Summary
- The enacted legislation provides the present basis for permission planning. The FCA's final PERG 18 guidance explains that legislation but cannot change it. The September draft proposes additional exclusions and revised commencement provisions. Those proposals cannot establish a present exemption. (SI 2026/102; PS26/18, paras. 1.6–1.8 and 1.14–1.16; September draft, regs. 1–4.)
- Permission depends on functions performed by each legal person. Issuance, custody, trading, dealing, arranging and staking require separate tests. Lending can engage several existing activity descriptions without a distinct lending permission. A service description or group authorisation cannot replace those tests. (SI 2026/102, reg. 40(5); PERG 18.1.12, 18.9 and 18.10.)
- Custody extends beyond possession of a private key. Control over transfers, customer return rights and arrangements with another custodian require examination. Narrow exclusions protect particular activities, not every service provided by a technical supplier or affiliated company. (Regulated Activities Order 2001, arts. 9N–9R, as inserted by SI 2026/102.)
- Overseas firms can fall within the regime through dealings with UK consumers. Statutory intermediary exceptions depend on the intermediary's precise permission and role. Professional-client classification under the Handbook does not itself remove an individual from the territorial consumer test. (SI 2026/102, reg. 41(6); PERG 18.1.13.)
- [UK] The protected application period runs from 30 September 2026 to 28 February 2027. A qualifying application made during that period can preserve business while the decision remains unresolved. Existing money-laundering registration does not convert into the required permission. (FCA direction under reg. 52, 20 February 2026, para. 2; SI 2026/102, reg. 53; PS26/18, para. 1.25.)
- Late applications and final refusals can lead to contractual run-off rather than ordinary continuation. The exemption covers only activity necessary to perform qualifying pre-existing contracts. Its outer limit runs from commencement, not from the firm's eventual refusal or entry into run-off. (SI 2026/102, regs. 55–56.)
- Public offers, admissions and market abuse require a separate analysis. The application savings provision disapplies specified authorisation-related changes, not Part 2 of the legislation. A pending permission application therefore does not establish exemption from those separate duties. (SI 2026/102, Parts 2 and 7, reg. 53(2).)
- The FCA has already published the principal operating rules for the new regime. Firms must prepare for the applicable capital, client-asset, conduct and complaints requirements. Authorisation does not extend Financial Services Compensation Scheme protection to the new cryptoasset activities. (FCA, PS26/9–PS26/13, 30 June 2026; PS26/13, ch. 12.)
Status of the enacted regime and September amendments
The enacted commencement date is 25 October 2027. The Treasury made SI 2026/102 on 4 February 2026, with earlier commencement for preparatory functions. The Financial Conduct Authority published PS26/18 on 16 September 2026. Its instrument distinguishes immediately effective guidance from changes commencing with the substantive regime. Publication of guidance therefore creates no general permission to conduct activities before authorisation becomes necessary. (SI 2026/102, reg. 1; Perimeter Guidance (Regulated Cryptoasset Activities) Instrument 2026, FCA 2026/55, cls. A–C.)
PERG 18 states the FCA's interpretation and does not bind the courts. The governing provisions are in the Financial Services and Markets Act 2000 (FSMA) and the relevant statutory instruments. References below to the Regulated Activities Order 2001 (RAO) concern the provisions inserted or amended by SI 2026/102. Published Handbook rules marked R have a different legal status from explanatory guidance. A favourable reading of PERG cannot create an exclusion absent from the legislation. (PERG 18.1.3; PS26/18, paras. 1.14–1.16.)
The Treasury laid the draft Financial Services and Markets Act 2000 (Cryptoassets) (Miscellaneous Amendments) Regulations 2026 on 15 September 2026 (the September draft). Parliament lists the instrument under the draft affirmative procedure, requiring approval by both Houses before it can be made. PS26/18 expressly excludes that instrument and identifies dealing, arranging and UK qualifying stablecoins as affected areas. The proposed amendments below must therefore be distinguished from the enacted provisions. (September draft, preamble; UK Parliament, Statutory Instruments register, entry laid 15 September 2026; PS26/18, paras. 1.6–1.8.)
The September draft would generally commence the day after being made, but its direct RAO and financial-promotion amendments would commence on 25 October 2027. Its amendments to the uncommenced provisions of SI 2026/102 would not start the substantive cryptoasset regime early. It would separately bring forward regulations 43, 46 and 47, concerning collective investment schemes, electronic money and alternative investment funds. Those provisions would commence 21 days after the day the amending instrument commences under its regulation 1(2). No calendar date for that earlier commencement follows without a made date. (September draft, regs. 1(2)–(3) and 4(2); SI 2026/102, reg. 1.)
Asset classification and permission mapping
Each activity requires an asset-specific assessment before a firm selects permissions. Article 88F requires a qualifying cryptoasset to be fungible, transferable and more than solely a record of value or contractual rights. Its exclusions address other specified investments, electronic money, currency and certain issuer-only or limited-network assets. A contractual transfer restriction does not itself answer every element. A token outside article 88F can still engage existing securities or other financial-services regulation. (RAO, arts. 3 and 88F; PERG 18.4.)
The September draft would define a UK qualifying stablecoin by issuance within article 9M and the issuer's corresponding Part 4A permission. Sterling denomination alone would not satisfy that test. Under the revised specified investment cryptoasset definition, the asset must be a Part 3 specified investment outside article 88F and related article 89 rights. It must also satisfy article 88F with paragraph (4) disregarded. The separate exclusion of electronic money in article 88F(4)(b) would remain. (September draft, reg. 4(5)(a)(ii)–(iii) and (c); RAO, art. 88F(4)(b).)
Article 88G applies a further test to qualifying stablecoins. The asset must seek a stable value by reference to a particular fiat currency through the specified backing arrangements. A gold target or currency basket does not become a qualifying stablecoin merely because prices are displayed in sterling. The FCA regards hybrid arrangements that combine algorithmic stabilisation with asset backing as outside that stablecoin definition. Such an asset can still be a qualifying cryptoasset. A wrapped token also requires its own assessment of rights and stabilisation arrangements. (RAO, art. 88G; PERG 18.4.5.)
The stablecoin exclusions from collective investment scheme and alternative investment fund treatment have cumulative conditions. The issuer must not pay, or arrange payment of, backing-asset interest, yield or benefits to holders. Under normal conditions, holders must have the specified right to redeem at the issue value in the referenced currency, excluding redemption fees. The electronic-money amendments have their own stablecoin definition and preserve the status of electronic money held as backing. Accelerated commencement would not remove those substantive conditions. (SI 2026/102, regs. 43, 46 and 47; September draft, reg. 4(2).)
Authorisation requires the relevant activity, business character and UK connection, subject to exclusions and exemptions. The cryptoasset business test asks whether the person carries on the business of engaging in the activity. Occasional personal trading does not establish that test by itself. Conversely, decentralised execution does not dispose of the question where an identifiable person performs the relevant commercial function. Contracts, control rights and transaction flows determine the result; a product name cannot establish it. (SI 2026/102, reg. 44; PERG 18.1.7, 18.1.10–18.1.12 and 18.2.)
An integrated service can require several permissions across different entities. A trading venue that controls customer assets and operates a separate lending service needs each function assessed. Exclusions for an activity already constituting issuance, platform operation or staking prevent specified overlaps. They do not exempt the firm's unrelated business. Existing permissions for traditional investments also require review where custody moves into the new activity. (RAO, arts. 9N, 9V(2), 9X(2), 9Z5(2) and 40, as amended; PERG 18.6.)
Permission planning also needs to address agreements to carry on activities where article 64 applies. The FCA's amended guidance excludes issuing qualifying stablecoins and operating qualifying cryptoasset trading platforms from that agreeing activity. Other new activities require the corresponding assessment. Advice and discretionary management also need examination under existing investment categories and any dealing or arranging functions actually performed. (PERG 2.7.21G and PERG 2 Annex 2, Table 1, note 1, as amended by FCA 2026/55; PERG 18.8.9–18.8.10.)
Article 9Z10 excludes certain cryptoasset activities undertaken for a supplier's sale of goods or supply of services. The supplier definition covers a person whose main business is selling goods or supplying services and members of its group. The exclusion does not cover safeguarding relevant specified investment cryptoassets. Its related-sale limb applies only to principal dealing, agency dealing and arranging. A regulated cryptoasset activity does not count as a supply of services for this exclusion. The FCA does not treat qualifying cryptoassets as goods for this purpose. (RAO, art. 9Z10; PERG 18.11.4–18.11.5.)
Stablecoin issuance and outsourcing
Qualifying stablecoin issuance requires the cumulative conditions in article 9M. The person must offer, or arrange an offer, from a UK establishment, including a previous offer. The asset must have been created by or for that person or its group. From a UK establishment, that person must undertake or arrange redemption and hold or arrange the backing assets. A firm that only writes code or mints tokens does not satisfy the offer element merely by doing so. (RAO, art. 9M(2)–(3).)
Assumption of a redemption undertaking can change the identity of the regulated issuer. Article 9M treats acceptance of a purchase invitation as offering and addresses assumption of a redemption undertaking. It also allocates issuer status where one person arranges for another to perform all the issuance functions. Outsourcing therefore requires examination of who undertakes the obligation, rather than who performs the operational task. The statutory allocation does not remove a contractor's separate custody or dealing activities. (RAO, art. 9M(4); PERG 18.5.)
The FCA's made rules retain the authorised issuer's responsibility when functions are delegated. CRYPTO 2.3.5R prevents delegation of responsibility for relevant regulatory obligations. CRYPTO 2.3.12R requires issuance proceeds to be received directly by the issuer rather than the third party. These rules affect contracts and cash flows even where the outsourced structure satisfies article 9M. An offshore coin's availability in the UK does not alone establish UK issuance, although its distributors and custodians require separate tests. The September draft's additional exclusions would require the particular asset, actor and transaction to satisfy their conditions. (CRYPTO 2.3.5R and 2.3.12R, in PS26/10; RAO, art. 9M; September draft, regs. 2 and 4(5)(b).)
Proposed article 9Z10A would exclude specified dealing and arranging involving transfers of UK qualifying stablecoins or exchanges for money and other permitted assets. It would not cover exchanges into other qualifying cryptoassets that are not UK qualifying stablecoins, or disposals subject to return rights. A separate collateral and repurchase route would cover all qualifying stablecoins, including overseas coins. It would be unavailable where the original holder is a consumer or an FCA-specified person or class member. Ordinary lending would not become excluded merely because the loan asset is a UK qualifying stablecoin. (September draft, reg. 4(5)(b)(x)–(xi), proposed RAO, art. 9Z10A(1)–(7); explanatory memorandum, paras. 5.2–5.3 and 6.11.)
Proposed articles 43A and 9QB would exclude particular backing-asset arrangements from the respective investment-custody activities. The person carrying on the arrangements must hold the issuance permission for the UK qualifying stablecoin concerned. These actor-specific exclusions would not automatically cover an outsourced custodian merely because it holds the issuer's reserves. (September draft, regs. 2(2) and 4(5)(b)(iv); explanatory memorandum, paras. 6.7 and 6.12.)
Systemic stablecoins require a further jurisdictional check. The FCA distinguishes its non-systemic issuer rules from joint regulation where Treasury recognition brings the Bank of England into the supervisory arrangements. FCA authorisation alone cannot establish all duties of a recognised systemic issuer. Any recognition order and applicable Bank requirements need separate examination; no issuer-specific recognition facts are supplied here. (PS26/10, paras. 2.1–2.8.)
Custody, control and contractual return rights
A custody assessment must identify who can transfer the benefit of the asset. Article 9N covers safeguarding qualifying cryptoassets and relevant specified investment cryptoassets for another person. It separately covers arranging for another person to safeguard them. The customer relationship can rest on ownership or a right to receive the asset back. Consequently, a provider cannot dismiss custody solely because the customer has transferred legal title. (RAO, art. 9N(1), (2) and (5).)
The statutory title-transfer collateral exclusion has a consumer limitation. A non-consumer transaction satisfying article 9N(2)(c) can fall outside safeguarding despite a contractual return obligation. Article 9N(2)(d) prevents that exclusion from applying to consumers and permits the FCA to specify further persons or classes. Applicable rules must therefore be checked before treating a non-consumer transaction as excluded. A loan or collateral agreement needs examination of the customer's capacity and return rights. Describing the arrangement as a repo or title transfer does not establish the exclusion. (RAO, art. 9N(2)(c)–(d).)
Private-key architecture supplies evidence of control but does not replace the statutory test. The FCA distinguishes a sub-threshold key share conferring only a veto from an ability to cause a transfer. Contractual or operational powers to obtain other shares, instruct signers or direct transfers can change the result. A supplier without transfer control can still arrange safeguarding. The analysis must therefore cover signing thresholds, recovery procedures and the service agreement together. (PERG 18.6.2; RAO, art. 9N.)
The exclusions require separate proof. Group safeguarding requires an authorised group custodian to assume responsibility on the prescribed terms. The custody-introduction exclusion requires introductions to an unconnected authorised cryptoasset custodian with a view to UK safeguarding, and no remuneration for the introducer from that custodian. Temporary settlement and instruction-only functions have their own conditions. The FCA's expectation that temporary settlement generally lasts no longer than 24 hours is guidance, not a statutory 24-hour safe harbour. Generic storage is excluded only on the terms of article 9R(2). Each additional power or service can defeat reliance on the relevant exclusion. (RAO, arts. 9O–9R; PERG 18.6.5–18.6.11.)
The September draft would replace article 9Q with an exclusion for temporary settlement safeguarding ancillary to dealing, arranging, platform operation or staking. Proposed article 9QA would separately exclude temporary holding of UK qualifying stablecoins connected with executing a payment transaction. Ongoing wallet custody would not qualify solely because customers sometimes use their balances for payments. Proposed article 9R(4) would cover specified investment cryptoasset arrangements operated by a recognised or third-country central securities depository. The depository must undertake to the person for whom the asset is safeguarded responsibility no less onerous than if it safeguarded the asset itself. (September draft, reg. 4(5)(b)(iii)–(v); explanatory memorandum, paras. 6.6–6.8.)
Trading, intermediation and technical services
A qualifying cryptoasset trading platform requires interaction between multiple third-party buying and selling interests within a system. That interaction must result in the specified exchange contract. A dealer transacting only as the customer's counterparty does not necessarily operate such a platform. A venue operator needs article 9S permission where the statutory system test is met, even if its branding describes an interface or matching service. Custody and separate principal dealing still require their own assessments. (RAO, arts. 3, 9S and 9T; PERG 18.7.)
Principal dealing, agency dealing and arranging have different elements. Article 9Y covers arrangements that bring about a transaction and arrangements made with a view to transactions. The absence of a causal contribution can exclude the first limb under article 9Z without resolving the second. A service that merely provides communications can qualify for article 9Z2, but added transactional functions require further examination. Receipt of commission alone does not necessarily defeat that communications exclusion. (RAO, arts. 9T, 9W, 9Y, 9Z and 9Z2; PERG 18.8.22.)
Own-account transactions are not automatically regulated principal dealing. Article 9U addresses absence of holding out, subject to its market-making, resale, underwriting and solicitation conditions. Article 9V contains further exclusions, including an intra-group exclusion for a person whose transactions as principal are exclusively with other members of the same group. Those conditions do not create a general exemption for every group company or treasury desk. A business that regularly quotes to customers requires a different assessment from an occasional purchaser. Proposed article 9UA would add alternative principal-dealing exclusions: activity not undertaken to provide another person a service, or market-making on a qualifying cryptoasset trading platform. The market-making limb is not conditional on satisfying the separate no-service limb. Neither limb would exclude a distinct custody or agency activity. (RAO, arts. 9U–9V; PERG 18.8.16 and 18.8.18; September draft, reg. 4(5)(b)(vi).)
Proposed article 9Z2A would exclude mere technical access services from arranging where the provider is neither authorised nor a payment service provider. Access must concern an appropriately authorised or exempt regulated service, or a decentralised protocol. The provider's own transactional role remains decisive; the proposal would not exempt every interface or decentralised business. The Treasury has not replicated this technical-services exclusion in the financial-promotion amendments. (September draft, reg. 4(5)(b)(viii); explanatory memorandum, paras. 5.9–5.10 and 6.10.)
Staking, lending and composite products
Staking permission concerns arrangements on behalf of another person for qualifying cryptoassets to be used in blockchain validation. The technical validation exclusion requires the statutory conditions, including the restriction on holding out a staking service. A customer-facing staking business cannot rely solely on its use of third-party validators. A person validating only its own assets must still be tested against the activity and business elements. (RAO, arts. 9Z6–9Z9; PERG 18.10.)
A yield product does not become staking merely because its marketing uses that term. Where returns arise from lending rather than validation, dealing or arranging can apply. A liquid-staking service also needs separate examination of receipt-token issuance, transfers and redemption. Permission for staking does not automatically authorise those distinct transactions or custody of the underlying assets. The applicable permissions depend on the contractual promises and actual transfer mechanics. (RAO, arts. 9N, 9T, 9W, 9Y and 9Z6; PERG 18.9–18.10.)
The legislation does not create a standalone cryptoasset lending permission. A business lending or borrowing qualifying cryptoassets can deal as principal when the transaction meets that activity's elements. An intermediary can arrange the transaction, and control of collateral can constitute safeguarding. A fiat-credit or derivative component requires separate consideration under existing financial-services law. No conclusion on consumer-credit permissions follows merely from calling a cryptoasset transfer a loan. (PERG 18.9; RAO, arts. 9N, 9T and 9Y.)
Overseas business and UK entity requirements
An overseas establishment does not by itself prevent UK authorisation requirements. The amended territorial provisions cover specified involvement in sales or subscriptions to or by a UK consumer. For the trading and intermediation route, the statutory exception requires an authorised platform operator or principal dealer acting in that capacity between the overseas person and consumer. An authorised agent or arranger alone does not satisfy that intermediary condition. Custody and staking have a different exception involving direction by a person authorised for the corresponding activity. (SI 2026/102, reg. 41(6), inserting FSMA, s. 418(6B)–(6F).)
A UK consumer is an individual in the UK acting outside a trade, business or profession for the relevant transaction. The same individual can be a professional client under Handbook categorisation rules. That designation does not remove the statutory territorial connection. Nor does the absence of consumers resolve activities actually carried on in the UK under the ordinary territorial rules. A firm's customer classifications and operational locations must therefore be assessed separately. (FSMA, s. 418, as amended by SI 2026/102, reg. 41(6); PERG 18.1.13 and 18.3.)
The FCA generally expects regulated cryptoasset activities to be conducted through a UK legal entity. FG26/7 describes supervisory expectations, not an absolute statutory incorporation rule. It permits case-specific consideration of a UK branch for trading-platform operations, with comparable home-state protections. Restricted matched-principal and settlement-custody permissions can also be considered within the stated branch conditions. Other activities retain the general UK-entity expectation. Dual-regulated firms receive a separate case-by-case assessment. (FCA, FG26/7, paras. 1.2, 5.2, 7.3–7.6 and 8.1–8.15.)
The restricted settlement-custody model provides less client-asset protection for the settlement float. CASS 17.1.3R disapplies CASS 17 for an overseas platform operator subject to the prescribed safeguarding restrictions. Those restrictions confine custody to settlement on a UK qualifying cryptoasset trading platform and require UK users' assets to arrive through a group member subject to and complying with CASS 17.3.5R. That rule permits the group custodian to release assets from trust subject to its cumulative conditions, including prior informed consent. The released amount must never exceed 2% of the same cryptoasset safeguarding class remaining in the custodian's trusteeship for that client. (CASS 17.1.3R–17.1.4G and 17.3.5R, in PS26/11; FG26/7, paras. 8.12–8.15.)
A proposed group structure must connect each service to the entity that will contract, control assets and hold permission. The branch exception cannot establish general offshore authority for customer custody. Under the territorial exceptions, replacing a principal intermediary with an agent can change the legal result despite identical customer-facing branding. These conclusions follow from the specified capacities and exclusions; they remain conditional on the actual contracts and transaction chain. (SI 2026/102, reg. 41(6); FG26/7, paras. 8.5–8.15.)
Applications and existing regulatory status
The FCA's direction fixes the relevant application period from 9:00am on 30 September 2026 to 11:59pm on 28 February 2027. It can extend the period, and applications remain possible afterwards. The legal consequence of the window concerns access to the savings provision. Filing later is therefore different from filing in time, even where the regulator has not decided either application by commencement. (FCA direction under SI 2026/102, reg. 52, 20 February 2026, paras. 2–3; SI 2026/102, reg. 52(5).)
The FCA treats a firm whose application is rejected for missing minimum information as not having applied unless it submits a valid replacement. A submission receipt alone consequently cannot establish protection under regulation 53. A replacement application must satisfy the relevant requirements within the protected period to support that route. A firm should preserve the submitted package, submission time and subsequent FCA correspondence for each requested permission. (FCA, Cryptoassets: The transitional provision, updated 24 August 2026, section "Firms that will not be eligible for the transitional provision"; SI 2026/102, regs. 51–53.)
Money-laundering registration, payment-services status and electronic-money status do not convert automatically into cryptoasset permission. Existing FSMA-authorised firms need the appropriate variation where their current permissions do not cover the new activity. Present registration and financial-promotion requirements continue to require separate compliance before commencement. Approval of a promotion under section 21 does not authorise the underlying regulated business. (PS26/18, paras. 1.24–1.26; PERG 18.1.8 and 18.1.15–18.1.16; FCA, Cryptoasset firms: Use of s.21 approvers, section on the new regime.)
The September draft would separately amend the Financial Promotion Order 2005. It would add qualifying-stablecoin issuance as a controlled activity and qualifying stablecoins as a controlled investment. It would extend specified overseas-communication routes and exempt communications required or authorised under the cryptoasset market-abuse provisions. Proposed article 67A would cover communications required or permitted by authorised platform rules or the FCA, limited to non-real-time or solicited real-time communications. Proposed article 73ZAA would provide stablecoin transaction exemptions with distinct return-right, asset and customer restrictions. Backing-asset and depository exclusions would also require their stated conditions. No proposed activity exclusion establishes an unrestricted right to promote a service. (September draft, regs. 3 and 4(6); explanatory memorandum, paras. 6.13–6.19.)
The FCA permits coordinated handling of FSMA and money-laundering applications in the circumstances it describes. That administrative process does not equate the two statuses. Its warning that money-laundering applications made after 31 July 2027 are unlikely to be decided before commencement is a processing warning, not a new statutory filing deadline. A firm proposing to launch earlier must establish the permissions or registration required on its actual launch date. (FCA, Registration under the MLRs ahead of the new FSMA regime, updated 16 September 2026, sections on applying and applications after 31 July 2027.)
Business continuation while decisions remain open
Regulation 53 can preserve ordinary business for a qualifying in-window applicant while its decision remains unresolved. It applies where the application is undetermined or a refusal remains open to review, subject to the specified FCA direction. For the activity covered by the application, the applicant and overseas group persons receive treatment as though Parts 3–6 had not commenced. Protection therefore depends on the application's scope as well as its timing and procedural status. It does not authorise an omitted activity. (SI 2026/102, reg. 53(1)–(2).)
This savings treatment differs from the existing-contract restriction in regulation 56. A qualifying applicant can continue the relevant business under the preserved legal position, including new business where otherwise lawful. That inference follows from regulation 53's disapplication of Parts 3–6 and its absence of regulation 56's contract limitation. Existing legal requirements remain relevant. Part 2, which contains the public-offer and market-abuse provisions, falls outside the specified disapplication. (SI 2026/102, regs. 53(2) and 56(3).)
The savings period has an outer limit of two years beginning with full commencement. It does not continue indefinitely because an application or review remains pending. Regulation 54 requires overseas persons relying on the savings provision to notify the FCA and later notify cessation on the stated conditions. Its wording should not be recast as an identical notification duty for every domestic applicant. Permission, review status and group participation require continuing checks during the saved period. (SI 2026/102, regs. 53(3) and 54.)
Contractual run-off after refusal or late application
The run-off route applies to specified applicants whose position does not support continued ordinary business. It includes timely applications finally refused or withdrawn. It also includes applications made after the protected window but before commencement which remain undetermined, have been refused or have been withdrawn. The overseas-group extension requires a UK-established group applicant whose in-window application has been finally refused or withdrawn. A late application alone does not establish that extension. A firm that never makes a qualifying application cannot assume automatic run-off protection. (SI 2026/102, reg. 55(1)–(4).)
Regulation 56 exempts only the relevant unpermitted activity necessary to perform a qualifying pre-existing contract. Conditional or contingent obligations can qualify, but the activity must be performed for that contract's purposes. A new contract with an existing customer does not qualify merely because the relationship predates commencement. Nor does a broadly worded master agreement establish that every later order performs an existing obligation. The agreement, later order and obligation must be examined together. (SI 2026/102, reg. 56(1)–(4).)
The contractual cut-off is not invariably 25 October 2027. Regulation 56(4) generally uses the later of commencement and satisfaction of the relevant trigger, with a separate rule for an FCA direction. A timely applicant lawfully continuing under regulation 53 can therefore have later contracts included when it subsequently enters run-off. That conclusion remains subject to the contract's date and the precise trigger. The two-year outer limit still runs from full commencement, so a later switch leaves less time to complete performance. (SI 2026/102, regs. 55(9) and 56(4).)
The FCA can move a timely applicant from savings to run-off after refusal while review remains open, on the statutory grounds. It must specify the effective date and give a decision notice; the recipient can refer the decision to the Tribunal. Run-off firms must make the prescribed notifications and explain their exempt status and material changes in customer protections. The FCA can vary or cancel the exemption and require information. These powers make the exemption conditional throughout its operation. (SI 2026/102, regs. 55(3), (5)–(8) and 57–61.)
The September draft would repair cross-references in regulation 59 concerning cancellation or variation and urgent decision notices. Those repairs would not enlarge the qualifying-contract category or extend the two-year run-off limit. (September draft, reg. 4(7); SI 2026/102, regs. 55(9), 56 and 59.)
Regulation 60 also modifies section 21(2) for a person in contractual run-off. Its substituted exception covers only communications necessary for performing a qualifying pre-existing contract. Promotion approval alone cannot establish that exception. (SI 2026/102, reg. 60.)
Public offers, admissions and market abuse
Part 2 creates obligations separate from the new regulated-activity permissions. The public-offer prohibition and exceptions require assessment of the communication, audience and offer terms. Schedule 1 includes offers not exceeding £1,000,000, subject to connected-offer aggregation over 12 months. Aggregation concerns offers of the same kind with a shared responsible person, and counts earlier offers only to the extent they relied solely on that small-offer exception. Other exceptions include offers solely to qualified investors and offers to fewer than 150 UK persons, excluding qualified investors. An issuer or distributor must establish the chosen exception rather than infer it from the token's eligibility for trading. (SI 2026/102, regs. 7–11 and Sch. 1, paras. 1–3 and 8.)
The other Schedule 1 routes have different conditions. They address a purchase or subscription of at least £100,000 for each separate offer, an offer made by an authorised qualifying-stablecoin issuer, admission-linked offers and specified employee or director arrangements. The stablecoin exception depends on the offeror's permission, so a distributor cannot establish it merely by pointing to an authorised issuer elsewhere in the chain. (SI 2026/102, Sch. 1, paras. 4–7.)
An exception from the public-offer prohibition does not remove every disclosure duty. For otherwise excepted offers reaching £500,000 or its equivalent, regulation 11 regulates selective disclosure of material information. Depending on the applicable document requirement, that information must enter the disclosure document or reach the other offerees. Connected offers by the same responsible person are aggregated over the prescribed 12-month period. A small-offer exception therefore cannot alone justify selective disclosure to preferred buyers. (SI 2026/102, reg. 11.)
Admissions require separate consideration under CRYPTO 3. For relevant retail admissions, the made rules require a qualifying cryptoasset disclosure document, publication on the operator's website, upload to the FCA repository and the prescribed assessment. The operator must also be reasonably satisfied that admission is unlikely to harm retail investors, subject to the stated exceptions. CRYPTO 3.3.5R excepts UK qualifying stablecoins and particular assets unavailable to retail investors on that platform, directly or through intermediaries. The statutory disclosure provisions also establish compensation liability and defences. A trading-platform operator's authorisation does not establish that every admission document or public offer complies. Defects require assessment against the responsible person's duty and the applicable defence, including the prescribed reasonable-belief and enquiry conditions. (CRYPTO 3.2.1R–3.2.2R, 3.3.1R and 3.3.5R, in PS26/9; SI 2026/102, regs. 13–14 and Sch. 2.)
Withdrawal under CRYPTO 3.5.3R requires the purchaser's agreement to follow publication of the initial disclosure document. A supplementary document must follow that agreement, and the circumstances requiring it must arise or be noted before admission. The exercise period is two working days after publication of the supplementary document, unless extended. UK qualifying stablecoins have separate conditions under CRYPTO 3.9, including an agreement contingent on admission. These rights do not give every purchaser an unrestricted post-admission cancellation right. Platform operators must retain the records required by CRYPTO 3.10 for five years, or up to seven years where the FCA requests. Contract dates, publication dates and the relevant offer route determine the purchaser's remedy. (SI 2026/102, reg. 15; CRYPTO 3.5.3R–3.5.6R, 3.9.2R–3.9.6R and 3.10.2R–3.10.3R, in PS26/9.)
The market-abuse provisions cover the specified admitted or admission-requested cryptoassets and related instruments. They prohibit insider dealing, unlawful disclosure and market manipulation, with statutory exceptions. The territorial provisions can reach overseas conduct. Platform operators and specified authorised intermediaries must maintain the prescribed market-abuse systems. Reporting, insider-list and information-sharing duties depend on the person and applicable statutory or designated-activity rules. A permission application cannot itself excuse conduct prohibited by Part 2, although each duty's own commencement, scope and any applicable rule transition must still be checked. (SI 2026/102, regs. 17, 22–25 and 28–32; CRYPTO 4, in PS26/9; SI 2026/102, reg. 53(2).)
The September draft would also revise the financial-instrument definition in regulation 17(5) and make the location of unlawful disclosure expressly immaterial under regulation 24. Those amendments concern market-abuse scope, separately from permission exclusions. (September draft, reg. 4(3)–(4).)
Operating duties and customer protection
Permission planning must incorporate the operating rules already made in June 2026. The FCA published the core package in PS26/9–PS26/13 on 30 June 2026. Those publications cover admissions and market abuse, stablecoins, conduct, client assets, prudential requirements and general Handbook application. PS26/18 confirms that the core regime remains settled, while further components are planned. A firm cannot justify postponing all operational preparation on the premise that the core rules remain proposals. (PS26/18, paras. 1.3 and 1.29–1.31.)
CP26/32, published on 4 September 2026, proposes rule deferrals rather than changing the made rules. For in-window platform applicants, draft CRYPTO TP 1 would permit asset-specific relief for up to six months after authorisation, ending earlier on disclosure-document publication. Only assets admitted before authorisation and notified to the FCA on the authorisation date would qualify. Retail disclosures and transaction warnings would apply; market-abuse requirements would continue. (FCA, CP26/32, ch. 4 and Appendix 3, draft CRYPTO TP 1.1–1.9.)
The proposed intermediary periods use fixed dates. Draft TP 2.5–2.9 would provide specified execution-policy, venue and admission-rule relief from 25 October 2027 to 25 January 2028. The associated disclosure and warning provisions for retail clients other than overseas retail clients would run to 25 April 2028. Neither period restarts on an intermediary's later authorisation. These proposals do not extend contractual run-off or establish present relief. (FCA, CP26/32, para. 4.3 and Appendix 3, draft CRYPTO TP 2.1–2.15.)
Stablecoin issuers must assess CRYPTO 2 and CASS 16 requirements for backing assets and redemption. Qualifying-cryptoasset custodians must assess the applicable CASS 17 rules. Relevant specified investment cryptoassets initially retain the stated CASS 6 treatment, despite the new custody permission. Client-asset permission, applicable segregation rules and compensation eligibility are separate questions. The FCA has not extended FSCS protection to the new cryptoasset activities, including the new safeguarding activity for relevant specified investment cryptoassets. (PS26/10, CRYPTO 2 and CASS 16 instruments; PS26/11, CASS 17 instrument; PS26/13, ch. 12, pp. 67–69.)
Prudential preparation requires the applicable COREPRU and CRYPTOPRU calculations. COREPRU 4.1.2R sets own funds by reference to the highest applicable permanent minimum, fixed-overheads and K-factor requirements. Separate payment-services or electronic-money requirements can remain additional. Firms must also determine which conduct rules apply to their services and customers. CRYPTO 5.5.1R requires role disclosure to retail and professional clients before executing their orders; the best-execution rules contain their own scope qualifications. Neither a single capital figure nor one retail policy establishes compliance across a mixed business. (COREPRU 4.1.2R and 4.1.3G, in PS26/12; CRYPTO 5.4.1R–5.4.4G and 5.5.1R, in PS26/11.)
The general Handbook package addresses senior management, financial crime, operational resilience, reporting, complaints and the Consumer Duty where applicable. Financial Ombudsman Service eligibility does not provide insolvency compensation or insure investment losses. Customer communications must distinguish the firm's permissions from the protections actually available for the activity and complainant. A group firm's regulated status cannot substantiate a promise of FSCS cover for an uncovered cryptoasset service. (PS26/13, chs. 3–13 and accompanying instruments; DISP amendments in PS26/13; PS26/13, ch. 12.)
