The UK's new cryptoasset regulatory gateway is now open. The Financial Conduct Authority opened the relevant application period on 30 September 2026. It runs until 11:59pm on 28 February 2027, ahead of the new cryptoasset regime coming into force on 25 October 2027.
For UK crypto and fintech firms, this is more than a future compliance date. The FCA says firms carrying on the new regulated cryptoasset activities will need the appropriate FCA authorisation or, for an already authorised firm, a variation of permission. Firms that intend to rely on saving and transitional provisions need to understand the application-window rules now.
Three dates to put on the board
| Date | What it means |
|---|---|
| 30 September 2026 | The FCA cryptoasset authorisation application period opened. |
| 28 February 2027 | The relevant application period closes at 11:59pm. |
| 25 October 2027 | The new UK cryptoasset regulatory regime is due to come into force. |
Who should be checking the perimeter?
The FCA's perimeter guidance is relevant to firms carrying out or planning activities such as safeguarding cryptoassets, operating a cryptoasset trading platform, arranging deals and staking. It also specifically points to already-authorised firms, firms registered under the Money Laundering Regulations, payment service providers, electronic-money issuers, traditional finance firms exploring cryptoassets and overseas firms serving UK consumers.
That makes this a cross-functional exercise. Product teams need to describe what the service actually does. Compliance needs to map those activities to the perimeter. Finance needs to understand the capital, liquidity and safeguarding implications. Engineering and operations need evidence around resilience, security, transaction flows and controls.
MLR registration and FSMA authorisation are different things
A firm currently registered for anti-money-laundering supervision under the MLRs should not treat that registration as a substitute for the new FSMA permission. Likewise, a firm that is already FCA authorised for another activity may need a variation of permission if it wants to carry on a regulated cryptoasset activity.
Payment and e-money firms should review the interaction carefully. The FCA's published material makes clear that existing Payment Services Regulations or Electronic Money Regulations status does not automatically solve the cryptoasset authorisation question when the firm carries out an activity inside the new perimeter.
A six-step readiness check before submitting
- Map every cryptoasset product, customer journey and revenue stream to the FCA's published perimeter guidance and identify which regulated activities may be carried on.
- Decide whether the firm needs a new authorisation or a variation of permission, and document the legal entity that will perform each regulated activity.
- Prepare a business plan that matches the actual operating model, customer types, distribution channels, outsourcing and technology rather than a generic compliance description.
- Review governance, senior-management responsibilities, financial resources, safeguarding, operational resilience, cybersecurity, complaints and financial-crime controls against the standards that will apply.
- Assemble evidence early. Policies are stronger when they are supported by board minutes, risk assessments, reconciliations, incident processes, testing evidence and management information.
- Use the FCA's pre-application support and published materials where relevant, and obtain independent legal or compliance advice if the perimeter or permission strategy is uncertain.
Why applying early matters
The FCA says applications submitted during the relevant application period are reviewed in the order they are submitted and encourages firms to apply as soon as possible. Firms applying inside the window may, if the relevant conditions are met, be able to rely on saving or transitional provisions while an application is determined.
By contrast, the FCA warns that firms applying after the application period will not be able to rely on those provisions in the same way and may need to stop relevant activity until authorisation is granted. The practical lesson is not to treat 28 February 2027 as a target submission date.
What finance teams should prepare
Authorisation work often exposes gaps in finance operations. The application story should be supported by reliable management accounts, reconciled bank and safeguarding positions where relevant, clear revenue models, forecasts, liquidity assumptions, vendor commitments and evidence that management can monitor the business against regulatory obligations.
For a fintech, the strongest compliance narrative is usually the one that agrees with the operational data. If the business plan says one thing, the product flow another and the finance records a third, the inconsistency becomes a risk in its own right. Start by making the underlying records and responsibilities clear.
The next action is a scope decision, not a form
The gateway being open does not mean every fintech should rush to submit the same application. The first decision is whether the firm's current and planned UK activities fall inside the new regulated perimeter and which legal entity needs permission. Once that is clear, the application can be built around the actual business rather than around assumptions.
Sources and further reading
- What you need to do when preparing for the new cryptoasset regulatory regime — Financial Conduct Authority
- Cryptoassets: How the gateway will operate — Financial Conduct Authority
- Overview of our cryptoassets regime policy statements — Financial Conduct Authority
- PS26/18: Cryptoasset perimeter guidance — Financial Conduct Authority
- FCA opens the gateway to regulated crypto — Financial Conduct Authority
- Pexels licence — Pexels
Cherry Money
Make the operational evidence match the regulatory story.
Cherry Money helps finance teams keep invoices, banking, reconciliations and financial workflows in one auditable workspace while compliance teams prepare the wider authorisation evidence.
Article feedback
Was this article helpful?
Your answer helps the Cherry Money Editorial Team improve future articles.