UK FCA Crypto Authorization Guidance: What Firms Must Do Before the September Window Opens
The UK Financial Conduct Authority has published its final guidance on when crypto activities will require authorization under the country's new digital asset regulatory regime, and the clock is already running. The application window opens on 30 September 2026. Any firm offering services in the UK that touches regulated crypto activity needs to understand this guidance immediately, because existing registrations and permissions do not carry over automatically.
What the FCA's Guidance Actually Covers
The guidance is designed to answer one practical question: does your firm's activity fall inside the new regulatory perimeter, and if so, what permissions will you need? The FCA has identified a set of activities that will require authorization or a variation of permission under the incoming regime.
Regulated activities named in the guidance
The FCA's final guidance identifies the following activity categories as falling within scope:
- Issuing qualifying stablecoins
- Operating a crypto trading platform (exchange or multilateral trading venue)
- Dealing in cryptoassets as principal or agent
- Arranging crypto transactions
- Safeguarding cryptoassets (custody)
- Arranging crypto staking services
The list is broader than the existing anti-money laundering registration regime, which covered only exchange and custody services. Firms that previously registered purely for AML purposes should not assume that registration translates into authorization under the new framework. The FCA has been explicit: firms must assess their own permission requirements from scratch.
The perimeter question and DeFi
The guidance is intended to help firms determine whether they sit inside or outside the regulatory perimeter. This is particularly relevant for decentralized finance protocols and tokenized asset platforms, where the boundary between a regulated activity and a purely software-based function is genuinely contested. The FCA has indicated it plans to consult on further perimeter guidance later in 2026, which means the picture may still move for DeFi-adjacent businesses. Firms in that space should treat the current guidance as necessary but not necessarily final.
The Three Dates Every Compliance Officer Needs
The FCA has set out a clear timeline, and missing any of these dates carries material regulatory risk.
30 September 2026: Application window opens
From this date, firms can submit applications for authorization or for a variation of existing permission under the new regime. Firms that have already been granted FCA authorization under other financial services legislation will still need to apply for the specific crypto permissions relevant to their activities.
28 February 2027: Transitional arrangements deadline
Firms that want to continue operating during the transition period while their authorization application is assessed must submit by 28 February 2027. Missing this deadline means a firm cannot rely on transitional protections and would need to cease in-scope activity until authorization is granted. For trading platforms, custodians, and stablecoin issuers, that is an existential commercial risk.
25 October 2027: Full regime goes live
This is the date the new framework takes full legal effect. Firms that have not obtained the necessary authorization by this point, and have not been granted a transitional arrangement, will be operating without permission. The FCA has enforcement powers that include public censure, financial penalties, and activity restrictions.
Accounting and Operational Implications for Firms
Authorization is not simply a legal project. It has direct consequences for how firms record, report, and reconcile digital asset activity, and those consequences need to feed into finance and operations teams now rather than in early 2027.
Permission scope shapes your chart of accounts
The permissions a firm holds will define what it is legally allowed to do. That scope must be reflected accurately in the firm's financial records. A custody business that also arranges staking, for example, needs distinct ledger treatment for assets held on behalf of clients versus assets generating staking rewards on behalf of those clients. Client assets under custody sit off-balance-sheet under CASS-equivalent rules; staking rewards may generate income recognition questions. Crypto bookkeeping software that cannot segregate activity by permission type will create audit risk from day one of the new regime.
Capital adequacy and prudential reporting
Authorization under the new regime is likely to bring prudential requirements tied to activity type. Firms dealing as principal will face different capital requirements from those acting purely as agents or custodians. CFOs will need to model capital adequacy against projected activity volumes well before the October 2027 go-live. Digital asset accounting software that can produce real-time exposure reports, broken down by asset class and activity type, will be essential for meeting any regulatory reporting obligations the FCA attaches to each permission category.
AML and transaction monitoring obligations
Authorization does not sit in isolation from the UK's existing AML framework. Authorized firms will be subject to the Money Laundering Regulations as well as FCA-specific rules on customer due diligence, transaction monitoring, and suspicious activity reporting. For firms adding newly scoped activities, such as staking or stablecoin issuance, existing transaction monitoring rules may need to be extended to cover new transaction patterns. Understanding how blockchain analytics feeds into sanctions compliance workflows is no longer optional for any firm applying for authorization.
Stablecoin issuers face a dual compliance track
Firms issuing qualifying stablecoins face a genuinely complex compliance structure. The FCA's authorization regime applies alongside the Bank of England's oversight of systemic stablecoins under the Financial Services and Markets Act framework. Issuers need to track reserve assets, redemption obligations, and issuance volumes in a way that is auditable by two separate regulators. That makes robust digital asset accounting software a compliance requirement rather than a nice-to-have. The guidance the FCA finalized in June 2026, combined with this authorization perimeter guidance, forms the operational basis for what those auditable records must contain. Good references on AML controls and stablecoin typologies your firm needs to track are worth reviewing alongside the FCA's own materials.
The Broader Regulatory Context
This guidance does not appear in a vacuum. Parliament approved bringing cryptoassets within the FCA's regulatory remit in February 2026. The regulator then finalized a broader package of rules and guidance in June. The authorization perimeter guidance published now is the third significant output from that process and the most operationally immediate, because it is the document that tells firms what they need to apply for and when.
Separately, the House of Lords voted 194 to 138 to add an amendment to the Financial Services and Markets Bill requiring the Treasury to develop a strategy covering cryptoassets, stablecoins, tokenized securities, and digital financial infrastructure within 12 months of the bill becoming law. That amendment signals ongoing parliamentary interest in shaping the regime beyond what the FCA has already set out, so the landscape is not fully settled even as firms prepare their applications.
The FCA has also been working in parallel on tokenized assets. It sought feedback on whether some tokenized funds should be exempt from existing UK fund rules, and the FCA and Bank of England have committed to publishing a joint roadmap for tokenization in wholesale financial markets before the end of 2026. Firms building or evaluating tokenized product lines need to follow that roadmap closely, as it may affect the permission categories relevant to their business model.
Practical Steps for Firms Right Now
David Geale, the FCA's executive director of consumers, payments and competition, framed the guidance plainly: getting ready for regulation starts with understanding how the regime applies to your specific business. That is the correct starting point, and it means internal scoping work cannot wait until the application window is open.
Activity mapping and gap analysis
Every firm that operates in the UK crypto market, or serves UK clients from overseas, should produce a written map of its current activities against the FCA's named activity categories. Where activities fall inside the perimeter, the firm needs to identify which permission or permissions it will apply for, whether it currently holds any overlapping authorizations, and what new policies, controls, and reporting infrastructure those permissions will require.
Systems readiness for authorization conditions
Authorization applications will require firms to demonstrate operational readiness, including adequate systems for record-keeping, client asset protection, and transaction monitoring. Crypto accounting software that produces clean, auditable ledgers broken down by activity type, counterparty, and asset will be central to those demonstrations. Firms that are still relying on manual spreadsheets or general-purpose accounting tools not designed for on-chain activity should treat the September 2026 application window as a hard deadline for upgrading their infrastructure.
Frequently Asked Questions
Does my existing FCA AML registration count as authorization under the new regime?
No. The FCA has confirmed that existing registrations and permissions do not automatically convert. Firms with AML registrations only must assess whether their activities require full authorization and submit an application through the new process starting 30 September 2026.
What happens if we miss the 28 February 2027 transitional deadline?
A firm that misses the transitional deadline cannot rely on the FCA's transitional protections to continue operating in-scope activities while its application is reviewed. In practice, that would mean pausing regulated activity until authorization is granted, which carries significant commercial and reputational risk.
Are DeFi protocols in scope?
The FCA has flagged that the perimeter question for decentralized protocols is not fully resolved and has indicated it will consult on further perimeter guidance later in 2026. DeFi-adjacent firms should monitor that consultation closely and take legal advice on their specific model rather than assuming they fall outside scope.
How should a custody firm account for client assets under the new regime?
Cryptoassets held in custody for clients should be recorded off-balance-sheet, consistent with the FCA's client asset protection rules. The firm's crypto bookkeeping software needs to segregate client assets from proprietary assets at the ledger level, with reconciliation records that can be produced on demand for regulatory review.
Will stablecoin issuers need to deal with both the FCA and the Bank of England?
Yes. Qualifying stablecoin issuers fall within the FCA's authorization perimeter for the issuance activity itself. Systemic stablecoin arrangements are also subject to Bank of England oversight under the Financial Services and Markets Act framework. Issuers should expect dual regulatory engagement and build their reporting infrastructure accordingly.
Source: Cointelegraph
