Skip to content

FCA Opens UK Crypto Authorisation With Five-Month Window

The Financial Conduct Authority (FCA) has opened its crypto authorisation gateway, giving firms that serve UK customers until 28 February 2027 to apply before the new regime takes effect that October.

FCA Opens UK Crypto Authorisation With Five-Month Window

The Financial Conduct Authority, the UK's financial regulator, began accepting authorisation applications from cryptoasset firms on 30 September, opening the gateway to a regime that will bring crypto businesses under full financial regulation for the first time. Firms have until 28 February 2027 to apply, and the rules take effect on 25 October 2027, after which operating without authorisation becomes unlawful.

"The UK's new crypto regime will give consumers greater protections and firms a clear framework to operate in," said Dominic Cashman, the FCA's director of authorisation.

Firms that apply within the window may carry on serving customers, including taking on new business, while the regulator works through their application, even after the regime starts. Those that miss the deadline do not get that protection.

What Now Requires Authorisation

The regime covers five activities: issuing qualifying stablecoins, operating cryptoasset trading platforms, dealing and arranging deals in cryptoassets, safeguarding cryptoassets, and arranging staking. The FCA published guidance on how the law applies to each of these on 16 September, and has offered pre-application meetings and webinars to firms unsure where they fall.

The rules themselves were finalised in June, covering capital requirements and stress testing, market integrity obligations against insider dealing and manipulation, standards for stablecoin issuers, and application of the Consumer Duty, the FCA's overarching obligation to deliver good outcomes for retail customers.

"We've created a framework that doesn't force firms to choose between regulatory certainty and room to innovate," said David Geale of the FCA when those rules were published.

A Much Higher Bar Than Registration

Crypto firms in the UK have dealt with the FCA before, under the Money Laundering Regulations, but that regime asked a narrower question: whether a business had adequate anti-money laundering controls and fit and proper management.

Authorisation asks for considerably more, including capital adequacy, verified segregation of client assets, complaint handling, the ability to detect market abuse, ongoing prudential supervision and accountability under the Senior Managers Regime, which makes named individuals personally answerable for parts of the business.

Firms that passed the AML registration should not assume the rest follows.

The Record Suggests This Will Be Hard

The history of the registration regime is the clearest warning. The FCA had completed 391 cryptoasset registration cases by 1 August this year, and only 17% ended in registration, with 67% withdrawn, 12% rejected and 4% formally refused.

Most of those firms were not rejected outright; they gave up partway through, usually because they could not answer the regulator's questions or did not have the compliance documentation to support their application. Authorisation asks harder questions across more areas.

Five months is not long to prepare a first-time application of this kind, and firms that start in January will be competing for the regulator's attention alongside everyone else who left it late.

Overseas Firms Are In Scope Too

Location offers no exemption. A firm that reaches UK consumers, directly or through an intermediary, can fall within the FCA's perimeter regardless of where it is based, which brings in exchanges, custody providers and staking platforms with no UK office or staff.

That is a familiar pattern in financial regulation but a new one for much of the crypto sector, where serving customers in a country without a presence there has been standard. Firms outside the UK that have British retail users should establish now whether they need to apply, because the alternative after October 2027 is withdrawing from the market.

The UK is arriving three months after the European Union's Markets in Crypto-Assets regulation finished its transition on 1 July, which required unauthorised providers to leave EU markets. Firms operating across both now face two authorisation processes with different requirements and timetables, on top of product-level obligations such as those in the EU's Cyber Resilience Act where they build hardware or connected services.

What Firms Should Be Doing

The practical advice from advisers working on these applications is to treat the coming months as scoping and preparation rather than filing. That means mapping which of the five regulated activities a business performs, identifying where UK customers sit in the chain, and assembling the financial, governance and operational evidence the FCA will ask for.

Businesses that depend on crypto service providers have their own homework. A payments company, a fintech or an enterprise using a custody provider should ask whether that provider intends to apply, when, and what happens to held assets if authorisation is refused or the firm withdraws from the UK.

Consolidation Is The Likely Outcome

Regimes of this kind tend to reduce the number of firms in a market, which is partly the point. Capital requirements, senior manager accountability and client asset rules cost money to meet, and the smallest operators often conclude the UK is not worth the effort.

What the UK gets in return is a market where the surviving firms are supervised like other financial businesses, which is what institutional money has been waiting for. The next 18 months will show how many firms make that trade, and the FCA's decisions on the first wave of applications will tell the rest of the sector how high the bar really is.

Add Morning Tick on Google