← Back to Resourcesdigital-assets

What must cryptoasset firms comply with under the FCA's new regime?

Karthigeyan R J
On 30 June 2026 the FCA published five policy statements, PS26/9 to PS26/13, finalising the UK cryptoasset regime. Firms carrying on regulated cryptoasset activities apply for authorisation between 30 September 2026 and 28 February 2027; the regime commences 25 October 2027. Obligations depend on activity: trading, intermediation, custody, staking, lending or stablecoin issuance.
Three things this article will leave you able to do
Locate your firm on the activity map and name the policy statement that governs it.
Start the evidence file the FCA's authorisation team will ask for.
Explain the prudential "highest of three" calculation to your CFO.
The waiting ended on 30 June 2026. After three years of consultation, the FCA published the five policy statements that turn the UK's cryptoasset regime from proposal into rulebook. The dates now bind: the application window opens 30 September 2026, closes 28 February 2027 and the regime itself commences on 25 October 2027.
The regime is activity-based. Nobody is regulated for "doing crypto"; firms are authorised for specific regulated activities, each with its own obligations. The first question is not "what do we comply with" but "which activities do we carry on".

Who this applies to

Any firm carrying on regulated cryptoasset activities in or into the UK: operating a trading platform, intermediating (broking and dealing), safeguarding cryptoassets, arranging staking, lending or borrowing cryptoassets or issuing qualifying stablecoins. DeFi arrangements are in scope where an identifiable controlling entity exists. Firms currently on the FCA's cryptoasset register under the money laundering regulations do not carry their registration across; authorisation under the new regime is a fresh application, made in the window.
The five policy statements, briefly
StatementGovernsThe headline obligation
PS26/9Admissions, disclosures and market abusePublished admission criteria, a qualifying cryptoasset disclosure document (QCDD) per token, market abuse detection systems
PS26/10Stablecoin issuanceBacking assets held in statutory trust per product, minimum 5% in on-demand bank deposits, T+1 redemption, quarterly disclosures, annual independent review
PS26/11Regulated activitiesActivity-specific conduct rules for platforms, intermediaries, custody, lending and staking
PS26/12Prudential requirementsCapital as the highest of three measures, plus basic liquid assets
PS26/13Handbook applicationConsumer Duty, SM&CR with mind and management in the UK, operational resilience

Obligations by activity

Trading platforms must be able to halt trading, initiate settlement within 24 hours and run the PS26/9 admission and market abuse machinery: published criteria, due diligence per token, a QCDD with digital token identifiers and surveillance capable of detecting manipulation.
Intermediaries owe best execution. The guidance expects price checks across three venues, UK retail orders executed on UK-authorised venues and express prior consent before executing off-platform.
Custodians come under the new CASS 17: daily reconciliations, immediate client notification of shortfalls and a settlement float capped at 2% per client per cryptoasset. Who may hold and transfer client cryptoassets is the subject of its own piece; the register rows start here.
Lending and borrowing to retail clients requires appropriateness assessments, mandatory over-collateralisation and a 50% cap on collateral supplementation without fresh consent.
Staking is workable at scale: auto-staking is permitted with annual notifications and the earlier idea of prior consent per transaction was dropped.
Stablecoin issuers carry PS26/10: sufficient core backing assets with at least 5% in on-demand deposits, statutory trusts per product, T+1 redemption, intragroup custody limited to 20% of the backing pool, quarterly disclosure updates and an annual independent review. Under PS26/13 they exit the CASS 7 client money rules, while enhanced SM&CR applies once backing assets pass £20bn on a three-year rolling average.

The prudential layer

PS26/12 sets capital as the highest of three measures: a permanent minimum requirement between £75,000 and £750,000 depending on activity, a fixed overheads requirement of one quarter of annual expenditure or activity-based K-factor requirements. Intangible assets are deducted in full, as are certain related-party cryptoasset holdings. Firms also hold basic liquid assets. The live guidance consultation on the overall prudential risk assessment (GC26/5) closed on 30 July 2026; final guidance is pending.
What you must evidence
ObligationReferenceWhat evidence proves it
Admission criteria and per-token diligencePS26/9Published criteria; diligence file per token; the QCDD with its digital token identifier
Market abuse surveillancePS26/9Surveillance system output; alert handling log; calibration reviews
Client asset safeguardingCASS 17 (PS26/11)Daily reconciliation outputs; shortfall notifications with timestamps; float monitoring against the 2% cap
Best executionPS26/11Three-venue price check records; venue selection rationale; consent records for off-platform execution
Stablecoin backingPS26/10Trust deeds per product; backing asset composition reports showing the 5% deposit floor; T+1 redemption logs; quarterly disclosures; the annual independent review
Capital adequacyPS26/12The highest-of-three calculation, dated and rerun on business change; liquid asset holdings
Consumer Duty and SM&CRPS26/13Outcome monitoring MI; Statements of Responsibilities showing UK mind and management
Start the file before the application, not after authorisation. The FCA's authorisation team assesses readiness on evidence and the window is five months long.

How firms handle this

Most crypto firms are running the authorisation project on spreadsheets built from law-firm summaries, which works for the application and starts failing the day the Handbook text moves. Some have hired UK compliance leads from traditional finance, which imports the evidence discipline but not the token-specific detail. Our Gap Analyser holds the PS26/9 to PS26/13 obligations as live register rows linked to the rule text, which is one way to keep the file current between application and commencement. However you do it, the test the FCA will apply in 2027 is the same one it applies to banks: show the rule, the control and the proof.

Primary sources

FCA, cryptoasset regime policy statements PS26/9, PS26/10, PS26/11, PS26/12 and PS26/13. All published 30 June 2026.
FCA, GC26/5 (prudential overall risk assessment guidance). Consultation closed 30 July 2026.
Thailand: royal decree amendments on digital asset businesses, effective 13 April 2025; Ministry of Digital Economy and Society blocking orders, 28 June 2025.
Volatile. Re-verify before each republish: the September 2026 consultations (A&D deferral for existing cryptoassets, QCDD deferral, financial crime updates, DeFi guidance) · GC26/5 final guidance · application window dates · the £20bn enhanced SM&CR threshold mechanics.