Summary
The principal rules are final and published, not yet operative. The protected application period ends on 28 February 2027, but applications remain legally possible afterward.
The FCA Board made eleven Handbook instruments on 25 June 2026. The FCA published PS26/9 through PS26/13 on 30 June 2026. Each instrument commences on 25 October 2027. Current FCA crypto oversight remains principally financial promotions and anti-money laundering supervision. (FCA 2026/35–45, commencement provisions; FCA press release, 30 June 2026.)
The relevant application period starts at 9:00 a.m. on 30 September 2026. It ends at 11:59 p.m. on 28 February 2027. The direction states no time zone. The FCA may extend the period through a replacement or amended direction. (FCA, Relevant Application Period Direction, paras. 2–3.)
Regulation 52(5) expressly permits applications outside that period. A timely unresolved application can receive the broader saving provision. A later pre-commencement application can receive only restricted run-off treatment if unresolved, refused, or withdrawn. (SI 2026/102, regs. 52–56.)
Existing FCA status does not remove the filing task. Money Laundering Regulations registration does not convert automatically. Existing FSMA-authorised firms must seek a variation of permission for newly regulated activities. (FCA, “Cryptoassets: How the gateway will operate,” updated 8 July 2026.)
The FCA will reject a PASS meeting request without “meaningful supporting information.” Firms must provide the business model, products, services, and customer types. Supporting material should include regulated-activity analysis. A promise to supply that material later is insufficient. (FCA, “Cryptoassets: How the gateway will operate,” “Requesting a pre-application meeting.”)
Application preparation can start from the final instruments and the FCA’s 8 July application preview. Firms can map permissions, test Threshold Conditions, assign board owners, draft evidence, and close control gaps now.
Monitoring still matters. The final application form, perimeter guidance, proposed statutory amendments, and several supplementary FCA workstreams remain outstanding as at 31 July 2026.
What is final now
The principal statutory design and FCA rule text are settled enough for implementation work. The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 were made on 4 February 2026. Regulation 1(3) activated preparatory powers before full commencement. Those powers cover FCA rules, guidance, directions, applications, and application decisions.
The substantive start date is different. Regulation 1(2) fixes 25 October 2027 as the “full commencement day.” The FCA’s eleven instruments use that same commencement date. The instruments are FCA 2026/35 through FCA 2026/45. The FCA Board made them on 25 June 2026 and published the policy package five days later. (SI 2026/102, reg. 1(2)–(3); FCA 2026/35–45, commencement provisions.)
The phrase “final rules are live” therefore overstates present legal effect. A safer statement is that the principal final rules have been made and published. Their text supports implementation and application preparation now. Their substantive duties generally bind from 25 October 2027.
The FCA confirms this distinction in its 30 June announcement. It states that current oversight remains limited to financial promotions and anti-money laundering controls until the new rules take effect. Existing duties in those areas continue during the preparation period. (FCA press release, 30 June 2026.)
Who needs to prepare
Regulation 40 inserts new activities into the Regulated Activities Order. They cover UK stablecoin issuance, cryptoasset safeguarding, arranging safeguarding, trading platforms, principal dealing, agent dealing, arranging deals, and staking arrangements. (SI 2026/102, reg. 40; RAO arts. 9M, 9N, 9S, 9T, 9W, 9Y and 9Z6.)
The same instrument creates admissions, disclosure, and market-abuse duties. Detailed exclusions remain important. A product label or existing FCA registration cannot answer the perimeter question by itself. (SI 2026/102, regs. 3–39.)
Each group should map legal entities, activities, locations, customers, assets, and contractual roles. Overseas firms need a direct-to-UK analysis. Stablecoin issuance has a separate UK-establishment case. Regulation 41(6) adds consumer-service cases to FSMA section 418(6B)–(6F). Direct platform, dealing, arranging, safeguarding, or staking activity involving UK consumers can count as UK activity. The exact test depends on the activity and any authorised intermediary. (SI 2026/102, regs. 40, 41(6); FSMA 2000, s. 418(6B)–(6F), as prospectively amended.)
An MLR-registered firm needs a new Part 4A permission if its activities fall within scope. An existing FSMA-authorised firm needs a variation of permission. Payment Services Regulations or Electronic Money Regulations status does not create automatic conversion. (FCA, “Cryptoassets: How the gateway will operate,” updated 8 July 2026.)
The protected application period
The FCA direction fixes the relevant application period. It starts at 9:00 a.m. on 30 September 2026. It ends at 11:59 p.m. on 28 February 2027. The direction does not identify a time zone. (FCA, Relevant Application Period Direction, para. 2.)
That period is a statutory-benefit window, not a permanent application bar. Regulation 52(5) says the direction does not prevent later applications. The FCA may extend the period, but no extension had been made by 31 July 2026. (SI 2026/102, reg. 52(3), (5).)
- Application filed during the relevant period and still pending: Regulation 53 treats Parts 3 to 6 as not in force for the relevant activity. FCA guidance says an existing provider may continue operations and new business while the FCA decides. A newly established firm cannot start until authorised. The saving lasts no more than two years after full commencement.
- Timely application refused but still open to review: Regulation 53 can continue to apply. The FCA may direct the firm into restricted transition under regulation 55(3).
- Timely application finally refused or withdrawn: Regulations 55 and 56 permit only activity needed to perform pre-existing contracts.
- Application filed after 28 February 2027 but before full commencement, then unresolved, refused, or withdrawn: Regulations 55 and 56 permit only activity needed to perform pre-existing contracts. The firm cannot enter new contracts with existing or new UK customers.
- No application before full commencement: No saving or transitional protection applies. The firm must stop or run off affected UK activity before 25 October 2027.
Regulation 53 does not disapply Part 2. Any applicable admissions, disclosure, and market-abuse duties therefore need separate treatment.
The saving and transition chapters expire at the end of 24 October 2029. They can end earlier in specified cases. The FCA can restrict or cancel a transitional exemption on statutory grounds. (SI 2026/102, regs. 53(3), 55(9), 59.)
Timely filing therefore has a commercial consequence. It can preserve ordinary operations while an unresolved application proceeds. Late filing can preserve only contract run-off. Without permission or an exemption, an unauthorised firm faces section 19. An already-authorised firm acting outside its permission faces section 20.
For an unauthorised person, contravention of section 19 is an offence, subject to a due-diligence defence. Affected agreements can also become unenforceable, with recovery and compensation consequences. (FSMA 2000, ss. 23, 26–28.) An authorised firm acting outside its permission instead contravenes section 20. That breach is not ordinarily the section 23 offence, apart from designated credit-related activity. (FSMA 2000, ss. 20, 23(1A)–(1E).)
The FCA expects to decide timely applications before commencement. It also plans to review applications in submission order. It will not accelerate a late application to offset delay. Early filing reduces the risk of an unresolved decision at commencement. (FCA, “New regime for cryptoassets regulation – Authorisations introductory webinar January 2026 – Responses to questions from firms,” February 2026, p. 5; FCA, “Cryptoassets: How the gateway will operate,” updated 8 July 2026.)
What a gateway-ready dossier requires
The FCA’s 8 July preview contains all planned crypto-specific sections. The online form remains under final development. Question wording and explanations may change. The preview still identifies the evidence firms can prepare now. (FCA, “Information about the authorisation application form for cryptoasset firms,” 8 July 2026, p. 1.)
A working application file should contain:
- A perimeter and permission map. It should link each legal entity and service to a specific RAO article, exclusion, customer type, and requested permission.
- The application route. It should identify a new Part 4A application or variation of permission, proposed limitations, client types, and any connected applications.
- Ownership and leadership evidence. This includes controllers, close links, group charts, senior-manager applications, responsibilities, competence, and fitness information.
- A regulatory business plan. It should explain the revenue model, customer journey, delivery chain, outsourcing, financial forecasts, staffing, systems, and wind-down assumptions.
- Threshold Conditions evidence. The firm should address effective supervision, appropriate resources, suitability, office location, and business-model viability. (FSMA 2000, s. 55B and Sch. 6.)
- Core control evidence. This includes financial-crime controls, compliance monitoring, complaints, Consumer Duty work, records, IT controls, incident response, and service continuity.
- Prudential evidence. The firm should map COREPRU or CRYPTOPRU requirements, capital, liquid assets, financial forecasts, and the overall risk assessment.
- Activity-specific evidence. Stablecoin issuers need redemption, backing-asset, disclosure, and trust arrangements. Custodians need trust, reconciliation, records, key-control, and third-party oversight evidence. Platforms need admissions, market-abuse, transparency, algorithmic-trading, conflict, and own-account controls. Intermediaries need execution, order-handling, conflict, and personal-dealing controls. Staking and lending services need customer, collateral, disclosure, and consent controls.
- Board evidence. The board should approve the scope, gap analysis, owners, budget, dependencies, test plan, and filing date.
The FCA warns that poor applications can face rejection, delay, or refusal. Existing firms may also lose the ability to continue affected activity. (FCA, “What you need to do when preparing for the new cryptoasset regulatory regime,” 30 April 2026.)
FSMA section 55V sets different decision periods. A complete application must be decided within six months. An incomplete application must be decided within 12 months after receipt. Completeness therefore affects both timing and the FCA’s ability to assess the Threshold Conditions.
The practical inference is that promised future policies will not carry the same weight as approved and tested arrangements. Firms should retain evidence of design, approval, operation, testing, and remediation. This inference follows from the application preview and the FCA’s demand for meaningful pre-application material.
What a PASS request must contain
PASS is optional and free. A meeting lets a firm explain its model and discuss the authorisation process. The FCA does not give legal advice, and a meeting does not predict approval.
The request must describe the proposed business model, products, services, and customer types. Supporting information should also analyse the regulated activities sought. The FCA may request legal advice supporting that analysis.
The rejection warning is precise. The FCA will reject requests that lack “meaningful supporting information.” A commitment to provide information after booking does not meet that standard. (FCA, “Cryptoassets: How the gateway will operate,” updated 8 July 2026.)
PASS should follow internal perimeter work. A useful request should attach a concise entity-and-activity map, draft permissions, business flow, target customers, and defined questions. It should identify the rules or application points on which FCA process feedback is sought.
What still requires monitoring
The remaining work does not justify delay. It does qualify any claim that future watching has ended.
The online application form was still being finalised on 8 July 2026. The FCA plans a perimeter policy statement in September 2026. HM Treasury also published draft amendments on 21 April 2026. Those amendments could change specified stablecoin-payment and other perimeter outcomes. (FCA press release, 30 June 2026; HM Treasury, Draft Cryptoassets Amendment Regulations 2026, 21 April 2026.)
The FCA has announced more work on DeFi, DLT service continuity, financial-crime guidance, and systemic stablecoins. PS26/9 also records planned consultation on temporary admissions treatment for cryptoassets already in circulation. (FCA press release, 30 June 2026; PS26/9, para. 1.7.)
Regulation 54 expressly imposes saving-provision notification only on a same-group overseas person using regulation 53. The FCA says it will confirm notification mechanics later. The made regulation 59 also contains two apparent internal cross-reference errors. HM Treasury’s April draft would repair them, but it was not binding as at 31 July 2026. (SI 2026/102, regs. 54, 59; Draft Cryptoassets Amendment Regulations 2026, reg. 2(4), 21 April 2026.)
Firms should run two workstreams. One should build the application against the made rules and current preview. The other should track defined open items and update the perimeter map when official text changes.
