Crypto Regulation in the UK
Key contacts
1. Current state of UK crypto-regulation
At the moment, regulation of cryptoassets and cryptoasset services in the UK is undergoing a transformative change. Over 2025 and 2026, the UK government and its financial services regulator, the Financial Conduct Authority (“FCA”), have been consulting on new rules governing the regulatory treatment of cryptoassets and cryptoasset activities, with the final rules having been published in June 2026. Until these proposed rules come into effect (which is expected to be in October 2027), existing rules will continue to apply to cryptoasset service providers operating in or selling to customers in the UK (under the Money Laundering Regulations 2017 and the UK’s financial promotions regime).
In this guide, we provide a summary of the proposed new rules. For a breakdown of the existing regime that currently applies to cryptoassets and cryptoasset service providers, until 25 October 2027, please refer to our UK CMS Expert Guide to Crypto Regulation in the United Kingdom.
2. Summary of incoming regimes
At a high level, the FCA’s general approach to regulating cryptoassets and cryptoasset services in the new regime has been to review existing “traditional finance” regulatory regimes, and adapt these existing rules as far as possible to apply to cryptoassets and cryptoasset services. The following is a summary of all the FCA’s rules, which have been published by way of policy statements (“PSs”). The PSs follow previous consultation papers (“CPs”), which have built on previous discussion papers (“DPs”), published as part of the FCA’s Crypto Roadmap during 2025 and 2026. At the time of writing, the FCA is seeking feedback in relation to non-Handbook guidance for prudential requirements for cryptoasset firms (GC26/4 and GC26/5), the outcomes of which are expected later in 2026. The FCA has also signalled that it intends to consult on certain specific issues raised in feedback to the consultation papers in due course.
Following this, the FCA’s authorisation gateway window will open from 30 September 2026 to 28 February 2027. Firms must submit their application within this window to secure FSMA authorisation ahead of the 25 October 2027 “go live” date for the new regime.
| Documents | Summary of rules (and status) |
Market abuse regime for cryptoassets (“MARC”) and admissions & disclosures (“A&D”) rules Documents: PS26/9 (June 2026), CP 25/41 (16 December 2025), updated from DP 24/4 (16 December 2024). | Policy Statement PS26/9 Crypto Regime: Admissions & Disclosures and Market Abuse Regime for Cryptoassets (June 2026). This PS follows CP25/41. The PS finalises the MARC and A&D rules, largely maintaining the approach consulted on with targeted refinements. MARC applies to qualifying cryptoassets admitted to, or seeking admission on, a cryptoasset trading platform (“CATP”), regardless of geographic location. The regime covers the use and disclosure of inside information, insider dealing and market manipulation and applies to issuers, offerors, and CATPs. While the cryptoasset tailored MARC rules are broadly based on the UK Market Abuse Regime, MARC is not intended to replicate UK MAR due to structural differences in cryptoasset markets. Key proposals include: 1. Inside information - Disclosure responsibilities for inside information are broadened beyond issuers to include offerors and CATPs for information that directly concerns them. The FCA has provided guidance on the different types of inside information, including what inside information is and when the information is considered public, as well as when delayed disclosure is possible. The final rules clarify that this disclosure obligation does not, of itself, require a firm to proactively seek out information it does not already possess. The FCA has also confirmed that protecting the security of an issuer or token (for example, delaying disclosure of a code vulnerability while it is being remediated) can constitute a “legitimate interest” justifying delayed disclosure, although any such delay cannot be indefinite; the FCA has deviated from its proposed rules in relation to this. The FCA has also clarified that whether information generated or disclosed during open development practices (where cryptoassets are developed or maintained in collaboration with third parties without a formal relationship between them) constitutes inside information depends on the particular facts, including the nature of the information, the stage of development, and whether it is public information; where such information does constitute inside information, disclosure made in the course of employment, profession or duties may still be excluded from the unlawful disclosure prohibition. The FCA has also confirmed it does not intend to publish a formal roadmap for convergence between MARC and UK MAR, noting that certain structural differences reflecting features of cryptoasset markets are not expected to converge in the near term. The FCA has also refined its non-exhaustive examples of inside information, including recasting the stablecoin example to focus on the ability to maintain intended value or fulfil redemption requests, and adding a new example addressing changes to market-making arrangements and the addition or withdrawal of liquidity providers. 2. Dissemination of Inside Information - Inside information must be published on the issuer’s, offeror’s, or CATP’s own website, where it has one. The explicit requirement for “active dissemination” through other channels (for example, social media) has been removed from the final rules, although the FCA notes that some active dissemination is still likely to be needed to meet the statutory standard. Disseminated inside information must also be uploaded to the FCA-owned centralised repository as soon as possible, tagged with a DTI as metadata. 3. Safe Harbours - Legitimate market practices are available in certain circumstances, including coin burning and cryptoasset stabilisation. The FCA has dropped “legitimate conduct reasons” (“legitimate reasons”) as a standalone legitimate market practice in the final rules, as, unlike the equivalent UK MAR safe harbour, it had unrestricted scope and risked misuse. For coin burning, automatic or non-discretionary burning is now a legitimate market practice where it is an automatic function of a protocol or non-discretionary; the “sole purpose” requirement has been narrowed to purposes supporting the effective functioning of the market; and firms must disclose their burning plans to the public before execution. The cryptoasset stabilisation legitimate market practice is retained unchanged from the proposed rules, including its 30-calendar-day time limit. Separately from the LMP framework, the final rules also confirm that a person is not treated as having 'used' inside information for insider dealing purposes where they are a market maker acting in that capacity, are authorised to act as a counterparty pursuing their legitimate business (including underwriting), or are executing client orders legitimately in the normal course of their duties. The FCA declined requests to designate Maximal Extractable Value (MEV), staking, market making, and governance participation as additional legitimate market practices, explaining that MEV can facilitate manipulation or unfair trading advantages so is better assessed under the general market abuse definitions, and that staking, market making, and governance participation do not ordinarily constitute market abuse so do not require separate LMP status; the FCA has said it will keep the list of LMPs under review as market practices evolve. 4. Market Abuse Systems and Controls - All CATPs and intermediaries must, at a minimum, implement systems and controls that cover existing UK MAR rules. This includes information barriers to limit employees' access to client orders (to prevent front-running), personal account dealing arrangements, and mandatory staff training on market abuse risks and the handling of inside information. Additional CATP specific requirements include platform specific rules and tools to prevent abusive activity. The FCA will not handle the receipt and assessment of suspicious transaction and order reports, or introduce the “persons discharging managerial responsibilities” disclosure obligations. In the final rules, the FCA notification threshold under Principle 11 now covers activity a firm cannot deal with itself, but is expressed as “including, but not limited to” that activity. Audits of systems and controls must now be carried out sooner than the usual annual cycle where a risk of market abuse is identified. Firms must also have the ability, where permitted by data protection legislation, to require an employee suspected of contravening internal controls or of undertaking cryptoasset market abuse to disclose their wallet addresses on request, and must have wider arrangements in place to support investigations into their employees. 5. On Chain Monitoring - Large CATPs must monitor on chain activities using appropriate tools and methods, including blockchain analytics, wallet clustering, and anomaly detection, but this obligation has been narrowed in the final rules to wallets “linked” to the platform (namely, wallets used to buy or sell on the platform, and other wallets reasonably identifiable as controlled by the same persons) and monitoring is only required where a risk of market abuse has been identified, rather than continuous monitoring of the whole chain. Smaller CATPs and intermediaries should carry out proportionate off chain monitoring. A new, lighter-touch requirement now applies to all UK CATPs (not only large ones) to monitor for material and persistent price dislocations between their own platform and other markets or trading venues they reasonably consider material for price formation. The £10m average revenue (3-year) threshold that triggers the large CATP on-chain monitoring and cross-platform information sharing obligations is unchanged. 6. Insider Lists - Issuers, offerors, and CATPs must maintain insider lists, and are responsible for lists maintained by third parties working on their behalf. In the final rules, wallet address fields have been removed from the insider list template due to security and verification concerns. Instead, firms must have arrangements with employees (for example, contractual terms) to support investigations, which could include a requirement for an employee to disclose their wallet addresses where needed. Insider lists must be kept for at least 5 years from the date on which they are drawn up or last updated. 7. Cross Platform Information Sharing - Large CATPs must share information to prevent, detect, and disrupt market abuse, and must share information with other Large CATPs without unnecessary delay where they have reasonable grounds to suspect that cryptoasset market abuse has occurred, is occurring, or is likely to occur, and it is necessary to disclose the information in order to detect, prevent or disrupt that suspected market abuse. This requirement has been finalised without substantive change from the position consulted on in CP25/41. Large CATPs must retain records of disclosures made, and of decisions not to disclose, under this obligation for a period of 5 years. The requirement under the MARC regime to disclose inside information works in conjunction with the A&D rules’ admission document requirements to give investors sufficient information regarding a cryptoasset at the point of admission. |
The A&D regime, now finalised by the FCA in Policy Statement PS26/9 following consultation under CP25/41, applies to CATPs that allow retail participation — described in the final rules as "retail UK QCATPs" — and to public offers to retail investors made in reliance on the exceptions in paragraph 6, Part 1 of Schedule 1 to the Cryptoassets Regulations, namely offers that are conditional on admission to trading or where the qualifying cryptoasset is, at the time of the offer, already admitted to trading on a UK QCATP. The final A&D rules also apply to advertisements relating to the admission to trading of qualifying cryptoassets on UK QCATPs. The underlying designated activities are created by regulations 7 (public offers of qualifying cryptoassets) and 8 (admissions to trading on a qualifying cryptoasset trading platform) of the Cryptoassets Regulations. The regime will apply to the following designated activities:
The majority of A&D rules will apply directly to the operators of CATPs which are authorised in the UK. There will also be a separate regime for UK-issued stablecoins. The proposed regime will implement the below requirements: 1. Eligibility and Admission to Trading - Instead of prescriptive rules, CATPs must set risk based, objective admission criteria to assess whether admitting qualifying cryptoassets (excluding UK-issued qualifying stablecoins) could harm retail investors. These criteria must be board approved, published on the CATP’s website, and regularly reviewed and updated. In the final rules, “fitness and propriety” has been replaced with “integrity and reputation”, and “sustainability” has been replaced with “continuing viability” (to avoid other regulatory connotations). Admission criteria must also be based on the potential risks to the interests of retail investors. The FCA has also provided guidance on matters relevant to a CATP’s assessment of integrity and reputation, including legal proceedings, regulatory action and adverse public information, and has removed the requirement for admission criteria to take into account the “quality” of QCDDs. 2. Due Diligence Requirements - CATPs must conduct due diligence and include the factors listed in their admission criteria. The final rules confirm that a reasonableness standard applies to the pre-admission assessment. The alternative test (permitting a CATP to proceed where it made reasonable efforts to verify information and adequately disclosed this) has been dropped, leaving only the “true and not misleading” test, though a QCDD can still be “not misleading” where it clearly and prominently states what information could not be obtained or verified. The separate “investor detriment assessment report” proposed in CP25/41 has also been dropped, in favour of simply keeping records of information that could not be verified. CATPs must make and keep appropriate records of their due diligence processes and admission or rejection decisions for at least 5 years, or at least 7 years if requested by the FCA. 3. Conflicts of Interest - Where a CATP admits a qualifying cryptoasset of its own motion, or an affiliated entity seeks admission, the CATP must apply the same due diligence standards as it would for a third-party applicant, disclose the conflict prominently in the QCDD (including in the summary of key information), and retain records evidencing that appropriate safeguards were in place to ensure its admission criteria were applied objectively. 4. Qualifying Cryptoasset Disclosure Documents (“QCDD”) - CATPs can only admit or offer a qualifying cryptoasset on a CATP if a QCDD is in place, summarising the asset’s governance and features, resilience and tech, ownership, and trading history/performance. 5. Industry Standards and Market Practice - The FCA continues to support industry-led initiatives to develop standardised QCDD disclosure templates, including through engagement via its Regulatory Sandbox, to promote greater consistency, usability and comparability of disclosures. Such templates are supporting tools only, and do not displace the statutory responsibility or liability that attaches to the person identified as responsible for the QCDD under the CATP’s rules. 6. Filing and Publication - CATPs must file approved QCDDs and Supplementary Disclosure Documents (“SDD”) with a centralised repository and on their own websites, and must maintain an up-to-date list on their website of the QCDDs and SDDs published for qualifying cryptoassets admitted to trading on their platform. The final rules require QCDDs and SDDs to carry a clear disclaimer stating that they do not require, and have not received, FCA approval. Use of the specified DTI is required to support searchability and consistent identification of qualifying cryptoassets, although the FCA is not mandating a broader machine-readable format for disclosures at this stage. To use the FCA-owned centralised repository, CATPs must also obtain and maintain a Legal Entity Identifier (LEI), where eligible, with an “issued” registration status on the GLEIF Global LEI Index. 7. Responsibility and Liability - A person seeking admission of a qualifying cryptoasset will be responsible and liable for its content, along with those accepting responsibility in these documents. If there is no identifiable issuer, the liability for disclosure attaches to the party that is responsible for the QCDD/SDD. An investor who relies on a QCDD or SDD when buying or subscribing for a qualifying cryptoasset has a right under the Cryptoassets Regulations to seek compensation from the person responsible for it, where the investor suffers loss because the document contains an untrue or misleading statement or omits required information. This framework has been finalised without substantive change from the position consulted on in CP25/41. 8. Consumer Duty and Protected Forward Looking Statements - The Consumer Duty does not apply to activities relating to public offers and admissions to trading of qualifying cryptoassets. In relation to protected forward looking statements, these remain voluntary for QCDDs and SDDs, as opposed to mandatory. The final rules are largely unchanged, save for minor drafting clarifications confirming that the consumer understanding requirements relate to the presentation of information. The Protected Forward Looking Statements regime is retained, with CRYPTO 3.7.9R amended so that content-specific accompanying information no longer needs to be repeated at every instance of a protected forward-looking statement, provided it appears immediately adjacent to at least one instance, with a cross-reference directing readers to that information for other instances. 9. Disclosures for UK-Issued Qualifying Stablecoins - UK issued qualifying stablecoin issuers must provide two forms of disclosures: disclosures in the form of information on the issuer’s website, available to holders, prospective holders, and the general public; and a UK-issued qualifying stablecoin QCDD, available on the issuer’s website and on an FCA-owned centralised repository. This regime has been finalised without substantive change from the position consulted on in CP25/41. 10. Supplementary Disclosure Documents - The FCA has revised the drafting of the trigger for an SDD to make it clearer, while keeping the same materiality threshold. Withdrawal rights remain exercisable within 2 working days of publication of an SDD, but the notification requirements have been strengthened so that equivalent day-of-publication notification is now required across both direct-offer and intermediary channels. 11 Advertisements and Financial Promotions - Advertisements relating to public offers and admissions of qualifying cryptoassets, where a QCDD is required, must identify the relevant QCDD, advise consumers to read it, and be consistent with the QCDD and any SDD. Only written electronic advertisements must include a hyperlink to the QCDD or SDD, and advertisements need only be updated following publication of an SDD where they would otherwise become misleading. 12. Transitional Arrangements – In CP26/32 (September 2026), the FCA proposed targeted deferral arrangements under the A&D regime for cryptoassets already in circulation at the point the wider crypto regime comes into force. This includes: a. Deferral of QCDD requirements for assets sold to UK retail investors: Retail UK QCATP operators that applied for authorisation during the relevant application window (30 September 2026 to 28 February 2027), and firms subsequently authorised via the saving provisions in regulation 53 of the Cryptoassets Regulations, may benefit from a 6-month deferral of the pre-admission assessment and QCDD requirements for qualifying cryptoassets already trading on their platform prior to UK authorisation. The deferral runs from the date of authorisation and ends on the earlier of publication of a QCDD for the relevant asset or 6 months after authorisation; newly admitted cryptoassets cannot benefit from the deferral period. Firms must submit a list of in-scope qualifying cryptoassets (with digital token identifiers) and an implementation roadmap to the FCA as part of the authorisation process. During the deferral period, firms and intermediaries must provide prescribed disclosures and a written risk warning to retail investors before each order, covering the absence of the pre-admission assessment and QCDD, the deferral end date, and the consequences, including that retail investors will not have a right of action under regulation 14 or withdrawal rights under regulation 15 of the Cryptoassets Regulations, and may have access to less information than otherwise required under regulation 13. MARC applies in full from commencement with no deferral. The deferral provisions do not apply to firms operating under the transitional provision in Chapter 3 of Part 7 of the Cryptoassets Regulations. b. Deferral of execution venue requirements for UK-authorised dealers and arrangers serving UK retail and elective professional clients: Under the new regime, intermediaries that are executing or receiving and transmitting orders for UK retail or elective professional clients must ensure that these orders are ultimately executed only on UK-authorised qualifying cryptoasset execution venues. Because UK-authorised dealers and arrangers routing orders to execution venues may not know which venues will or will not have obtained authorisation at the time of go-live and may have to adjust their processes if their usual execution venues fail to obtain authorisation at the commencement date, the FCA has proposed to defer the application of its execution venue requirement for retail and elective professional orders for a period of three months from go-live. c. Deferral of execution policy requirements for intermediaries: Because UK-authorised dealers and arrangers may not know which venues will and will not have obtained authorisation at the time of go-live, these firms will struggle to update their order execution policy with information on the qualifying cryptoasset execution venues where they execute client orders and obtain client consent to that updated order execution policy ahead of day 1 of the regime. The FCA therefore proposes to defer the application of those execution policy requirements for a three-month period from go-live, to give sufficient time for execution policy updates and to obtain client consent. Firms will still need to provide clients with, at a minimum, a high level execution policy that is compliant in principle with CRYPTO 5.4 requirements. |
| Documents | Summary of rules (and status) |
The regulated cryptoasset activities regime Documents: PS26/11 (June 2026), CP25/40 (16 December 2025), updated from DP25/1 (2 May 2025), PS26/18 (September 2026), CP26/13 (April 2026) | Policy Statement PS26/11 Crypto Regime: Regulated Cryptoasset Activities (June 2026) and Policy Statement PS26/18 Crypto Regime: Cryptoasset Perimeter Guidance (September 2026). PS26/11 follows CP25/14, CP25/40 and CP26/4. The PS finalises the regulated cryptoasset activities within scope of the new regime including operating a qualifying cryptoasset trading platform (QCATP), dealing, arranging, lending and borrowing (although note this is not a separate regulated activity), staking, safeguarding and the FCA’s current approach to decentralised finance (DeFi), largely maintaining the overall framework, while making targeted amendments and providing further guidance. PS26/18 follows CP26/13. PS26/18 finalises the FCA’s perimeter guidance on regulated cryptoasset activities, given effect through the Perimeter Guidance (Regulated Cryptoasset Activities) Instrument 2026 (FCA 2026/55). A new PERG 18 has been inserted into the Perimeter Guidance Manual, with consequential amendments to PERG 1, PERG 2 and PERG 8. In relation to perimeter guidance: 1. Scope and purpose - PERG 18 provides guidance on determining whether a person is carrying on a regulated cryptoasset activity for which authorisation is required. It sets out a five-step framework: (i) is the person carrying on a regulated activity; (ii) is the activity carried on in the UK; (iii) is it carried on by way of business; (iv) does an exclusion apply; and (v) does an exemption apply. The guidance emphasises that the perimeter depends on the substance of the activity and the role performed, not the terminology used. 2. Territorial scope (‘in the UK’) - The guidance expands on when activities are considered to be carried on ‘in the UK’, including the deeming provisions in section 418 of FSMA specific to regulated cryptoasset activities. The overseas persons exclusion (OPE) does not apply to regulated cryptoasset activities; overseas persons should carefully consider whether, and if so on what basis, activity is carried on in the UK, and whether any alternate exclusions or exemptions apply. 3. ‘By way of business’ test - The guidance provides the FCA’s views on the narrower ‘by way of business’ test, which requires a person to carry on ‘the business of engaging in’ a regulated cryptoasset activity. The FCA notes this is deliberately narrower than the traditional FSMA business test, focusing the perimeter on persons whose business model involves providing or operating the relevant activity (e.g. as a service to customers), rather than persons merely using such services or participating on their own account. 4. Specified investments - The guidance confirms the distinction between qualifying cryptoassets (including qualifying stablecoins) and specified investment cryptoassets (SICs). Qualifying cryptoassets are the new specified investment created by the Cryptoasset Regulations, which must be fungible, transferable and not solely a record of value or contractual rights. SICs are cryptoassets that fall within the scope of existing specified investments (such as shares or debt instruments) and largely remain subject to existing regulatory treatment, other than in relation to safeguarding. The dealing activities do not extend to SICs; buying and selling SICs falls within the scope of dealing in investments as principal or dealing in investments as agent. The guidance addresses wrapped tokens, confirming that where a wrapped token represents a qualifying cryptoasset that is not a SIC, the wrapped token is also likely to be a qualifying cryptoasset. In relation to CATPs: 5. Location, incorporation and authorisation - An operator of a CATP based in the UK must seek authorisation. Overseas CATP operators that wish to provide services to UK consumers must also be UK authorised, and establish either a UK subsidiary and/or a UK branch. Overseas firms only serving UK institutional clients will not require authorisation. Firms are not required to have a separate UK order book where an overseas QCATP operator is authorised in the UK via a branch. Authorisation via a branch requires a whole-firm assessment, bringing the entire overseas entity’s regulated activities into scope of UK regulation, including the threshold conditions and applicable Handbook requirements. The application of both COBS and DISP is limited to UK-based users of branch-authorised QCATPs. 6. Platform access and operation requirements - CATPs must ensure fair access to non-discriminatory trading and orderly market access. Each CATP must establish objective criteria for platform access and non-discretionary rules for order execution. These rules align in principle with those required for MTFs under MAR 5. Where a firm permits co-location in relation to a CATP, its rules on co-location services must be transparent, fair and non-discriminatory. 7. Market making arrangements – Operators of CATPs are required to identify and monitor users who carry out market making strategies on the CATP, and must document and disclose incentive schemes or other arrangements with market makers or liquidity providers. 8. Algorithmic or automated trading – The FCA will adopt a principles based approach, setting out high level principles firms need to comply with. CATPs must define their own rules on algorithms and monitor compliance with those rules, along with publishing their approach publicly. 9. Mitigating harm and consumer duty - Operators of CATPs will be responsible to mitigate harm where they allow direct retail access. The Consumer Duty will not apply between trading participants on the CATPs. 10. Retail customer protections - UK QCATP operators must ensure UK retail investors can only access qualifying cryptoassets admitted to trading with an A&D-compliant QCDD (unless the product is a UK-issued qualifying stablecoin). Operators must direct retail customers to the relevant QCDD(s) (and SDD(s), where applicable) before an order is placed, have arrangements in place to meet notification and disclosure obligations if a cryptoasset is withdrawn from trading, and provide clear and timely disclosures on terms, fees, trading rules, settlement arrangements and conflicts of interest. However, under deferral arrangements proposed in CP26/32 (September 2026), the QCDD requirement is temporarily relaxed for qualifying cryptoassets that were already trading on a platform prior to its UK authorisation, for a period of up to 6 months from the date of authorisation. During this deferral period, retail investors must instead be provided with prescribed disclosures and risk warnings (see item 12 of the A&D rules above and item 5 of the intermediary rules below). 11. User agreement disclosures - A CATP operator must clearly disclose in any user agreement the client’s rights in respect of a qualifying cryptoasset traded on the platform in the event of a change in the underlying software protocols governing its operation, and in the event the client elects to terminate the agreement. 12. Principal dealing - Operators of CATPs are allowed to hold principal dealer permissions and conduct matched principal or own account dealing on their own venue, subject to rules that mitigate prudential and execution risks, and conflicts of interest. 13. CATPs issuing their own tokens - Admission of own tokens is allowed, provided the operator of the CATP discloses this to users and complies with general rules on conflicts of interest. Affiliates of a UK QCATP operator may also trade on the platform. 14. CATPs managing market and counterparty risk - Operators of CATPs are prohibited from extending credit to counterparties, beyond credit exposure arising from settlement. 15. Transparency and reporting requirements - The FCA has not proceeded with pre-trade transparency for principal dealers. Pre-trade transparency applies only to large UK QCATP operators, being those with average annual revenue of at least £10m over a rolling 3-year period. Post-trade transparency applies to both UK QCATP operators and principal dealers, requiring publication as close to real time as technically possible and, in any case, within 1 minute of execution. Data may be published for free or on a reasonable commercial basis (in which case it must be made available for free within 15 minutes of initial publication). Firms may apply their own waiver and deferral policies. 16. Settlement - High level expectations for settlement to be efficient and effective. Firms can internalise or externalise settlement and firms may settle transactions off-chain where it may be more cost-effective and therefore able to achieve better execution outcomes for clients. They must ensure clients understand the firm’s settlement responsibilities. CRYPTO 6 guidance clarifies that the FCA expects settlement to be initiated within 24 hours of trade execution. In relation to Intermediaries 17. Perimeter guidance - The guidance confirms that the dealing and arranging activities mirror the existing RAO framework (articles 14, 21 and 25). Dealing includes buying, selling, subscribing for or underwriting qualifying cryptoassets; 'buying' and 'selling' include acquisition and disposal for valuable consideration. Arranging includes two distinct activities: arranging (bringing about) deals and making arrangements with a view to transactions. Advising on qualifying cryptoassets and managing qualifying cryptoassets are confirmed as not being new regulated cryptoasset activities, though managing relevant SICs may fall within managing investments. 18. Best execution, clients instructions and total consideration - Firms must execute orders promptly and fairly, with retail outcomes based on total consideration (price and costs). Firms should check at least three reliable UK authorised price sources. Execution is not a mechanical, transaction-by-transaction test; firms must instead maintain effective overarching arrangements supported by periodic post-trade analysis. The best execution rules do not apply to UK QCATP operators conducting matched principal trading on their own platform. Firms must provide clients with appropriate information on their order execution policy and obtain the client’s prior consent to it, and must review the policy and their execution arrangements at least annually and upon any material change. 19. Duty of portfolio managers, receivers and transmitters - A firm providing portfolio management services must comply with the client’s best interests rule when transmitting orders to other persons for execution. This duty also applies to a firm that receives and transmits client orders for execution as part of arranging deals in qualifying cryptoassets. 20. Pre-trade disclosure requirements for principal dealers - Before executing a client’s order, a firm dealing as principal must disclose: (i) a firm price at which the order can be executed; (ii) the duration for which that price is available; and (iii) any fees or charges for execution. Requirements (i) and (ii) do not apply to matched principal trading conducted on a UK QCATP’s own non-discretionary rules. 21. Client order handling - Firms must implement procedures and arrangements for the prompt, fair and expeditious execution of client orders relative to other orders or the firm’s own trading interests, including sequential treatment of comparable orders save where impracticable or contrary to the client’s interest. Firms must also ensure that orders executed on behalf of clients are promptly and accurately recorded and allocated, and must inform a retail client promptly of any material difficulty relevant to the proper carrying out of their order. 22. Dealing or arranging deals with UK retail clients - Intermediaries serving UK consumers must only execute transactions on UK authorised execution venues. Intermediaries may also only serve retail clients in relation to cryptoassets which have already been admitted to trading on at least one CATP and comply with the relevant disclosure and document requirements, subject to an exemption for UK issued qualifying stablecoins. Placing client orders on venues outside of the UK is not permitted. When a firm executes orders for retail or elective professional clients as a principal, it must not systematically or predominantly source liquidity from a QCATP where the operator of that QCATP is in the same group as the firm and is not authorised as a UK QCATP operator. 23. Conflicts of interest – Intermediaries require a functional separation, including separate governance structures between proprietary trading and client order execution, as a minimum. The personal account dealing rules for traditional finance firms applies to all cryptoasset intermediaries. 24. Payment for order flow (PFOF) - The FCA expects that cryptoasset intermediaries engaging in PFOF are unlikely to meet requirements on best execution, conflicts of interest and restrictions on inducements when serving retail or professional clients. 25. Transparency requirements - Pre-trade transparency does not apply to intermediaries dealing as principal, with principal dealers now out of scope of pre-trade transparency. Post-trade transparency obligations do apply to principal dealers, requiring publication within 1 minute of execution, as well as the same record keeping requirements and the same requirement to report to immediate clients on order execution. 26. Record keeping and client reporting - Intermediaries must generally retain records of their clients’ transactions for 5 years (rather than up to 7 years), save that the FCA may request retention for up to 7 years. Firms must identify cryptoassets by Digital Token Identifier (DTI) in order/transaction records and client reporting, and transaction hashes and associated addresses (such as wallet and smart contract addresses) and network fees must be recorded where applicable. Where an asset does not have a DTI, reporting can include an alternative unique and unambiguous identification code for each qualifying cryptoasset involved in an order/transaction. Client reporting must be provided promptly and at least by the end of the day of execution, cancellation or data receipt (or the next working day, if this occurs after the end of the working day). Clients must be able to access a 3-year transaction history on request, and a settlement method indicator has been added to the required content of client reports. The FCA has confirmed that it will not systematically receive or assess Suspicious Transaction and Order Reports or other individual cryptoasset transaction records. 27. Settlement - Where an intermediary arranges or oversees settlement, it must clearly inform the client of the settlement process and associated risks. The FCA expects final settlement to be initiated within 24 hours of execution. Cryptoasset lending and borrowing (“L&B”) activities L&B activities will not be new regulated activities, but may fall within the regulated dealing or arranging activities. 28. Lending and borrowing - 'Qualifying cryptoasset lending' is defined as the disposal of a qualifying cryptoasset from person A to or via person B, subject to an obligation or right to reacquire the same or equivalent qualifying cryptoasset, typically with yield paid to A. In most instances, these transactions will amount to deals, not loans, because disposal and acquisition for valuable consideration constitutes dealing. The guidance clarifies that where L&B involves dealing, it is very unlikely to constitute consumer credit lending (which is about the provision of credit, not dealing). Arrangements described as L&B that involve forms of margin trading may engage other regulated activities, such as derivatives. 29. Retail access to L&B - Retail clients will be permitted to access L&B services relating to qualifying cryptoassets or stablecoins, subject to new consumer understanding, express prior consent, and operational risk requirements. 30. Consumer understanding - An extensive list of specified information must be provided to retail clients each time they engage with L&B services and before they are bound by any L&B related agreements or services begin. Firms may use a single set of systems to discharge the requirements set out in CRYPTO 9 and COBS. 31. Operational risks - Firms must not use their own proprietary tokens in connection with L&B services provided to retail clients (this prohibition does not apply to L&B services provided to non-retail clients). Cryptoasset L&B firms must also conduct appropriateness assessments, comply with prudential requirements, and will be subject to additional record keeping requirements. 32. Cryptoasset borrowing - The FCA will not apply the Consumer Credit Sourcebook to cryptoasset borrowing for retail clients. Firms must obtain the retail client’s express prior consent before supplementing the collateral on the retail client’s behalf, and the amount a firm may supplement is capped at 50% of the market value of the initial collateral (clients may top up their collateral themselves above this cap). Borrowing arrangements are subject to mandatory over-collateralisation, so the value of the collateral exceeds the amount borrowed (the FCA will, however, keep mandatory over-collateralisation under review as part of its evaluation of the regulatory regime). Firms must model loan limits and levels (loan-to-value ratio, margin call level and liquidation level) such that a margin call or liquidation is not expected within the first 6 months. Negative balance protection ensures retail clients cannot lose more than the collateral specifically dedicated to the borrowing arrangement. Borrowing collateral must be safeguarded on trust, and title cannot transfer to the firm except to discharge the client’s indebtedness with the client’s consent; Title Transfer Collateral Arrangements (TTCA) are prohibited for retail clients (though permitted for non-retail clients). 33. Deferral arrangements - The FCA published CP26/32 in September 2026, confirming the proposed deferral arrangements for intermediaries. The execution venue requirement for UK-authorised dealers and arrangers serving retail and elective professional clients is deferred for 3 months from go-live, recognising that intermediaries may not know which execution venues will have obtained authorisation at commencement. During the deferral, firms must have adequate systems and controls to ensure client orders are not executed on unauthorised venues. The execution policy requirements under CRYPTO 5.4 are also deferred for 3 months. From commencement, firms must nevertheless provide clients with at least a high-level execution policy compliant in principle with CRYPTO 5.4. Client consent to the finalised execution policy must then be obtained within the three-month deferral period. In addition, intermediaries may deal or arrange deals in qualifying cryptoassets for retail clients during a 6-month A&D deferral, to 25 April 2028, even where no QCDD is available, subject to prescribed disclosure and risk-warning obligations. See the Transitional Arrangements section under the Market abuse regime for cryptoassets (“MARC”) and admissions & disclosures (“A&D”) rules tab for an overview of the deferral arrangements. Staking proposals 34. Staking – PERG 18 explains the scope of the arranging qualifying cryptoasset staking activity. A technical services exclusion applies where a person provides a purely technical service (such as operating a validator node) and does not hold itself out as offering staking to the public. If the service goes beyond purely technical means, by offering some ‘added value’, the exclusion will not apply. A validator node operator that merely provides the technical means through which users may participate in staking services offered by third parties may be able to rely on the exclusion. 35. Consumer understanding - Firms must provide customers with information on the risks of staking, and notify them in good time of any material changes. Firms must obtain a retail client’s consent to stake current and future holdings, but blanket consent to stake any cryptoassets is not permitted. Firms will not be required to provide information and obtain consent prior to each, separate instance of staking retail clients’ cryptoassets. For auto-staking, the terms must state that the firm may stake future holdings and explain how the service can be cancelled. Firms must notify retail clients at least every 12 months of the staking service used (including the amount staked, rewards earned, fees and commission charged, and the most recent terms), although earlier notification may be appropriate in some circumstances, such as client inactivity. 36. Technological, cyber, and third party risk - Operational resilience rules and prudential requirements apply to staking firms, as explained further in CP25/25 and CP25/42, and as set out in the FCA’s finalised guidance on cryptoasset operational resilience (FG26/6). The FCA do not require automatic compensation for retail losses arising from preventable operational or technological failures. 37. Record keeping - Firms must keep records of staking services, including liquid staking token transfers, generally for 5 years (or for the duration of the client relationship if longer, in certain cases), limited to clients whose identity is known to the firm. Firms must also record the type and amount of cryptoassets provided to clients as part of a staking service. Decentralised Finance ("DeFi") DeFi activities are not covered by the incoming UK cryptoasset regulatory regime where they are truly decentralised. The FCA will apply its rules and guidance to firms engaging in DeFi where there is a clear controlling person carrying on a regulated cryptoasset activity, assessed on a case-by-case basis. Separate DeFi guidance, covering indicators of decentralisation and how to mitigate operational resilience and financial crime risks, is expected to follow later in 2026. Exclusions The guidance explains the general exclusions in the Cryptoasset Regulations that are relevant for all the regulated cryptoasset activities, including for activities carried on for the sale of goods or supply of services (Article 9Z10) and activities incidental to a regulated profession or business (Article 9Z11). Article 9Z10 has two limbs: a 'supplier to customer' limb (which does not apply to safeguarding SICs) and a narrower 'related sale or supply' limb (applying only to dealing and arranging deals). This may apply to firms providing information, analytics, data or dashboard services, provided their main business is to sell goods or supply services to their customers. Existing general exclusions for UCITS/AIF managers and insolvency practitioners apply. Tailored exclusions are not subject to the MiFID overlay in article 4(4) of the RAO. The Financial Services and Markets Act 2000 (Cryptoassets) (Miscellaneous Amendments) Regulations 2026 introduce further exclusions (including for technical services, proprietary trading, market making, UK qualifying stablecoin transactions (TTCA and repo), and CSD activities) on which the FCA plans to consult. |
| Document | Summary of proposed rules (and status) |
Stablecoin issuance and cryptoasset custody Documents: PS26/10, PS26/11, CP25/14 (28 May 2025). PS26/10 finalises the FCA’s rules on stablecoin issuance, following consultation under CP25/14. Related safeguarding and other issues consulted on in CP25/25 and CP26/4 have been finalised separately in PS26/11 (see below). | Policy Statement PS26/10 Crypto Regime: Stablecoin Issuance (June 2026), Policy Statement PS26/11 Crypto Regime: Regulated Cryptoasset Activities (June 2026) and Policy Statement PS26/18 Crypto Regime: Cryptoasset Perimeter Guidance (September 2026). PS26/10 finalises the rules on the issuance of UK-issued qualifying stablecoins, covering backing assets, segregation and the statutory trust, third-party safeguarding of backing assets, record-keeping and reconciliations, redemption, the use of third parties and disclosures, largely maintaining the framework consulted on in CP25/14 while making targeted refinements to improve clarity, operability and proportionality. PS26/11 finalises the rules on cryptoasset safeguarding, including appointment of third parties in cryptoasset custody, private key management and security, reconciliations, addressing shortfalls and excesses, and record-keeping. The Cryptoassets Regulations define a “qualifying stablecoin” as a “qualifying cryptoasset” referencing one or more fiat currencies that seeks or purports to maintain a stable value (by the issuer holding fiat currency or fiat currency and other assets). PERG 18 clarifies that products using hybrid stabilisation mechanisms (e.g. part backing assets and part algorithmic) are not qualifying stablecoins. Wrapped tokens relating to stablecoins are not in themselves automatically qualifying stablecoins. The issuing activity has three limbs and excludes the person from the dealing and arranging activities only where all three limbs are undertaken by (or arranged on behalf of) the person who created the qualifying stablecoin. The FCA intends to consult on guidance on the distinction between e-money and qualifying stablecoins. On top of needing to seek authorisation and comply with the conduct of business standards applicable to authorised financial services firms, qualifying stablecoin issuers will be required to:
|
PS26/11 finalises the rules on cryptoasset safeguarding, including appointment of third parties in cryptoasset custody, private key management and security, reconciliations, addressing shortfalls and excesses, and record-keeping. It includes the rules for a new CASS 17. This introduces new rules that apply to cryptoasset custodians in relation to qualifying cryptoassets (“QCAs”).CASS 17 will apply to all firms that control cryptoassets through any means that would enable them to bring about a transfer of the benefit of the cryptoassets to another person, including where the person holds private keys or operates multi-signature or sharded key arrangements, whether they themselves hold them or not. PERG 18 distinguishes operational control from beneficial ownership: title transfer collateral arrangements and repurchase agreements (where full legal and beneficial ownership is transferred to the firm) are excluded from the safeguarding perimeter for non-consumers. There is no express exclusion for technology providers. The FCA is still intending to consult on further guidance on the temporary settlement exclusion. CASS 17 will not apply to qualifying cryptoassets that are transferred to the firm under a cryptoasset lending arrangement. CASS 17 does not extend to the custody of specified investment cryptoassets (including relevant specified investment cryptoassets, “RSICs”); firms safeguarding RSICs will instead need to apply CASS 6 requirements (obtained via a variation of permission, including Article 9N), pending further FCA engagement on tailored RSIC safeguarding rules. CASS 6 will also apply to small AIFMs’ safeguarding of RSICs where they carry on Article 9N activity, despite the exclusion in Article 72AA of the RAO, just as it does currently in relation to their ‘excluded custody activities’. The FCA and PRA are currently consulting on how CASS rules should apply to RSIC custody in the longer term (Call for Input: The future of tokenisation - A joint vision from the authorities for UK wholesale financial markets). Self-custody models are not subject to CASS rules provided the firm genuinely has no means to bring about the transfer of the benefit of the cryptoasset. Under CASS 17, qualifying cryptoasset custodians will be required to:
In comparison, CASS 8 applies to mandate arrangements where a firm has authority to instruct or direct a client’s assets without itself having control. CASS 17 applies to any cryptoasset firm that has control of cryptoassets within the meaning of Article 9N, subject to limited exceptions. The FCA has provided the diagram shown below at “Diagram 1” to illustrate how CASS 17 applies in different scenarios to firms with different levels of control. UK QCATPs are permitted to hold up to 2% of each client’s cryptoassets, calculated per client and per cryptoasset class, outside the trust in a global settlement wallet for settlement purposes (the settlement float limit). This is subject to the client’s informed consent (which may be withdrawn). Firms may operate separate trusts through separate virtual addresses or combine client cryptoassets at different virtual addresses into the same trust, but firms cannot allocate the same single virtual address to different trusts, as this does not meet the FCA’s co-mingling requirement. Third parties must also meet the same requirements if appointed for safeguarding purposes. Firms appointing third parties for safeguarding will also need to consider the jurisdiction as part of their due diligence. Firms are permitted to use DLT as an external source of information to confirm the per-trust/class cryptoasset resource (i.e. the amount and class of cryptoasset being safeguarded on trust for clients) where a third party is not appointed for safeguarding, but the same source of information cannot be used to calculate the per-trust/client/class cryptoasset requirement. Firms must investigate discrepancies, remove all excesses, top up any shortfalls and notify the FCA in writing if a shortfall has not been topped up by the next reconciliation. Firms must immediately notify clients affected by shortfalls. These new rules largely mirror the existing custody rules in CASS 6 (which relate to “traditional” safe custody assets). A firm safeguarding client cryptoassets would need client agreement in order to return an equivalent asset to their client via a different blockchain than the one on which the safeguarding arrangement began. |
| Documents | Summary of proposed rules (and status) |
| Documents: PS26/12 (June 2026), CP25/42 (16 December 2025); CP25/15 (28 May 2025) | Policy Statement PS26/12 Crypto Regime: A Prudential Regime for Cryptoasset Firms (June 2026). This PS follows CP25/15 and CP25/42. PS26/12 finalises the prudential framework for regulated cryptoasset firms, covering capital, liquidity, risk management and public disclosure requirements. The FCA has largely maintained the proposed framework while making targeted recalibrations and clarifications to improve proportionality and usability. The framework introduces an integrated prudential sourcebook that brings together core prudential requirements ("COREPRU"), along with a sourcebook setting out sector specific requirements for firms doing regulated cryptoasset activities ("CRYPTOPRU"). Both COREPRU and CRYPTOPRU will apply to CRYPTOPRU firms. The COREPRU includes rules on: overall financial adequacy; definition of own funds; own funds requirement (overall calculation); fixed overhead requirement; concentration risk monitoring; and basic liquid asset requirement. The CRYPTOPRU includes rules on: permanent minimum requirement; K-factor requirement (including operational and exposure-based K-factors); issuer liquid asset requirement; overall risk assessment; and sectoral prudential disclosure requirements. The final rules include the following key elements:
|
| Document | Summary of proposed rules (and status) |
Application of FCA Handbook for Regulated Cryptoasset Activities II Documents: PS26/13 (June 2026), PS26/11, CP26/4, CP25/25 | Policy Statement PS26/13 Crypto Regime: Application of FCA Handbook for Regulated Cryptoasset Activities (June 2026). This PS follows CP25/25 and CP26/4. PS26/13 finalises the rules and guidance on how key cross-cutting FCA Handbook obligations will apply to regulated cryptoasset activities, including standards on conduct, governance, resilience, redress, and reporting. The FCA has largely maintained the proposed framework while making targeted refinements to improve clarity and proportionality. PS26/11 finalises the rules in relation to cryptoasset trading platforms, lending and borrowing and safeguarding, as consulted on in CP26/4.
|
Our industry work
Our FS Reg team is proud to support CryptoUK, having helped shape its responses to every FCA Discussion Paper and Consultation Paper on the new cryptoasset regime. Sam Robinson and Yasmin Johal also co-chair CryptoUK’ s regulatory working group, keeping us right at the heart of policy development in this fast-evolving space.
We are equally proud to support the Digital Pound Foundation, having assisted with its submissions in response to a range of FCA Discussion Papers and Consultation Papers on the new cryptoasset regime.
Best Digital Assets Law Firm
CMS UK has been named the Best Digital Assets Law Firm at The Digital Commonwealth Awards. The Digital Commonwealth Awards is an extraordinary celebration of innovation and excellence in the realms of digital assets, ScienceTech, and Web3.