Existing Money Laundering Regulations registration, payment or electronic-money authorisation, and financial-promotion approval do not convert automatically. Each firm must map its activity, legal entity, UK territorial connection, customers, and requested permission before choosing a new authorisation application or a variation of permission.
Key takeaways
- The 2026 gateway is an application window, not the commencement of the full UK cryptoasset regime.
- Permission follows the activity and legal entity; FCA registration or group status does not cover every product.
- Applying inside or outside the designated window produces materially different continuation rights after 25 October 2027.
Who must apply for FCA crypto authorisation
A firm must apply when it carries on one of the new regulated cryptoasset activities by way of business in the UK and no exclusion applies. The Cryptoassets Regulations 2026 define the perimeter, while the FCA rule package determines the controls that each business model must operate.
| Business model or activity | Permission question | Main FCA package | Boundary to verify |
|---|---|---|---|
| Qualifying cryptoasset trading platform | Does the entity operate the system that brings together buying and selling interests? | PS26/11 plus PS26/9 for admissions and market abuse | A software interface is not necessarily the venue operator |
| Dealing as principal or agent | Does the entity trade with the customer or execute on the customer’s behalf? | PS26/11 plus PS26/9 where admission or market conduct applies | Principal dealing and agency execution are different activities |
| Arranging deals | Does the entity bring about or make arrangements for a qualifying cryptoasset transaction? | PS26/11 | Referral, routing, and execution flows need separate analysis |
| Safeguarding cryptoassets | Does the entity control, hold, or arrange control of client cryptoassets? | PS26/11 and CASS 17 requirements | Marketing a wallet does not identify the custody entity |
| Issuing a qualifying stablecoin | Is the entity responsible for UK issuance, backing assets, and redemption? | PS26/10 plus relevant admissions rules | Listing a stablecoin does not make the exchange its issuer |
| Arranging qualifying cryptoasset staking | Does the entity arrange the staking relationship for customers? | PS26/11 | Protocol participation and an intermediary’s customer service differ |
| Public offer or admission to trading | Is the activity governed through the designated-activities regime? | PS26/9 | The activity can trigger disclosure or market rules without making every participant an authorised firm |
All authorised firms need the core Handbook and prudential packages, including PS26/13 and PS26/12. Lending products require separate mapping of custody, dealing, arranging, collateral, and customer protection. Leveraged products may instead enter a derivatives perimeter. TheCCPress’s product-specific regulator map shows why a product label alone cannot identify the permission or authority.
An overseas firm dealing directly with UK consumers can fall within the regime before it establishes a UK company. If authorisation is required, however, the FCA’s international-firm guidance sets a baseline expectation that regulated cryptoasset activities operate from a UK legal entity and a UK presence. A branch route is a limited exception, principally for an overseas QCATP whose home regime offers comparable protection; custody and unrestricted principal dealing normally remain in a UK entity.
The territorial test still changes by activity. Direct trading, dealing, or arranging for UK consumers may create a UK permission question even when execution occurs overseas, whereas institutional-only business or transactions intermediated by a UK-authorised firm can produce a different result. Groups should map the contracting entity, customer type, order flow, asset controller, and UK personnel for each service rather than treating incorporation or an offshore licence as a blanket exemption.
The gateway creates three different operating outcomes
The filing date determines whether a firm can continue normal activity, service only existing contracts, or must leave the market when the regime commences. The FCA gateway guidance therefore matters as much as the final application deadline.
| Position before 25 October 2027 | Status if the application is unresolved at commencement | Commercial consequence |
|---|---|---|
| Existing firm submits a complete application or variation from 30 September 2026 through 28 February 2027 | Saving provision may apply if the application remains open | The firm may continue the specified existing activity while the FCA determines the application |
| Startup with no existing in-scope UK activity submits during the application period | Filing creates no operating permission to preserve | The startup must wait for authorisation and commencement before launching the regulated service |
| Application submitted after 28 February 2027 but before commencement | Transitional provision applies if permission is still unresolved | Only activity necessary to perform pre-existing contracts can continue; no new contracts with new or existing UK customers |
| Application is withdrawn, finally refused, or no longer open to review before commencement | Eligible existing firms enter the transitional provision | The firm can run off pre-existing contracts but cannot take new business; the exemption lasts no more than two years |
| No application before commencement | No saving or transitional route | The firm must run off the UK cryptoasset business before the regime starts |
| Existing MLR, PSR, EMR, or other FSMA status | New application or variation is still required for in-scope crypto activities | Current registration or permission does not convert automatically |
The distinction corrects a common oversimplification. The saving provision protects continuity for qualifying existing activity; it does not let a newly formed applicant begin regulated business merely because a form was filed. Applying after the window does not always stop every operation, but an unresolved late applicant is restricted to the pre-existing-contract activity allowed by the transitional rules.
Withdrawal, rejection, and refusal also have different effects. An eligible firm that withdraws a valid application or receives a final refusal can use the transitional provision only to exit through existing contracts. A submission rejected for missing minimum information does not count as a valid application; without a replacement filing, the firm must complete its run-off before commencement.
Financial-promotion approval does not become future cryptoasset permission. Cross-border groups must identify the UK applicant and every overseas entity relying on its continuation rights. The resulting business-continuity risk resembles the pressure created when Singapore restricted unlicensed overseas crypto services, although the legal mechanisms differ.
What a complete FCA application needs
A complete application needs an evidenced operating model, not generic policies. Each customer journey should connect to its entity, regulated activity, revenue, control owner, safeguarding, dependencies, forecast, and requested permission. Those names and flows must remain consistent across the application, contracts, organisation chart, risk assessment, and financial data.
The FCA’s Pre-Application Support Service is optional and free, but a meeting request must include the proposed business model, products, services, customer types, and analysis of the regulated activities. The FCA says it can reject requests that lack meaningful supporting information. PASS helps a firm understand expectations; it does not provide legal advice or guarantee approval.
The application combines standard FSMA information with crypto-specific questions. Required evidence covers controllers, governance, financial resources, Consumer Duty, operational resilience, financial crime, safeguarding, outsourcing, market conduct, and wind-down. Its financial data template must reconcile the narrative with capital, revenue, costs, client assets, and runway.
What supervision changes after authorisation
Authorisation creates continuing obligations rather than a one-time badge. Firms must keep satisfying Threshold Conditions and applicable reporting, prudential, conduct, Consumer Duty, Senior Managers and Certification Regime, financial-crime, and operational-resilience requirements. The rule set changes with the activity, which is why a custodian, stablecoin issuer, trading platform, and staking arranger should not receive the same compliance checklist.
Consumer Duty requires a defensible target market, fair-value assessment, understandable communications, and effective support. Operational resilience requires important-business-service mapping, impact tolerances, dependency records, and severe-but-plausible testing. Custodians need ownership, reconciliation, recordkeeping, and private-key controls; platforms need admission due diligence, disclosures, surveillance, conflicts management, and market-abuse escalation.

The prudential rules convert this obligation into measurable capital treatment rather than a generic promise of financial strength. Under PS26/12, the operational-risk K-factor for stablecoin issuance is 1%, reduced from the proposed 2%, while the stablecoin framework permits an excess backing-asset pool of up to 5%. Cryptoassets that can be prudently valued and trade on a UK QCATP attract a 40% net-position requirement and a 40% counterparty-credit volatility adjustment.
Assets that fail those conditions are deducted from regulatory capital and receive a 100% volatility adjustment. These percentages are inputs, not a universal minimum-capital figure: each applicant must calculate own funds, fixed overheads, activity-specific K-factors, liquidity, concentration, and wind-down resources from its actual model.
The FCA policy-statement overview is the most efficient rulebook map because it shows which documents apply to each firm type. It should still be paired with the final permission and live product terms. A long compliance page cannot substitute for evidence that the named entity has permission for the advertised activity.
How to verify a UK crypto provider
Start with the legal entity in the customer agreement, then search the FCA register by legal and trading name. Record the permission or registration type, status, restrictions, trading names, and verification date. “Registered,” “authorised,” “appointed representative,” “application pending,” and “overseas” describe different positions and should never be collapsed into “FCA approved.”
Next, map the product: identify the executor for spot trading, key controller for custody, arranger for staking, and communicator for promotions. Check warnings separately. The 2026 crypto regulator watchlist identifies the authority, but only the current register and product documents establish status.
Retail users should verify fees, withdrawals, complaints, fraud reporting, and loss protection. Institutional buyers should add agreements, audits, outsourcing, incidents, sanctions controls, service levels, and asset-release authority. FCA permission improves accountability within its scope; it does not create deposit protection or remove market, custody, liquidity, and counterparty risk.
What authorisation does not solve
Banking access can fail even when the reader focuses on an exchange’s regulatory status. In a UK discussion about the FCA warning-list expansion, a participant described banks refusing crypto-related payment processors and making fiat transfers harder. The report cannot establish a market-wide bank policy or attribute a specific refusal to an FCA instruction.
The experience identifies a separate control point: banks and payment processors can interrupt funding or withdrawal regardless of the exchange interface. The UK inquiry into banks restricting crypto firms reflects the same concern. Test payment rails, beneficiary matching, limits, landed amounts, withdrawals, and escalation before committing funds.
Authorisation also does not prove best execution, solvency, service quality, or uninterrupted access. Those claims require separate evidence such as executable prices, financial resources, custody reconciliation, incident history, complaints outcomes, and contractual exit rights. Regulatory status should be one verified field in a provider comparison, not the entire score.
What firms should complete before the gateway
Before submission, the board should approve the activity perimeter, permission strategy, gap analysis, budget, and delivery plan. Every gap needs an owner, evidence requirement, dependency, remediation date, and product-continuation decision. The firm must also test whether overseas group entities can keep serving UK customers.
Application readiness is measurable when the product inventory reconciles with contracts, permissions, safeguarding, financial forecasts, operational-resilience maps, Consumer Duty evidence, market-abuse controls, promotions, and wind-down planning. Filing early does not guarantee approval, but it gives the FCA time to assess a coherent file and reduces the risk that unresolved permission leaves the business limited to old contracts.
Conclusion
Trading platforms, dealers, arrangers, custodians, qualifying stablecoin issuers, and staking arrangers should treat 2026 as the FCA application-preparation year. The critical decision is whether the named entity performs an in-scope UK activity and whether it can submit a complete application during the designated gateway window.
The strongest plan separates current MLR and promotion obligations from future FSMA permission, maps every product to the correct rule package, and budgets the controls required after authorisation. Register status, banking access, customer protection, and product risk must then be verified separately rather than compressed into one “FCA regulated” claim.
Frequently asked questions
Does FCA registration mean a crypto exchange is fully regulated?
No. MLR registration addresses a narrower anti-money-laundering status. It does not provide every FSMA permission required for trading, custody, stablecoin issuance, staking, or other regulated cryptoasset activities under the 2027 regime.
When should a crypto firm apply?
The designated application period runs from 30 September 2026 through 28 February 2027. Applying during that window can preserve access to the saving provision if the application remains unresolved at commencement, subject to the statutory conditions.
Can an overseas crypto company serve UK customers without authorisation?
Not automatically. Direct activity involving UK consumers can fall within the territorial perimeter even when the firm is overseas. Intermediation, institutional-customer status, exclusions, and the exact activity require a fact-specific analysis.
Is the UK regime the same as MiCA?
No. The UK and EU use separate authorities, registers, permissions, and transition mechanisms. TheCCPress’s coverage of when MiCA became fully applicable explains the EU timeline, but an EU CASP passport does not create UK permission.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
