The UK is changing how it regulates cryptoasset businesses. Until now, many UK crypto firms have operated under the Money Laundering Regulations (MLRs), with the Financial Conduct Authority (FCA) supervising them primarily for anti-money laundering (AML) and counter-terrorist financing purposes.
The new framework brings a wider range of cryptoasset activities into the Financial Services and Markets Act 2000 (FSMA) authorisation regime, with the FCA assessing firms against broader requirements for governance, financial resources, safeguarding, consumer protection, financial crime, technology and operational resilience.
If you provide cryptoasset services in the UK, you need to establish whether your activities fall within the new regulatory perimeter, which permissions you need and what your business will need to demonstrate to the FCA.
What is FCA crypto regulation?
The Financial Conduct Authority (FCA) is the UK regulator responsible for supervising financial markets and firms. It regulates how authorised firms operate, protects consumers, supports market integrity and oversees conduct across financial services.
Under the new UK cryptoasset regime, the FCA will authorise and supervise firms carrying out regulated cryptoasset activities. This includes assessing their governance, financial resources, custody arrangements, financial crime controls, consumer protection measures, technology and operational resilience.
Which crypto activities need FCA authorisation?
Eight activities fall inside the new perimeter:

Three areas require particular attention.
MLR registration does not become FSMA authorisation. Firms registered under the Money Laundering Regulations (MLRs) will need to apply for the relevant Financial Services and Markets Act (FSMA) permission if they carry out activities within the new regime. Firms already authorised under FSMA, the Payment Services Regulations or the Electronic Money Regulations may also need new or varied permissions.
International entities need to assess their UK structure. The FCA has published separate guidance covering international cryptoasset firms, including the requirements for UK establishment and branches. The assessment should account for which entity provides the service and where the relevant activities are carried out.
DeFi requires a perimeter assessment. Calling a protocol decentralised does not, by itself, determine whether it falls within the regulatory perimeter. Firms should document who controls its design and operation, including administrative permissions, upgrade mechanisms and any arrangements involving client assets.
UK crypto regulation: key dates
30 June 2026 — FCA final rules published
The FCA published its main final rules and guidance for the new cryptoasset regime, including requirements covering prudential standards, safeguarding, consumer protection and operational resilience.
30 September 2026 — applications open
Firms can start applying to the FCA for authorisation to perform cryptoasset activities covered by the new FSMA regime.
28 February 2027 — protected application window closes
Existing companies that apply by this date can continue certain cryptoasset activities while the FCA reviews their application, subject to the transitional rules.
25 October 2027 — new regime comes into force
From this date, entities must be authorised by the FCA to continue regulated cryptoasset activities in the UK, unless a specific transitional rule or exemption applies.
Enterprises that miss the application period can still apply, but they will not benefit from the same saving provision. If an existing firm applies after the application period and its application remains unresolved when the new regime starts, the transitional provision is more restrictive.
Key areas of FCA readiness assessment
The FCA assesses whether a firm has the governance, resources, systems and controls required to carry out its regulated activities.
Depending on the business model, this covers:
The FCA will assess these areas as parts of the same operating model. For example, custody cannot be treated as a standalone policy if the actual custody model depends on external signing infrastructure, cloud services and several layers of internal approval. Those dependencies need to be reflected in risk management, governance, operational resilience and third-party controls.
The same applies to security. If smart contracts, blockchain infrastructure or external technology providers support a regulated service, they form part of the environment the firm needs to understand and control.
Cybersecurity under the FCA crypto regime
There is no single UK law covering cybersecurity for crypto businesses. Requirements come from the FCA Handbook and crypto-specific guidance, alongside legislation that applies to the firm's activities, such as the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018.
The FCA's FG26/6, Cryptoasset Operational Resilience, is particularly relevant. It applies the FCA's operational-resilience framework to cryptoasset firms and addresses technology and operational risks specific to the sector.
Firms need to identify important business services, establish impact tolerances, understand the dependencies supporting those services and test their ability to continue operating during disruption.
For digital asset businesses, those dependencies can include:
- private-key and signing infrastructure
- custody systems
- smart contracts
- blockchain networks
- validators and oracles
- cloud infrastructure
- other critical technology providers.
The FCA does not require firms to use a specific security architecture or technology. MPC (multi-party computation), multisignature wallets, hardware security modules (HSMs) and wallet segregation are examples of controls that may be appropriate depending on the firm's risks and operating model. Firms should be able to explain why their chosen controls are appropriate and demonstrate that they work as intended.
Five steps before you apply
- Confirm your regulatory perimeter. Identify every regulated activity and entity within scope.
- Find the gaps. Compare your existing controls with the requirements that apply to your activities.
- Test material controls. Prioritise security, custody, operational resilience and other controls supporting important business services.
- Remediate and retest. Track findings through closure and retain evidence of the results.
- Assemble one evidence set. Make sure your policies, technical documentation, testing records and application describe the same operating environment.
The FCA recommends that firms review the final rules and guidance, determine whether authorisation is required and consider using PASS before applying.
For a control-by-control breakdown of the requirements and evidence to prepare, download the UK Crypto CISO Readiness Checklist.




