Brief

Cryptoasset Perimeter Guidance: Authorisation Requirements from October 2027

The FCA’s final cryptoasset perimeter guidance clarifies which activities will need FSMA authorisation from 25 October 2027, outlines the transitional application window and sets out practical steps for firms across the crypto, payments and traditional finance sectors.

MC

Michaela Clarke

Operations & Compliance Coordinator

Week of 21 September 20267 min read
A row of credit cards fanned out on a dark leather desk beside a small bronze padlock and a compliance checklist on a clipboard, warm brass lamp light

At a Glance

At a Glance - The FCA’s PS26/18 guidance defines the regulatory perimeter for cryptoasset activities that will require FCA authorisation from 25 October 2027, and it details a transitional application window that opens on 30 September 2026 and closes on 28 February 2027.

Source date and implementation pathway Source-backed facts are separated from MEMA analysis stages SOURCE FCA publication 16 Sept 2026 MEMA Scope assessment MEMA review stage MEMA Governance decision MEMA review stage MEMA Evidence and action MEMA review stage Primary-source fact MEMA analysis or control stage
MEMA visual analysis. Source anchor: PS26/18: Cryptoasset perimeter guidance. Only the green source nodes reproduce FCA dates; the gold nodes are MEMA review stages, not regulatory deadlines. On smaller screens, scroll the visual horizontally to see every stage.

The FCA is expanding the regulated perimeter to cover activities such as safeguarding cryptoassets, operating trading platforms, arranging deals and staking. Existing permissions under the Money Laundering Regulations, Payment Services Regulations or Electronic Money Regulations will not automatically transfer, meaning firms must assess whether a new FSMA authorisation or a variation of permission is needed.

The guidance is aimed at crypto‑focused firms, traditional finance organisations exploring crypto markets, payment service providers and any entity that registers under the MLRs. It links to the broader cryptoasset regime published on 30 June 2026 and signals the FCA’s intent to support a smooth transition through webinars, pre‑application support and ongoing engagement with the PRA.

What the Final Rules Change

New regulated cryptoasset activities

From 25 October 2027 the Cryptoasset Regulations introduce a set of regulated activities, including safeguarding cryptoassets, operating a trading platform, arranging deals and staking, which will require FCA authorisation unless an exemption or transitional provision applies.

Transitional application window

The FCA has opened a specific window for firms wishing to use the savings and transitional run‑off provisions; applications can be submitted from 30 September 2026 and must be received by 28 February 2027. This window is the only period during which firms can rely on the transitional provisions.

Interaction with existing regimes

Existing registrations under the Money Laundering Regulations, Payment Services Regulations or Electronic Money Regulations do not convert automatically to FSMA authorisation. Firms must map current permissions against the new cryptoasset activities and determine whether a variation or fresh authorisation is required, while continuing to satisfy threshold conditions and financial‑crime rules.

Implementation Dependencies

Firms should begin by mapping each of their crypto‑related services against the activity list in Chapter 4 of the guidance. This mapping will identify whether a service falls within the regulated perimeter and, if so, which specific permission - for example, safeguarding or arranging - is required. The analysis must consider the interaction with the Money Laundering Regulations, as the FCA expects continued compliance with AML rules post‑authorisation. MEMA recommends establishing a cross‑functional working group that includes compliance, legal, product and technology to produce a definitive perimeter assessment within the next four weeks.

The application window creates a hard deadline for firms that wish to rely on the savings and transitional provisions. Preparation should include gathering evidence of existing controls, drafting a variation request where an existing FSMA permission is being extended, and arranging pre‑application meetings (PASS). Dual‑regulated firms must also coordinate with the PRA. MEMA advises scheduling the PASS booking by early November 2026 to allow sufficient time for FCA feedback before the 28 February 2027 cut‑off.

Who Must Act

The guidance directly targets firms that currently carry out or plan to carry out regulated cryptoasset activities in the UK. This includes crypto‑asset custodians, trading platform operators, arrangers of staking services, issuers of electronic money, payment service providers and traditional finance firms that are testing crypto markets overseas. It also applies to entities already authorised under the FSMA, as well as those registered under the Money Laundering Regulations, who may need additional permissions for crypto activities.

While the PS is relevant to any organisation interested in the evolving cryptoasset framework, the FCA explicitly states that the guidance is for firms that will be carrying on regulated cryptoasset activities by way of business in the UK. Firms that are merely monitoring the market but do not intend to undertake a regulated activity are not required to seek authorisation, although they should stay informed of future consultations.

Board Assurance

The board should ask whether any current business lines will fall within the newly defined regulated cryptoasset activities and, if so, whether the firm holds the appropriate FSMA authorisation or a valid exemption. Evidence required includes the activity mapping, legal opinions on exemptions and a timeline for any required authorisation applications, all of which should be presented at the next board risk committee meeting.

The board must also consider the operational impact of transitioning from MLR registration to FSMA authorisation, including the need to satisfy threshold conditions, maintain AML controls and align reporting with the FCA’s financial‑crime rules. Documentation of the transition plan, resource allocation for the authorisation process and confirmation of PRA engagement for dual‑regulated entities will provide the assurance the board needs to endorse the transition strategy.

Implementation Priorities

ActionOwnerStatusTimingEvidence
Map current crypto‑related services to the regulated activity list in PS26/18 Chapter 4 Head of Product & Compliance MEMA recommended action 4 weeks from publication PS26/18
Determine whether an exemption or transitional provision applies and document the rationale Legal Counsel MEMA recommended action 6 weeks from publication PS26/18
Prepare and submit FCA authorisation or variation application within the 30 Sep 2026 - 28 Feb 2027 window Authorisations Lead Implementation deadline 28 February 2027 PS26/18
Book pre‑application support (PASS) and attend FCA webinars on the new regime Compliance Operations MEMA recommended action Early November 2026 PS26/18
Engage the PRA for dual‑regulated firms to align supervisory expectations Risk & Prudential Lead Risk‑based action Prior to FCA submission PS26/18

Source Evidence

SourceDocument typePublishedWhy it matters
PS26/18: Cryptoasset perimeter guidance PS (PS26/18) 2026-09-16 Primary FCA source for Cryptoasset perimeter guidance, including the stated audience, detailed proposals and next steps in PS26/18.

Plain English Glossary

  • AML - Anti-Money Laundering. Controls and processes firms must operate to detect, prevent, and report money laundering activity.
  • PRA - Prudential Regulation Authority. Bank of England body responsible for prudential supervision of banks, building societies, insurers, and major investment firms.
  • PS - Policy Statement. FCA publication confirming final rules following consultation, typically with the new Handbook text and feedback summary.

Disclaimer

This article is for general information only and does not constitute legal or regulatory advice. Firms should assess the application of regulatory requirements by reference to their permissions, products, customers and operating model.

How MEMA Can Help

MEMA can help firms translate regulatory change into practical controls, policies, monitoring activity and board evidence. Book a free scoping call to discuss what this development means for your firm.

MEMA helps firms apply regulatory developments through its FCA authorisation support.

Further reading: FCA authorisation timelines and planning.

Frequently asked questions

Which crypto‑related activities will require FCA authorisation from 25 October 2027?

The FCA states that activities such as safeguarding cryptoassets, operating a trading platform, arranging deals and providing staking services are now regulated under the Cryptoasset Regulations. Firms carrying out any of these activities by way of business in the UK must seek FSMA authorisation unless they qualify for an exemption or use the transitional provisions, as set out in PS26/18.

Can existing permissions under the Money Laundering Regulations be used instead of a new FCA authorisation?

No. PS26/18 makes clear that existing registrations or permissions under the Money Laundering Regulations, Payment Services Regulations or Electronic Money Regulations will not automatically convert to FSMA authorisation. Firms must assess each crypto activity against the new perimeter and apply for a fresh authorisation or a variation where required.

What is the purpose of the transitional application window and when does it close?

The transitional window, opening on 30 September 2026 and closing on 28 February 2027, allows firms to apply for authorisation while relying on the savings and transitional run‑off provisions. This window is the only period during which firms can benefit from those provisions, and the FCA encourages early engagement through its pre‑application support service. This answer is grounded in PS26/18.

Do dual‑regulated firms need to involve the PRA in the authorisation process?

Yes. PS26/18 advises dual‑regulated firms to engage the Prudential Regulation Authority when applicable. Coordination with the PRA ensures that both supervisory expectations are met and that any prudential considerations are addressed alongside the FCA authorisation.

What ongoing obligations will apply once a firm is authorised under the new cryptoasset regime?

After authorisation, firms must continue to meet the FCA Handbook threshold conditions, comply with all applicable financial‑crime rules, and maintain appropriate systems and controls for the regulated activity. This answer is grounded in PS26/18.

Need expert regulatory guidance?

Our ex-regulator team helps firms navigate complex requirements and evidence compliance with confidence.

Book a Free Scoping Call