July 2026

      In June 2026, the FCA published its final policy statements for the UK’s cryptoasset regime, setting the rules that will take effect from October 2027. While the final framework broadly tracks with the FCA’s consultation proposals, the regulator has made targeted refinements in response to industry feedback, with the most substantive changes being made to prudential requirements and stablecoin issuance rules. The result is a regime that seeks to manage the distinct risks of cryptoasset markets while supporting innovation, growth and the UK’s competitiveness. This article highlights the key changes firms should understand as they prepare for authorisation and implementation, and the cryptoasset activities to which they apply.

      At a glance:

      • The FCA’s final cryptoasset regime broadly tracks the consultation proposals, with targeted refinements rather than a fundamental shift in approach. The most substantive changes relate to prudential requirements and stablecoin issuance.
      • For firms, the priority is now to move from interpretation to implementation. Existing preparation should remain broadly relevant, but application materials, governance arrangements, prudential models, stablecoin controls and customer-facing processes should be tested against the final rules.
      • The final framework provides important clarity across the Handbook, including the application of Consumer Duty, SYSC, SM&CR, CASS, operational resilience, COBS, ESG and dispute resolution requirements to cryptoasset firms.
      • Stablecoin issuers and firms with cryptoasset exposures should pay particular attention to the revised backing asset, redemption, custody and capital requirements, including the reduced stablecoin issuance K-factor and simplified market risk framework.
      • Firms that can evidence readiness, close policy and control gaps, and demonstrate how their business model meets the FCA’s expectations will be better placed to navigate authorisation and implementation ahead of the October 2027 regime start date.

      The FCA has made some refinements to the scope, definitions and requirements of the activities captured by the regime.

      • Principal dealers have been removed from pre-trade transparency requirements, aligning the cryptoasset regime more closely with the updated approach for non-equity traditional finance.
      • Best execution rules have been adjusted to require firms to check prices from at least three reliable UK-authorised execution venues where possible, but they will not be required to execute on those venues or undertake mechanical transaction-by-transaction checks, provided they maintain effective overall arrangements supported by periodic post-trade analysis.

      The final rules also provide further detail on retail protections for cryptoasset lending, borrowing and staking, targeted refinements to collateral and auto-staking rules.

      For DeFi, the FCA is proceeding on the basis that the rules apply where there is an identifiable controlling entity. Separate guidance is expected on how decentralisation will be assessed in practice.

      The FCA has made a number of targeted changes to its rules for the issuance of non-systemic UK issued qualifying stablecoins intended to simplify the regime while preserving core safeguards for holders.

      The final rules:

      • Remove the need for issuers to estimate redemption forecasts when determining backing asset composition
      • Confirm that backing assets must be held on statutory trust
      • Remove the concept of unallocated backing fund accounts
      • Allow a limited 5% excess in the backing asset pool and introduced flexibility for limited intragroup custody, provided appropriate safeguards are in place.
      • The final position also clarifies several customer-facing obligations:
      • For redemptions, KYC checks should be completed before the redemption period starts and the application of requirements in secondary market contexts has been clarified.
      • Issuers will also need to ensure holders can access historical disclosures and that prospective holders are made aware of their withdrawal rights

      These clarifications reinforce the FCA’s focus on transparency, orderly redemption and consumer protection.

      The FCA and the BoE are also consulting on their approach to the joint regulation of systemic stablecoin issuers – proposing how issuers could transition to the BoE rules for systemic stablecoins once they are designated as systemic by HM Treasury.

      We summarised the FCA and BoE proposals for stablecoin issuance: Proposed UK rules for stablecoin issuance

      The FCA has largely maintained the framework proposed for the prudential regime in its consultation but has introduced several important adjustments to improve proportionality and simplify implementation. This acts upon industry feedback that the original proposals risked making the UK uncompetitive as they were too conservative:

      • The operational risk K-factor capital requirement for stablecoin issuance has been reduced from 2% to 1%
      • The market risk framework has been simplified: cryptoassets that can be prudently valued and are admitted to a UK qualifying cryptoasset trading platform will be subject to a single 40% net risk position requirement for K-NCP (net cryptoasset position) and a 40% volatility adjustment for K-CCD (counterparty credit default). Cryptoassets that do not meet those conditions will instead be deducted from regulatory capital and subject to a 100% volatility adjustment for K-CCD.
      • Public disclosure regime has been made more proportionate

      The FCA is also consulting upon non-handbook guidance to help firms complete the overall risk assessment under COREPRU (the core prudential requirements across all types of the firms the FCA prudentially regulates) and CRYPTOPRU (the sector-specific prudential standards for cryptoasset firms)

      This policy statement sets out the FCA’s final rules and guidance on how key cross-cutting FCA Handbook obligations will apply to regulated cryptoasset activities.

      Designated investment business

      The FCA has made no changes to its definition of designated investment business.

      Approach to International Cryptoasset Firms (AICF): non-handbook guidance

      The FCA has made limited changes to its approach for international firms. The expectation that cryptoasset activities should be conducted through a UK legal entity, rather than a branch, will apply to solo-regulated FCA firms under the AICF. Dual-regulated firms may carry on cryptoasset activities from a branch, subject to PRA approval, satisfaction of the FCA’s threshold conditions at authorisation, and holding the relevant permission.

      Consumer Duty:

      The FCA is proceeding with the application of Principle 12 (A firm must act to deliver good outcomes for retail clients) and PRIN 2A to cryptoasset firms, supplemented by finalised non-Handbook guidance (FG26/5). The Duty will apply in full to cryptoasset firms, subject to limited exemptions for admissions and disclosures activities and trading between participants on a UK qualifying cryptoasset trading platform. The guidance is framed around retail market business and makes clear that a firm’s responsibilities will depend on its role and level of influence over retail customer outcomes in practice, rather than solely on contractual allocation.

      The final guidance also provides additional colour on consumer understanding, fair value, territorial scope, consumer support and the respective responsibilities of manufacturers and distributors in the supply chain. The FCA has clarified that firms do not need to offer support across every possible channel, but the channels they do provide must meet customer needs, including for customers with non-standard issues or characteristics of vulnerability. It also signals that firms should avoid complex redemption mechanisms, such as multi-step stablecoin redemptions, while still carrying out required anti-money laundering checks.

      See our analysis of the FCA’s proposals for consumer duty and cryptoasset firms here:

      CASS

      The final rules clarify how the client money and custody regimes apply across cryptoasset activities. CASS 7 will apply where firms receive or hold client money in connection with safeguarding client cryptoassets or undertaking execution, dealing or arranging activities involving qualifying cryptoassets or relevant specified investment cryptoassets (tokenised traditional financial instruments). The FCA has also disapplied the professional client opt-out in CASS 7 for money held in connection with qualifying cryptoasset activities.

      For Stablecoin Issuers: The FCA has also clarified the boundary between CASS 7 and CASS 16 for qualifying stablecoin issuers. Firms carrying on the activity of issuing qualifying stablecoins will not be subject to CASS 7 in relation to money held as backing assets, or other money arising from stablecoin issuance, although they may still be subject to other CASS chapters for separate business lines. Stablecoin issuers must also keep backing assets separate from money held under other CASS regimes, while firms safeguarding relevant specified investment cryptoassets will remain subject to CASS 6 for the time being.

      SYSC

      No change - cryptoasset firms will generally be treated as “other firms” under SYSC unless they are otherwise common platform firms. This means that cryptoassets firms will be have the same general organisation and governance requirements as ‘traditional’ firms.

      Senior Managers and Certification Regime (SM&CR)

      The FCA is proceeding with applying the SM&CR in full to authorised cryptoasset firms, subject to minor amendments to the Annex of SYSC 23. Given the wider SM&CR is under review, the FCA will use a modification by consent approach to avoid imposing requirements that may soon change. Assessment of Certification Regime compliance will therefore be deferred during the gateway until the Phase 2 SM&CR review changes have been finalised.

      The FCA has noted that it may approve Senior Management Function applications for individuals based overseas, for example where a group individual is responsible for implementing strategy in the UK entity. However, the regulators general expectation remains that the firm’s “mind and management” should be located in the UK, with particular attention to physical location for SMF16 (Compliance Oversight) and SMF17(Money Laundering Reporting function)applications.

      The final position also removes the requirement for individuals involved in backing asset management for stablecoin issuance to be certified under the proprietary trader certification function.


      See our article on SMCR for crypto firms here: UK Cryptoasset Regulatory Regime: Senior Managers & Certification Regime (SM&CR)

      Operational resilience

      The FCA is proceeding with applying SYSC 15A to cryptoasset firms without change and will not treat permissionless DLTs as outsourcing under SYSC 8.

      The final non-Handbook guidance FG26/6 provides additional clarity on outsourcing expectations, setting impact tolerances, mapping exercises, scenario testing and communications, supported by examples of emerging and established good practice from industry. An additional illustrative example of a firm arranging deals in qualifying cryptoassets to show how operational resilience requirements could apply in practice has also been added to the guidance.

      Later this year, the FCA intends to consult on non-Handbook guidance on operational resilience for DLT use, aimed at helping firms manage DLT-specific operational and technological risks across both permissionless and permissioned use cases.

      See our detailed summary of the Operational Resilience rules here: Operational resilience for cryptoasset firms

      Financial crime

      No change – the FCA is proceeding with its proposal to apply the financial crime elements of SYSC 6, together with the Financial Crime Guide and Financial Crime Thematic Reviews, to cryptoasset firms.

      COBS

      The FCA has made some targeted refinements to the application of COBS which sets out the cored standards governing how firms interact with clients.

      For CATPs: COBS will be disapplied for non-UK users of overseas-incorporated UK-authorised QCATPs operating via a branch, based on the user’s habitual residence or country of establishment.

      Additional guidance has also been added under COBS 6 (Information about the firm) to support consumer understanding.

      The FCA has provided further clarification on appropriateness under COBS 10 and plans to consult further on how strengthened appropriateness requirements should apply to existing clients. It is also disapplying COBS 16 client reporting requirements for staking activities, while otherwise proceeding with the remaining COBS proposals.

      ESG

       The FCA is proceeding with its proposal to apply the ESG Sourcebook requirements in ESG 4.1.1R and ESG 4.3.1R to all cryptoasset firms. These rules prevent cryptoasset firms from using sustainability labels and require cryptoasset firms to ensure that any sustainability references are clear, fair and not misleading, However, it will not extend ESG provisions that are designed for specific firm types, such as asset managers, asset owners and distributors, where those provisions are not relevant to cryptoasset firms.

      Dispute resolution

      The FCA is proceeding with applying DISP 1 complaint-handling requirements to all cryptoasset firms, subject to any relevant exemptions. It has adjusted the proposed wording for third-party complaint forwarding so that complaints must be forwarded “promptly” rather than “immediately”.

      The final position also confirms that non-UK clients will not have access to the Financial Ombudsman Service and that FSCS protection will not be extended to cover cryptoassets.

      Reporting

      From go-live firms will be expected to submit all existing returns which are not specific to cryptoasset firms , baseline returns, the crypto-specific returns developed ahead of commencement in conjunction with firms, and the applicable prudential reporting.

      A demonstration form is to be published by the regulator as an example after the application period closes but before gateway opens. Along with their returns firms may also submit additional supplementary questions. There will then be post implementation refinement after which the regulator will launch a consultation.

      Relevant to Stablecoin Issuers, Lending and Borrowing activities, Intermediaries and CATPs

      For admissions and disclosures, the FCA has made targeted changes to clarify and refine the regime while keeping the core policy approach intact.

      The final rules:

      • Introduce the Specified Digital Token Identifier standard
      • Clarify the scope of the exception to the qualifying cryptoasset due diligence requirements, and provide further detail on withdrawal rights notifications.
      • The FCA has also clarified admissions criteria, due diligence requirements and the triggers for supplementary disclosure documents, while limiting the application of certain requirements to UK qualifying cryptoasset trading platforms to support retail investment.

      For the Market Abuse Regime for Cryptoassets, the FCA has largely maintained the approach consulted on in CP25/41, with the final rules remaining substantially unchanged.

      The regime continues to place a more significant role on UK QCATPs and intermediaries than exists under UK MAR, reflecting the FCA’s view that these firms are best placed to monitor activity on their own platforms and among their customers and employees. The FCA has also retained the threshold for on-chain monitoring and cross-platform information-sharing requirements, while preserving proportionality for firms.

      The FCA notes the relative nascence of cryptoasset markets means that some residual market abuse risk is likely to remain higher than in more established markets, reinforcing the need for ongoing monitoring and iterative refinement of the regime as the market evolves.

      See our detailed summary of the MARC proposals here: Market Abuse Regulation for Cryptoassets

      Preparing for authorisation

      The final rules give firms a clearer basis for authorisation planning ahead of the gateway opening in September. For most firms, the impact of any changes will not require most firms to restart preparation, but to sharpen it. Work already undertaken should remain broadly relevant, but firms should now test their application materials, governance arrangements, prudential models, stablecoin controls and customer-facing processes against the final requirements. The areas that were previously uncertain, such as the application of ESG requirements, have now been clarified, allowing firms to move from interpretation to implementation. Firms that use this period to evidence readiness, close policy and control gaps, and demonstrate how their business model meets the FCA’s expectations will be better placed to navigate authorisation and implementation with confidence.

      How KPMG in the UK can help

      KPMG professionals have extensive experience helping firms apply for FSMA Part 4A permissions.

      Our insights

      Sign up for the latest regulatory insights shaping the future of financial services – delivered straight to your inbox.

      Our people

      Kate Dawson

      Capital Markets, EMA FS Regulatory Insight Centre

      KPMG in the UK

      Nicholas Mead

      Partner, Financial Services

      KPMG in the UK