Open navigation
Search

Crypto Regulation in the UK

11 Mar 2026 (UPDATED: 04 Aug 2026) United Kingdom 3 min read
This page provides an overview of the FCA’s proposed new rules for regulating cryptoassets in the UK under a new regime which goes live on 25 October 2027.

1. Current state of UK crypto-regulation

At the moment, regulation of cryptoassets and cryptoasset services in the UK is undergoing a transformative change. Over 2025 and 2026, the UK government and its financial services regulator, the Financial Conduct Authority (“FCA”), have been consulting on new rules governing the regulatory treatment of cryptoassets and cryptoasset activities, with the final rules having been published in June 2026. Until these proposed rules come into effect (which is expected to be in October 2027), existing rules will continue to apply to cryptoasset service providers operating in or selling to customers in the UK (under the Money Laundering Regulations 2017 and the UK’s financial promotions regime). 

In this guide, we provide a summary of the proposed new rules. For a breakdown of the existing regime that currently applies to cryptoassets and cryptoasset service providers, until 25 October 2027, please refer to our UK CMS Expert Guide to Crypto Regulation in the United Kingdom.

2. Summary of incoming regimes

At a high level, the FCA’s general approach to regulating cryptoassets and cryptoasset services in the new regime has been to review existing “traditional finance” regulatory regimes, and adapt these existing rules as far as possible to apply to cryptoassets and cryptoasset services. The following is a summary of all the FCA’s rules, which have been published by way of policy statements (“PSs”). The PSs follow previous consultation papers (“CPs”), which have built on previous discussion papers (“DPs”), published as part of the FCA’s Crypto Roadmap during 2025 and 2026. At the time of writing, the FCA is yet to publish its final perimeter guidance and is seeking feedback in relation to non-Handbook guidance for prudential requirements for cryptoasset firms (GC26/4 and GC26/5), the outcomes of which are expected later in 2026. The FCA has also signalled that it intends to consult on certain specific issues raised in feedback to the consultation papers in due course. 

Following this, the FCA’s authorisation gateway window will open from 30 September 2026 to 28 February 2027. Firms must submit their application within this window to secure FSMA authorisation ahead of the 25 October 2027 “go live” date for the new regime.

DocumentsSummary of proposed rules (and status)

Market abuse regime for cryptoassets (“MARC”) and admissions & disclosures (“A&D”) rules  

Documents: PS26/9 (June 2026), CP 25/41 (16 December 2025), updated from DP 24/4 (16 December 2024).

CP 25/41 on Regulating Cryptoassets: Admissions & Disclosures and Market Abuse Regime for Cryptoassets (see our full analysis here).

MARC will apply to qualifying cryptoassets admitted to, or seeking admission on, a cryptoasset trading platform (“CATP”), regardless of geographic location. The regime covers the use and disclosure of inside information and market manipulation and applies to issuers, offerors, and CATPs.

While the cryptoasset tailored MARC proposals are broadly based on the UK Market Abuse Regime, MARC is not intended to replicate UK MAR due to structural differences in cryptoasset markets.

Key proposals include:

  1. Inside information - Disclosure responsibilities for inside information are broadened beyond issuers to include offerors and CATPs for information that directly concerns them. The FCA has provided guidance on the different types of inside information, including what inside information is and when the information is considered public, as well as when delayed disclosure is possible.
  2. Safe Harbours - Legitimate market practices will be available in certain circumstances, including; coin burning, cryptoasset stabilisation, and legitimate conduct reasons.
  3. Market Abuse Systems and Controls - All CATPs and intermediaries must, at a minimum, implement systems and controls that cover existing UK MAR rules. Additional CATP specific requirements include platform specific rules and tools to prevent abusive activity. The FCA will not handle the receipt and assessment of suspicious transaction and order reports, or introduce the “persons discharging managerial responsibilities” disclosure obligations.
  4. On Chain Monitoring - Only large CATPs need to monitor on chain activities, using appropriate tools and methods, including blockchain analytics, wallet clustering, and anomaly detection. Smaller CATPs and intermediaries should carry out proportionate off chain monitoring.
  5. Insider Lists - Issuers, offerors, and CATPs must maintain insider lists, and are responsible for lists maintained by third parties working on their behalf. 
  6. Cross Platform Information Sharing - The FCA proposes that large CATPs share information to prevent, detect, and disrupt market abuse and must share information with other Large CATPs without unnecessary delay if they have reasonable grounds to suspect market abuse and disclosure is happening. 

The proposed requirement under the MARC regime to disclose inside information will work in conjunction with the A&D rules’ admission document requirements to give investors sufficient information regarding a cryptoasset at the point of admission.

A&D (see our full analysis here)

The A&D regime will apply CATPs that allow retail participation, and to public offers to retail investors made under the new cryptoasset regulations proposed by the FCA (see our summary here). The regime will apply to the following designated activities:

  • Offering a qualifying cryptoasset to the public in the UK;
  • Disclosing information about an offer of a qualifying cryptoasset;
  • Disclosing information relating to a qualifying stablecoin offered to the public in the UK;
  • Requesting or obtaining the admission of a qualifying cryptoasset to trading on a CATP;
  • Disclosing information about an admission, or proposed admission, of a qualifying cryptoasset to trading on a CATP; and
  • Admitting a qualifying cryptoasset to trading on a CATP.

The majority of A&D rules will apply directly to the operators of CATPs which are authorised in the UK. There will also be a separate regime for UK-issued stablecoins. The proposed regime will implement the below requirements:

  1. Eligibility and Admission to Trading -Instead of prescriptive rules, CATPs must set risk based, objective admission criteria to assess whether admitting qualifying cryptoassets (excluding UK-issued qualifying stablecoins) could harm retail investors. These criteria must be board approved, published on the CATP’s website, and regularly reviewed and updated.
  2. Due Diligence Requirements - CATPs must conduct due diligence and include the factors listed in their admission criteria. 
  3. Qualifying Cryptoasset Disclosure Documents (“QCDD”) - CATPs can only admit or offer a qualifying cryptoasset on a CATP if a QCDD is in place, summarising the asset’s governance and features, resilience and tech, ownership, and trading history/performance.
  4. Filing and Publication - CATPs must file approved QCDDs and Supplementary Disclosure Documents (“SDD”) with centralised repository and on their own websites.
  5. Responsibility and Liability - A person seeking admission of a qualifying cryptoasset will be responsible and liable for its content, along with those accepting responsibility in these documents. If there is no identifiable issuer, the liability for disclosure attaches to the party that is responsible for the QCDD/SDD.
  6. Consumer Duty and Protected Forward Looking Statements - The Consumer Duty will not apply to activities relating to public offers and admissions to trading of qualifying cryptoassets. In relation to protected forward looking statements, these will now be voluntary for QCDDs and SDDs, as opposed to mandatory. 
  7. Disclosures for UK-Issued Qualifying Stablecoins - UK issued qualifying stablecoin issuers must provide two forms of disclosures: disclosures in the form of information on the issuer’s website, available to holders, prospective holders, and the general public; and a UK-issued qualifying stablecoin QCDD, available on the issuer’s website and on an FCA-owned centralised repository.

The CP process for these proposals was completed in February 2026. The FCA will consider feedback and publish their final rules in 2026.

DocumentsSummary of proposed rules (and status)

The regulated cryptoasset activities regime 

Documents: PS26/11 (June 2026), CP25/40 (16 December 2025), updated from DP25/1 (2 May 2025)

Policy Statement PS26/11 Crypto Regime: Regulated Cryptoasset Activities (June 2026). 

This PS follows CP25/14, CP25/40 and CP26/4. The PS finalises the regulated cryptoasset activities within scope of the new regime including operating a qualifying cryptoasset trading platform (QCATP), dealing, arranging, lending and borrowing (although note this is not a separate regulated activity), staking, safeguarding and the FCA’s current approach to decentralised finance (DeFi), largely maintaining the overall framework, while making targeted amendments and providing further guidance.

In relation to CATPs:

  1. Location, incorporation and authorisation - An operator of a CATP based in the UK must seek authorisation. Overseas CATP operators that wish to provide services to UK consumers must also be UK authorised, and establish either a UK subsidiary and/or a UK branch. Overseas firms only serving UK institutional clients will not require authorisation. Firms are not required to have a separate UK order book where an overseas QCATP operator is authorised in the UK via a branch. Authorisation via a branch requires a whole-firm assessment, bringing the entire overseas entity’s regulated activities into scope of UK regulation, including the threshold conditions and applicable Handbook requirements. The application of both COBS and DISP is limited to UK-based users of branch-authorised QCATPs. 
  2. Platform access and operation requirements - CATPs must ensure fair access to non-discriminatory trading and orderly market access. Each CATP must establish objective criteria for platform access and non-discretionary rules for order execution. These rules align in principle with those required for MTFs under MAR 5. Where a firm permits co-location in relation to a CATP, its rules on co-location services must be transparent, fair and non-discriminatory.
  3. Market making arrangements – Operators of CATPs are required to identify and monitor users who carry out market making strategies on the CATP, and must document and disclose incentive schemes or other arrangements with market makers or liquidity providers.
  4. Algorithmic or automated trading – The FCA will adopt a principles based approach, setting out high level principles firms need to comply with. CATPs must define their own rules on algorithms and monitor compliance with those rules, along with publishing their approach publicly.
  5. Mitigating harm and consumer duty - Operators of CATPs will be responsible to mitigate harm where they allow direct retail access. The Consumer Duty will not apply between trading participants on the CATPs.
  6. Retail customer protections - UK QCATP operators must ensure UK retail investors can only access qualifying cryptoassets admitted to trading with an A&D-compliant QCDD (unless the product is a UK-issued qualifying stablecoin). Operators must direct retail customers to the relevant QCDD(s) (and SDD(s), where applicable) before an order is placed, have arrangements in place to meet notification and disclosure obligations if a cryptoasset is withdrawn from trading, and provide clear and timely disclosures on terms, fees, trading rules, settlement arrangements and conflicts of interest.
  7. User agreement disclosures - A CATP operator must clearly disclose in any user agreement the client’s rights in respect of a qualifying cryptoasset traded on the platform in the event of a change in the underlying software protocols governing its operation, and in the event the client elects to terminate the agreement.
  8. Principal dealing - Operators of CATPs are allowed to hold principal dealer permissions and conduct matched principal or own account dealing on their own venue, subject to rules that mitigate prudential and execution risks, and conflicts of interest.
  9. CATPs issuing their own tokens - Admission of own tokens is allowed, provided the operator of the CATP discloses this to users and complies with general rules on conflicts of interest. Affiliates of a UK QCATP operator may also trade on the platform. 
  10. CATPs managing market and counterparty risk - Operators of CATPs are prohibited from extending credit to counterparties, beyond credit exposure arising from settlement.
  11. Transparency and reporting requirements - The FCA has not proceeded with pre-trade transparency for principal dealers. Pre-trade transparency applies only to large UK QCATP operators, being those with average annual revenue of at least £10m over a rolling 3-year period. Post-trade transparency applies to both UK QCATP operators and principal dealers, requiring publication as close to real time as technically possible and, in any case, within 1 minute of execution. Data may be published for free or on a reasonable commercial basis (in which case it must be made available for free within 15 minutes of initial publication). Firms may apply their own waiver and deferral policies.
  12. Settlement - High level expectations for settlement to be efficient and effective. Firms can internalise or externalise settlement and firms may settle transactions off-chain where it may be more cost-effective and therefore able to achieve better execution outcomes for clients. They must ensure clients understand the firm’s settlement responsibilities. CRYPTO 6 guidance clarifies that the FCA expects settlement to be initiated within 24 hours of trade execution.

In relation to Intermediaries

  1. Best execution, clients instructions and total consideration - Firms must execute orders promptly and fairly, with retail outcomes based on total consideration (price and costs). Firms should check at least three reliable UK authorised price sources. Execution is not a mechanical, transaction-by-transaction test; firms must instead maintain effective overarching arrangements supported by periodic post-trade analysis. The best execution rules do not apply to UK QCATP operators conducting matched principal trading on their own platform. Firms must provide clients with appropriate information on their order execution policy and obtain the client’s prior consent to it, and must review the policy and their execution arrangements at least annually and upon any material change.
  2. Duty of portfolio managers, receivers and transmitters - A firm providing portfolio management services must comply with the client’s best interests rule when transmitting orders to other persons for execution. This duty also applies to a firm that receives and transmits client orders for execution as part of arranging deals in qualifying cryptoassets.
  3. Pre-trade disclosure requirements for principal dealers - Before executing a client’s order, a firm dealing as principal must disclose: (i) a firm price at which the order can be executed; (ii) the duration for which that price is available; and (iii) any fees or charges for execution. Requirements (i) and (ii) do not apply to matched principal trading conducted on a UK QCATP’s own non-discretionary rules.
  4. Client order handling - Firms must implement procedures and arrangements for the prompt, fair and expeditious execution of client orders relative to other orders or the firm’s own trading interests, including sequential treatment of comparable orders save where impracticable or contrary to the client’s interest. Firms must also ensure that orders executed on behalf of clients are promptly and accurately recorded and allocated, and must inform a retail client promptly of any material difficulty relevant to the proper carrying out of their order.
  5. Dealing or arranging deals with UK retail clients - Intermediaries serving UK consumers must only execute transactions on UK authorised execution venues. Intermediaries may also only serve retail clients in relation to cryptoassets which have already been admitted to trading on at least one CATP and comply with the relevant disclosure and document requirements, subject to an exemption for UK issued qualifying stablecoins. Placing client orders on venues outside of the UK is not permitted. When a firm executes orders for retail or elective professional clients as a principal, it must not systematically or predominantly source liquidity from a QCATP where the operator of that QCATP is in the same group as the firm and is not authorised as a UK QCATP operator.
  6. Conflicts of interest – Intermediaries require a functional separation, including separate governance structures between proprietary trading and client order execution, as a minimum. The personal account dealing rules for traditional finance firms applies to all cryptoasset intermediaries.
  7. Payment for order flow (PFOF) - The FCA expects that cryptoasset intermediaries engaging in PFOF are unlikely to meet requirements on best execution, conflicts of interest and restrictions on inducements when serving retail or professional clients.
  8. Transparency requirements - Pre-trade transparency does not apply to intermediaries dealing as principal, with principal dealers now out of scope of pre-trade transparency. Post-trade transparency obligations do apply to principal dealers, requiring publication within 1 minute of execution, as well as the same record keeping requirements and the same requirement to report to immediate clients on order execution.
  9. Record keeping and client reporting - Intermediaries must generally retain records of their clients’ transactions for 5 years (rather than up to 7 years), save that the FCA may request retention for up to 7 years. Firms must identify cryptoassets by Digital Token Identifier (DTI) in order/transaction records and client reporting, and transaction hashes and associated addresses (such as wallet and smart contract addresses) and network fees must be recorded where applicable. Where an asset does not have a DTI, reporting can include an alternative unique and unambiguous identification code for each qualifying cryptoasset involved in an order/transaction. Client reporting must be provided promptly and at least by the end of the day of execution, cancellation or data receipt (or the next working day, if this occurs after the end of the working day). Clients must be able to access a 3-year transaction history on request, and a settlement method indicator has been added to the required content of client reports. The FCA has confirmed that it will not systematically receive or assess Suspicious Transaction and Order Reports or other individual cryptoasset transaction records.
  10. Settlement - Where an intermediary arranges or oversees settlement, it must clearly inform the client of the settlement process and associated risks. The FCA expects final settlement to be initiated within 24 hours of execution.

Cryptoasset lending and borrowing (“L&B”) activities

L&B activities will not be new regulated activities, but may fall within the regulated dealing or arranging activities.

  1. Retail access to L&B - Retail clients will be permitted to access L&B services relating to qualifying cryptoassets or stablecoins, subject to new consumer understanding, express prior consent, and operational risk requirements.
  2. Consumer understanding - An extensive list of specified information must be provided to retail clients each time they engage with L&B services and before they are bound by any L&B related agreements or services begin. Firms may use a single set of systems to discharge the requirements set out in CRYPTO 9 and COBS. 
  3. Operational risks - Firms must not use their own proprietary tokens in connection with L&B services provided to retail clients (this prohibition does not apply to L&B services provided to non-retail clients). Cryptoasset L&B firms must also conduct appropriateness assessments, comply with prudential requirements, and will be subject to additional record keeping requirements.
  4. Cryptoasset borrowing - The FCA will not apply the Consumer Credit Sourcebook to cryptoasset borrowing for retail clients. Firms must obtain the retail client’s express prior consent before supplementing the collateral on the retail client’s behalf, and the amount a firm may supplement is capped at 50% of the market value of the initial collateral (clients may top up their collateral themselves above this cap). Borrowing arrangements are subject to mandatory over-collateralisation, so the value of the collateral exceeds the amount borrowed (the FCA will, however, keep mandatory over-collateralisation under review as part of its evaluation of the regulatory regime). Firms must model loan limits and levels (loan-to-value ratio, margin call level and liquidation level) such that a margin call or liquidation is not expected within the first 6 months. Negative balance protection ensures retail clients cannot lose more than the collateral specifically dedicated to the borrowing arrangement. Borrowing collateral must be safeguarded on trust, and title cannot transfer to the firm except to discharge the client’s indebtedness with the client’s consent; Title Transfer Collateral Arrangements (TTCA) are prohibited for retail clients (though permitted for non-retail clients).
  5. Deferral arrangements - The FCA intends to consult on deferral mechanisms in several areas, including extending by 3 months (to January 2028) the time for intermediaries to obtain client consent to updated execution policies, the execution venue requirement, and the admission-to-trading requirement (extending to April 2028).

Staking proposals

  1. Consumer understanding - Firms must provide customers with information on the risks of staking, and notify them in good time of any material changes. Firms must obtain a retail client’s consent to stake current and future holdings, but blanket consent to stake any cryptoassets is not permitted. Firms will not be required to provide information and obtain consent prior to each, separate instance of staking retail clients’ cryptoassets. For auto-staking, the terms must state that the firm may stake future holdings and explain how the service can be cancelled. Firms must notify retail clients at least every 12 months of the staking service used (including the amount staked, rewards earned, fees and commission charged, and the most recent terms), although earlier notification may be appropriate in some circumstances, such as client inactivity.
  2. Technological, cyber, and third party risk - Operational resilience rules and prudential requirements apply to staking firms, as explained further in CP25/25 and CP25/42, and as set out in the FCA’s finalised guidance on cryptoasset operational resilience (FG26/6). The FCA do not require automatic compensation for retail losses arising from preventable operational or technological failures.
  3. Record keeping - Firms must keep records of staking services, including liquid staking token transfers, generally for 5 years (or for the duration of the client relationship if longer, in certain cases), limited to clients whose identity is known to the firm. Firms must also record the type and amount of cryptoassets provided to clients as part of a staking service.

Decentralised Finance ("DeFi"

DeFi activities are not covered by the incoming UK cryptoasset regulatory regime where they are truly decentralised.

The FCA will apply its rules and guidance to firms engaging in DeFi where there is a clear controlling person carrying on a regulated cryptoasset activity, assessed on a case-by-case basis. Separate DeFi guidance, covering indicators of decentralisation and how to mitigate operational resilience and financial crime risks, is expected to follow later in 2026.

DocumentSummary of proposed rules (and status)

Stablecoin issuance and cryptoasset custody

Documents: PS26/10, PS26/11, CP25/14 (28 May 2025).

PS26/10 finalises the FCA’s rules on stablecoin issuance, following consultation under CP25/14. Related safeguarding and other issues consulted on in CP25/25 and CP26/4 have been finalised separately in PS26/11 (see below).

Policy Statement PS26/10 Crypto Regime: Stablecoin Issuance (June 2026) and Policy Statement PS26/11 Crypto Regime: Regulated Cryptoasset Activities (June 2026). 

PS26/10 finalises the rules on the issuance of UK-issued qualifying stablecoins, covering backing assets, segregation and the statutory trust, third-party safeguarding of backing assets, record-keeping and reconciliations, redemption, the use of third parties and disclosures, largely maintaining the framework consulted on in CP25/14 while making targeted refinements to improve clarity, operability and proportionality.

PS26/11 finalises the rules on cryptoasset safeguarding, including appointment of third parties in cryptoasset custody, private key management and security, reconciliations, addressing shortfalls and excesses, and record-keeping. 

The Cryptoassets Regulations define a “qualifying stablecoin” as a “qualifying cryptoasset” referencing one or more fiat currencies that seeks or purports to maintain a stable value (by the issuer holding fiat currency or fiat currency and other assets).

On top of needing to seek authorisation and comply with the conduct of business standards applicable to authorised financial services firms, qualifying stablecoin issuers will be required to:

  • back qualifying stablecoins with secure, liquid assets held in a backing asset pool subject to a statutory trust for qualifying stablecoin holders, with all money and assets in the pool held in the stablecoin’s denominated reference currency (the FCA has decided against permitting multi-currency backing);
  • offer redemption of qualifying stablecoins at par value in exchange for money to all holders within a T+1 timeframe; and clearly disclose their policy for redemption and the composition of backing assets to consumers.
  1. Backing Assets - UK stablecoin issuers that utilise expanded backing assets are subject to the Backing Asset Composition Requirement (“BACR”), which requires them to calculate a minimum proportion of the total backing pool that needs to be held in core backing assets for any individual token issuance, albeit the forward-looking daily redemption estimate originally proposed by the FCA has been removed. The BACR is intended to support prudent risk management by providing a baseline for sufficient liquidity in the backing pool to meet redemption requests and minimise the need for forced sales of assets under stress. Firms holding expanded backing assets must hold a Core Backing Asset Requirement equal to the higher of 5% of the backing pool or the highest daily redemption percentage over the preceding 180 redemption days, calculated on every redemption day (rather than every 14 days as originally proposed). The FCA has retained the proposed range of permissible core and expanded backing assets.
  2. Segregation and Statutory Trust - The backing asset pool must be held on statutory trust for the benefit of token holders, with a separate trust required for each stablecoin product. All minted stablecoins (including those held by the issuer) must be fully backed, save for tokens permanently removed from circulation by burning.
  3. Third-Party Safeguarding - Intragroup custodians may be used subject to a 20% cap on the value of the backing asset pool that may be safeguarded by intragroup custodians (subject to a disproportionality exemption, by analogy with CASS 7 which the firm must notify the FCA of before relying on it), together with SYSC 10 conflicts controls and periodic diversification reviews. Firms must obtain a single signed acknowledgement letter per custodian (electronic letters are permitted) confirming the trust arrangement.
  4. Record-Keeping and Reconciliations - Firms must conduct daily internal and external reconciliations of the backing asset pool. The FCA has removed the proposed “unallocated backing funds” account concept, and will now permit firms to retain a limited excess of up to 5% of the value of the relevant stablecoin pool within the backing asset pool (subject to the statutory trust), rather than requiring same-day removal of all excesses. Shortfalls must be resolved by the end of the business day on which they are identified, with FCA notification required where this is not possible.
  5. Redemption - The T+1 redemption timeline commences on receipt of the stablecoin to be redeemed (rather than on receipt of a full redemption request, as originally proposed), so that AML/KYC checks are completed before the T+1 period begins. Issuers must have a contract with each holder setting out the conditions of redemption, and must ensure that redemption obligations transfer effectively in law to subsequent holders on the secondary market.
  6. Third Parties - The FCA has introduced bespoke outsourcing rules requiring issuers that appoint third parties to carry out elements of the issuance activity (including redemption) to conduct due diligence and maintain a UK law-governed contract with the third party, while remaining fully responsible for compliance with the issuer’s regulatory obligations.
  7. Disclosures - Firms must update backing asset and stablecoin-in-circulation information at least every 3 months, and must publish the identity of any third party holding more than 20% of the backing asset pool. UK stablecoin issuers must undertake an annual independent review of the 1:1 backing ratio. The FCA has aligned the frequency of updates between website disclosures and the stablecoin QCDD as far as reasonably practicable, and requires disclosures to be retained for 5 years and made available to holders on request.
  8. Other Issues - Issuers passing interest or income from the backing asset pool to token holders is prohibited, although third parties may still pay their own rewards from their own account. The FCA has also confirmed that, under the Treasury’s final legislation, multi-currency stablecoins are out of scope of the qualifying stablecoin regime.

Joint Regulation of Systemic Stablecoins - Alongside PS26/10, the FCA and the Bank of England have published their approach to the joint regulation of systemic stablecoin issuers, covering how each authority’s rules will apply as firms move from being solo-regulated by the FCA to joint regulation, including a consultation on the application of the Bank’s draft rules during the transitional period and the proportionate requirements that would apply to firms recognised as systemic at launch under the ‘step-up’ regime.

PS26/11 finalises the rules on cryptoasset safeguarding, including appointment of third parties in cryptoasset custody, private key management and security, reconciliations, addressing shortfalls and excesses, and record-keeping. It includes the rules for a new CASS 17. This introduces new rules that apply to cryptoasset custodians in relation to qualifying cryptoassets (“QCAs”).

CASS 17 will apply to all firms that control cryptoassets through any means that would enable them to bring about a transfer of the benefit of the cryptoassets to another person, whether they themselves hold them or not. 

CASS 17 will not apply to qualifying cryptoassets that are transferred to the firm under a cryptoasset lending arrangement. 

CASS 17 does not extend to the custody of specified investment cryptoassets (including relevant specified investment cryptoassets, “RSICs”); firms safeguarding RSICs will instead need to apply CASS 6 requirements (obtained via a variation of permission, including Article 9N), pending further FCA engagement on tailored RSIC safeguarding rules. CASS 6 will also apply to small AIFMs’ safeguarding of RSICs where they carry on Article 9N activity, despite the exclusion in Article 72AA of the RAO, just as it does currently in relation to their ‘excluded custody activities’. 

The FCA and PRA are currently consulting on how CASS rules should apply to RSIC custody in the longer term (Call for Input: The future of tokenisation - A joint vision from the authorities for UK wholesale financial markets). 

Self-custody models are not subject to CASS rules. 

Under CASS 17, qualifying cryptoasset custodians will be required to:

  • segregate client cryptoassets from their own;
  • hold those qualifying cryptoassets on behalf of clients in a trust;
  • have accurate books and records of clients’ cryptoassets holdings (including the type, quantity and location of cryptoassets held and any other persons with the capacity or control to effect a transfer); and
  • have adequate controls and governance to protect clients’ cryptoasset holdings.
  • cryptoassets may be removed from the trust for cryptoasset lending, on client instruction to transfer, to discharge a debt owed to the firm in accordance with agreed terms and conditions, where a UK QCATP (or group company) operates a settlement float model with the client’s informed consent, or where an absolute transfer of title is necessary to deliver a product or service with the client’s informed consent; a further exception applies where a firm holds only a back-up key and the client retains full control and can act independently. Cryptoassets safeguarded outside of the trust will not be subject to CASS record-keeping requirements. 

In comparison, CASS 8 applies to mandate arrangements where a firm has authority to instruct or direct a client’s assets without itself having control. CASS 17 applies to any cryptoasset firm that has control of cryptoassets within the meaning of Article 9N, subject to limited exceptions.

The FCA has provided the diagram shown below at “Diagram 1” to illustrate how CASS 17 applies in different scenarios to firms with different levels of control. 

UK QCATPs are permitted to hold up to 2% of each client’s cryptoassets, calculated per client and per cryptoasset class, outside the trust in a global settlement wallet for settlement purposes (the settlement float limit). This is subject to the client’s informed consent (which may be withdrawn).

Firms may operate separate trusts through separate virtual addresses or combine client cryptoassets at different virtual addresses into the same trust, but firms cannot allocate the same single virtual address to different trusts, as this does not meet the FCA’s co-mingling requirement. Third parties must also meet the same requirements if appointed for safeguarding purposes. Firms appointing third parties for safeguarding will also need to consider the jurisdiction as part of their due diligence. 

Firms are permitted to use DLT as an external source of information to confirm the per-trust/class cryptoasset resource (i.e. the amount and class of cryptoasset being safeguarded on trust for clients) where a third party is not appointed for safeguarding, but the same source of information cannot be used to calculate the per-trust/client/class cryptoasset requirement. 

Firms must investigate discrepancies, remove all excesses, top up any shortfalls and notify the FCA in writing if a shortfall has not been topped up by the next reconciliation. Firms must immediately notify clients affected by shortfalls. 

These new rules largely mirror the existing custody rules in CASS 6 (which relate to “traditional” safe custody assets).

A firm safeguarding client cryptoassets would need client agreement in order to return an equivalent asset to their client via a different blockchain than the one on which the safeguarding arrangement began.

DocumentsSummary of proposed rules (and status)
Documents: PS26/12 (June 2026), CP25/42 (16 December 2025); CP25/15 (28 May 2025)

Policy Statement PS26/12 Crypto Regime: A Prudential Regime for Cryptoasset Firms (June 2026).

This PS follows CP25/15 and CP25/42. PS26/12 finalises the prudential framework for regulated cryptoasset firms, covering capital, liquidity, risk management and public disclosure requirements. The FCA has largely maintained the proposed framework while making targeted recalibrations and clarifications to improve proportionality and usability. The framework introduces an integrated prudential sourcebook that brings together core prudential requirements ("COREPRU"), along with a sourcebook setting out sector specific requirements for firms doing regulated cryptoasset activities ("CRYPTOPRU"). Both COREPRU and CRYPTOPRU will apply to CRYPTOPRU firms.

The COREPRU includes rules on: overall financial adequacy; definition of own funds; own funds requirement (overall calculation); fixed overhead requirement; concentration risk monitoring; and basic liquid asset requirement.

The CRYPTOPRU includes rules on: permanent minimum requirement; K-factor requirement (including operational and exposure-based K-factors); issuer liquid asset requirement; overall risk assessment; and sectoral prudential disclosure requirements.

The final rules include the following key elements:

  1. Permanent minimum requirement (“PMR”) - PMRs of: £750,000 for dealing in qualifying cryptoassets as principal; £350,000 for issuing qualifying stablecoins; £150,000 for operating a qualifying CATP, safeguarding qualifying cryptoassets, or arranging qualifying cryptoasset staking; and £75,000 for dealing in qualifying cryptoassets as agent or arranging deals in qualifying cryptoassets. The PMR is not designed to be risk-sensitive; risk sensitivity is delivered through the K-factor framework and the overall risk assessment.
  2.  K-factor requirement - The final rules confirm K-factors as follows. For operational risk K-factors: K-SII (stablecoin issuance) has been reduced from 2% to 1% of average qualifying stablecoins in issuance; K-RCS (cryptoassets safeguarded, formerly K-QCS) is retained at 0.04% of average cryptoassets safeguarded; K-CCO (client cryptoasset orders) at 0.1% of average client cryptoasset orders; K-CTF (cryptoasset trading flow) at 0.1% of average daily trading flow; and K-CCS (clients’ cryptoassets staked) at 0.04% of average client cryptoassets staked. For exposure-based K-factors, the market risk framework has been significantly simplified: K-NCP (net cryptoasset position) now applies a single 40% position risk adjustment to the net exposure value of each qualifying cryptoasset that can be prudently valued and is admitted to a UK QCATP, replacing the previously proposed Category A/Category B classification. Cryptoassets that do not meet these conditions are deducted from regulatory capital. K-CCD (cryptoasset counterparty default) volatility adjustments have been aligned at 40% for qualifying cryptoassets admitted to a UK QCATP, and 100% for collateral that would ordinarily be deductible from regulatory capital. K-CON (concentration risk) is confirmed as consulted, aligning with the MIFIDPRU framework.
  3. Fixed overhead requirements (“FOR”) – The FOR is calculated as one quarter of the firm’s relevant expenditure during the preceding year, reflecting fixed costs for crypto trading, including 100% or 80% deductions for pass-through venue/broker/CCP fees (with limits) and a deduction for trading losses, while excluding membership fees and loss sharing obligations. The FCA has retained the dual test for a material increase as either a 30% increase in projected relevant annual expenditure, or a £2m increase in the FOR.
  4. Overall risk assessment (thresholds and group risk) – Ongoing overall risk assessments require firms to set and monitor firm specific capital and liquid asset thresholds (covering risks beyond baseline requirements, including stress and wind down planning) and to identify and manage group risks, holding additional capital or liquidity where those risks cannot be mitigated. Alongside PS26/12, the FCA is consulting on non-Handbook guidance GC26/4 and GC26/5 to support firms with their overall risk assessment.
  5. Liquidity (BLAR/ILAR) – The FCA has confirmed the Basic Liquid Assets Requirement (BLAR) as consulted on, calculated as one-third of the fixed overheads requirement plus 1.6% of client guarantees, and has declined to expand the list of qualifying core liquid assets (for example, trade receivables, physical gold and broader foreign exchange holdings). For UK stablecoin issuers, the Issuer Liquid Asset Requirement (ILAR) has also been maintained as consulted on, based on the Bank of England/PRA haircut approach and the UK CRR, and remains limited to on-demand deposits. The FCA has not introduced a specific capital requirement for foreign exchange risk arising where a stablecoin’s reference currency differs from the issuer’s balance sheet currency, leaving this to be addressed through the firm’s overall risk assessment.

Disclosure and reporting - The final rules make two targeted changes to the disclosure framework: (i) the requirement to publicly disclose the own funds threshold requirement (OFTR) and liquid asset threshold requirement (LATR) has been removed; and (ii) firms whose own funds requirement is determined by the PMR (rather than the FOR or K-factor requirement) are exempt from the detailed CRYPTOPRU 8 disclosure requirements. Where a cryptoasset firm is subject to other prudential regimes (e.g. MIFIDPRU and COREPRU/CRYPTOPRU), disclosure requirements must be met across both regimes but firms may publish a single, consolidated set of prudential disclosures

DocumentSummary of proposed rules (and status)

Application of FCA Handbook for Regulated Cryptoasset Activities II

Documents: PS26/13 (June 2026), PS26/11, CP26/4, CP25/25

Policy Statement PS26/13 Crypto Regime: Application of FCA Handbook for Regulated Cryptoasset Activities (June 2026). This PS follows CP25/25 and CP26/4. PS26/13 finalises the rules and guidance on how key cross-cutting FCA Handbook obligations will apply to regulated cryptoasset activities, including standards on conduct, governance, resilience, redress, and reporting. The FCA has largely maintained the proposed framework while making targeted refinements to improve clarity and proportionality. PS26/11 finalises the rules in relation to cryptoasset trading platforms, lending and borrowing and safeguarding, as consulted on in CP26/4.

  1. Approach to authorising overseas cryptoasset firms - The FCA has clarified that, in limited circumstances, an overseas firm may be authorised to operate a CATP through a UK branch where this supports access to global liquidity and improves pricing and execution (including matching UK and overseas orders within the same legal entity). However, other cryptoasset activities (such as safeguarding) should be carried out via a separate UK legal entity. The expectation of a legal entity rather than a branch as the basis for a firm’s cryptoasset activities will only apply to firms which are solo-regulated by the FCA. Dual-regulated firms (i.e. those regulated by both the FCA and PRA) are permitted to carry on cryptoasset activities from a branch, subject to approval by the PRA as the lead regulator and provided the firm meets the general threshold conditions as assessed at the FCA authorisations gateway and holds the relevant permission. The FCA’s finalised guidance is published as FG26/7.
  2. Consumer Duty - The FCA has published final non-Handbook guidance on the Consumer Duty for cryptoasset firms in FG26/5, clarifying the application of the Duty including the cross-cutting rules and Outcomes, territorial scope, fair value, consumer support, consumer understanding, and the roles of distributors and manufacturers in the supply chain. The Duty will not apply to trading between participants of a UK QCATP (implemented via PRIN 3.1.1.14R), but will apply to how CATP operators interact with retail customers more broadly (including onboarding, communications, and customer service). The Duty will not apply to the designated activities relating to public offers and admissions to trading of qualifying cryptoassets (other than UK-issued qualifying stablecoins), but will apply to public offers and admissions to trading of UK-issued qualifying stablecoins. A UK QCATP operator, when acting in that capacity, is only a manufacturer of the trading platform product and not of the cryptoassets traded on the platform; it is instead a distributor of the cryptoassets traded.
  3. Complaints handling, FOS and FSCS – The FCA will apply DISP 1 complaints handling rules to the newly regulated cryptoasset activities from the go-live date, with complaints reporting phased in initially through a lighter-touch quarterly return (rather than the more detailed six-monthly return used for traditional finance firms). For UK-qualifying stablecoin issuers, third parties appointed to carry out parts of the issuance activity must forward complaints to the issuer promptly, and complaints should be resolved within 8 weeks of the third party receiving them. FOS compulsory jurisdiction will extend to complaints about the newly regulated cryptoasset activities, but only where the activity is carried on from a UK establishment. Complaints by non-UK customers of overseas-incorporated QCATPs authorised via a UK branch are carved out of the FOS compulsory jurisdiction. The FOS voluntary jurisdiction will not be extended to cover complaints about the new cryptoasset activities. FSCS coverage will not be extended to regulated cryptoasset activities, nor at this time to claims arising from safeguarding of relevant specified investment cryptoassets (RSICs).
  4. Application of COBS - The FCA extends the Handbook definition of “designated investment business” to include all newly regulated cryptoasset activities, meaning COBS requirements will apply to these firms. COBS is disapplied for non-UK users of overseas-incorporated QCATPs authorised in the UK via a branch. UK-issued qualifying stablecoins are excluded from the definition of restricted mass market investments (RMMIs) and will not be subject to RMMI marketing restrictions (including cooling-off periods and appropriateness requirements). All other qualifying cryptoassets remain classified as RMMIs. Financial promotions for non-UK-issued qualifying stablecoins must include additional risk warning information. The FCA has mandated the appropriateness test in COBS 10 Annex 4 as a rule (previously guidance), establishing a consistent minimum standard for retail clients’ understanding of cryptoasset risks. COBS 15 cancellation rights will not apply to any cryptoasset activities.
  5. Client reporting - The FCA will disapply most COBS 16 reporting for trading/execution, lending/borrowing, and staking activities, with similar requirements moving into the CRYPTO sourcebooks. COBS 16 will apply and be enhanced for safeguarding activities, including the provision of online access to client holdings and detailed asset information. For staking, firms must provide a notification to retail clients at least every 12 months on the staking service (including the amount staked, rewards earned and fees charged), as set out in the CRYPTO sourcebook.
  6. Use of credit to purchase cryptoassets - Cryptoasset purchases using credit cards or credit lines will be permitted.
  7. SM&CR Tiering and Training Competence - The FCA will apply SM&CR in full to authorised cryptoasset firms, with a ‘modification by consent’ waiver approach for the Certification Regime pending the outcome of the SM&CR Review. The requirement for relevant individuals involved in the ‘backing asset management’ element of stablecoin issuance to certify under the ‘proprietary trader’ certification function has been removed. Enhanced SM&CR thresholds have been set at £100bn in safe custody assets and client cryptoassets combined for cryptoasset safeguarding firms, and £20bn in backing assets (per stablecoin product, calculated as a three-year rolling average) for UK-stablecoin issuers (adjusted from the £65bn consulted on, to align with the Bank of England’s proposed threshold for systemic stablecoins). The FCA’s training and competence regime will apply to cryptoasset firms servicing retail clients.
  8. Regulatory reporting - The FCA is taking a phased approach to regulatory reporting requirements. Existing returns in SUP 16 will apply to all qualifying cryptoasset firms from the go-live date. New crypto-specific baseline returns will apply from commencement of the regime, covering activity-specific data for stablecoin issuance, QCATP operation, intermediation, staking, lending and borrowing, and safeguarding (with monthly safeguarding returns). Complaints data will be reported quarterly through a lighter-touch return. Supplementary data collections will be introduced alongside the baseline returns, and the FCA will consult on the final form of cryptoasset regulatory reporting requirements following a post-implementation refinement process. Prudential regulatory reporting (beyond the Baseline Financial Resilience Report FIN073) will also be developed iteratively with firms.
  9. Safeguarding - Custodians must generally hold client cryptoassets on trust, but the final rules provide for limited exceptions. CASS 17 will not, at this stage, be extended to custody of specified investment cryptoassets; firms safeguarding relevant specified investment cryptoassets (RSICs) must instead apply CASS 6 requirements, pending further FCA engagement on tailored RSIC safeguarding rules. Firms combining custody with staking, or CATP integrated custody, must comply with the relevant CASS 17 requirements. Lent assets are generally excluded and retail borrowing collateral must be safeguarded by the firm providing the borrowing service.
  10. Reconciliation and shortfalls - Firms must maintain safeguarding records to allow them to establish the entitlement of each client to the client cryptoassets held by the firm, as well as allowing the firm's own cryptoassets to be distinguished from client cryptoassets. The firm will also need to carry out reconciliation checks once every business day. Where the firm identifies a shortfall, it must resolve this within 24 hours. Shortfalls must be resolved in the relevant class of cryptoassets. 
  11. Private key management and security - Private key management applies to client cryptoassets held in trust and any operational surplus held on trust. The rules will apply where a firm has control over the “means of access” to a client cryptoasset, including both private keys and “shards”. Means of access rules also apply to firms providing a back-up solution. Firms must promptly update the record as often as necessary for the details within them to remain accurate.
  12. Third-party custody arrangements – CASS 17.6 only applies to third parties appointed to safeguard client cryptoassets where they are being held on trust.
  13. Financial Crime - The FCA will apply the financial crime elements of SYSC 6 (systems and controls, senior manager responsibility, and the Money Laundering Reporting Officer function), together with the Financial Crime Guide (FCG) and Financial Crime Thematic Reviews (FCTR), to cryptoasset firms in the same way as they apply to traditional finance firms. This sits alongside firms’ existing obligations under the Money Laundering Regulations 2017 and the Travel Rule. The FCA will continue to engage with the Joint Money Laundering Steering Group to support updated sector-specific guidance.
  14. Environmental, Social and Governance (ESG) - The FCA will apply the ESG Sourcebook’s anti-greenwashing rules (ESG 4.1.1R and ESG 4.3.1R) to all cryptoasset firms, prohibiting the use of sustainability labels and requiring any sustainability references to be clear, fair, not misleading, and consistent with the product or service’s actual sustainability characteristics. The FCA has declined to extend other ESG provisions that apply only to specific firm types (such as asset managers) or to introduce new climate-related disclosure requirements at this stage, and will apply the same ESG treatment uniformly across all cryptoasset activities.
Crypto Updates Diagram
Crypto Regulation in the UK Roadmap.png

Our industry work

Our FS Reg team is proud to support CryptoUK, having helped shape its responses to every FCA Discussion Paper and Consultation Paper on the new cryptoasset regime. Sam Robinson and Yasmin Johal also co-chair CryptoUK’ s regulatory working group, keeping us right at the heart of policy development in this fast-evolving space.

We are equally proud to support the Digital Pound Foundation, having assisted with its submissions in response to a range of FCA Discussion Papers and Consultation Papers on the new cryptoasset regime.

Best Digital Assets Law Firm

CMS UK has been named the Best Digital Assets Law Firm at The Digital Commonwealth Awards. The Digital Commonwealth Awards is an extraordinary celebration of innovation and excellence in the realms of digital assets, ScienceTech, and Web3. 

Back to top Back to top
You will now find all Law-Now content on CMS.law
Opens in new window