qualifying cryptoasset trading platform
  • The FCA clarified Consumer Duty guidance on territorial scope, fair value, consumer support, consumer understanding and manufacturer or distributor roles
  • COBS standards apply to relevant cryptoasset conduct and communications
  • Firms need evidence that products, services, support and communications deliver appropriate outcomes
  • DISP and Financial Ombudsman Service access apply to relevant complaints
  • Compensation and redress rules are part of the broader Handbook application
Implementation Implementation should include Consumer Duty outcome mapping by activity, customer journey review, product governance, fair value assessment, communication testing, support standards, vulnerability considerations, complaints data, MI dashboards and board reporting. Crypto firms should prove that customers understand custody, stablecoin, staking, lending, execution and volatility risks before and after purchase.
Consultation Outcome
  • The FCA made clarifications rather than retreating from applying Consumer Duty and conduct standards
  • UK issued qualifying stablecoins were excluded from the definition of restricted mass market investments
  • Consumer Duty guidance was clarified across fair value, support, understanding and supply chain roles
  • The final approach signals that crypto conduct standards should converge with regulated financial services expectations
NCFA Perspective This is one of the strongest differences between regulated crypto and offshore crypto. The UK model requires firms to evidence consumer outcomes, not only publish risk warnings. Firms that can make complex products understandable may have a material trust advantage.

Governance and SM&CR

Requirements The FCA applies Senior Management Arrangements, Systems and Controls and the Senior Managers and Certification Regime to cryptoasset firms. Governance requirements cover risk management, controls, accountability, prescribed responsibilities, operational resilience, financial crime, custody and board oversight.
  • SYSC 4 to SYSC 10 apply to qualifying cryptoasset firms according to firm type and common platform status
  • SM&CR applies to relevant cryptoasset firms with proportionality and threshold treatment
  • The enhanced SM&CR threshold for qualifying UK stablecoin issuers is set at £20 billion, intended to capture the most significant stablecoins over time
  • Smaller and medium sized stablecoin issuers are not expected to fall into enhanced SM&CR at commencement
  • Existing prescribed responsibilities are used for custody rather than creating separate digital asset custody PRs
  • Senior management responsibilities include financial crime, operational resilience, compliance, safeguarding, prudential risk and conduct outcomes where relevant
  • Governance must support FCA supervision, authorisation evidence and ongoing compliance
Implementation Firms should build a management responsibilities map, committee structure, board reporting pack, policy owner register, control owners, prescribed responsibility allocation, SMF evidence, certification population, conduct training, breach escalation and decision records. Stablecoin issuers should monitor whether scale could bring enhanced SM&CR into scope over time.
Consultation Outcome
  • The FCA adjusted the enhanced threshold for qualifying UK stablecoin issuers in light of Bank of England proposals
  • The FCA expects the £20 billion threshold to capture 1% or less of the firm population and likely no firms at commencement
  • The FCA declined to create separate prescribed responsibilities for cryptoasset custody
  • Governance requirements were largely maintained with targeted proportionality refinements
NCFA Perspective Governance is where regulatory permission becomes accountable execution. The UK is not just authorising products. It is assigning responsibility to named leaders, boards and control functions. That will shape who can credibly scale.

Operational Resilience

Requirements The FCA extends SYSC 15A operational resilience to cryptoasset firms and provides FG26/6 to explain cryptoasset specific risks. Firms must identify important business services, set impact tolerances, map dependencies and conduct scenario testing. SYSC 4, SYSC 7 and SYSC 8 complement the framework through risk management, controls and outsourcing requirements.
  • Firms must have sound, effective and comprehensive strategies, processes and systems proportionate to their nature, scale and complexity
  • Important business services must be identified and mapped across people, processes, technology, facilities and information
  • Impact tolerances must be set and tested through severe but plausible scenarios
  • Crypto specific risks include smart contract vulnerabilities, private key security risks, validator risks, service disruptions, cyber risks, DLT dependencies and emerging technologies such as AI and quantum computing
  • FG26/6 highlights cyber and technology resilience, cryptographic key and infrastructure safeguarding, continuity and disruption planning
  • Outsourcing expectations cover custody infrastructure, MPC and HSM providers, validator services, cloud providers and security critical transaction signing infrastructure
  • Permissionless DLT use should not be treated as outsourcing under SYSC 8.1.1R, but firms remain responsible for operational resilience controls
  • Firms should conduct targeted vulnerability scans, penetration tests and maintain monitoring and logging evidence
Implementation Implementation should produce a live resilience map for every important business service. Firms need dependency mapping, wallet and key infrastructure controls, validator due diligence, smart contract testing, cyber controls, incident playbooks, impact tolerance testing, penetration testing, cloud and third party oversight, logging, operational dashboards and board reporting. Scenario tests should include private key compromise, smart contract failure, validator outage, chain disruption, trading outage, stablecoin reconciliation failure and custodian failure.
Consultation Outcome
  • 91% of respondents supported extending SYSC 15A to cryptoasset firms and 88% supported the guidance approach
  • 98% supported the view that permissionless DLTs should not be treated as outsourcing
  • The FCA kept the extension of operational resilience while adding crypto specific guidance
  • Further non Handbook guidance on DLT operational resilience is expected later
NCFA Perspective Operational resilience is where the FCA regime becomes more than conduct regulation. Crypto firms are technology firms with financial risk. The UK framework makes uptime, key security, third party dependency and recovery capability part of the regulatory value proposition.

Financial Crime

Requirements PS26/13 applies the financial crime elements of SYSC 6, the Financial Crime Guide and Financial Crime Thematic Reviews to firms conducting regulated cryptoasset activities. These obligations sit alongside the Money Laundering Regulations and Travel Rule obligations already applicable to UK cryptoasset exchange providers and custodian wallet providers.
  • Cryptoasset firms conducting regulated activities must follow the same financial crime framework as other FSMA authorised firms where applicable
  • Relevant Handbook references include SYSC 6.1.1R adequate policies and procedures, SYSC 6.3.1R systems and controls, SYSC 6.3.3R financial crime risk assessments, SYSC 6.3.8R senior manager responsibility and SYSC 6.3.9R MLRO
  • Firms must comply with MLRs and the Travel Rule alongside FSMA obligations
  • Policies and procedures must be comprehensive and proportionate to the nature, scale and complexity of activities
  • Controls should identify, assess, monitor and manage money laundering, sanctions, fraud, terrorist financing, bribery, corruption and market abuse related risk
  • Financial crime evidence must connect to onboarding, transaction monitoring, wallet screening, custody, stablecoin issuance, trading, lending and staking
Implementation Implementation should include risk assessment, customer due diligence, wallet and blockchain analytics, sanctions screening, Travel Rule workflow, suspicious activity reporting, transaction monitoring, fraud controls, stablecoin redemption screening, market abuse escalation, MLRO governance, senior manager accountability, periodic control testing and audit trails.
Consultation Outcome
  • The FCA retained the proposal to apply financial crime rules and guidance to cryptoasset firms
  • The FCA views the same financial crime baseline as proportionate for cryptoasset firms despite sector specific risks
  • The regime operates alongside MLR registration and Travel Rule obligations, so firms face overlapping compliance layers
  • Financial crime controls become part of authorisation readiness and ongoing supervision
NCFA Perspective Financial crime is central to regulatory legitimacy. The UK regime will reward firms that can combine on chain analytics with traditional financial crime governance. This is also a clear opportunity for regtech, wallet intelligence and compliance automation.

Reporting and Redress

Requirements PS26/13 applies reporting, dispute resolution and redress architecture to regulated cryptoasset activities. Firms need to report to the FCA, maintain records, handle complaints, provide access to the Financial Ombudsman Service where relevant and preserve evidence across product, custody, execution, conduct and prudential areas.
  • Regulatory reporting applies to cryptoasset firms under the Handbook application package
  • Firms need data on activities, clients, complaints, prudential position, operational resilience, financial crime controls and other supervisory metrics
  • DISP and access to the Financial Ombudsman Service apply where relevant
  • Complaint handling must connect to Consumer Duty, client reporting, custody, execution, lending, staking and stablecoin redemption issues
  • Record keeping requirements apply across admissions, market abuse, client orders, transactions, lending, borrowing, staking, safeguarding and reporting
  • Public disclosure obligations apply in the prudential regime with proportionality refinements
  • Firms need evidence retention policies that allow supervisory reconstruction of decisions and client outcomes
Implementation Firms should build a reporting data model before go live. Required work includes regulatory returns ownership, data lineage, complaints taxonomy, FOS workflow, prudential reporting data, custody records, client statements, execution data, surveillance cases, operational incidents, financial crime alerts and board MI. Manual reporting will be risky given the breadth of the regime.
Consultation Outcome
  • The FCA made focused amendments to reporting requirements in PS26/13
  • The prudential disclosure regime was made more proportionate
  • The overall approach keeps crypto inside existing FCA supervisory and redress architecture
  • Reporting and redress obligations will expose weak data governance quickly after authorisation
NCFA Perspective Reporting is the regime’s memory. Firms that cannot reconstruct decisions, client outcomes, custody records or prudential positions will struggle to defend their operating model. Good reporting infrastructure becomes a strategic asset, not only a compliance cost.

International Firms

Requirements The FCA’s approach to international cryptoasset firms sets expectations for firms seeking UK authorisation while serving UK consumers. It focuses on threshold conditions, location of offices, effective supervision, appropriate resources, suitability and business model. The final guidance clarifies branch treatment for dual regulated firms where PRA conditions are satisfied.
  • International firms requiring FCA authorisation must meet minimum standards at application and on an ongoing basis
  • The FCA considers location of offices, effective supervision, appropriate resources, suitability and business model
  • The FCA identifies higher consumer and market harm risk where international firms serve UK customers through branches rather than UK legal entities
  • Dual regulated firms may operate through a UK branch where the PRA is satisfied threshold conditions and ongoing requirements are met
  • International models must demonstrate accountability, supervision, client protection, operational resilience and financial crime controls
  • Cross border liquidity access may be relevant, but does not remove UK authorisation and governance expectations
Implementation International firms should prepare a UK market access file covering branch or subsidiary choice, governance, UK senior managers, service model, outsourcing, group support, capital, liquidity, client disclosures, data location, custody, financial crime, operational resilience and how UK customers are protected if overseas operations fail.
Consultation Outcome
  • The FCA clarified the international firm approach after feedback in CP26/4
  • The final guidance acknowledges branches for dual regulated firms where PRA expectations are met
  • The FCA did not make overseas access easy simply because liquidity is global
  • The approach tries to balance global liquidity with UK accountability and effective supervision
NCFA Perspective This is where the UK tries to attract global crypto firms without importing offshore risk. The strongest firms will treat UK authorisation as a credible market badge, not a light touch registration.

DeFi

Requirements The FCA’s current approach to decentralised finance is to apply rules where there is an identifiable controlling entity, with separate guidance to follow on how decentralisation will be assessed in practice. DeFi is treated as a range of financial services marketed with a high degree of automation rather than as a blanket exemption from regulation.
  • Rules apply where there is an identifiable controlling entity
  • Separate guidance is expected on how decentralisation will be assessed
  • DeFi interfaces, arrangements and controlling entities may fall within regulated activity analysis
  • Automation does not by itself remove regulatory obligations
  • Firms must assess governance, control, user interface, protocol dependency, custody, financial promotion, market abuse, lending, staking and consumer risk
  • DeFi related activity may also raise operational resilience, financial crime, Consumer Duty and international firm issues
Implementation Firms should document who controls the interface, protocol parameters, governance keys, admin rights, fee flows, custody, upgrade authority, user onboarding, compliance controls and consumer communications. A DeFi implementation file should show whether the business is genuinely decentralised or whether an identifiable entity directs regulated activity.
Consultation Outcome
  • The FCA retained the principle that identifiable controlling entities bring DeFi activity within regulatory reach
  • The FCA acknowledged the need for separate guidance on decentralisation assessment
  • The final approach avoids treating DeFi labels as determinative
  • This remains a watch area because future guidance will likely affect interface operators, protocol sponsors and infrastructure providers
NCFA Perspective DeFi is the frontier test for the regime. The key issue is control. If a business can control access, fees, governance, listings or user experience, regulators are unlikely to treat it as outside the market structure simply because the protocol uses smart contracts.

UK Cryptoasset Regulations FAQ

When do the UK cryptoasset regulations start?

The new FCA cryptoasset regime starts on 25 October 2027.

When can firms apply for FCA cryptoasset authorisation?

The scheduled application period runs from 30 September 2026 to 28 February 2027. Firms seeking to rely on saving and transitional provisions should apply within that period.

Does an existing MLR registration become FCA authorisation?

No. Existing registrations and permissions do not automatically convert. A firm carrying on an in scope regulated cryptoasset activity will need the relevant FSMA permission.

Which cryptoasset activities are covered?

The regime covers activities including operating qualifying cryptoasset trading platforms, dealing, arranging, stablecoin issuance, custody, lending, borrowing and staking. Admissions, disclosures and market abuse rules also apply.

Which FCA rulebooks apply to cryptoasset firms?

The package includes the CRYPTO sourcebook, CASS 16 and CASS 17, CRYPTOPRU and COREPRU, plus relevant Consumer Duty, COBS, SYSC, SM&CR, DISP, reporting and operational resilience requirements.

What should firms prioritise before applying?

Firms should confirm scope, prepare governance and financial resource evidence, document custody and resilience controls, assess Consumer Duty outcomes and build a complete authorisation file for their business model.

Continue Exploring

How Tokenization Became a Business Investors Can MeasureConnects the FCA regime to the shift from crypto speculation toward measurable, investable tokenized infrastructureRead the story
How Is Crypto Custody Regulation Changing?Useful for custody, safeguarding, CASS 17, institutional trust and operational control questionsRead the question
UK FCA Plans Full Crypto Licensing Regime by 2026Background on the UK path from policy design and consultation toward a full cryptoasset regimeReview the buildout
FCA Chair on Crypto, Stablecoins and Digital Asset RegulationPolicy signal connecting crypto regulation, stablecoins, consumer risk, scams and the FCA's long running supervisory directionRead the speech context
Stablecoin Data Shows Payments Reality GapMarket evidence on why stablecoin payments need trust, liquidity, distribution and operating infrastructureRead the analysis
Tokenized Infrastructure Is Changing How Markets OperateMarket infrastructure context for tokenized cash, settlement, collateral, custody and regulated railsRead the insight

From Regulation to Opportunity

The FCA regime creates demand for regulated infrastructure across stablecoins, custody, market surveillance, disclosure, trading systems, prudential analytics, operational resilience, Consumer Duty evidence, reporting and compliance automation. The closest NCFA opportunity layer is the Programmable Stablecoin Payments brief, which examines where compliant stablecoin infrastructure can create practical payment and settlement use cases.

Open the Stablecoin Payments Opportunity Brief


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights

NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Leave a Reply

Your email address will not be published. Required fields are marked *