Key Considerations for Cryptoasset Service Providers (CASPs): FCA Policy Statement PS26/11
- James Ross

- Jul 12
- 12 min read
REGULATORY REPORT
FCA Policy Statement PS26/11 — Crypto Regime: Regulated Cryptoasset Activities (June 2026)
Prepared July 2026 · Consolidated synthesis of Chapters 2–10
Executive Summary
PS26/11 sets out the FCA's final conduct rules and guidance for the UK's new regulated cryptoasset activities: operating a qualifying cryptoasset trading platform (QCATP), dealing and arranging (intermediation), pre- and post-trade transparency, record keeping and client reporting, lending and borrowing, safeguarding (custody), staking, and the FCA's current approach to DeFi. It is the centrepiece of a coordinated package of policy statements — PS26/9, PS26/12 and PS26/13 alongside PS26/11 — delivered under the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 (SI 2026/102), and its rule instruments come into force on 25 October 2027.
The consultation feedback (CP25/14, CP25/40, CP26/4) was broadly supportive, and the FCA has retained its overall framework while making targeted concessions: principal dealers have been removed from pre-trade transparency; best execution is confirmed as outcomes-based rather than a mechanical per-trade test; the safeguarding settlement float doubled from 1% to 2%; auto-staking survives (with guardrails); and burdensome daily reviews of private-key records were dropped. Against these concessions sit firm retail protections: mandatory UK execution venues, QCDD-gated retail asset eligibility, the effective end of PFOF, per-transaction consent and over-collateralisation for retail lending and borrowing, a retail ban on TTCA and proprietary tokens, and a new CASS 17 custody regime built on non-statutory trusts and daily reconciliations.
The strategic through-line is "same risk, same regulatory outcome": crypto business models are being pulled into TradFi-grade conduct standards, adapted for 24/7 markets and on-chain settlement. The FCA rejected essentially every request for lighter-touch treatment — for small firms, occasional dealers, or self-styled "decentralised" arrangements where a controlling person exists. With the authorisation gateway open from 30 September 2026 to 28 February 2027† and go-live on 25 October 2027, the preparation window is short, and applications must show controls that are embedded, not planned.

1. The Regime at a Glance: Status and Timeline
Legal foundation. The FSMA 2000 (Cryptoassets) Regulations 2026 (SI 2026/102), passed 4 February 2026†, create the new regulated activities. PS26/11 supplies the conduct rulebook (new CRYPTO sourcebook, CASS 17 and related Handbook material).
The wider package. PS26/9 (admissions & disclosures and the MARC market-abuse regime), PS26/12 (prudential: CRYPTOPRU/COREPRU), PS26/13 (cross-cutting Handbook application: Consumer Duty, COBS, SM&CR, DISP, reporting) and FG26/7 (international firms) all interlock with PS26/11 and must be read together.
Not yet settled. September 2026 consultations are expected on implementation deferrals (execution venue rules proposed to January 2028; asset admission/QCDD rules proposed to April 2028, including an optional 6-month QCDD deferral mechanism) plus further work on settlement and detailed DeFi guidance (late 2026). Deferrals remain proposals until confirmed.
Key dates
Date | Milestone |
|---|---|
30 June 2026† | Cryptoasset policy statement package published (PS26/9, PS26/11, PS26/12, PS26/13, with finalised guidance including FG26/6 and FG26/7); PS26/11 itself is dated June 2026 |
30 Sep 2026 – 28 Feb 2027† | FCA authorisation application window (pre-application support meetings available from July 2026†); deferral consultation expected September 2026 |
25 October 2027 | Rule instruments come into force; regulated cryptoasset activities require FCA authorisation. |
Jan / Apr 2028 (proposed) | Proposed deferred compliance dates for the execution venue requirement and asset admission/QCDD requirement (subject to consultation) |
† Sourced from FCA announcements and companion publications rather than the text of PS26/11 itself; PS26/11 refers to the authorisation gateway and the September 2026 consultations without stating these dates.
2. Cross-Cutting Themes
TradFi alignment, crypto adaptation. The rulebook imports MTF-style venue standards, COBS-style best execution and consent mechanics, CASS-style client asset protection and SI-style transparency — recalibrated for 24/7 markets (same-day reporting concessions), on-chain settlement (hash- and wallet-address record-keeping) and private-key custody (technology-agnostic "means of access" rules).
Retail/non-retail bifurcation. The heaviest obligations — appropriateness tests, express consent, disclosure documents, collateral restrictions, proprietary tokens and TTCA bans, staking disclosures — apply to retail (and in places, elective professional) clients. Institutional business maintains flexibility, but recordkeeping and client reporting generally apply across the entire book.
No lighter touch for anyone. The FCA rejected carve-outs for smaller firms, occasional dealers and niche models, reasoning that uniform standards stop bad actors migrating to less-scrutinised firms.
Substance over form. Perimeter outcomes turn on what a firm actually does — controlling person(s) in DeFi, "control" via means of access in custody, matched-principal look-throughs in intermediation — not on branding or technology choices.
Data architecture is now a regulatory issue. With no routine transaction reporting to the FCA, the evidential burden falls on firms: 5-year datasets, ISO 24165 DTIs, on-chain/off-chain linkage, named decision-makers, per-day staking records, daily custody reconciliations, and 1-minute trade publication all presuppose modern, integrated data pipelines.
Principles-based flexibility, firm-owned burden. Where the FCA grants discretion — waiver/deferral policies, algo-trading controls, LTV modelling, key-management arrangements — the firm carries the burden of defensible, documented, data-driven design.
3. Trading Platforms (QCATPs) — Chapter 2
Authorisation and UK presence. Operating a QCATP in the UK, or serving UK consumers from overseas, requires FCA authorisation and a UK presence; the overseas persons exclusion does not apply. Overseas firms may combine a UK legal entity with UK branch authorisation of the overseas entity — assessed on a case-by-case basis at the gateway — and a UK branch is not required to run a separate UK order book. COBS/DISP application is confined to UK users of branch-authorised platforms.
Venue neutrality. Operators must publish objective, non-discriminatory access criteria and non-discretionary execution rules; algorithmic trading is governed on an outcomes basis rather than by MiFID RTS 6-style prescriptions; kill-switch obligations protect UK users (no global override required); market-making relationships need not be contractual but must be documented, monitored, and publicly disclosed.
Retail token eligibility. Retail access is limited to UK-issued qualifying stablecoins or tokens admitted with an A&D-compliant QCDD; making new tokens available to retail via a QCDD is reserved for QCATP operators. An optional 6-month QCDD deferral for tokens already in circulation will be consulted on in September 2026.
Conflicts and credit risk. Matched principal trading is permitted within the same legal entity; a non-matched principal desk may sit in the same entity only with zero access to the group's own QCATP; affiliates may trade on-platform under non-discriminatory access and co-location rules; platforms may list tokens they hold interests in, subject to robust mitigations. Taking credit risk (beyond settlement risk) inside the operating entity is banned — legal entity separation is required where it arises.
4. Intermediaries: Dealing and Arranging — Chapter 3
The location policy. Orders for UK retail and elective professional clients must be executed on UK-authorised venues. Arrangers must take all reasonable steps to the same end; principal dealers cannot systematically or predominantly source liquidity from unauthorised overseas group QCATPs; matched-principal pass-throughs to offshore platforms are closed off. Retail-facing intermediaries should also expect UK legal-entity structuring requirements under the FCA's international firms guidance (FG26/7†).
Retail asset eligibility (QCDDs). Intermediaries cannot deal or arrange for UK retail clients unless the asset is admitted to trading on a retail UK QCATP in compliance with CRYPTO 3, and the QCDD (or stablecoin QCDD) must be made available to the client before the client initiates the transaction.
PFOF effectively closed off; functional separation. The FCA states that intermediaries engaging in payment-for-order-flow behaviours are unlikely to meet its best execution, conflicts of interest and inducement requirements when serving retail or professional clients — an effective bar on the PFOF revenue model, framed as a supervisory expectation rather than an express prohibition. Proprietary trading must be functionally separated from client order execution, with personal account dealing controls similar to COBS 11.7 and regard to the market-abuse systems and controls requirements under PS26/9's MARC regime.
Best execution. An outcomes-based framework: effective overarching arrangements, periodic monitoring and post-trade analysis. Guidance (not a hard rule) says firms should check at least three reliable UK-authorised price sources where available; execution on those venues is not compelled where the location policy does not bite (institutional flow, hedging), and mechanical per-trade checks are not required.
Client consent and settlement. Firms must disclose principal/agent capacity; executing outside a UK QCATP (where permitted) needs express prior client consent. Where a firm arranges a settlement, it is expected to initiate final settlement within 24 hours of execution, with the process and risks disclosed — further settlement consultation is signalled.
5. Pre- and Post-Trade Transparency — Chapter 4
Principal dealers are exempted from pre-trade. In a significant change from CP25/40, pre-trade transparency is confined to QCATP operators — mirroring the FCA's recalibration for TradFi non-equity systematic internalisers. Principal dealers remain fully in scope for post-trade transparency and client-facing disclosure.
The £10m entity-level trigger. QCATP operators with average annual revenue of £10m+ over a rolling 3-year period must publish prescribed pre-trade data (e.g., the best 5 bids/offers with volumes per trading pair). The threshold counts all of the entity's revenue — including non-crypto lines and predecessor entities — so diversified groups can be caught by revenue unrelated to digital assets. Market data may be commercialised but must be free in machine-readable form 15 minutes after publication.
1-minute post-trade reporting. All UK QCATP operators and principal dealers, regardless of size, must publish prescribed trade data as close to real time as technically possible and within 1 minute of execution — a re-architecture for any firm relying on batch processing.
Waivers and deferrals. Firms may waive pre-trade and defer post-trade disclosure where publication would adversely affect clients' trading interests, under a documented policy that applies objective factors (the final rules point to liquidity levels, average spread size, and other objective characteristics of the asset). Post-trade deferrals are hard-capped at 3 months; hedging large or illiquid positions is expressly recognised as a legitimate use.
6. Record Keeping and Client Reporting — Chapter 5
No transaction reporting — higher record-keeping bar. The FCA will not systematically receive order/transaction data; the evidential burden sits with firms. A prescribed minimum dataset for every order and transaction must be retained for at least 5 years and be readily available on request, with firms expected to assess any additional requirements imposed by MARC, the MLRs, and CARF.
Data standards. Assets must be identified by ISO 24165 Digital Token Identifiers in records and client reports (alternative identifiers only for institutional-only assets lacking a DTI). On-chain data — transaction hashes, wallet and smart contract addresses, network fees — must be captured alongside off-chain data, and the internal decision maker behind each order must be recorded.
Client reporting. Reports are due promptly by the end of the working day of execution/cancellation/data receipt (next working day for events that fall after hours — a 24/7-markets concession; the clock runs from when the reporting firm receives the data). Content additions include settlement method, client-specific instructions and cancellation reasons. Clients must be able to access a 3-year transaction history at any time, and delivery may be digital, subject to durable-medium conditions.
No exemptions. Requests for lighter treatment of small firms, occasional dealers and arrangers to non-custodial wallets were all rejected.
7. Lending and Borrowing — Chapter 6
Retail friction by design. Retail L&B requires appropriateness testing before any service and express prior consent per transaction — one-time consent models are prohibited — with Consumer Duty-compliant interfaces to manage consent fatigue.
Leverage constrained. Retail borrowing requires over-collateralisation; LTV, margin call and liquidation levels must be modelled so neither is expected within the first 6 months; negative balance protection applies (CfD-style); firm-initiated collateral top-ups need express prior consent and are capped at 50% of the market value of the initial collateral (clients may still top up further themselves). The FCA confirms the intent is to limit retail margin/leveraged trading, which is kept under review.
Retail bans. Title Transfer Collateral Arrangements are banned for retail clients — retail collateral must be safeguarded on trust at all times — and proprietary tokens (group-issued or supply-controlled, other than UK-issued qualifying stablecoins) cannot be used in retail L&B.
Institutional flexibility, universal records. TTCA and title transfer remain available for non-retail clients. Still, CRYPTO 9 record-keeping and client reporting apply to the entire L&B book — and the FCA expressly rejected reliance on on-chain records. Practical consequence: bifurcated consent UX, risk engines and custody structures on a unified all-client data architecture.
8. Safeguarding: The CASS 17 Regime — Chapter 7
Scope: control via means of access. CASS 17 applies where a firm holds or stores the means of access (private keys, key shards) enabling it to transfer client cryptoassets — directly or via third parties. Pure self-custody is out of scope; custody of relevant specified investment cryptoassets (RSICs) stays under CASS 6 pending further consultation.
Non-statutory trust. Client cryptoassets must be held in a non-statutory trust, separate from the firm's assets. Omnibus wallets are permitted, but one virtual address cannot serve two trusts. Firms may, where necessary, hold an operational surplus in the trust (e.g., gas fees, staking minimums) in a different cryptoasset class.
Exceptions. A 2% settlement float (doubled from the proposed 1%) per client, per cryptoasset class, with informed consent, for QCATPs on global settlement models; a new back-up key holder exception (key security rules still apply; no third-party appointments); plus lending, client-instructed transfers, consented absolute title transfers and debt discharge under agreed terms.
DLT independence and daily reconciliation. The blockchain cannot be used to calculate what the firm should hold — the requirement must live on independent internal ledgers; DLT may confirm the resource only where no third party is appointed. Reconciliations run daily, per trust, per client, per cryptoasset class. Shortfalls must be topped up in the same class (alternative assets only with client agreement), affected clients notified immediately, and the FCA notified in writing if a shortfall survives to the next reconciliation, with no carve-out for timing or network congestion.
Keys and third parties. Key management rules are technology-agnostic (HSMs, MPC, hot/cold); the daily means-of-access record review was dropped in favour of prompt updates, and firms must consider dependency risk. Third-party custody appointments require documented due diligence to a "no increased risk" standard, and liens or rights of set-off over client assets are prohibited.
9. Staking — Chapter 8
Retail-focused disclosures. Pre-service information, key terms (fees; how rewards are determined and their variability; lock-up duration; rights attached to any issued tokens), and express prior consent apply to retail clients only, with risks such as slashing highlighted. The bar is the client's understanding of the economic nature and consequences, not technical fluency.
Auto-staking preserved, with guardrails. The per-instance consent proposal was dropped. Upfront consent may cover existing and future holdings of specified cryptoassets; blanket consent for unspecified assets is prohibited; cancellation terms must be stated and consented to.
Ongoing engagement. Retail clients must receive at least 12-monthly summaries (assets staked, rewards, fees and commission, latest terms), sooner where in the client's best interests (e.g. prolonged platform inactivity), and be notified in good time of material changes to key terms.
Liquid staking and records. Recordkeeping extends only to clients whose identities the firm knows (not to downstream transferees of liquid staking tokens), balanced by a duty to record the type and amount of tokens issued to clients. Records apply to retail and non-retail businesses alike: 5 years or the duration of the relationship, with per-day reward records; CASS 17 applies concurrently where the firm also safeguards.
10. Decentralised Finance — Chapter 9
Control, not code. The rules in Chapters 2–6 apply to DeFi arrangements in which a clear controlling person carries on regulated cryptoasset activity by way of business — an approach supported by 91% of respondents under "same risk, same regulatory outcome". Only truly decentralised activity, with no person carrying it on by way of business, sits outside the perimeter; assessment is case-by-case, as outlined in the perimeter guidance consulted on in CP26/13 — under which the presence of smart contracts or elements of decentralisation does not by itself determine the perimeter position.
Direction of travel. Separate DeFi guidance will be consulted on in late 2026, covering indicators of degrees of (de)centralisation, interaction with the activity rules, and operational resilience and financial crime expectations for firms integrating with DeFi. Respondent-proposed candidate indicators — safeguarding client assets, discretion over execution or settlement, and account relationships — are now a prudent self-audit framework, though not a settled policy.
Practical step. Firms touching DeFi should map control, governance and asset flows against the perimeter today, and document the substance of each arrangement — the analysis will turn on economic reality, not branding.
11. Cost-Benefit Analysis — Chapter 10
The FCA estimates total present-value costs of £788m against benefits of £1,140m — a net benefit of +£352m (EANDCB £66.4m). Firm costs: custody of qualifying cryptoassets £290m; intermediaries £239m; staking £84m; lending and borrowing £83m; trading platforms £79m; RSIC custody £12m. Quantified consumer benefits comprise £395m in reduced losses from improved custody and £745m in the value of regulatory protections. The FCA maintained its assumptions against challenge, including on regulatory arbitrage — assessing that only a small share of UK consumers would migrate to unregulated platforms — and flagged unquantified costs from business-model restrictions and a possible "halo effect" whereby regulation is mistaken for protection against price volatility.
12. Priority Actions Before the Gateway
Authorisation readiness (now–Sep 2026). Existing MLR registrations do not convert to authorisation†. Scope permissions activity-by-activity (dealing, arranging, operating a QCATP, safeguarding, staking, L&B), stand up UK legal entities where retail is served, and request an FCA pre-application support meeting (available from July 2026†). Applications must evidence embedded governance.
Re-baseline builds against final rules. Reset implementation plans against the final CRYPTO/CASS 17 text: pre-trade transparency descoped for principal dealers; 2% settlement float; outcomes-based best execution; retain contingency for the September 2026 deferral consultation and further settlement/DeFi consultations.
Data and technology programme. Integrate DTIs across trade capture and reporting; link on-chain settlement data to off-chain order records with named decision-makers; stress-test post-trade publication against the 1-minute SLA; build daily reconciliation and same-class shortfall top-up capabilities; automate staking summaries and same-day client reporting.
Business model decisions. Exit PFOF-dependent revenue; untangle reliance on unauthorised offshore group liquidity; bifurcate retail vs institutional L&B rails (consent UX, risk engines, custody) on a unified data layer; review proprietary token usage in retail products; audit DeFi touchpoints against the controlling-person test.
Legal and custody restructuring. Constitute non-statutory trusts; strip liens and set-off rights from sub-custodian contracts; implement the 2% float with informed-consent capture; separate credit-risk-bearing business from platform entities.
Notes: (1) Items marked † are drawn from FCA announcements and companion publications (e.g. the launch press release and related policy statements) rather than the text of PS26/11, and should be confirmed against those sources. (2) Proposed 2028 deferral dates and the QCDD deferral mechanism reflect FCA statements of intent and remain subject to the September 2026 consultation. (3) Confirm Handbook rule citations against the final instruments in PS26/11 Appendix 1 before relying on them.



Comments