OUT-LAW ANALYSIS 8 min. read

FCA finalises cryptoasset regime ahead of 2027 authorisation deadline

fcareception2upscale

The FCA's reforms signal a clear regulatory objective.


The Financial Conduct Authority's (FCA) publication of a comprehensive framework for regulated cryptoasset activities marks a pivotal moment in the development of the UK's cryptoasset sector ahead of the regime's implementation on 25 October 2027.

Taken together, the FCA's reforms signal a clear regulatory objective: to bring cryptoasset firms within a framework that more closely resembles traditional financial services regulation, with a particular focus on governance, risk management, consumer protection and financial resilience.

Central to the FCA's approach is the authorisation process. From October 2027, firms wishing to carry on regulated cryptoasset activities in the UK will generally need to obtain FCA authorisation and demonstrate that they are capable of meeting the regulator's expectations on an ongoing basis. This extends beyond simple compliance with technical rules. Firms will need to evidence robust governance arrangements; appropriate systems and controls; effective risk management frameworks; adequate financial resources; and processes designed to deliver good customer outcomes.

While the implementation date remains over a year away, firms intending to seek authorisation should begin assessing their readiness now. Many of the FCA's requirements will require significant operational, governance and compliance enhancements, meaning that early gap analysis and implementation planning are likely to be critical to a successful authorisation application.

Crypto regime: regulated cryptoasset activities

FCA policy statement PS26/11 (265-page / 2.63MB PDF) sets out the core new conduct and operational requirements applicable to new regulated cryptoasset activities. This is primarily through the introduction of a new CRYPTO sourcebook, alongside amendments to areas of the FCA Handbook.

Firms should consider the policy statement and associated legislation in detail when assessing their readiness for authorisation. In practice, applicants will need to demonstrate that the necessary governance arrangements, policies, systems and controls are in place to satisfy the FCA’s expectations on an ongoing basis.

Best execution requirements

Most importantly for qualifying cryptoasset trading platforms (QCATPs), dealings with UK clients will be subject to new execution venue and best execution requirements, designed to promote market integrity and reduce opportunities for regulatory arbitrage. Cryptoasset intermediaries executing orders, or receiving and transmitting orders, for UK retail or elective professional clients will need to "take all reasonable steps" to ensure that orders are executed on UK-authorised execution venues and that the best possible result is achieved for clients.

Taken together, these measures create a largely self-contained UK regulatory ecosystem for retail cryptoasset trading, while preserving limited routes to global liquidity for certain overseas QCATP operators through the FCA's branch framework.

Lending and borrowing

The FCA has also outlined a series of significant reforms to the way cryptoassets can lend and borrow. Many of these requirements will be familiar to firms operating in traditional financial services, including appropriateness assessments, enhanced pre-contract disclosures and information requirements, alongside additional safeguards designed to reduce the risks associated with leveraged cryptoasset products.

Most notably, the FCA has introduced prescriptive collateral requirements for retail lending and borrowing arrangements. Such arrangements will require over-collateralisation, with retail clients benefiting from negative balance protection. The rules also restrict the circumstances in which firms may supplement client collateral and require express client consent before collateral can be topped up or otherwise used in specified ways.

Beyond these operational requirements, the FCA has introduced enhanced protections for retail client collateral. Collateral provided by retail clients will need to be safeguarded in accordance with applicable CASS requirements, ensuring that it is held for the benefit of the client rather than transferred outright to the firm. This represents a significant departure from certain existing market practices and reflects the FCA's focus on improving customer outcomes in the event of firm failure or market stress. 

By contrast, firms dealing with non-retail clients retain greater flexibility in their collateral arrangements, including the continued use of title transfer collateral arrangements.

Staking

The FCA’s approach to staking remains focused on consumer understanding and informed decision-making. Rather than outright restricting access to staking services, the final rules require firms to provide retail clients with clearer information regarding the nature of staking services, the risks involved and the terms of any staking arrangements before clients enter into a contract. The FCA’s intention is to focus on improving customer understanding of services that involve complex technological processes, while preserving access to legitimate staking activities.

Firms should also consider the FCA’s broader expectation that regulated cryptoasset activities should be carried on through a UK legal entity, subject to certain limited exceptions. In addition, the enhanced role of QCATPs under the new admission and disclosure regime places significant new obligations on trading platform operators, requiring robust due diligence, governance and monitoring arrangements.

Given the breadth of the reforms introduced by PS26/11, firms should review the policy statement and associated legislation in detail when preparing for authorisation. Some processes will require extensive internal reform and development, which will need to be in place and appropriately documented to meet the authorisation deadline.

A prudential regime for cryptoasset firms

Alongside the more activity-focused PS26/11, the FCA has also introduced the final prudential framework for regulated cryptoasset firms (244-page / 2.10MB PDF), which it has set out in a separate policy statement, PS26/12. For many cryptoasset firms, these requirements represent a material shift from operating in an environment with no prudential expectations to one that more closely resembles traditional financial services regulation.

Specifically, PS26/12 introduces new CORPRU and CRYPTOPRU sourcebooks, making firms subject to requirements covering capital, liquidity, risk management, concentration risk and public disclosure, mirroring prudential architecture already familiar to investment firms under MiFIDPRU. 

At the heart of the regime are new "own funds" and liquidity requirements intended to ensure firms can absorb losses, continue operating through periods of stress and, where necessary, wind down in an orderly manner. Firms will be required to maintain regulatory capital at all times, which may change depending on the firm’s activities, alongside maintaining sufficient liquid resources to meet short-term obligations by meeting a ‘basic liquid assets requirement’.

Firms seeking authorisation under the new regime will need to assess whether their capital structures, liquidity arrangements and risk management frameworks are sufficient ahead of the regime's implementation.

Application of FCA Handbook to regulated cryptoasset activities

The FCA has also confirmed how important provisions of the FCA Handbook will apply to regulated cryptoasset activities, with regulated cryptoasset activities now falling within the definition of “designated investment business”. This will mean that existing FCA Handbook provisions associated with traditional financial services firms will apply to authorised cryptoasset firms. As a result, cryptoasset firms will need to consider a broad range of existing requirements relating to governance, systems and controls, operational resilience, financial crime prevention, regulatory reporting and senior management accountability.  

Firms dealing with retail clients will become subject to the consumer duty, requiring them to deliver good consumer outcomes and avoid foreseeable harm throughout the customer journey. The FCA recognises that certain features of the digital assets sector, including product complexity, volatility and rapid innovation, can create challenges for consumers that are less prevalent in traditional financial services. Firms will therefore be expected to avoid product features that may mislead or disadvantage consumers, such as hidden fees or unnecessarily complex redemption mechanisms, and to communicate clearly and transparently about product features, risks and limitations.

Perhaps most significantly, cryptoasset firms will be expected to do more to test, monitor and adapt customer communications to ensure that consumers genuinely understand the products and services being offered. For many firms, this is likely to require a substantial review of existing processes and customer-facing communications to ensure compliance with the duty.

While these requirements are well established within traditional financial services, they represent a substantial shift for firms that have historically operated outside the scope of the wider FCA Handbook. Many firms will therefore need to undertake significant implementation and gap analysis exercises ahead of the authorisation deadline. 

Admissions, disclosures and market regime for cryptoassets

A third FCA policy statement, PS26/9 (214-pages / 2.01MB PDF), introduces the FCA's final admissions and disclosures (A&D) framework, as well as the market abuse regime for cryptoassets (MARC). Both will be rather similar to operators in traditional finance but mark a substantial shift in operation of the cryptoasset space.

Under the A&D framework, UK-authorised QCATPs effectively become the gatekeepers to retail cryptoasset markets. Before a qualifying cryptoasset can be admitted to trading for retail clients, a QCATP will be required to conduct appropriate due diligence to assess whether its cryptoasset will be detrimental to consumers - and to reject listing where it would be - and ensure that a qualifying cryptoasset disclosure document is published ahead of admission to listing.

PS26/9 also provides for the introduction of MARC, itself being influenced by the UK Market Abuse Regulation (UK MAR), with adaptations in line with cryptoasset markets. This framework incorporates aspects of the market abuse regime, including insider dealing, unlawful disclosure of inside information, and market manipulation.

Historically, the sector has seen a number of high-profile cases involving insider trading and information asymmetries, particularly where a small group of individuals have obtained advance knowledge of market-moving events, such as the listing of a cryptoasset on a trading platform. Recent examples, including SEC v Wahi – the US Securities and Exchange Commission’s case against individuals at Coinbase – demonstrate the risk of market abuse in this space, with UK MAR having limited scope to address some of these harms.

Under MARC, and partly due to the more fragmented nature of cryptoasset markets, the FCA has adopted a unique industry-led approach, placing primary responsibility for the prevention, detection and disruption of market abuse on QCATPs and relevant intermediaries. Those firms will therefore need to implement market surveillance arrangements, maintain appropriate systems and controls to detect market abuse, and establish processes for creating and maintaining insider lists. These obligations sit alongside existing anti-money laundering, counter-terrorist financing and proliferation financing requirements, and are likely to require substantial investment in compliance and surveillance capabilities.

Firms should also be mindful of the potential interaction between MARC and UK MAR, particularly where a cryptoasset falls within the definition of a specified investment. In such circumstances, firms may need to comply with obligations under both regimes and should ensure that their systems and controls are sufficiently robust to identify and manage market abuse risks accordingly.

FCA guidance on international cryptoasset firms

Alongside the FCA's wider cryptoasset regime, the FCA has also published final guidance on its approach to international cryptoasset firms. Most significantly, many firms may find it difficult to rely on the overseas persons exclusion, potentially bringing them within the UK regulatory perimeter even where their activities may previously have been regarded as taking place overseas. Beyond this, we are also awaiting the FCA's updated PERG guidance, which is expected to provide further detail and clarification on the application of the new regime.

Next steps

Prior to the new regime coming into force, the FCA will continue to provide guidance, including the long-awaited perimeter guidance, which should help provide clarification on the specific nature of in-scope activities. 

In the meantime, firms should begin assessing their readiness for authorisation, to prevent any kind of business interruption come October 2027. The FCA has indicated that applications for authorisation under the new regime may be submitted between 30 September 2026 and 28 February 2027. Given the substantial nature of the reforms and the very narrow window for authorisation, it is vitally important for firms already operating in the UK to review their internal governance processes and prepare documentation, policies and supporting evidence expected as part of the authorisation process.

We are processing your request. \n Thank you for your patience. An error occurred. This could be due to inactivity on the page - please try again.