In April 2026 the FCA published Consultation Paper CP26/13, setting out proposed guidance on the perimeter of the forthcoming UK cryptoasset regime. The gateway for authorisation applications opens 30 September 2026 under SI 2026/102. The guidance tells firms, for the first time with any specificity, what activities will require authorisation and how the FCA will read the boundary cases.
Key points
- CP26/13 defines three core activity buckets: custody, exchange, and dealing as principal. Most multi-service platforms will touch all three.
- The application gateway opens 30 September 2026 and closes 28 February 2027. Missing the window means operating without authorisation from 25 October 2027.
- The FCA has defined “safeguarding” as a primary custody obligation; firms that commingle client and own assets will not pass threshold conditions.
- Overseas firms with UK-nexus clients are in scope unless they can demonstrate genuine reverse solicitation for every relevant transaction.
What CP26/13 is
CP26/13 is the FCA’s consultation on how it will read the perimeter of the new UK cryptoasset authorisation regime established by SI 2026/102 (the Financial Services and Markets Act 2000 (Cryptoassets) Order 2026). The Order creates a new regulated activity: “carrying on a cryptoasset business.” The FCA’s proposed guidance tells firms what falls within that definition and, more usefully for practitioners, where the boundary cases lie.
The consultation period closed on 15 June 2026. Final guidance will be published before the gateway opens on 30 September, though the FCA has indicated it may publish interim guidance before then given the volume of firms asking for clarity.
The three primary activity buckets
Custody. Holding cryptoassets on behalf of clients is the clearest trigger. The guidance treats custodying cryptoassets as a regulated activity regardless of whether the firm also trades or provides advice. Importantly, the FCA proposes to treat “omnibus” wallet arrangements differently from individual segregated custody: firms maintaining pooled wallets where clients have a beneficial interest but no individually identifiable holding are squarely in the custody perimeter. The safeguarding obligation that accompanies this is substantive: client assets must be legally and operationally separated from the firm’s own assets at all times.
Exchange. Operating a venue where buyers and sellers transact in cryptoassets is a regulated activity under the new regime. CP26/13 applies this broadly: order-book exchanges, RFQ platforms, peer-to-peer marketplaces, and automated market maker protocols with a UK legal entity or UK-facing commercial presence all appear to fall within the definition. The guidance distinguishes between operating an exchange (regulated) and merely providing the software or protocol (currently outside the perimeter, though the FCA has flagged this as an area it will revisit).
Dealing as principal. Firms that buy and sell cryptoassets on their own account, with clients as the counterparty, are dealing as principal. OTC desks, market makers, and treasury operations that service client flow fall into this bucket. The guidance makes clear that the regulated activity is the dealing, not the scale: a single bilateral trade with a UK client as counterparty can trigger the perimeter if the firm is doing so in the course of carrying on a business.
The overseas firm question
The overseas persons exclusion that applies under existing FSMA is not automatically carried across to the new regime. CP26/13 proposes a narrower version of the exclusion: an overseas firm without a UK establishment will be outside the perimeter only if its services to UK clients are genuinely provided from outside the UK and the client approached the firm on their own initiative without any UK-directed marketing.
The practical consequence is that most international platforms with active UK user bases will be in scope. The FCA has been explicit that a foreign-domiciled firm operating a website accessible to UK users, with no active UK marketing, is still likely to be in scope if it is onboarding UK residents and servicing their accounts. The reverse-solicitation argument that has circulated in industry will not provide cover for firms with ongoing relationships with UK clients.
The application window
The gateway opens 30 September 2026 and closes 28 February 2027. Only firms with a submitted application can continue operating after 25 October 2027, when the new regime commences. A firm that misses the window and has not applied faces the same position as an entirely new entrant: it cannot operate until it has obtained authorisation, and it has lost the benefit of the transitional provisions.
The application itself requires the firm to address threshold conditions in the same way as any FSMA-authorised firm, plus specific cryptoasset-regime requirements around systems and controls for asset safeguarding, conflicts of interest, client order handling, and record-keeping. The FCA’s supervisory approach for cryptoasset firms will borrow from its approach to investment firms under MiFID II, but with tighter requirements around the safeguarding of digital assets specifically.
What a well-prepared file needs to contain
On the basis of CP26/13 and the FCA’s published expectations for the gateway, a complete application will require at minimum: a detailed regulatory business plan covering each cryptoasset activity in scope; a safeguarding framework that demonstrates client asset segregation, reconciliation procedures, and the approach to key management; an AML/CFT framework compliant with the UK’s Money Laundering Regulations; governance documentation covering senior management responsibilities and the SMCR regime as it will apply to crypto firms; and a conflicts-of-interest policy that addresses the specific conflicts arising from vertically integrated crypto businesses.
Firms that have been through a MiCA CASP application in the EU will have much of this infrastructure already. The FCA’s regime is substantively similar in structure, though there are differences in the safeguarding requirements and in the approach to algorithmic trading that will require tailoring.
The practical timeline now
For a firm that has not yet started preparation, the window between now and 30 September is tight but not unworkable. A CASP-equivalent file built for an EU jurisdiction can be adapted with four to six weeks of focused work if the underlying infrastructure exists. For a firm starting from scratch, the file preparation will take longer than the window allows if work starts in August or later.
We are working with several firms on UK gateway applications alongside their EU MiCA applications, and the process is manageable if the organisational and governance infrastructure is already in place from the EU work. For firms without that foundation, the gateway is a harder problem.
Preparing for the FCA cryptoasset gateway?
We prepare cryptoasset authorisation files for EU MiCA and UK FCA applications. If you are working toward the 30 September 2026 gateway, book a call to understand what your specific activities require and how long the file preparation will take.
Related
- Crypto Licensing (VASP / MiCA): EU and UK crypto authorisation, including CASP applications we file directly
- MiCA / CASP Licensing: Full MiCA authorisation route and NCA selection
- The MiCA grandfathering deadline is 1 July 2026: What EU-facing CASPs need to do before that date
- Back to Blog