UK crypto FSMA final rules: the 30 June 2026 package and the 30 September gateway

UK crypto FSMA final rules: the 30 June 2026 package and the 30 September gateway

On 30 June 2026 the FCA published its final rules and guidance for the UK cryptoasset FSMA regime, which will apply to cryptoasset firms granted permission to operate under FSMA on or after 25 October 2027. The package is for MLR-registered cryptoasset firms that need a new FSMA permission, already-authorised FSMA firms that need a variation of permission, payments and e-money firms, firms using s.21 approvers, and overseas firms serving UK customers. The relevant application period in the FCA’s direction of 20 February 2026 runs from 09:00 on 30 September 2026 to 23:59 on 28 February 2027.

Why operational teams should care

MLR registration does not convert. If you carry on a new regulated cryptoasset activity by way of business in the UK you will need Part 4A permission (or a variation). Firms that apply inside the direction window can use the SI saving provision if the FCA has not determined the file by 25 October 2027. Firms that apply after 28 February 2027, and are not authorised by full commencement, fall into the transitional provision by operation of law: pre-existing contracts only, no new UK customers. Firms that do not apply must run off before 25 October 2027 or they risk the general prohibition.

Operational consequences:

  • Activity mapping (stablecoin issuance, custody, trading platforms, dealing, arranging, staking, admissions and market abuse)
  • COREPRU / CRYPTOPRU: permanent minimum, fixed overheads, K-factors, liquidity, overall risk assessment; CASS 16 / 17 where those activities apply
  • A gateway file, financial-data template, and an optional PASS meeting

Read the statements from the overview page. Do not use guessed HTML slugs for the individual PSs.

Crypto FSMA requirements by business type

All firms carrying on regulated cryptoasset activities should read the Handbook-application and prudential statements; activity packs sit on top.

Firm type What to read (via the overview) Prudential floor to model first Official references
All CRYPTOPRU firms Handbook application, Consumer Duty, operational resilience, international-firms guidance, aggregate CBA Higher of PMR, FOR and K-factor requirement. Own funds under COREPRU Overview; PS26/12 PDF
UK stablecoin issuers Plus stablecoin issuance (backing assets, statutory trust, redemption, CASS 16) PMR £350,000. K-SII now 1% of average qualifying stablecoins in issuance (was 2% at consultation) Overview “Who needs to read what”; PS26/12 PDF Chapter 3
Cryptoasset custodians Plus safeguarding (CASS 17); CASS 7 for related client money. RSIC custody uses CASS 6 for now PMR £150,000. K-RCS 0.04% of average cryptoassets safeguarded (includes third-party delegates) Overview; PS26/12 PDF
Trading platforms (UK QCATPs) Plus regulated activities and A&D / MARC PMR £150,000. K-CCO / K-CTF at 0.1% of the relevant flow Overview table
Dealing as principal Plus regulated activities; K-NCP / K-CCD on the trading book PMR £750,000. K-NCP 40% of net position in prudently valued, UK-QCATP-admitted cryptoassets; others deducted from CET1 PS26/12 PDF Chapter 3
Dealing as agent / arranging Plus regulated activities PMR £75,000 PS26/12 PDF §3.4
Staking Plus staking disclosures, consent, record-keeping PMR £150,000. K-CCS 0.04%; if safeguarding and staking apply to the same assets, apply the safeguarding K-factor only Overview; PS26/12 PDF
Already-authorised FSMA / PSR / EMI firms Variation of permission Dual COREPRU + MIFIDPRU: highest PMR, COREPRU FOR, sum of K-factors. PRA-authorised persons sit outside the CRYPTOPRU firm definition Overview “What you need to do”; PS26/12 PDF Chapter 2
MLR-registered CASPs New FSMA application. No automatic conversion Same PMR / FOR / K-factor stack Gateway page

Operational tip: Own funds requirement is the highest of PMR, FOR and KFR, not the sum of those three. K-factors do add across activities.

Step-by-step: initial project plan

Step Action What operational staff must deliver Official reference
1 Lock the three dates SI made 4 February 2026; final rules 30 June 2026; full commencement 25 October 2027 New-regime hub; milestones
2 Lock the gateway from the direction 09:00 on 30 September 2026 to 23:59 on 28 February 2027. Direction dated 20 February 2026, regulation 52 Direction PDF
3 Map regulated activities One row per product and legal entity. That row drives which overview columns you read and which PMR applies Overview “Who needs to read what”
4 Stand up COREPRU / CRYPTOPRU CET1-heavy own funds; deductions (intangibles; own-issued tokens; non-QCATP / non-prudent positions). PMR by activity. FOR on whole-firm expenditure (gas fees: 100% if passed on, 80% otherwise). K-SII at 1%; K-NCP 40% where the tests are met PS26/12 PDF
5 Decide saving vs transitional vs run-off Apply inside the window if you need the saving provision. Late files are not expedited. No application means run-off before 25 October 2027 How the gateway will operate
6 PASS, form, webinars Optional PASS meeting — take a real business-model note or the request is rejected. Form live from 30 September 2026. Milestones page: PASS in July 2026. Webinars 7 / 11 / 15 / 18 / 22 / 29 September 2026 Gateway page; framework one-pager; new-regime hub
7 Track still-open guidance GC26/4 (COREPRU) and GC26/5 (CRYPTOPRU) sit alongside PS26/12. Resolution, financial-crime guide updates and reporting packs are later work on the overview page — do not invent close dates Overview “Prudential” and “What we will do”

Run a first pass on capital: FCA Crypto Prudential Readiness Diagnostic.

Practical checklist for operational teams

  • Permission matrix – Legal entity, activity, PMR, new authorisation vs variation. MLR number does not carry over.
  • Capital dashboard – PMR vs FOR vs each K-factor vs the binding OFR. Recalculate K-SII at 1%, not the consulted 2%.
  • Trading-book policy – 40% K-NCP only where the asset is admitted to a UK QCATP and can be prudently valued; otherwise CET1 deduction.
  • CASS map – CASS 16 for backing assets; CASS 17 for client crypto; CASS 7 for related client money; CASS 6 if you will safeguard RSICs at the outset.
  • Gateway file – Programme of operations, controllers, SM&CR, financial-data template, ICT/resilience.
  • Customer run-off plan – Dated path if you will not apply, or if you will miss the window.

Common operational pitfalls

  • Treating 30 June 2026 as the date you must already be authorised. Rules apply on or after 25 October 2027; the gateway is 30 September 2026–28 February 2027.
  • Citing a 30 June publication date from the PS26/12 PDF cover. The PDF says June 2026; the day is on the FCA HTML hubs.
  • Using guessed ps26-9ps26-13 HTML slugs. Those 404. Use the overview page and the PS26/12 PDF.
  • Applying after 28 February 2027 and assuming the FCA will catch you up. The gateway page says it will not expedite late files.
  • Summing PMR, FOR and KFR instead of taking the highest, or missing that dual MIFIDPRU firms add the two K-factor stacks.

How GRT Consulting can help

GRT Consulting supports operational teams with:

  • Activity-to-permission mapping and a COREPRU / CRYPTOPRU model against PS26/12
  • Gateway evidence packs (including variation-of-permission files)
  • CASS 16 / 17 operating models and saving-provision vs transitional vs run-off options against the direction clock

Start with the FCA Crypto Prudential Readiness Diagnostic. The regulatory agenda tracks the same 30 September 2026 / 25 October 2027 marks. Contact us: T: +44 20 3695 9251 E: info@grtconsult.com Web: grtconsult.com


Sources

.., 30th June 2026

GRT Consulting

Speak to us about how we can help you

T: +44 20 3695 9251

E: info@grtconsult.com

Submit Request for Proposal