Set in stone: Five landmark crypto Policy Statements
On 30 June 2026, the FCA published five Policy Statements containing finalised rules for cryptoasset firms: PS26/9 (admissions, disclosures and market abuse regime for cryptoassets), PS26/10 (stablecoin issuance), PS26/11 (regulated cryptoasset activities), PS26/12 (the prudential regime for cryptoasset firms) and PS26/13 (application of the wider FCA Handbook for regulated cryptoasset activities). These FCA rules will provide the underlying detail supporting the new UK Cryptoasset Regulations 2026, which is expected to commence on 25 October 2027.
The following materials were also published on 30 June 2026, which we plan to cover separately:
- finalised non-Handbook FCA Guidance related to the Consumer Duty’s application to regulated cryptoasset firms (FG26/5), operational resilience (FG26/6) and its approach to regulating international cryptoasset firms (FG26/7);
- an additional FCA consultation paper containing draft non-Handbook Guidance, which relates to the overall risk assessment required under the new prudential rules for CRYPTOPRU firms (GC26/5); the consultation period closes on 30 July 2026; and
- a Bank of England and FCA joint approach paper outlining how they intend to regulate systemic stablecoin issuers in the UK.
This briefing takes each of the five Policy Statements in turn and focuses on what changed between consultation and the final rules. For in-depth summaries of the FCA’s earlier proposals, see our previous posts. The FCA also notes that there will be subsequent consultations, including on financial crime requirements through updates to the Financial Crime Guide, on the resolution of crypto custodians and on tailored DeFi guidance.
One practical point to be aware of: existing MLR registrations will not automatically convert to equivalent Part 4A permissions when the regime comes into force, so firms already carrying on business in the UK (and those that plan to) should start preparing their applications now so that they can submit once the application window opens on 30 September 2026 (that window is scheduled to close on 28 February 2027).
To help guide you through the multitude of publications, we’ve summarised the recent publications in a mapping table set out in our separate post.
PS26/9: Admissions, disclosures and the market abuse regime
PS26/9 finalises the admissions and disclosures regime (A&D) governing how a cryptoasset is brought onto a UK trading platform and related disclosures, as well as the market abuse regime for qualifying cryptoassets (MARC). It finalises proposals consulted on in CP25/41, together with related financial-promotion points that were consulted on separately in CP26/4. The FCA has, in its words, “largely maintained the approach consulted on, while making targeted refinements to improve proportionality, clarity and operability”.
The key changes in the final rules relate to: proportionate due diligence, clarifying the admission criteria, a refined trigger for supplementary disclosures, a mandated digital token identifier (DTI) standard across both regimes, strengthened withdrawal-right notifications, and the removal of the fungibility exception so that a qualifying cryptoasset disclosure document (QCDD) is needed for every in-scope token before admission. On market abuse, the industry-led model and the £10m large-platform threshold are retained, with on-chain monitoring narrowed and legitimate market practices refined. Global firms should note that the FCA has clarified that the £10m large-platform threshold applies to total group revenue across all activities and jurisdictions.
The FCA intends to consult in September 2026 on a proposed deferral of the A&D regime for cryptoassets already in circulation at the point that the wider crypto regime comes into force, although work is continuing on this and it remains subject to change.
Admissions and disclosures
The core A&D regime remains largely unchanged, although the rules have been restructured, effectively to limit the application of most of the A&D rules to UK qualifying cryptoasset trading platforms (QCATP) which allow retail investors to trade. Under the previous proposals, most A&D rules applied broadly with express exemptions where trading was limited to qualified investors. The final rules instead focus the regime on retail-facing platforms, “limiting the application of most A&D rules to UK QCATPs that allow retail investors to trade”. As a result, the proposed “broad exemptions for qualified investor-only trading are… no longer needed, except where a UK QCATP limits trading in a specific asset to non-retail investors”. The core principles are that a UK QCATP may only admit a qualifying cryptoasset if it is reasonably satisfied that it is not likely to be detrimental to the interests of retail investors and that the QCDD meets the relevant conditions.
Admission process
UK QCATPs may not admit a qualifying cryptoasset to trading unless reasonably satisfied that the admission is not likely to be detrimental to the interests of retail investors. A UK QCATP’s decision on whether to admit a qualifying cryptoasset to trading will be based on its due diligence assessment. UK QCATPs must put in place and use admission criteria to support that assessment.
Admission criteria
A UK QCATP must establish and publish its admission criteria, consistent with IOSCO Recommendation 6 (i.e. recommended international standards for securities regulators), but is not obliged to publish detailed methodologies or individual rejection decisions. At a minimum, the admission criteria should take into account the non-exhaustive factors in CRYPTO 3.2, which provide the basis for the retail investor detriment test.
Due diligence, verification of information and record-keeping
The FCA has made changes to the due diligence and verification requirements with a view to those being more proportionate. The FCA clarifies that while UK QCATPs must make reasonable enquiries and obtain sufficient information, they are not expected to guarantee an asset's performance or independently verify what cannot reasonably be checked. If information cannot be obtained, the UK QCATP should factor that in when assessing whether admission is reasonably unlikely to be detrimental to retail investor interests. During the FCA’s consultation process, a UK QCATP could proceed even where it could not verify information, provided it had made reasonable efforts and the gap was disclosed in the QCDD. That alternative has been removed, leaving only the “true and not misleading” test. The FCA guidance provides that a platform “may still be reasonably satisfied that the relevant information... is not misleading” where the QCDD states clearly and prominently that it could not be obtained or verified.
Qualifying cryptoasset disclosure documents
The consultation proposed that a QCDD be prepared before a token’s admission to trading, with limited exceptions – including a “fungibility” exception under which a new QCDD was not required to be prepared if the token was fungible with another token, and that other token was already admitted on the same platform under a QCDD that was published prior to admission. The FCA has removed this exception from the final rules because “retaining the exception could lead to inconsistent application across UK QCATPs and create a risk that cryptoassets with materially different features or risks are admitted without a QCDD”. The practical effect is a large increase in the number of QCDDs required, which the FCA’s own cost-benefit analysis estimates at around 200% (c. 250 rising to 750 in total, and around 50 rising to 150 a year), raising the entry cost for certain tokens (e.g. tokens launched on new blockchains).
On QCDD content, the outcomes-based framework is kept, with new guidance on the main categories of information that QCDDs (and supplementary disclosure documents (SDDs)) are expected to cover. Separately, a specific DTI, an ISO 24165 code that uniquely identifies a token, must now be included in QCDDs (or an alternative identifier where a DTI is unavailable). The FCA says this requirement is “intended to improve consistency and data quality while preserving the outcomes-based nature of the framework”, and it has “also included the option of an alternative identifier… where the specified DTI standard is not available”. The short summary of key information in each non-stablecoin QCDD proceeds “with targeted changes” but with no “standardised format, order or template” prescribed.
The protected forward-looking statements regime (PFLS) – a liability safe-harbour for forward-looking statements accompanied by content-specific information – is largely unchanged, but the rules are amended so that the accompanying information “does not need to be repeated each time the corresponding PFLS appears… as long as it appears immediately adjacent to at least one instance”. Withdrawal rights are retained on a two-working-day window, with notification strengthened so that “equivalent day-of-publication notification applies across both direct-offer and intermediary channels”.
Supplementary disclosure documents
The FCA has revised the trigger wording for an SDD. An SDD is required where, after a QCDD is published but before admission to trading, the person who produced the QCDD becomes aware of new information or a mistake or inaccuracy relating to the information included in the QCDD or any SDD, and the relevant matter may be material to a person considering buying or subscribing for the qualifying cryptoasset.
The market abuse regime
The MARC framework draws on UK MAR but there are adaptations, as the FCA considered that simply transposing UK MAR would not produce appropriate outcomes for consumer protection or market integrity. Essentially, insider dealing, the unlawful disclosure of inside information and market manipulation are prohibited, and firms subject to the regime must have appropriate arrangements to prevent, detect and disrupt these behaviours.
The FCA has largely maintained its policy approach and the final rules remain substantially unchanged, applying the insider-dealing, unlawful-disclosure and market-manipulation prohibitions to qualifying cryptoassets, supported by obligations to detect, prevent and report suspicious activity.
Inside information
On the disclosure of inside information, the FCA has clarified the obligation to disclose information does not in itself require a firm to proactively seek out information that is not already in its possession. The FCA agrees that the protection of the security of the issuer or token may constitute a legitimate interest for delayed disclosure and is amending the rules to make this clear, although delayed disclosure cannot be indefinite.
The required method of disseminating inside information has also been revised. The FCA has removed the explicit requirement for active dissemination although still considers that some form of active dissemination is likely to be needed to meet the standard under the Cryptoasset Regulations.
The list of legitimate market practices (LMPs), which will not be treated as market abuse, has been revised following consultation. The “legitimate reasons” practice has been removed from the list of LMPs – the proposal went beyond UK MAR because this practice is only a safe harbour in UK MAR when combined with an activity that the FCA has designated as an “accepted market practice”. The proposal in MARC was not limited to accepted market practices and it had a very broad scope, so this has been removed. Coin burning is also confined to being considered an LMP only under automatic, non-discretionary and pre-disclosed programmes.
Market abuse systems and controls
The systems-and-controls model remains industry-led: the FCA has confirmed that it will not perform the same central market oversight role as in TradFi markets (noting the continuous operation of cryptoasset markets, fragmentation across venues and the scale of global retail participation), leaving responsibility for detection and disruption with UK QCATPs and intermediaries. Several obligations are nonetheless expanded.
The Principle 11 duty to notify the FCA of matters it would reasonably expect to be told about has also been widened; the draft rules had said this would cover only activity a firm cannot deal with itself, but the final rules state that it includes, but is not limited to, such activity, with the FCA giving serious or repeated abuse as an example of information it would expect to be notified of.
Under Regulation 30(3) of the Cryptoasset Regulations, where an intermediary reasonably suspects actual or attempted insider dealing or market manipulation, the UK QCATP must be notified, rather than the FCA. However, the FCA also sets out guidance that intermediaries may be required to submit suspicious transaction and order reports to all UK QCATPs that trade that cryptoasset, not only the platform where the order was to be placed.
So-called “large UK QCATPs” will be required to participate in cross-platform information sharing and on-chain monitoring. Large UK QCATPs are those which have average revenue calculated at £10m or more per year, for the previous three years. Critically, revenue is measured across all of a firm’s activities rather than its UK or platform business alone: the FCA did not consider it appropriate to restrict the threshold to UK-only revenue or UK QCATP-only revenue on the basis that total revenue is a better indicator of a firm’s overall capacity across all aspects of compliance. This means that a relatively small UK branch of a non-UK venue (as permitted by the FCA’s approach to international firms) could be in-scope of the more onerous obligations.
PS26/10: Stablecoin issuance and the backing-assets regime
PS26/10 finalises the issuance regime for qualifying stablecoins (i.e. qualifying cryptoassets that seek to maintain a stable value by reference to a fiat currency), drawing on both CP25/14 and CP25/41. It sets the backing-asset, safeguarding, redemption and disclosure requirements for UK stablecoin issuers. Issuers that HM Treasury recognises as systemic are carved out of this regime and will be covered under a separate Bank of England and FCA approach, which this briefing does not cover.
At a very high level, the FCA has largely maintained the proposed framework with a few targeted refinements to improve clarity, operability and proportionality.
Backing assets
Overall, the backing-assets proposal is similar to the version consulted on. The final rules maintain the same range of permissible backing assets. Regarding redemptions, firms must consider the liquidity requirements so that they can meet redemptions within the T+1 timeline. The rules do not prohibit the use of tokenised versions of backing assets, but firms will need to ensure that their use complies with CASS 16 and any applicable custody requirements.
The main change compared to the consultation proposal relates to the backing asset composition requirement (which was known as the backing asset composition ratio during the consultation) (BACR). This only applies to UK stablecoin issuers that utilise expanded backing assets. The purpose of the BACR is such that firms calculate a minimum proportion of the total backing pool that needs to be held in core backing assets for any individual token issuance.
The consultation set out that the BACR was a percentage calculated by adding the peak estimated daily redemption amount over a 14-day forward time horizon to the core backing asset requirement (CBAR), dividing that figure by the total value of assets in the backing pool. Part of the BACR would be the requirement to hold a minimum proportion (5%) of their backing assets in on‑demand bank deposits, known as the on‑demand deposit requirement (ODDR). The proposal was to calculate the BACR every 14 redemption days. The CBAR is calculated by reference to firms’ historic redemption needs.
The FCA recognised that the requirement to estimate the daily redemption amount over a forward time horizon introduced complexity and implementation challenges to UK stablecoin issuers and has therefore simplified the calculation. The new rule, set out in CASS 16.2.25R, requires that the percentage of core backing assets in the backing asset pool is at least equal to the sum of the ODDR and the CBAR. Firms must calculate the BACR every redemption day.
Segregation, the statutory trust and custody
The statutory trust requirement will be implemented as proposed with a separate trust per product so that backing assets will be held separately for tokenholders and, if the issuer fails, fall outside its estate. Full backing is confirmed as being required from the moment of minting.
At consultation, an unconnected third-party custodian was required and intragroup custody was prohibited. The FCA will not proceed with that proposed prohibition on intragroup custody. However, to mitigate related risks, they have introduced a 20% limit on the value of the backing asset pool that may be safeguarded by intragroup custodians, with a disproportionality exemption. The issuer must also obtain an acknowledgement letter from each custodian confirming trust status before holding backing assets with them, which should be kept accurate and up to date.
Records, reconciliations and redemption
Most of the record-keeping and reconciliation proposals proceed, including daily internal and external reconciliations, though the consulted unallocated backing funds staging accounts are dropped (i.e. the earlier proposals requiring funds to be placed into unallocated backing funds before being transferred into backing funds accounts or funds’ own accounts). Where UK stablecoin issuers identify discrepancies in their backing asset pool, the same-day resolution requirement is retained but a limited excess is now permitted.
The redemption timeline has been revised, a change the FCA has made in response to competitiveness concerns. At consultation, the T+1 redemption window ran from receipt of a full redemption request, with know-your-customer and anti-money-laundering checks to be performed within the window. Under the final rules, the T+1 redemption timeline will commence when UK stablecoin issuers receive the UK-issued qualifying stablecoin being redeemed in their wallet rather than a full redemption request, with those KYC and AML checks completed beforehand, so that onboarding and screening delays no longer eat into the deadline. The timeline will not apply if it would lead to a breach of the money laundering legislation.
An issuer will still be required to put in place a contract between itself and anyone to whom it issues stablecoins. Regarding the legal mechanism which provides for legally enforceable obligations between the issuer and those that obtain UK-issued qualifying stablecoins on the secondary market, the FCA is not mandating which legal mechanism should be used. The practical point is that a person who acquires the coin from someone other than the issuer must still be able to redeem it, because the issuer’s redemption obligation must pass in law from holder to holder.
Disclosures and other issues
Issuers of UK stablecoins will be required to update their backing asset information, and information on the number of stablecoins in circulation, at least once every 3 months. This is a minimum, as firms can choose to update this information more frequently, for example where it better supports consumer understanding or market confidence. The annual independent review of the one-to-one backing statement is retained. Firms must update other general disclosure information when it would otherwise become inaccurate or misleading in line with firms’ obligations under the Consumer Duty.
Firms must retain disclosures for at least five years and provide earlier versions to holders on request.
A new disclosure requirement is introduced in the final rules: only custodians holding more than 20% of the asset pool have to be disclosed.
The prohibition on UK stablecoin issuers passing on interest or income from the backing asset pool to stablecoin holders is maintained. Interestingly, the FCA indicated that this did not receive a large number of challenges. However, the FCA confirms that the final rules do not prohibit third parties paying rewards to their own customers from their own account (although this must not involve interest or income from the backing asset pool). The FCA confirmed that since multi‑currency stablecoins are out of scope of being regulated as qualifying stablecoins under the final legislation, it will not address such stablecoins in its stablecoin rules.
PS26/11: Regulated cryptoasset activities
PS26/11 is the longest of the five Policy Statements and finalises rules consulted on in CP25/40, CP25/14 and CP26/4. It covers trading platforms, intermediaries, transparency, record-keeping, lending and borrowing, safeguarding of client cryptoassets, staking and decentralised finance.
There are five headline moves in PS26/11:
- principal dealers are no longer subject to pre-trade transparency requirements (in line with the updated approach for non-equity traditional finance) and best execution is confirmed as an arrangements-based obligation rather than a trade-by-trade requirement;
- retail lending and borrowing protections proceed with targeted collateral flexibilities;
- Client Assets Sourcebook (CASS) 17 will be taken forward broadly as consulted; however, it will not apply to the custody of relevant specified investment cryptoassets (RSICs) at this stage. Instead, custody of RSICs will remain subject to existing CASS 6 requirements for now;
- staking is amended to permit auto-staking with annual notification; and
- DeFi is regulated where there is an identifiable controlling entity, with tailored guidance to follow.
Trading platforms
The rules for trading platforms proceed largely as consulted. The FCA has confirmed that an overseas platform can be authorised through a UK branch alongside a UK legal entity although, where a firm seeks UK authorisation for an overseas QCATP via a UK branch, it will need to demonstrate why authorisation as a branch is appropriate for its business model and carefully assess the scope of UK regulatory requirements. If an overseas QCATP provides services through a UK branch, the Conduct of Business Sourcebook (COBS) and the dispute-resolution rules (DISP) would apply only to activities carried on with the platform’s UK-based users.
Access and operation rules are also unchanged, with two useful clarifications: a kill switch to halt trading need not extend across global activity, and settlement should be initiated within 24 hours of a trade. A consultation on an optional QCDD-deferral mechanism will follow in September 2026.
Intermediaries
The proposed best-execution rules, which broadly require firms to take sufficient steps to get the best available execution result for their client, will be retained.
As proposed, the FCA will also expect firms to check prices from at least three reliable UK-authorised execution venues (where available), but notes in the summary of PS26/11 that firms “are not required to execute on those venues or undertake mechanical transaction-by-transaction checks, provided they maintain effective overall arrangements supported by periodic post-trade analysis”. The three-venue check is guidance rather than a rule and the FCA has also clarified that this guidance is not intended to require a firm to execute a client order on the UK-authorised execution venues it has checked. The FCA has also clarified that the proposed best execution rules do not apply where UK QCATP operators are conducting matched principal trading on their own platform.
However, the message in the summary about the FCA not requiring execution on UK venues is inconsistent with some of the rules set out in Appendix 1 to PS26/11. CRYPTO 5.2.2R requires that firms “must ensure that, when executing orders or receiving and transmitting orders for execution for a client, the order is executed on a UK qualifying cryptoasset execution venue”, which applies to a retail client or elective professional client who is not an overseas retail client or overseas elective professional client (i.e., a UK retail or elective professional client). It is unclear whether this is always likely to be in a client’s best interests (e.g., if the total consideration is materially lower when trading on a non-UK venue) and presumably it does not apply if there has been a specific instruction from a client (firms are required to execute orders in line with specific instructions, under CRYPTO 5.4.13R). Furthermore, a firm arranging deals in qualifying cryptoassets must take all reasonable steps to ensure that the arrangements it provides only result in a UK retail or elective client’s order to be executed on UK-authorised venues. This is a change from the consultation approach - at consultation the requirement only applied to firms executing or transmitting orders and not to arrangements.
The order-handling rules have also been revised in that a firm must obtain express prior client consent before executing client orders outside a UK QCATP (see CRYPTO 5.4.26R(2)). This is slightly odd because the FCA’s description of this in its response to feedback is that “[w]here a firm’s order execution policy provides for the possibility that client orders may be executed outside a UK QCATP, a firm must, in particular, inform its retail or professional clients about that possibility. It must also obtain express prior client consent before proceeding to execute their orders outside a UK QCATP.” It is hard to square that explanation with the requirement in CRYPTO 5.2.2R which requires UK retail and elective professional client orders to be executed on a UK venue (perhaps it is intended to be a reference to non-UK retail and professional clients) and it is also inconsistent with the wording of the rule itself (which does not refer to retail or professional clients at all). In the absence of changes to the rules, we should follow the requirements of the rules themselves, rather than the purported explanation, but it seems somewhat inconsistent and may lead to different approaches.
Transparency, records and client reporting
The FCA has not proceeded with its proposal to require pre-trade transparency to the market from principal dealers. This aligns with recent changes to the systematic internaliser regime that applies to bonds and derivatives in traditional finance. Pre-trade transparency obligations now apply only to large platform operators (i.e., those with average annual revenues equal to or exceeding £10m). Post-trade transparency proceeds as consulted: all platform operators and principal dealers must publish trade information as close to real time as possible, and at most within one minute of execution, with deferrals clarified to cover time for a dealer to hedge large or illiquid positions.
Lending, borrowing and staking
The qualifying cryptoasset lending and borrowing rules proceed broadly as consulted. The FCA is proceeding with its proposal to require an appropriateness assessment for lending and borrowing services, which requires firms to assess whether the client has the knowledge and experience to understand the risks of the service, and a requirement to obtain the client’s express prior consent for each lending or borrowing transaction.
The FCA is also proceeding with its proposed rules on mandatory over-collateralisation of retail client loans and managing loan-limit levels. The FCA notes that it is proceeding with its rules requiring firms to seek prior express consent before the firm can supplement collateral on the retail client’s behalf up to 50% of the market value of the original collateral provided by the retail client at the commencement of the borrowing service. However, the FCA clarifies that retail clients may top up their own collateral above the 50% limit.
For borrowing, collateral posted by a retail client must be safeguarded, or arranged to be safeguarded, by the firm providing the service so that it is held on trust for the benefit of the client at all times. Ownership cannot be transferred to the firm or any other party, except where the firm takes ownership to discharge the indebtedness of the retail client. These rules effectively limit what firms can do with qualifying cryptoasset borrowing collateral, although the FCA considers that it should be possible for a firm to provide certain services as long as the relevant rules are complied with (there is guidance in the final rules that firms could provide a qualifying cryptoasset staking service for such collateral if certain conditions are satisfied (CRYPTO 9.6.10)). The position for non-retail clients is different: other than record-keeping and client reporting requirements, CRYPTO 9 does not apply to non-retail lending and borrowing, so a firm could take ownership of the collateral and use Title Transfer Collateral Arrangements (TTCA). For retail clients, TTCA is explicitly prohibited.
For staking (i.e. committing a client’s tokens to help operate a blockchain in return for rewards), the proposed requirement to obtain consent before each separate instance has been removed. Consent may instead cover a client’s existing and future holdings of specified cryptoassets, enabling auto-staking, although blanket consent covering unspecified assets is not permitted and firms must provide retail clients with certain information relating to the staking service they are using at least every 12 months.
Safeguarding client cryptoassets under CASS 17
The FCA has made several material changes to its proposed safeguarding regime. The key policy change, as noted above, is that RSICs are, for now, excluded from CASS 17 and will instead remain subject to CASS 6.
The FCA is retaining the exceptions to the requirement to safeguard client cryptoassets on trust that it consulted on. Broadly, these apply in certain circumstances for lending and for QCATPs, where necessary for other services, for transfers to other persons on express client instructions and where the client is indebted to the firm. The FCA has added a new exception where a firm holds a back-up key for a client who retains full control of the cryptoasset. The settlement float - a small buffer of client assets that a QCATP may hold outside the trust for the purpose of facilitating settlement - has been raised from 1% to 2% of each client’s cryptoassets, calculated per client and per cryptoasset class.
On reconciliations, firms must now immediately notify clients affected by a shortfall, and an alternative same-value asset may be used for illiquid shortfalls. Firms will still be required to promptly update records relating to a client’s means of access, however the FCA has dropped the proposed requirement for firms to conduct a daily review of each client’s means of access. The FCA also confirms it will take a technology-agnostic approach to private key management, rather than mandating specific technical solutions.
When appointing third parties, firms may not grant a security interest, lien or right of set-off to those third parties, meaning they cannot give those third parties claims over client assets.
Decentralised finance
For decentralised finance, the FCA confirmed it will proceed to apply its rules where a clear controlling person carries on the activities, with separate guidance on decentralisation to follow.
PS26/12: The prudential regime
PS26/12 sets out the final prudential regime for authorised cryptoasset firms. The regime broadly sets how much capital and liquidity an authorised cryptoasset firm must hold.
At its centre is the own funds requirement (i.e. the minimum regulatory capital a firm must hold), which is the higher of three measures: a permanent minimum requirement (PMR), a fixed overheads requirement (FOR) and an activity-based requirement built from a set of K-factors that scale with the risks a firm’s business actually generates.
The FCA flags three substantive changes from the version consulted on: (i) the K-factor for stablecoin issuance (K-SII) coefficient falls from 2% to 1% of stablecoins in issuance; (ii) simplifying the market risk framework; and (iii) introducing greater proportionality in the public disclosure regime. The FCA is separately consulting on non-Handbook guidance (GC26/4 and GC26/5) to support a firm’s overall risk assessment.
Own funds: Definition and deductions
All intangible assets will continue to be deducted from capital, as they cannot reliably absorb losses, and the FCA has confirmed this expressly includes cryptoassets classified as intangibles under the relevant accounting standards.
Firms must deduct holdings of a qualifying cryptoasset issued by, or where supply is controlled by, (i) the firm, (ii) a member of the firm’s group, (iii) a controller, shareholder or member of the firm, (iv) a director, other officer or employee of the firm, or of any member of the same group as the firm or (v) a “close relative” (as defined in the FCA Handbook) of any person in (iii) or (iv). This restriction is in place to prevent a firm from artificially inflating its capital position. However, “CASS 16 stablecoins” (any qualifying stablecoin which is part of a qualifying stablecoin product that includes a UK qualifying stablecoin) do not need to be deducted and nor do qualifying cryptoassets that are already fully deducted in accordance with another rule in COREPRU 3.3. Firms must calculate their holdings based on a gross long position.
Finally, it is worth noting that firms do not need to reapply for permission to recognise a capital instrument as CET1 if they already hold that permission under a similar regime, such as MIFIDPRU or the UK Capital Requirements Regulation.
Own funds requirements and the K-factors
The PMRs (ranging from £75,000 to £750,000 depending on activity) and the FOR (one-quarter of a firm’s relevant annual expenditure) are carried forward as consulted. There is one material addition to the final rules: a deduction from total expenditure for gas fees (the transaction fees paid to a blockchain network), permitting firms to deduct 100% of gas fees passed on to customers and 80% of the rest.
The first of three flagged changes is to K-SII - the charge for stablecoin issuance. The coefficient (i.e. the percentage multiplier applied to the relevant amount) has been reduced from 2% to 1% of average stablecoin in issuance; the FCA states that “other than this change the final rules are as consulted on”.
The second flagged change simplifies the K-NCP market risk framework, which captures the risk of changes in the value of cryptoassets a firm holds outside custody. At consultation, the framework used a more complex, multi-category model that the FCA accepted “could have added complexity to the requirement and could have had cliff-edge effects” and “could have produced inconsistent outcomes, with the same cryptoasset being treated differently across firms”. The final rules instead retain “a single position risk adjustment of 40%, applied to the net exposure value of each cryptoasset within scope” - that is, to the holding after permitted offsets. A cryptoasset that is either not admitted to a UK QCATP or that cannot be prudently valued in the trading book is not charged at 40% but is instead treated as intangible and deducted from regulatory capital in full.
Under the third flagged change, the risk factor for retail clients of 83.33% has been clarified such that it only applies to retail clients with negative-balance protection.
Concentration, liquidity and disclosure
On liquidity, the basic liquid assets requirement proceeds as consulted, but the provision of guarantees component has been narrowed so that it captures only formal financial guarantees a firm makes to clients rather than informal assurances.
The FCA has made two changes to its proposed public disclosure requirements. First, firms will no longer be required to disclose publicly their own funds threshold requirement or liquid asset threshold requirement. This proposal was informed by Pillar 3 style disclosures but would have been different from the approach under the equivalent framework in MIFIDPRU 8. Second, a new exemption is introduced so that, where the PMR is the binding component, the CRYPTOPRU 8 disclosure requirements do not apply (including group disclosures).
PS26/13: Application of the FCA Handbook
PS26/13 sets out how the existing FCA Handbook will apply to cryptoasset firms and comments on the proposed non-Handbook guidance, outlining the minimum standards that the FCA expects international cryptoasset firms requiring FCA authorisation to meet.
In short, the FCA confirms the existing Handbook applies to regulated UK cryptoasset firms, including the Consumer Duty, COBS, senior managers and certification regime (SM&CR), operational resilience and financial crime frameworks, which will be supported by finalised guidance (FG26/5 on the Consumer Duty, FG26/6 on operational resilience, FG26/7 on international firms).
The material changes in PS26/13 relate to the details of how certain rules and expectations will apply, including: (i) the branch route for dual-regulated firms; (ii) CASS 7 disapplied for firms carrying on the activity of issuing qualifying stablecoins; (iii) a UK qualifying stablecoin issuer will be subject to the Enhanced SM&CR regime when they hold £20bn in backing assets, calculated as a three‑year rolling average; (iv) the disapplication of COBS to non‑UK users of an overseas‑incorporated QCATP authorised in the UK via a branch; and (v) the FOS carve-out for non-UK branch customers of overseas-incorporated QCATPs.
Approach to international firms
The approach to international firms has been revised slightly. At consultation, international firms were generally expected to use a UK legal entity, with a branch permitted only in limited cases (essentially QCATP operators). However, the final position allows dual-regulated firms (that is, firms supervised by both the PRA and the FCA) to carry on cryptoasset activities from a UK branch, subject to PRA approval, meeting the threshold conditions and holding the requisite permissions. As such, the expectation to operate through a UK legal entity now applies only to solo-regulated firms. The related guidance has been finalised as FG26/7.
The Consumer Duty
The Consumer Duty applies to cryptoasset firms in full, subject to limited exemptions for A&D activities and for trading between participants on a UK QCATP. The disapplication to participant trading is implemented with no material change. The final rules do not apply the Duty to public offers and admissions to trading for qualifying cryptoassets other than UK‑issued qualifying stablecoins. The sector-specific guidance consulted on in draft as GC26/2 has been finalised as FG26/5, clarifying territorial scope, fair value, consumer support and understanding and distributor and manufacturer roles, including for UK stablecoin public offers and admissions.
Designated investment business and client assets
A material change is that firms issuing qualifying stablecoins now fall outside the ordinary client money rules in CASS 7 altogether; the FCA confirms that “under the final rules, firms carrying on the activity of issuing qualifying stablecoins will not be subject to CASS 7 at all, whether this relates to the money held as backing assets, or to any other money arising from stablecoin issuance”. Instead, backing assets will be subject to CASS 16 (as noted above).
The professional-client opt-out from the client money rules is disapplied, such that a professional client cannot contract out of CASS 7 protection for money held in connection with qualifying cryptoasset activities. The FCA considered that such activities carry heightened risks “given the extent of vertical integration and concentration of the market at present”, and that the case for bespoke professional-client arrangements was outweighed by the risks to market integrity and consumer protection, noting the feedback did not provide evidence that removing the opt-out would harm the market.
Custody of tokenised securities and similar regulated instruments does not move into the new cryptoasset safeguarding regime. Instead, firms safeguarding RSICs will be subject to CASS 6 (the CASS rules that apply to custody of assets), pending a longer-term review. This is a custody point only, so money arising from RSIC safeguarding may still fall within CASS 7. CASS 7 applies only to money the firm receives or holds that is due to clients, so it does not apply where returns are credited as cryptoassets rather than fiat, or where proceeds accrue directly to client-controlled wallets without the firm receiving or holding client money.
Finally, the mandate rules in CASS 8 will not apply to firms safeguarding cryptoassets within the meaning of Article 9N. The FCA draws the line on the meaning of “control”: in CASS 8, control “relates to the firm's authority to instruct or direct a client's assets”, whereas in Article 9N it “relates to the firm's ability to bring about a transfer of benefit of a client's cryptoassets”. One consequence worth noting: CASS 8 can still apply to non-custodial staking (where a firm stakes assets it does not safeguard) if it holds mandate authority to instruct on those assets, though the FCA notes its understanding that most current non-custodial models do not involve this type of authority.
The senior managers regime and operational resilience
The systems and controls and training and competence rules apply as they do to other FCA-authorised firms. Cryptoasset firms will be considered as ‘other firms’ in SYSC, unless they are otherwise common platform firms, and requirements will apply accordingly. On the SM&CR, which makes named individuals personally accountable for a firm’s conduct, the FCA has dropped its previous plans to treat backing-asset management as “proprietary trading”, which would have pulled it into the certification regime.
The most significant change is the threshold for the enhanced senior managers regime for stablecoin issuers. At consultation, this was set at £65bn of backing assets, but the final rules change that threshold to £20bn (as calculated as a three-year rolling average). The FCA notes that it has reviewed market data which indicates that although it is unlikely that any firms conducting stablecoin issuance will meet the new threshold when the regime commences in October 2027, over time this threshold will capture the most significant stablecoins within the FCA regime. The £100bn threshold for custodians is retained and the regime otherwise applies in full, although assessment of Certification Regime compliance is deferred during the gateway, by modification by consent, pending HM Treasury’s SM&CR review (and more certainty about the future of the Certification Regime).
On senior managers, we also note that the FCA has been quite specific in relation to the location of certain senior managers. The FCA states that: “[w]e may approve SMF applications for individuals based overseas, such as where an individual within the wider group is responsible for implementing the firm’s strategy in the UK entity. The general expectation when authorising a firm, and approving its SMF applications, is that ‘mind and management’ should be, and should continue to be, located in the UK. We particularly consider physical location when considering SMF17 and SMF16 applications. We expect the persons holding these roles will work from the firm’s principal place of business in the UK.” This is aligned with the FCA’s general approach to international firms, where the FCA typically expects senior managers who are directly involved in the firm’s UK activities to spend an adequate and proportionate amount of time in the UK.
Operational resilience rules in SYSC 15A, which broadly require a firm to withstand and recover from disruption, will apply to all cryptoasset firms. The FCA has added new examples of emerging and established good practices as guidance in FG26/6 and confirmed that permissionless distributed-ledger technology will not be treated as outsourcing.
Conduct, complaints and compensation
The territorial reach of the conduct rules has been narrowed. COBS will be disapplied for non-UK users of an overseas-incorporated platform that is authorised in the UK through a branch. The FCA expects that the relevant test for “non-UK user” will be the user’s habitual residence or having a UK place of business. The disapplication of COBS to non‑UK users of an overseas QCATP authorised in the UK via a branch is intended to be a proportionate approach which protects UK (retail) customers while preventing conflict with overseas requirements.
The financial promotions regime will retain the categorisation of qualifying cryptoassets as restricted mass-market investments (RMMIs) (i.e., the financial promotions classification that triggers risk warnings and the appropriateness test), although UK-issued qualifying stablecoins will not be categorised as RMMIs given their lower risk profile.
Authorised firms are currently required to apply appropriateness assessments where a retail client’s transaction in qualifying cryptoassets is prompted by a direct offer financial promotion, but they will also be required to assess appropriateness when offering qualifying cryptoasset lending or borrowing services to a retail client. The FCA intends to consult in September 2026 on deferral for existing clients.
COBS 16 (reporting information to clients) has been disapplied for staking activities, as well as certain other cryptoasset activities (e.g., operating a UK QCATP and dealing or arranging in qualifying cryptoassets). For staking, there will be a new requirement to notify retail clients of the staking service at least every 12 months.
On safeguarding-related disclosures, the FCA will require firms that are safeguarding cryptoassets on trust to provide clear, plain language disclosures so that clients can understand how safeguarding arrangements affect their protections and the risks they face. While cancellation rights are not applied to safeguarding firms, a new requirement obliges firms safeguarding cryptoassets to tell clients whether, and on what basis, they may terminate the firm’s safeguarding services. The FCA has also clarified that firms may use a single integrated set of systems, controls, policies, procedures, communications or contractual arrangements to discharge overlapping COBS and CRYPTO obligations, as long as these arrangements meet the requirements applicable to the firm.
The most significant change related to complaints impacts the jurisdiction of the Financial Ombudsman Service (FOS). The FCA has agreed a carve-out so that the FOS does not have compulsory jurisdiction over complaints by non-UK customers of overseas-incorporated platforms authorised via a UK branch. “Non-UK customers” will be identified as those not established or habitually resident in the UK. This essentially amounts to clarifying the FOS’s existing scope. However, absent the clarification, this could result in high volumes of complaints reaching the FOS, requiring triage and investigation, even if the complaints were ultimately determined to be outside its jurisdiction.
The FCA does not plan to extend the Financial Services Compensation Scheme (FSCS) to new regulated cryptoasset activities. The FCA has expressly chosen not to extend FSCS coverage to the safeguarding of RSICs (which will be a new regulated activity under the RAO, which will, as we have noted previously, require existing custodians of RSICs to vary their existing permission), which means that RSICs will be treated differently from their non-tokenised equivalents. The FCA acknowledges this similarity but believes that RSICs can be distinguished in several ways which mean that it is not appropriate to extend FSCS coverage to claims arising from safeguarding RSICs. That will mean that today, customers who have RSICs safeguarded by an authorised firm could have FSCS protection available, but after October 2027, that will not be the case. We expect that any custodians providing safeguarding of tokenised specified investments to “eligible claimants” (as defined in COMP 4.2) today will need to provide clear information about the reduction of protection in advance of October 2027.
