FCA PS26/9: Admissions & Disclosures and the Market Abuse Regime for Cryptoassets
- James Ross

- Jul 29
- 22 min read
Prepared by James Ross, Head of Advisory, denouement · 29 July 2026 · Source: FCA Policy Statement PS26/9 (June 2026), responding to CP25/41 and, on advertisements, CP26/4 · Read with PS26/10 (UK-issued qualifying stablecoins), PS26/11 (intermediaries and retail access), PS26/13 (Consumer Duty across the crypto regime), and the aggregate cryptoasset CBA.
The material considerations for UK QCATP operators, and for applicants to operate a UK qualifying cryptoasset trading platform.
1. Summary judgement
The FCA has not moved on architecture. It has moved on scope. The gatekeeper burden created by CP25/41 did not change in kind between consultation and final rules—it changed in volume, and the change is severe.
The single most consequential decision in PS26/9 is the removal of the proposed "fungibility" exception to the QCDD requirement. According to the FCA's own figures, this raises the number of qualifying cryptoasset disclosure documents required by the regime's implementation date from 250 to 750, and the ongoing annual volume from 50 to 150 (paragraph 4.11).
Every wrapped token, every cross-chain representation, every asset a platform previously expected to admit on the back of an existing disclosure now requires its own document, its own responsible person, and its own due diligence file.
The aggregate cost picture moves with it. Total quantified costs across the A&D and MARC package rise from £140.9m in the CP25/41 cost benefit analysis to £230.3m in the updated analysis, with the equivalent annual net direct cost to business rising from £16.4m to £26.8m (Tables 1 and 2). Market abuse systems and controls alone account for £124.8m of that total, up from £70m. Two drivers explain most of the increase: a larger in-scope firm population, revised from 180 to 325, and higher per-firm familiarisation costs, revised from £8k to £15k.
The strategic read for a platform operator is straightforward. The FCA rejected every material request for relief on the industry-led model, the £10m large-platform threshold, and transitional arrangements for MARC.
It granted relief in three narrow areas—the scope of on-chain monitoring, the removal of wallet addresses from insider lists, and the removal of "legitimate reasons" as a standalone legitimate market practice—the last of which is a narrowing of a safe harbour dressed up as a simplification. Where the FCA gave ground on the burden, it did so by shifting obligations rather than removing them.
We recommend that platforms should stop treating the QCDD as a listing artefact and start treating it as a production line. A firm that admits 150 assets a year under this regime is operating a disclosure factory with a statutory liability attached to each unit of output. That is an operating model question, not a compliance project.

2. The material considerations, ranked
The considerations below are ordered by our assessment of materiality to a retail UK QCATP operator—that is, by the combination of cost, liability exposure, and the difficulty of retrofitting compliance late. Regime labels indicate whether the point sits in the Admissions & Disclosures rules (CRYPTO 3) or the Market Abuse Regime for Cryptoassets (CRYPTO 4).
2.1 The "Disclosure Volume Shock": removal of the fungibility exception [A&D]
What changed
CP25/41 proposed that no new QCDD would be required where a cryptoasset was fungible with one already admitted to trading on the same platform and a QCDD had been published for that asset. The FCA has removed that exception from the final rules (response following paragraph 2.49) on the basis that "fungibility" was insufficiently clear and risked admitting assets with materially different features without asset-specific disclosure.
Why it is material
This is a 200% increase in QCDD volume, according to the FCA's own estimate. The FCA acknowledges the change bites hardest on wrapped tokens and cross-chain tokens (paragraph 4.11), and expressly accepts, in its competition assessment, that it raises barriers to supporting new blockchains: a platform must now bear QCDD production and review costs for the chain and every wrapped token on it, and "where the incentives of the blockchain owner and the UK QCATP do not align, this may lead to it being harder to get new blockchains supported" (paragraph 4.13 response).
The FCA's costing assumes roughly 90% content overlap between a repeat QCDD and the original, and therefore prices the marginal document at 10% of a unique one, and increases due diligence costs by 25%. That assumption is only achievable by firms that have built for reuse. A platform producing each QCDD as a bespoke document will not see the FCA's marginal cost—it will see close to the full cost, 750 times over.
What to do
Build a modular QCDD template with chain-level and issuer-level components that can be reused across wrapped and cross-chain representations, and an asset-specific layer that cannot be reused across representations. The FCA expressly permits drawing on existing information and other QCDDs, provided the document for that admission complies in its own right (response following paragraph 2.49).
Model the listing pipeline for 150 QCDDs per year and identify the volume at which the review function breaks. Reviewing and approving QCDDs is a platform obligation, not one that can be pushed to the applicant.
Reassess the commercial case for supporting new chains. The economics of chain support have changed, and the FCA has acknowledged as much.
2.2 The pre-admission test: a documented process is not a defence [A&D]
What changed
The rules have been restructured so that the core principle sits at the front: a UK QCATP may not admit a qualifying cryptoasset unless reasonably satisfied that admission is not likely to be detrimental to the interests of retail investors (CRYPTO 3.2, CRYPTO 3.3). The FCA has added a new rule requiring platforms to take reasonable steps to identify and obtain sufficient information to make that assessment, and has confirmed a reasonableness standard rather than a guarantee.
It has also recalibrated the criteria themselves. "Fitness and propriety" is replaced by "integrity and reputation", with guidance on legal proceedings, regulatory action and adverse public information; "sustainability" is replaced by "continuing viability"; and the obligation for admission criteria to take account of the "quality" of QCDDs has been removed.
Why it is material
The critical sentence is in the response following paragraph 2.34: when judging compliance with CRYPTO 3.2.1R, the FCA will consider whether the platform followed a robust and documented process, but “following such a process will not, by itself, be determinative". The platform must be able to demonstrate, in each case, the basis on which it was reasonably satisfied. This is a case-by-case evidential standard, not a systems-and-process standard. A well-drafted policy applied mechanically will not discharge it.
The FCA declined every request to prescribe a methodology, which leaves the calibration risk with the firm. Where a platform sets its published criteria loosely to preserve flexibility, it inherits the burden of explaining each admission decision on its facts; where it sets them tightly, it will be held to them.
What to do
Restructure the admission file so that it concludes with a reasoned conclusion signed by an accountable individual, rather than a completed checklist. The conclusion is the deliverable the FCA has said it will test.
Re-run the published criteria against the revised concepts—integrity and reputation, continuing viability—and secure fresh governing body approval. Publication on the website is mandatory; publication of detailed methodologies or individual rejection decisions is not.
Set record retention at 7 years, not 5. The rules require 5 years but permit the FCA to require up to 7 on request, aligned with CRYPTO 5 and 6. Operating two retention clocks is a false economy.
2.3 The verification standard tightened between CP and PS [A&D]
What changed
CP25/41 offered platforms an alternative route when information in a QCDD could not be verified: proceed based on reasonable efforts plus adequate disclosure, rather than being reasonably satisfied that the information was true and not misleading. The final rules remove that alternative. Only the "true and not misleading" test survives (response following paragraph 2.36).
The FCA replaces it with a narrower guidance path: the platform may still be reasonably satisfied that the information is not misleading, provided that the QCDD or SDD clearly and prominently states that the platform could not obtain or verify the information in question. Separately, the proposed investor detriment assessment report has been dropped in favour of a record-keeping obligation.
Why it is material
This is one of the few places where the final rules are harder than the consultation draft, and it is easy to miss because it is presented as a simplification. A rule-level safe harbour has become a guidance-level accommodation. The platform now has to reach an affirmative conclusion that the information is not misleading—the disclosure of the verification gap supports that conclusion but does not substitute for it. Where the unverifiable information goes to the heart of the asset, prominent disclosure will not save the admission.
What to do
Introduce a "Verification Gap Register" per admission, recording what could not be obtained or verified, what was done to try, and why the residual uncertainty does not make the document misleading. That register is the audit trail for both the QCDD assessment and the investor detriment assessment.
Standardise the clear, prominent unverified-information statement in the QCDD template and make it mandatory, not optional.
2.4 Where liability actually sits [A&D]
What changed
Nothing, and that is the point. The FCA declined to introduce split liability, reimbursement-and-recourse models, or a separate regulated disclosure vehicle. Responsibility rests with the person requesting admission, with the retail UK QCATP where it admits an asset of its own motion, and with each person who accepts responsibility and is stated in the document as doing so (response following paragraph 2.107). This applies even where there is no identifiable issuer.
Why it is material
Two distinct liability channels run through this regime, and they should not be conflated. First, statutory compensation under regulation 14 of the Cryptoassets Regulations, which attaches to untrue or misleading statements and omissions in a QCDD or SDD and reaches the platform whenever the platform is the responsible person. Second, the designated activity rules themselves, breach of which does not give rise to a right of action for damages under section 138D FSMA (response following paragraph 2.38). Due diligence failures are a supervisory and enforcement exposure; disclosure failures on own-motion listings are a civil compensation exposure.
"Own-Motion Liability" is therefore the exposure to manage. Every asset a platform admits on its own initiative converts it from a reviewer to an author, with the negligence standard and a reversed burden of proof that apply to statements that are not protected forward-looking statements. The FCA also confirms that the platform prepares and approves its own QCDD in those cases, with conflicts disclosed prominently, including in the summary of key information, and records kept of the mitigation measures applied.
What to do
Maintain a hard commercial distinction between applicant-led and own-motion admissions, and price the second accordingly. The rules do not mandate insurance—the FCA declined to include it as a regulatory cost on the basis that it is elective (paragraph 4.11)—but it is a board-level decision that should be taken deliberately.
Use the protected forward-looking statement regime deliberately where it is available. CRYPTO 3.7 gives a recklessness or dishonesty standard with the burden on the claimant, but CRYPTO 3.7.4R excludes anything included to comply with CRYPTO 3.4, the platform's own rulebook, or regulation 13(1). PFLS is a voluntary-disclosure tool, not a general shield.
Note the one drafting relaxation: CRYPTO 3.7.9R now allows the content-specific accompanying statement to appear immediately adjacent to only one instance of a repeated PFLS, with cross-references elsewhere, aligning with the proposed changes to PRM 8.2.3R consulted on in CP26/8.
2.5 MARC systems and controls: the industry-led model is confirmed [MARC]
What changed
Very little in principle, and that was the most strongly contested point in the consultation. The FCA maintained the industry-led framework in full, rejecting arguments that firms lack investigatory powers, a market-wide view, and cross-cutting information, and rejecting the proposition that commercial conflicts make platforms unsuitable detectors of abuse in their own order flow. It answers that continuous, fragmented, globally retail markets make centralised FCA surveillance impractical, and that regulation 30 of the Cryptoassets Regulations directs suspicious transaction and order reports to platforms rather than to the FCA in any event.
Why it is material
At £124.8m, this is the largest single cost line in the package, and four discrete changes made between CP and PS all increase the operating burden:
Price dislocation surveillance, applying to all platforms. Every UK QCATP—not only large ones—must be able to detect material and persistent dislocations between the price of an asset on its platform and the publicly available price on other markets and venues it reasonably considers material for price formation. The FCA introduced this as a counterweight to the narrowing of on-chain monitoring and assumes most platforms already do it commercially.
A wider Principle 11 notification duty. The draft rules confined FCA notification to activity a firm could not deal with itself. The final rules state that the duty "includes, but is not limited to" such activity, with the FCA expecting notification of serious or repeated abuse regardless of whether the firm has handled it. Firms that calibrated their notification triggers to the CP draft will under-report.
Employee investigation arrangements. Systems and controls must include arrangements with employees that support investigations into whether an employee has complied with internal controls or engaged in market abuse—for example, an employment contract term requiring wallet information on request. This replaces routine wallet address collection in insider lists and pushes the obligation into HR and employment documentation.
Event-driven audit. The annual assessment requirement in CRYPTO 4.7.31 and 4.8.37 is supplemented by a requirement to audit sooner where a risk of market abuse is identified. An annual cycle alone is no longer sufficient.
Two requests that firms had hoped would land were refused. There is no carve-out for non-price-forming activity, the FCA relying on the statutory definitions of inside information and market manipulation to do that work. And monitoring of external communications stays, the FCA taking the view that excluding it would leave significant gaps.
The inbound reporting problem
The FCA has clarified—as new guidance, in response to feedback that the point was unclear—that intermediaries may be required to submit suspicious transaction and order reports to every UK QCATP that trades the relevant cryptoasset, rather than only to the platform where the order was placed. The FCA expects intermediaries to know which platforms trade the assets they deal in as part of normal commercial operations.
For a platform that accepts a wide range of assets, this is an inbound volume problem that the CP did not price in. Every intermediary dealing in any of your listed assets is a potential source of reports about activity that never touched your platform, and each report requires your own assessment.
What to do
Stand up an inbound STOR triage function with defined service levels before go-live. Build it to receive volume from parties with whom you have no contractual relationship.
Re-baseline Principle 11 notification thresholds against the final "includes, but is not limited to" wording, and document the seriousness and repetition tests you apply.
Get the employment contract amendments into the HR cycle now. Contract variation across an existing workforce is slower than any system build in this list.
Note that SYSC 8 outsourcing is expressly available for elements of MARC compliance, subject to appropriate safeguards. The FCA raised it as a proportionality answer, and several RegTech providers are building for this regime—though the FCA will neither mandate nor endorse a solution.
2.6 The £10m large platform threshold survives intact [MARC]
What changed
Nothing, despite 42% of respondents opposing it. A large UK QCATP remains one with average revenue, calculated at 12-month intervals, of £10m or more over the three previous years. The FCA declined to restrict the measure to UK revenue or to revenue derived from operating the platform, on the basis that total revenue better indicates overall compliance capacity. It declined to substitute or supplement trading volume, market share, user numbers or asset mix. Its modelling showed £10m captures 95% of the current market by revenue while excluding firms for which the controls would be disproportionate.
Why it is material
Group-wide total revenue is the test. A UK platform with modest domestic revenue inside a large international group is a large UK QCATP. It carries over on-chain monitoring and cross-platform information-sharing obligations from day one. Firms sitting near the line need a three-year forward projection and a governance trigger because the obligations attach to a rolling three-year average and cannot be built up quickly. The FCA explicitly anticipated firms "legitimately" managing activity around the threshold and accepted that risk rather than removing it.
On-chain monitoring, as narrowed
This is the clearest relief in the paper. Large platforms are no longer required to continuously monitor the entire chain. The obligation is now confined to wallets linked to the platform—wallets holding assets bought or sold there, and wallets reasonably identifiable as associated with platform users through clustering analysis or information received from intermediaries or other platforms—and monitoring is triggered by an identified risk of market abuse rather than running continuously. The FCA also removed the express proportionality wording, on the basis that proportionality already applies to systems and controls generally.
Cross-platform information sharing, as retained
Large platforms must share information with other large platforms when they have reasonable grounds to suspect that market abuse has occurred, is occurring, or is likely to occur, and disclosure is necessary to prevent, detect, or disrupt it. The FCA refused to prescribe common data fields, refused to coordinate a technical solution, refused further guidance on "necessity" and "proportionality", and refused a transitional period outright—"we do not intend to delay implementation".
Two operational points are worth extracting. Civil liability, for breach of confidence or defamation, is excluded where the specified conditions are met and the sharing was in good faith, drawing on the Economic Crime and Corporate Transparency Act model. And there is no requirement to establish that the subject is active on the recipient platform before sending—a user abusing one venue may register on another later.
2.7 Inside information: platforms are disclosure obligors [MARC]
What changed
The FCA confirmed that disclosure obligations under regulation 26 extend beyond issuers to offerors and UK QCATPs, a deliberate departure from the issuer-only model in UK MAR justified by the absence of an identifiable issuer for many assets. It rejected limiting platform obligations to own-motion admissions.
It made one significant clarification in firms' favour: the disclosure obligation does not, by itself, require a firm to seek out information it does not already hold. It made one significant concession on delayed disclosure: protection of the security of the issuer or the token is a legitimate interest, so disclosure of a code vulnerability may be delayed. At the same time, it is contained and remediated—but not indefinitely, because susceptibility to security breaches is itself likely to be significant to investors.
Why it is material
The "no duty to seek out" clarification is narrower than it first reads. The FCA states plainly that it "does not affect other obligations to obtain such information, such as under the A&D rules or our outsourcing rules". A platform that is required by CRYPTO 3 to take reasonable steps to obtain information for its pre-admission assessment cannot then claim it does not hold that information for MARC purposes. The two regimes interlock, and the interlock runs against the firm.
On dissemination, the FCA has created a trap for the literal-minded. It removed the explicit requirement for active dissemination from the rules, requiring publication on the platform's own website where it has one—but stated in guidance that "some form of active dissemination is likely to be needed to meet the standard under the Cryptoassets Regulations". The rule got shorter; the standard did not. Website-only publication is unlikely to discharge the statutory obligation to disseminate in a way that reaches a wide range of likely investors.
Disclosures must subsequently be uploaded to the FCA-owned centralised repository as soon as possible, with a digital token identifier included as metadata. The FCA declined to set a fixed time limit for that upload, to mandate prominence on the website, or to require press notices where there is no website. It also declined to publish a roadmap for convergence with UK MAR—the differences are structural and are not expected to converge in the near term.
Guidance on the examples
The stablecoin example has been refined from "viability" and "instability" to the ability to maintain intended value or fulfil redemption requests. A new example covers changes to market-making arrangements and the addition or withdrawal of liquidity providers. The FCA confirmed that routine technical updates and routine personnel changes will not generally meet the significant price effect threshold, and declined to add a catch-all example on the basis that the list is already non-exhaustive.
2.8 Identifiers, filing and the repository: the plumbing [A&D / MARC]
The FCA has specified a particular digital token identifier standard and introduced a defined term that applies across both A&D and MARC, with an alternative identifier permitted where the specified standard is unavailable, and the relevant conditions are met. This is the one place where the FCA moved towards standardisation, preferring not to mandate a machine-readable disclosure format at this stage.
The operational consequences for a platform are cumulative, and none of them is difficult in isolation:
Obtain and maintain a legal entity identifier, where eligible, with "issued" registration status on the GLEIF Global LEI Index. Without it, you cannot use the FCA repository, and registration and submission may run through the Electronic Submission System.
Upload every approved QCDD and any SDD to the FCA-owned centralised repository before trading starts, and publish the same documents on your website—by the time an offer starts where the offer is conditional on admission, and before admission in all other cases.
Maintain and publish an up-to-date list of QCDDs and SDDs for all assets admitted on the platform.
Include the required disclaimer making explicit that QCDDs and SDDs do not require FCA approval and have not been approved by the FCA. This is a new requirement introduced in response to concerns about regulatory signalling.
Tag inside information disclosures uploaded to the repository with a DTI as metadata to align MARC filings with the A&D identifier requirement.
The FCA expects the filing to be "straightforward" and declined to add prescriptive requirements regarding timing, version control, timestamps, change histories, or an authoritative source of record. That absence of prescription is not an absence of obligation: where the repository record and the website record diverge, the platform owns the problem.
2.9 SDDs, withdrawal rights and the feedback loop into admission [A&D]
What changed
The materiality threshold for a supplementary disclosure document is unchanged, but the trigger has been redrafted. An SDD is required where, after a QCDD is published but before admission to trading, the person who produced the QCDD becomes aware of new information or a mistake or inaccuracy relating to information in the QCDD or any SDD. The matter may be material to a person considering buying or subscribing for the asset. Guidance ties materiality to regulation 13(1)(a) to (f)—features and risks, stability mechanisms, connected persons, control arrangements affecting price or value, and underlying assets.
The FCA has confirmed emphatically that this is a pre-admission mechanism only. It creates no ongoing obligation to update a QCDD after admission; post-admission transparency runs through MARC. The summary of key information must state clearly that an SDD may be published only before admission.
On withdrawal rights, the window remains two working days from publication of the SDD unless extended. The FCA amended the notification requirements so that equivalent day-of-publication notification now applies across both direct-offer and intermediary channels, having accepted that withdrawal rights are worthless if investors are not told.
Why it is material
The FCA added guidance that materially changes the risk profile of a late SDD: information that comes to light before admission—including anything disclosed in an SDD or any failure to comply with the withdrawal rights notification requirements—may affect the platform's pre-admission assessment. A notification failure by an applicant or an intermediary is no longer only their problem. It feeds back into whether the platform can be reasonably satisfied that admission is not likely to be detrimental to retail investors, which is the gateway test the platform itself must satisfy.
Platforms should therefore treat SDD publication as an event that reopens, rather than merely supplements, the admission decision.
2.10 Legitimate market practices: a safe harbour narrowed [MARC]
What changed
The FCA removed "legitimate reasons" as a legitimate market practice in its own right. It reasons that the CP proposal went substantively beyond UK MAR, where the equivalent text provides a safe harbour only in combination with an FCA-designated Accepted Market Practice—a power the FCA has never exercised. Because the definition of "legitimate reasons" is largely unrestricted, the FCA judged it created a risk that abusive behaviour would be permitted and that firms would interpret it inconsistently.
Why it is material
This is presented as reducing the investigative burden on firms, and in a narrow sense it does—there is one fewer exception to assess. But it removes a broad defence that firms responding to the cost survey may have assumed would be available. The FCA acknowledges this directly: "Some firms may incur limited cost implications if they answered our cost survey on the basis that they could apply this exception more broadly" (paragraph 4.11). Conduct that would previously have been assessed against a general legitimate reasons test must now be assessed against the base statutory definitions of insider dealing and market manipulation.
What survives
Coin burning, in two forms. Where burning is an automatic function of a protocol or otherwise non-discretionary, it is a legitimate market practice provided the burning mechanism has been publicly disclosed—with no time or quantity limit, and no requirement that it form part of a trade or transaction. Discretionary burning retains the requirement in CRYPTO 4.11.5 to specify the burn period, and now explicitly requires publicly disclosing burning plans before execution. The "sole purpose" condition is confined to burning done to support the effective functioning of the market by reducing the amount in circulation.
Crypto-stabilisation, permitted for 30 calendar days post-offer, with disclosure obligations, modelled on traditional finance stabilisation.
Maximal extractable value, staking, market making, and governance participation were all requested as additional legitimate market practices and were all refused. The FCA's position is that these do not ordinarily constitute market abuse unless conducted abusively, and are better handled through the base definitions—CRYPTO 4.4.14 already addresses the use of inside information for market making. On MEV specifically, the FCA warned that designation "may risk normalising behaviours that could undermine fair and orderly cryptoasset markets".
2.11 Consumer Duty disapplied, and where it still bites [A&D]
The Consumer Duty is disapplied for the designated activities under regulations 7 and 8 of the Cryptoassets Regulations by amending the definition of "retail market business". In its place, CRYPTO 3.4.3R imposes consumer understanding requirements aligned to PRIN 2A.5.3, with the advantage that they apply whether or not the person responsible for the QCDD is FCA-authorised. Minor drafting changes clarify that the requirements relate to the presentation of information.
The disapplication is narrower than it sounds. It reaches QCDDs and SDDs, which are separately exempt from the financial promotion restriction under the amended article 70 of the Financial Promotion Order. It does not reach a firm's communication or approval of financial promotions likely to be received by a retail customer, and PS26/13 applies the Consumer Duty across the cryptoasset regime for authorised firms in any event. For an authorised platform operator, the Duty is disapplied for two documents and applies to almost everything else.
The advertisement rules in CRYPTO 3.12 sit alongside COBS rather than within it. Advertisements relating to public offers and admissions where a QCDD is required must identify the relevant QCDD, advise consumers to read it, and be consistent with the QCDD and any SDDs. The final rules dropped separate requirements for retail communications, aligning scope with CRYPTO 3.3.1R. Only written electronic advertisements must carry a hyperlink; advertisements need updating after an SDD only if they have become misleading; and amendments to oral advertisements need not be disseminated in the same way as the original.
3. What the FCA refused
The refusals matter as much as the changes, because each represents an exposure that firms asked to have removed and will now have to carry. In summary:
Request | FCA position in PS26/9 |
|---|---|
A central FCA surveillance and STOR-receipt role | Refused. Continuous, fragmented, globally retail markets make it impractical; regulation 30(3) directs intermediary reports to platforms, and the FCA cannot change that. |
A transitional period for MARC systems and controls or cross-platform sharing | Refused. "We do not intend to delay implementation." |
Raising or re-basing the £10m threshold | Refused, though kept under review. Total group revenue, not UK or platform revenue. |
Prescribed data formats for cross-platform sharing | Refused. Data protection assessments are firm-specific, and alerts require individual review. |
Guidance on "proportionate", "necessity" and "proportionality" | Refused as inherently fact-specific. |
Split or alternative liability models for QCDDs | Refused. Clear single-point responsibility is treated as fundamental to the compensation regime. |
Exemptions for well-established assets with extensive public information | Refused. Asset-specific disclosure is the gateway safeguard. |
Excluding external communications monitoring; carve-out for non-price-forming activity | Both refused. The statutory definitions are treated as doing the limiting work. |
A published roadmap for convergence with UK MAR | Refused. Differences are structural and not expected to converge in the near term. |
One general safety valve is worth recording: the FCA added guidance to both CRYPTO 3 and CRYPTO 4 reminding firms of its general power under section 138A FSMA to waive or modify its rules. That is an unusual signal to plant in a policy statement, and firms with a genuinely anomalous position should read it as an invitation rather than boilerplate.
4. Timing and open items
PS26/9 does not itself fix the commencement date for the regime; that sits with the wider cryptoasset package and the Cryptoassets Regulations. Three timing points are stated in the paper and should drive planning.
The A&D deferral consultation, September 2026. The FCA intends to consult on deferral arrangements for cryptoassets already in circulation when the wider regime comes into force, likely including a 6-month deferral of the relevant A&D requirements to reduce cliff-edge effects. Work is ongoing, and the FCA states it remains subject to change. Plan on the assumption that it may not arrive in the described form, and do not build a listing backlog that depends on it.
No deferral for MARC. The deferral discussion is confined to A&D. On-chain monitoring, cross-platform information sharing, price dislocation detection, insider lists, and inside information disclosure are all day-one obligations.
Rolling threshold measurement. The large platform test looks back over three previous years of average revenue. Firms should determine their status now rather than at go-live, because a firm that discovers it is in scope late has no runway.
The made rules are in Appendix 1 to the policy statement. Every CRYPTO reference in this memorandum is taken from the narrative of PS26/9. It should be confirmed against the final instrument before it is relied on in a policy document or a rulebook amendment.
5. Prioritised actions
Sequenced by lead time rather than by the order of the analysis above. Items in the first group have external dependencies and should start immediately.
# | Action | Driver | Owner |
|---|---|---|---|
1 | Determine large UK QCATP status on a three-year average total group revenue basis and record the calculation | £10m threshold | Finance / Compliance |
2 | Vary employment contracts to require wallet and related information on request in support of market abuse investigations. | MARC systems and controls | HR / Legal |
3 | Obtain or confirm an LEI with an "issued" status on the GLEIF index, and register it for repository submission. | Repository access | Company Secretary |
4 | Re-baseline the listing pipeline against 150 QCDDs a year; design a modula,r reusable template with a mandatory verification-gap field. | Fungibility exception removed | Listings / Product |
5 | Rewrite published admission criteria around "integrity and reputation" and "continuing viability"; obtain governing body approval; publish | CRYPTO 3.2 | Compliance / Board |
6 | Redesign the admission file to close on a reasoned, individually attributable conclusion rather than a checklist. | CRYPTO 3.2.1R evidential standard | Compliance |
7 | Build inbound STOR triage capable of receiving reports from intermediaries with no platform relationship, with defined service levels. | Regulation 30(3) clarification | Surveillance |
8 | Implement price dislocation detection against venues material for price formation, and document the venue selection rationale. | New requirement, all platforms | Surveillance |
9 | Recalibrate Principle 11 notification triggers to the "includes, but is not limited to" standard, covering serious or repeated abuse already handled internally. | Widened notification scope | Compliance |
10 | Scope linked-wallet, risk-triggered on-chain monitoring and cross-platform sharing arrangements (large platforms only) | CRYPTO 4.9 | Surveillance / Legal |
11 | Establish an inside information identification and delayed disclosure procedure, including the security-of-token legitimate interestin security-of-token and its limits. | Regulation 26 | Compliance |
12 | Set record retention at 7 years across due diligence, admission decisions, QCDD and SDD assessments, publication decisions and conflicts mitigation | CRYPTO 3 record keeping | Operations |
6. Our view
PS26/9 confirms a regime in which the trading platform is simultaneously the gatekeeper, the disclosure reviewer, the surveillance function, the recipient of the market's suspicious activity reports, and—on own-motion listings—the party carrying statutory compensation liability for the document it wrote and approved. No other participant in this market carries that combination.
We regard the FCA's core judgement as defensible. A centralised surveillance model for a continuously fragmented, globally operating retail market was never realistic within the available timetable, and the £10m threshold does keep the heaviest obligations away from new entrants. But the removal of the fungibility exception was treated as a disclosure-quality decision, and its consequences are structural: it raises the marginal cost of supporting a new chain, as the FCA has said itself in its competition assessment. The firms best placed to absorb 750 disclosure documents at go-live are the largest incumbents. Those are also the firms that are already over the £10m threshold and are already running blockchain analytics. The regime is coherent and not neutral about who wins.
The practical conclusion for a platform operator is that the compliance build is not the hard part—the operating model is. Firms that treat the QCDD as a document produced by the listings team will be capacity-constrained within a year. Firms that treat it as a manufactured product with reusable components, a version-controlled source of record, and a defined liability owner per unit will not.
Open
Commencement date for the wider regime, which PS26/9 does not state.
Whether the September 2026 deferral consultation proceeds on the 6-month basis described, and how it treats the backlog of assets a platform would have admitted under the removed fungibility exception.
Final CRYPTO numbering and drafting in the Appendix 1 instrument, against which the references in this memorandum should be checked.



Comments