UK Crypto Firms Face New FCA Authorization Rules

11 min read
2 views
Sep 17, 2026

UK crypto firms just learned that old registrations will not carry over. Applications open soon, yet one February deadline could decide who keeps operating when the new regime starts.

Financial market analysis from 17/09/2026. Market conditions may have changed since publication.

If you run a crypto business that touches British customers, the next twelve months will feel less like a policy debate and more like a filing calendar. The UK regulator has now published final perimeter guidance that tells firms, in fairly plain language, which activities need approval under the incoming regime. Applications open on 30 September. The rules themselves land on 25 October 2027. That gap looks generous until you notice the earlier cut-off for transitional relief: 28 February 2027. Miss that date and you may still apply, but you may not get the same runway once the new framework switches on.

What The Fresh Authorization Process Actually Changes

I have watched plenty of “new crypto regimes” arrive with slogans and then stall. This one is different in a practical way. Parliament already approved the statutory instrument that pulls extra digital asset services inside the regulatory perimeter. The rulebook package was largely finalized earlier in the year after several consultation rounds. What landed this week is the map: a final set of perimeter notes that firms can use to decide whether their products need permission, a variation of permission, or a full authorization from scratch.

The important shift is conceptual. The regulator is not asking how you brand yourself. It is asking what functions you perform. Issue a qualifying stablecoin? That is one activity. Operate a trading platform? Another. Deal in digital assets, arrange transactions, safeguard client cryptoassets, or arrange staking? Each of those can sit in a different permission bucket. A company that once filed a single anti-money laundering registration now has to unbundle its stack and match every service to the incoming handbook.

Getting ready for regulation starts with understanding how the regime applies to your business. This guidance gives firms the clarity they have asked for so they can prepare with confidence.

– Senior regulatory official commenting on the perimeter notes

That quote is doing more work than it first appears. Clarity is useful. It is also a warning. Once the perimeter is defined, “we thought we were just a tech vendor” becomes a weaker argument. Limited exclusions exist for certain technical service providers, but most operating businesses should assume they are in unless a lawyer can show they are out.

Old Registrations Will Not Travel With You

This is the part founders keep underestimating. Existing AML registrations do not automatically become authorizations. Other financial permissions you already hold do not magically cover crypto activities that were outside the old perimeter. If you already sit inside the wider financial services world, you may need a variation of permission rather than a brand-new license. If you only had the narrower registration used for money-laundering controls, you start the authorization journey almost from zero.

In my view, that is the cleanest way to think about it. The old register was a gate for financial crime supervision. The new framework is a full conduct, prudential, custody, and consumer-treatment regime. Treating them as the same product is how firms waste six months writing the wrong application.

  • AML registration is not a substitute for activity-based authorization.
  • Existing permissions may need a formal variation if crypto services are added.
  • Each product line should be mapped to a function, not a marketing label.
  • Technical intermediaries may qualify for limited exclusions, but that is not the default.

The Two Dates That Matter More Than The Press Release

Keep the calendar simple. Applications open on 30 September. The regime takes effect on 25 October 2027. Firms that want transitional arrangements need to apply by 28 February 2027. That February line is the one I would put on a whiteboard in the office kitchen. Eligible applicants who file by then can use a transition mechanism when the new rules begin. Firms that wait may still get through the door later, but they may not enjoy the same continuity tools.

A year sounds long until you remember what an authorization file actually contains: governance charts, wind-down plans, safeguarding arrangements, capital calculations, operational resilience evidence, consumer journey maps, and a description of every on-chain and off-chain process that touches client assets. Pre-application meetings and webinars are being offered so firms can learn the handbook, the process, and the prudential expectations before they submit. Use them. They are not a courtesy. They are a filter.

MilestoneDateWhy It Matters
Applications open30 SeptemberFormal filing window begins
Transitional application cut-off28 February 2027Access to transition tools for eligible firms
Regime start25 October 2027New permissions and conduct rules apply
Targeted follow-up consultationOctober windowStablecoins, market making, some tech providers

Which Activities Sit Inside The Perimeter

The guidance walks through a cluster of activities that will look familiar to anyone who has built a modern digital asset business. Issuing qualifying stablecoins is in. Running crypto trading platforms is in. Dealing in digital assets and arranging transactions is in. Safeguarding cryptoassets can require approval, depending on how control, records, and client asset protection are structured. Arranging staking services may also need permission, again depending on the operating model rather than the slide deck.

Perhaps the most interesting aspect is how stubbornly functional the test is. Two firms can call themselves “wallets” and end up in different places. One merely displays balances. The other holds keys, batches withdrawals, and stands between the customer and the chain. Guess which one looks like safeguarding.

Stablecoin issuers should expect rules on backing assets, asset protection, disclosures, and redemption. Custodians should expect detailed safekeeping standards. Platforms and intermediaries pick up obligations tied to admissions, market conduct, and the way they treat retail users. Capital requirements and operational resilience sit across the package rather than in a single annex that you can ignore until year two.

How To Unbundle A Business Model Without Losing A Week

Start with a product inventory, not a legal memo. Write down every customer-facing service in one column and the operational steps in the next. Who holds the keys? Who can halt a withdrawal? Who sets the reserve mix? Who matches orders? Who markets the product to UK residents? Those answers usually tell you more than the white paper.

  1. List every service a UK customer can actually use today.
  2. Map each service to a function in the perimeter notes.
  3. Flag anything that looks like issuance, dealing, arranging, custody, or staking.
  4. Decide whether you need a new authorization or a variation of existing permissions.
  5. Build the evidence pack around governance, capital, safeguarding, and consumer treatment.
  6. Book a pre-application conversation before the file hardens into a 200-page guess.

I have found that teams skip step three because it feels political. Nobody wants to admit the “yield product” is arranged staking, or that the “account” is custody. Better to have that argument internally in October than with a case officer in March.

Stablecoins, Custody, Platforms, And Staking In Practice

Qualifying stablecoins sit at the center of the package for a reason. If a token is meant to hold value and be redeemed, the public is entitled to know what sits behind it, who can freeze it, and how fast cash comes back in a stress event. Reserve quality, segregation, and disclosure are not optional extras. They are the product.

Custody is the quiet heavyweight. Safeguarding client cryptoassets is where operational sloppiness becomes a regulatory event. Record-keeping, reconciliation, key management, insolvency remote structures, and the ability to return assets without a heroic all-nighter will all be tested. If your model relies on a third-party sub-custodian, you still own the customer outcome.

Trading platforms pick up a different bundle: admissions standards, surveillance, conflicts, and the treatment of retail order flow. Intermediaries that arrange deals without running a full venue still need to explain how they sit in the chain. Staking arrangements are the messy middle. Sometimes they look like a technical protocol interaction. Sometimes they look like a packaged investment with a promoter standing in the middle. The guidance is designed to catch the second case even when the first case is used as cover.


Overseas Firms Are Not Automatically Off The Hook

This is where a lot of non-UK boards will get a surprise. If you serve customers in Britain or operate into the UK market, you may sit inside the perimeter even if your headquarters, servers, and board meetings stay elsewhere. American exchanges, custodians, stablecoin businesses, and staking providers are explicitly in the conversation. A license or registration at home does not replace UK authorization for regulated activity aimed at UK users.

The two countries are also moving on different clocks. Britain now has a fixed start date and a defined application window. The United States is still working through market-structure legislation and agency interpretations. Permission in one place does not grant access in the other. International groups that want both markets will need two maps, two files, and two answers to the same product question.

Is that inefficient? Yes. Is it avoidable? Not really, unless you geofence the UK with more discipline than most growth teams prefer. Soft targeting — English-language ads, sterling pairs, UK payment rails, and a support desk that happily onboards British postcodes — is how firms wander into the perimeter without meaning to.

What The Completed Rule Package Is Trying To Do

The authorization process is only the front door. Behind it sits a broader conduct and prudential design. Rules cover stablecoin reserves and redemptions, crypto custody, operational resilience, consumer treatment, and capital. Separate provisions deal with token admissions and misconduct on trading platforms. In other words, market entry is not the whole story. Staying in the market will require ongoing systems, not a one-off certificate on the wall.

There will be more paper in October. Officials plan to consult on targeted updates involving qualifying UK stablecoins, proprietary trading, market making, and some technology providers. The review is also expected to look at decentralized protocols, custody models that involve central securities depositories, and financial promotion rules. That last item matters more than people admit. Promotions are how products actually reach households. If the on-ramp copy is sloppy, the authorization can still fail in public.

Policy work is also continuing outside the handbook. Lawmakers have pushed for a national digital asset strategy covering cryptoassets, stablecoins, tokenized securities, and digital market infrastructure. Regulators have been asking whether certain tokenized gold products should sit outside collective investment and alternative fund rules. Wholesale-market tokenization — securities, collateral, clearing, settlement — is on a separate roadmap with the central bank. None of that changes the authorization calendar. It does change the environment in which authorized firms will operate after 2027.

A Practical Readiness Checklist For Founders And Compliance Leads

If I were sitting with a UK-facing crypto team this week, I would not start with a slogan about “embracing regulation.” I would start with four files on a shared drive.

  • A perimeter memo that maps each live product to a regulated function.
  • A gap analysis against safeguarding, capital, resilience, and consumer-duty style expectations.
  • A timeline that works backward from 28 February 2027, not from October 2027.
  • A board paper that states, without theatre, whether the firm can fund the build.

That last point is uncomfortable and necessary. Authorization is expensive. So is building segregated custody, redemption operations, and surveillance that can survive a supervisory visit. Some business models will not clear the bar. That is not a moral judgment. It is a capital allocation fact. Better to redesign the product now than to spend a year polishing an application for a service you cannot support.

Banks and payment partners are watching the same calendar. Even before the regime starts, access to accounts and rails can tighten if counterparties decide a firm looks unprepared. I have seen that movie. The license process and the banking process feed each other. A weak safeguarding narrative in the FCA file becomes a weak onboarding narrative at the bank.

Consumer Treatment Is Not A Soft Chapter

People in this industry sometimes treat consumer rules as the chapter you write after the technology chapter. That habit will not age well. The incoming package puts retail outcomes next to reserves and custody, not underneath them. Disclosures have to match the product. Redemption promises have to be operationally true. Marketing has to stay inside financial promotion boundaries. Complaints handling cannot be a shared inbox with no owner.

Ask a blunt question: if a customer needed sterling back on a bad Monday, who would do what by 4 p.m.? If the answer is a group chat and a hope that market makers are awake, you do not have a redemption process. You have a story. Supervisors can tell the difference.

Decentralized Language Will Not Hide A Central Operator

October’s follow-up work on decentralized protocols will be closely read, and it should be. Plenty of teams describe themselves as “just a front end” while still setting fees, curating markets, holding admin keys, or running the matching logic. Perimeter guidance that looks through labels will eventually look through those claims too. If a human company is arranging, promoting, or safeguarding, the protocol story is context, not a shield.

That does not mean every smart contract becomes a regulated firm. It means control and customer interface still matter. In my experience, the honest test is simple. Could the team turn the product off, change the economics, or recover user assets? If yes, you are closer to an operator than to a pamphlet.

What Success Looks Like After Authorization

Getting approved is not the finish line. It is the moment the operating burden becomes continuous. Capital has to stay at the required level. Safeguarding reviews cannot be annual theatre. Incident reporting has to be real. Staff who understand both the chain and the handbook are scarce, which means hiring plans belong in the same pack as the legal analysis.

There is a competitive angle here that does not get enough airtime. Firms that file early, use the transition window, and can show clean custody and redemption rails may find it easier to keep banking partners and institutional counterparties. Firms that treat 2027 as “later” may discover that counterparties treated it as “now.” Regulation is slow. Market access decisions are not.

Readiness snapshot:
  Map functions first
  File with the February cut-off in mind
  Fund custody and redemption operations
  Treat UK users as in-scope unless proven otherwise

A Straight Answer For Boards That Want Less Fog

So what should a board actually decide this quarter? First, whether the UK is a market the firm intends to serve after October 2027. If the answer is yes, authorization work starts now, not after the next product launch. Second, which current services are truly core. Anything that creates a messy permission with thin economics is a candidate for shutdown or redesign. Third, whether the group will apply as a UK entity, a branch-like model, or a carefully geofenced offshore setup. Each path has a cost. Pretending there is a fourth path called “wait and see” is how firms arrive at February with a half-written form.

I do not think this regime will end crypto in Britain. I do think it will end the idea that a thin registration and a slick app are enough. The firms that come through will look more like financial institutions that happen to use blockchains, and less like software companies that happen to hold customer assets. Some readers will hate that sentence. Fair enough. It is still the direction of travel.

The guidance is out. The window is about to open. The interesting question is no longer whether Britain is “pro crypto.” It is whether your operating model can survive a function-by-function reading of the perimeter, a February filing discipline, and a 2027 go-live that will not slip just because the industry is busy. That is the work. Everything else is commentary.

The art of living lies less in eliminating our troubles than growing with them.
— Bernard M. Baruch
Author

Steven Soarez passionately shares his financial expertise to help everyone better understand and master investing. Contact us for collaboration opportunities or sponsored article inquiries.

Related Articles

?>