Material Considerations for UK Cryptoasset Service Providers
- James Ross

- Jul 25
- 14 min read
FCA Policy Statement PS26/13 — Crypto Regime: Application of the FCA Handbook for Regulated Cryptoasset Activities (June 2026)
Prepared 24 July 2026
Executive summary
PS26/13 is the connective tissue of the FCA's new cryptoasset regime. Published on 30 June 2026 alongside PS26/9 (admissions & disclosures and market abuse), PS26/10 (stablecoin issuance), PS26/11 (regulated cryptoasset activities, including CASS 17 custody) and PS26/12 (prudential regime), it confirms how the existing, cross-cutting FCA Handbook — the Consumer Duty, COBS, SYSC, SM&CR, CASS, DISP/FOS access, ESG and regulatory reporting — will apply to firms carrying on regulated cryptoasset activities. The FCA has largely proceeded as consulted on in CP25/25 and CP26/4 (with CASS amendments from CP26/8), making targeted refinements for clarity and proportionality.
The overriding message is that crypto is being brought within the traditional regulatory perimeter, not given a bespoke, lighter regime: the same conduct, governance, resilience, redress, and reporting standards, with calibrated carve-outs only where the technology genuinely differs. In our assessment, the ten most material considerations for CASPs are:

Crypto becomes "designated investment business". The Handbook glossary definition of DIB is expanded to cover all qualifying cryptoasset activities (including stablecoin issuance), switching on SYSC, COBS, CASS and related sourcebooks wholesale (Chapter 4).
The Consumer Duty applies in full, subject to two narrow carve-outs: participant-to-participant trading on a UK QCATP, and admissions & disclosures activities for non-stablecoin cryptoassets. Sector-specific guidance is finalised in FG26/5 (Chapter 3).
Client money protection is stricter than in traditional finance. The CASS 7 professional-client opt-out and the DvP/commercial-settlement-system exemption are both disapplied for qualifying cryptoasset activities: pre-funded money is client money for the whole settlement period (Chapter 5).
Stablecoin issuance sits wholly outside CASS 7. Backing assets are governed exclusively by CASS 16, with strict account-level segregation from money held under any other CASS chapter (Chapter 5).
SM&CR applies in full, with a UK-anchored "mind and management" expectation (SMF16/SMF17 expected to work from the UK principal place of business), an Enhanced-tier threshold cut to £20bn of backing assets (three-year rolling average) for stablecoin issuers, £100bn for custodians, and Certification Regime assessment deferred by "modification by consent" pending the SM&CR review (Chapter 7).
Operational resilience (SYSC 15A) extends to all authorised cryptoasset firms, but use of permissionless DLT is not treated as outsourcing under SYSC 8 (Chapter 8).
Marketing friction stays. Qualifying cryptoassets (including BTC and ETH — the FCA rejected calls to carve them out) remain Restricted Mass Market Investments; UK-issued qualifying stablecoins are removed from the RMMI category, while non-UK stablecoins attract additional risk warnings (Chapter 10).
The appropriateness assessment becomes a hard rule (COBS 10 Annex 4R minimum question set), with tailored testing for lending/borrowing risks; application to existing clients will be consulted on in September 2026 (Chapter 10).
FOS access without an FSCS safety net. The Financial Ombudsman's compulsory jurisdiction extends to the new activities (with a carve-out for non-UK customers of overseas-incorporated QCATP branches). Still, FSCS protection is not extended — including for safeguarding of tokenised traditional assets (RSICs) — and standardised risk disclosures must say so (Chapter 12).
Reporting is more frequent than TradFi in key areas: a monthly safeguarding return (untiered by size), quarterly baseline complaints data (versus six-monthly in traditional finance) and quarterly FIN073 financial-resilience reporting from commencement (Chapter 13).
Key dates
Date | Milestone |
4 February 2026 | FSMA 2000 (Cryptoassets) Regulations 2026 made by Parliament, creating the new regulated activities (including Article 9N safeguarding) |
30 June 2026 | FCA publishes final-rules package: PS26/9–PS26/13, plus finalised guidance FG26/5 (Consumer Duty), FG26/6 (operational resilience) and FG26/7 (international firms) |
13 July 2026 | CP26/17 Chapter 3 (FOS levy/fees proposals, including the provisional £75 flat levy) closes |
September 2026 | FCA intends to consult on how the strengthened appropriateness rule applies to existing clients (possible deferrals and implementation timelines) |
30 September 2026 | Authorisation gateway application window opens (per the FCA's cryptoasset regime overview) |
28 February 2027 | Gateway application period closes (PS26/13, Chapter 13 indicative timeline) |
25 October 2027 | Regime go-live; authorised firms begin submitting baseline and existing regulatory returns |
Firms that miss the gateway window risk being unable to carry on regulated cryptoasset activities lawfully at go-live. The practical planning horizon for authorisation-readiness — governance, CASS arrangements, disclosures, reporting build — is therefore now.
1. The perimeter mechanism: designated investment business (Chapter 4)
The foundational change is a single glossary amendment: "designated investment business" now includes all qualifying cryptoasset activities, including the issuance of qualifying stablecoins. Subject to each sourcebook's own scope, most existing Handbook rules and guidance therefore apply to CASPs in the same way as to traditional finance firms — notably SYSC, COBS and CASS. Some requirements remain conditional: elements of SM&CR apply only where firms meet the relevant criteria, and the Training and Competence (TC) sourcebook applies only to a subset of firms (paragraph 6.12). The FCA's stated principle is consistent baseline compliance standards — same risk, same regulatory outcome — with crypto-specific calibration only where justified.
2. Structure for international firms: UK entity vs branch (Chapter 2, FG26/7)
The finalised non-Handbook guidance on the FCA's approach to international cryptoasset firms (AICF), published as FG26/7, is the most structurally consequential element for global groups:
Solo-regulated firms: the FCA will generally expect international cryptoasset firms to operate through a UK legal entity rather than a branch, citing heightened risk of consumer harm and consumer research showing persistent misunderstanding of cryptoasset risks. This is a strong general expectation, not an absolute rule.
Dual-regulated (FCA/PRA) firms — the significant clarification following pushback from international banks — may carry on cryptoasset activities from a UK branch, subject to the PRA , as lead regulator , being satisfied, and to meeting threshold conditions at the gateway and on an ongoing basis, assessed case by case.
QCATP flexibility: in some circumstances a firm may combine an authorised UK legal entity with an authorised UK branch of an overseas QCATP; branch-authorised overseas QCATP operators may also provide matched principal trading and operate a settlement float, subject to CASS 17 safeguarding conditions.
No blueprint and no equivalence: the FCA declined to publish further guidance on permissible structures at this stage, and cannot commit to any timeframe for international equivalence arrangements (which would usually require legislation). Firms must plan to meet UK standards independently.
Scope reminder: the AICF guidance is relevant to firms already FSMA-authorised for other activities (needing a variation of permission), crypto MLR-registered firms not yet FSMA-authorised, and firms currently serving UK customers via the section 21 financial-promotions gateway. Determining solo- vs dual-regulated status early is the gating strategic decision — it now determines whether a firm budgets for a standalone UK entity or builds the case for a branch.
3. The Consumer Duty (Chapter 3, FG26/5)
The Duty (Principle 12 and PRIN 2A) applies in full to CASPs' retail market business. Consultation support was strong (100% supported applying the Duty with sector-specific guidance). Two carve-outs matter:
UK QCATP trading exemption: the Duty is disapplied for trading between participants on a UK QCATP (implemented via PRIN 3.1.1.14R), because the operator is not a counterparty and CRYPTO 6 already secures non-discretionary, fair and transparent trading. The exemption is narrow: onboarding, communications and customer service remain fully in scope. FG26/5 also classifies a QCATP operator as the manufacturer of the platform product only and as the distributor of the cryptoassets traded on it.
A&D carve-out: the Duty does not apply to public offers and admissions to trading of qualifying cryptoassets other than UK-issued qualifying stablecoins (carved out of "retail market business", as proposed in CP25/41), because the tailored A&D rules do that work. By contrast, the Duty applies to all retail market business relating to UK-issued qualifying stablecoins — including public offers and admissions — reflecting their potential use as digital money and the fact they may be offered outside the A&D regime.
Responsibility across the supply chain follows a firm's actual role and influence over retail outcomes in practice, not merely its contractual terms. Firms should also note FG26/5's operational clarifications: avoiding unnecessarily complex (e.g., multi-step) redemption journeys without diluting AML obligations; supporting channels that meet customer needs (including vulnerable customers); and providing new good- and bad-practice examples for arranging qualifying cryptoasset staking. The application of the Duty to non-UK customers and distribution chains is still evolving through CP26/23.
4. Client money and the custody boundary (Chapter 5; CASS 1, 7, 8)
4.1 Stricter-than-TradFi client money rules
No professional-client opt-out. Despite generally unsupportive feedback, the CASS 7 opt-out does not apply to money held in connection with qualifying cryptoasset activities; institutional-only businesses must still fully segregate client money. The FCA cites heightened sector risks — vertical integration and market concentration — and will keep the position under review.
No DvP exemption where the delivery obligation relates to a cryptoasset. With no recognised commercial settlement systems for crypto, money received before delivery (pre-funding) is client money for the entire settlement period. Models where the firm never receives or holds client money (true atomic settlement) are unaffected.
Alternative approach available, with conditions. The CASS 7 alternative approach to segregation (including for omnibus/pooled structures) can be used for crypto businesses where the existing conditions are met — a documented appropriateness assessment, an independent auditor's opinion on systems, controls, and MPSA design, and FCA notification. Adding a crypto business line may itself be a "material change" for MPSA purposes.
Standard methodology applies. CASS 7.16.22E individual client balance calculations extend to qualifying cryptoassets; 24/7 trading, multi-venue execution and on-chain settlement are implementation matters, not grounds for departing from CASS 7 methodology. The CASS 7.10.16R banking exemption is unchanged.
4.2 Stablecoin issuance ring-fenced
Beyond the consultation proposal, the final rules provide that firms carrying on the activity of issuing qualifying stablecoins are not subject to CASS 7 for that activity — backing assets are governed by CASS 16. Issuers with other business lines remain subject to other CASS chapters and must not hold backing assets in the same backing funds account as money held under any other CASS chapter. Failure and distribution rules for CASS 16 and CASS 17 firms will be consulted on.
4.3 Custody flows, staking and mandates
Money arising from safeguarding client cryptoassets is client money under CASS 7 — including where a third party safeguards them (the third party must pay relevant money into the firm's client bank account).
CASS 7 follows the money, not the asset: staking rewards credited as cryptoassets, or proceeds accruing directly to client-controlled wallets, are out of scope.
Custody is bifurcated: qualifying cryptoassets fall under the new CASS 17 (see PS26/11); tokenised traditional investments (RSICs) sit under CASS 6 for the time being, pending the tokenisation call for input.
CASS 8 (mandates) does not apply to a firm safeguarding cryptoassets within Article 9N — the FCA distinguishes CASS 8 "authority to instruct or direct" from Article 9N "ability to bring about a transfer of benefit". A CASS 8 mandate can still exist (e.g. a discretionary manager's power of attorney), and non-custodial staking is caught only if mandate authority and all CASS 8.2.1R conditions exist — which the FCA understands most current models do not involve. PERG perimeter guidance is being consulted on in CP26/13.
5. Governance: SYSC, TC and SM&CR (Chapters 6–7)
5.1 SYSC and Training & Competence
The SYSC sourcebook (notably SYSC 4–10 and 18: organisation, skills, compliance and risk controls, record-keeping, conflicts, whistleblowing) applies as it does to other FSMA-authorised firms; cryptoasset firms are treated as "other firms" unless they are common platform firms. The FCA sees SYSC as technology-neutral and declined to tailor it. The TC sourcebook applies where employees serve retail clients in three activities: dealing in qualifying cryptoassets as principal or agent (including lending and borrowing), safeguarding qualifying cryptoassets or RSICs (including arranging), and arranging qualifying cryptoasset staking — though no qualifications are required at this time while the training market matures.
5.2 SM&CR
Full application with minor amendments to the SYSC 23 Annex. Certification Regime assessment is deferred during the gateway via a "modification by consent" waiver until the Phase 2 SM&CR review outcomes are known.
Mind and management in the UK. Overseas SMF appointments are possible, but the FCA expects a firm's mind and management to be and remain UK-located, and pays particular attention to physical location for SMF16 (Compliance Oversight) and SMF17 (MLRO), whom it expects to work from the firm's UK principal place of business.
Enhanced tier: stablecoin issuers become Enhanced firms at £20bn in backing assets (three-year rolling average) — reduced from the consulted £65bn per product, calibrated against the Bank of England's systemic stablecoin proposals; cryptoasset custodians at £100bn (safe custody assets plus client cryptoassets, unchanged). The FCA expects the thresholds to capture roughly 1% or fewer of firms, and considers it unlikely any stablecoin issuer will qualify at commencement in October 2027.
Dropped/declined proposals: managing stablecoin backing assets will not require "proprietary trading" certification, and no separate prescribed responsibility for crypto custody was created — Prescribed Responsibility Z (CASS compliance) covers both traditional and digital assets under a single senior manager.
6. Operational resilience (Chapter 8, FG26/6)
SYSC 15A is extended to all authorised cryptoasset firms — including firms that would not otherwise be in scope — unchanged from consultation. Firms must identify important business services, map the people, processes, technology, facilities, and information that support them, set impact tolerances, and test their ability to remain within them. Two points stand out:
Use of permissionless DLT is not treated as an outsourcing arrangement under SYSC 8.1.1R — 98% of respondents agreed — reflecting the absence of contractual relationships with DLT providers.
Finalised non-Handbook guidance sits in FG26/6 and is developed to be consistent with IOSCO Crypto and Digital Assets Recommendation 17; separate non-Handbook guidance on operational resilience for DLT use (permissionless and permissioned) will be consulted on later this year.
7. Financial crime (Chapter 9)
There is no bespoke crypto financial-crime rulebook. The financial crime elements of SYSC 6, the Financial Crime Guide (FCG) and Financial Crime Thematic Reviews (FCTR) apply as for other FSMA-authorised firms — on top of continuing Money Laundering Regulations obligations (registration required since January 2020; Travel Rule since September 2023). The FCA declined to write crypto-specific rules for risks such as mixers and tumblers, pointing firms instead to JMLSG sector guidance, HM Government risk assessments and FATF standards and reports to adapt their SYSC 6 frameworks to crypto-native risks. Dual-regime compliance (MLRs + FSMA rules) should be reflected in business-wide risk assessments and control mapping.
8. Conduct of business (Chapter 10)
8.1 Territorial scope
COBS is disapplied for non-UK users of overseas-incorporated QCATPs authorised via a UK branch (determined by habitual residence or UK establishment) — so a UK branch does not drag a global client base into UK conduct rules — while services provided from overseas to UK retail clients are fully in scope. Even where COBS is disapplied, the Principles for Businesses, SYSC common platform requirements and CRYPTO sourcebook conduct obligations still apply. Relevant COBS requirements also apply to Gibraltar-based firms serving UK clients.
8.2 Financial promotions
Qualifying cryptoassets remain Restricted Mass Market Investments — the FCA rejected calls to exempt widely traded assets such as BTC and ETH, finding insufficient evidence for asset-level differentiation, but will keep the classification under review.
Stablecoin bifurcation: UK-issued qualifying stablecoins exit the RMMI category (and its cooling-off and appropriateness frictions); promotions for non-UK-issued qualifying stablecoins must carry additional risk warnings that they are not subject to UK issuance and backing-asset requirements.
8.3 Appropriateness hardened into a rule
Citing poor practice since 2023 (weak knowledge testing; clients allowed to proceed despite "not appropriate" outcomes), the FCA converts the appropriateness assessment from guidance into a rule: firms must ask questions covering at least the matters in COBS 10 Annex 4R (83% supported). Lending and borrowing require assessment of leverage, liquidation risk, margin calls, and counterparty risk — all of which are integrable into the broader crypto assessment. The application to existing clients remains unresolved; a September 2026 consultation will address potential deferrals and timelines. Legacy-client remediation decisions should wait for it.
8.4 Other COBS positions
Safeguarding disclosures (COBS 6): plain-language explanation of trust structures, firm-failure outcomes, use of exceptions and consents, security arrangements and third-party custodian reliance; a technical glossary is suggested guidance, not mandatory.
Cancellation rights (COBS 15) are disapplied for cryptoasset products and activities, reflecting irreversible on-chain settlement; firms must instead disclose how clients can terminate safeguarding services or retrieve assets.
Staking: COBS 16 reporting is disapplied for qualifying cryptoasset staking; instead, a CRYPTO-sourcebook notification at least every 12 months must cover amounts staked, rewards earned and fees charged.
COBS 11 (dealing and managing) is disapplied — execution and order-handling standards sit in CRYPTO 5; personal account dealing requirements are retained where applicable.
Firms subject to overlapping COBS and CRYPTO requirements may run a single integrated compliance framework, provided the overall framework meets all applicable requirements, including crypto-specific mandates (e.g., express consent, enhanced disclosures).
9. ESG (Chapter 11)
A targeted subset of the ESG sourcebook applies (ESG 4.1.1R and 4.3.1R): cryptoasset firms must not use sustainability labels, and any sustainability references must be clear, fair, not misleading and consistent with the product's actual characteristics (anti-greenwashing). The rules apply uniformly across all cryptoasset activities — the FCA declined to tailor them at the activity level — and no new climate or sustainability disclosure requirements are imposed at this stage, given the early stage of market development and limited data. The FCA will monitor energy consumption and emerging business models.
10. Redress: FOS in, FSCS out (Chapter 12)
Complaints handling: DISP 1 applies as for other authorised firms. UK qualifying stablecoin issuers must contractually oblige appointed third parties (e.g. distributors carrying out issuance activity) to forward complaints "promptly" (softened from "immediately"); new DISP 1 guidance sets an expectation of resolution within 8 weeks of the third party receiving the complaint. Genuinely independent intermediaries are not caught.
FOS compulsory jurisdiction extends to the new activities. A carve-out confirms it does not cover complaints from non-UK customers of overseas-incorporated QCATPs authorised via a UK branch — a clarification of the existing UK-establishment limit (DISP 2.6.1R). No equivalent clarification was made for UK-incorporated QCATPs. The Financial Ombudsman decided not to extend its voluntary jurisdiction to these activities for EEA/Gibraltar-based firms.
Funding: case fees apply from the outset; the annual compulsory jurisdiction levy is deferred until the FOS confirms its 2028/29 budget. A provisional £75 flat levy for firms dealing in qualifying cryptoassets as principal or issuing qualifying stablecoins is consulted on in CP26/17.
No FSCS protection for the new regulated cryptoasset activities: the FCA judges it too early to conclude benefits outweigh risks (consistent with FS22/5's second principle) and is wary of signalling safety. Notably, safeguarding of RSICs — tokenised versions of traditional investments — is also outside FSCS cover, following the Cryptoassets Regulations 2026 (made 4 February 2026) moving that activity from RAO Article 40 to Article 9N; the FCA has left open a future exception.
Disclosure consequences: standardised risk summaries in financial promotions must state that cryptoasset activities are not FSCS-covered (COBS 4 Annex 1R); these do not apply to UK-issued qualifying stablecoins, but safeguarding firms must explain protections and risks including the effect of any trust-property shortfall on firm failure (COBS 6.1.7BR(3)(a)(ii)).
Practical implication: firms bear FOS redress exposure (uncapped by any compensation scheme backstop) for acts and omissions that cause consumer loss — though the FOS's fair-and-reasonable test makes redress unlikely where loss stems from market performance alone. Complaint-handling capability, root-cause analysis and prompt third-party escalation chains become genuine financial risk controls.
11. Regulatory reporting (Chapter 13)
Existing SUP 16 returns apply, supplemented by new crypto-specific baseline returns and supplementary data collections from commencement, refined iteratively post-implementation (96% supported the phased approach). Key features:
Monthly safeguarding return for all cryptoasset safeguarding firms, modelled on the CMAR but not tiered by firm size — justified by the speed at which holdings change in scale and composition and by operational/technological risks, and aligned with the new monthly safeguarding return for payments firms. Firms may use the ISO 24165 Digital Token Identifier where possible.
Quarterly complaints baseline (two questions) — twice the frequency of the six-monthly TradFi cycle, offsetting the lighter content.
Stablecoin issuers report backing-asset composition and any use of an excess in the backing pool (CASS 16.4.16R); the redemption-suspension count was dropped because CRYPTO 2.4.24R already requires immediate notification of such events.
QCATPs and intermediaries report on a territorial basis — activity carried on in or from the UK or affecting a UK retail customer.
Prudential: quarterly FIN073 (Baseline Financial Resilience Report) from commencement; the fuller prudential reporting framework will be consulted on via a staged process with template testing. A version of the reporting interface will be made available before commencement.
The reporting build is a systems programme, not a compliance memo: monthly safeguarding data, DTI-level asset identification, and quarterly cycles require that automated data pipelines be specified during the authorisation-preparation window.
12. Priority actions
Fix the structure question first. Determine solo- vs dual-regulated status and target legal form (UK entity, branch, or QCATP hybrid); build the threshold-conditions evidence pack for case-by-case gateway scrutiny.
Stand up the CASS programme. Map every money and asset flow against CASS 7/16/17 (and CASS 6 for RSICs); re-paper settlement and pre-funding arrangements now that the DvP exemption and professional opt-out are gone; if using the alternative approach, commission the auditor's opinion early.
Localise governance. Plan SMF16/SMF17 hires or relocations to the UK principal place of business; map prescribed responsibilities (including PRz for custody); prepare for Enhanced-tier monitoring if near the £20bn/£100bn thresholds.
Rebuild onboarding and marketing journeys. Implement the COBS 10 Annex 4R question set (with lending/borrowing modules), bifurcated stablecoin promotion treatment, FSCS-absence risk summaries, and revised safeguarding disclosures and exit procedures.
Run the operational resilience cycle. Identify important business services, set impact tolerances and test against DLT-specific scenarios, using FG26/6.
Specify the reporting stack. Build for monthly safeguarding, quarterly complaints and FIN073 returns, with DTI asset identification; engage with the FCA's voluntary testing of supplementary questions.
Track the open consultations: September 2026 (appropriateness for existing clients), CP26/23 (Duty — non-UK customers and distribution chains), CP26/17 (FOS levy), CP26/13 (PERG perimeter guidance), the DLT operational-resilience guidance consultation, and future CASS 16/17 failure and distribution rules.



Comments