The UK Cryptoasset Regime After PS26/9
- James Ross

- Aug 4
- 7 min read
Material considerations for cryptoasset service providers — board briefing, August 2026
Executive summary
On 30 June 2026, the FCA published PS26/9, finalising the Admissions & Disclosures (A&D) rules and the Market Abuse Regime for Cryptoassets (MARC), made under the Designated Activities Regime and inserted into the Cryptoassets Sourcebook (CRYPTO 3 and CRYPTO 4), in force from 25 October 2027. On the central design questions, the FCA heard the industry’s objections and did not move.
Six points are material at board level:
The regime is industry-led by design. The FCA will not perform its traditional central surveillance role: platforms gatekeep admissions under A&D, firms carry the MARC surveillance burden, and suspicious order and transaction reports flow between firms, not to the regulator.
There is no transitional period for MARC. Phase-in requests were refused; baseline systems and controls—including price dislocation detection at every platform—must be operational from day one.
A £10m revenue threshold defines “Large UK QCATPs”, adding two obligations: on-chain monitoring (narrowed to platform-linked wallets) and cross-platform information sharing. The test is total revenue—not UK-only, and not platform activity alone.
Disclosure obligations reach beyond issuers. Issuers, offerors and UK QCATPs must all publicly disclose inside information directly concerning them—a deliberate departure from UK MAR’s issuer-only model, since many cryptoassets have no identifiable issuer.
Defences are narrower than consulted on. The “legitimate reasons” safe harbour was removed; only coin burning and crypto-stabilisation survive. The A&D “fungibility” exception to preparing a disclosure document also went.
Timing is compressed. The gateway opens 30 September 2026; the saving-provision deadline for firms already operating is 28 February 2027. A September 2026 consultation on deferral for in-circulation assets—likely 6 months—remains subject to change; firms cannot plan on it.

1. Where PS26/9 sits, and the dates that matter
PS26/9 is one of five policy statements published on 30 June 2026, completing most of the conduct framework (PS26/10–13 cover stablecoin issuance, regulated activities and intermediaries, prudential requirements, and the wider Handbook including the Consumer Duty). All rest on the FSMA 2000 (Cryptoassets) Regulations 2026 (SI 2026/102), which prohibit public offers of qualifying cryptoassets (with exceptions), introduce the “material information” requirement, create statutory compensation for disclosure documents, and establish the market abuse prohibitions.
Four dates: 30 September 2026—the gateway opens; 28 February 2027—last day to apply and retain the right to continue operating while a determination is pending; September 2026—intended deferral consultation; 25 October 2027—the eleven instruments, including FCA 2026/37 (A&D) and FCA 2026/38 (market abuse), take effect. The application window opens within weeks; the compliance build must be scoped now to be credible in an application and operational by October 2027.
2. Admissions & Disclosures: the gatekeeper role is real, and it is documented
A retail UK QCATP may admit a qualifying cryptoasset only where reasonably assured admission would not harm retail investors (CRYPTO 3.2.1R). Admission criteria must be general, risk-based and objective, owned and consistently applied by the governing body, and published—covering creator integrity, governance, technology risk and disclosure reliability. Due diligence must be documented case-by-case, with no reliance on another QCATP’s work and information gaps disclosed; records must be kept for at least 5 years (7 on FCA request), with financial interests in admissions stated in the disclosure documents.
A point easy to miss: most content and presentation requirements bind via the platform’s own rulebook, which must impose them on the applicant and the person responsible for the disclosure document—the rulebook is itself a compliance artefact, and on own-motion admissions the platform owes the duties directly.
3. Disclosure documents: one QCDD per asset, liability calibrated, withdrawal rights narrow
Each admitted asset requires a qualifying cryptoasset disclosure document (QCDD), published on the platform’s website and uploaded to the FCA-owned repository before admission—and before any public offer relying on it. The “fungibility” exception was removed; limited exceptions remain, including UK-issued qualifying stablecoins (which follow PS26/10) and assets retail investors cannot trade. Overseas-issued stablecoins are ordinary qualifying cryptoassets whose QCDDs must warn prominently that the issuer lacks UK stablecoin permission.
Content is outcomes-based: in English, meeting retail information needs, clear, fair and not misleading, with a two-A4-page summary cap and the specified identifiers (DTI; an active LEI); templates do not relieve liability. Compensation under regulation 14 defaults to negligence, with the burden on the defendant; protected forward-looking statements (PFLS)—a voluntary regime for qualifying projections, unavailable for mandatory disclosures—attract a recklessness or dishonesty standard, with the burden on the claimant. Liability sits with whoever requested admission, the platform on own-motion admissions, and anyone accepting responsibility—not advisers merely for advising.
A supplementary disclosure document (SDD) is required only where material new information, a mistake or an inaccuracy emerges after publication but before admission; neither document is updated after admission—ongoing disclosure transfers to MARC. Withdrawal rights are narrow—an agreement to buy after QCDD publication, an SDD then published, triggering circumstances pre-admission—with a two-working-day window; offerors and intermediaries must notify buyers of an SDD same-day.
The Consumer Duty is disapplied for the A&D activities—QCDDs and SDDs are also exempt from the financial promotion regime—in favour of tailored consumer understanding requirements; it still applies to promotions outside the documents, UK-issued stablecoin activities and, under PS26/13, the firm’s wider cryptoasset business.
4. MARC: the FCA has delegated the surveillance function to the industry
MARC is a civil regime prohibiting insider dealing, unlawful disclosure and market manipulation (regulations 22, 24 and 28), applying to any qualifying cryptoasset admitted—or subject to an admission application—on a UK QCATP, wherever the behaviour occurs. Despite this being the strongest consultation concern, the FCA will not replicate central surveillance, judging continuous trading, fragmented venues and global retail scale make it impractical. Three consequences follow.
Reporting flows sideways, not upwards. Intermediaries notify suspicious orders and transactions to UK QCATPs, not the FCA (regulation 30(3))—and may need to notify every UK QCATP trading the asset, not only the intended venue.
The FCA still expects to hear about serious abuse. Principle 11 expectations were widened: serious or repeated abuse should be notified, not merely what a firm cannot handle itself; escalation protocols need recalibrating.
Proportionality is bounded. A proportionality requirement, small-platform carve-outs, SYSC 8 outsourcing and the section 138A waiver power all exist; none softens the day-one start.
5. Inside information: duties beyond issuers, dissemination in two steps
Under regulation 26, issuers, offerors and UK QCATPs must publicly disclose inside information directly concerning them—deliberately broader than UK MAR, since platforms hold price-sensitive information (admissions, cancellations, vulnerabilities). Firms need not disclose what they do not hold, nor seek it out.
Delayed disclosure is available where immediate disclosure would prejudice legitimate interests, the delay would not mislead, and confidentiality holds—with records kept for the FCA. Security is expressly a legitimate interest (an unresolved code vulnerability, though not indefinitely). Routine technical updates and personnel changes generally fall below the “significant effect on price” threshold; market-making and liquidity-provider changes now sit above it.
Dissemination is website-first: publish on the firm’s own site, then upload to the repository. The express “active dissemination” requirement was removed, but guidance suggests active dissemination—including social media—will be needed in practice. Prominence rules, fixed deadlines and central verification were rejected for day one, and may be revisited.
6. Legitimate market practices: two survive, one was removed
Exactly two practices are designated: coin burning and crypto-stabilisation. The consulted-on “legitimate reasons” safe harbour was removed as going substantively beyond UK MAR—any planning built on it must be reassessed. Stabilisation runs 30 calendar days post-offer; discretionary burning requires a specified period and advance public disclosure of plans; protocol-level burning qualifies where publicly disclosed, without limits. MEV, staking, market making and governance participation were declined—MEV flagged as capable of facilitating manipulation—so those activities are judged on the facts under the base prohibitions.
7. Systems and controls: the baseline, and the extras above £10m
Every UK QCATP and intermediary needs: personal account dealing rules, information barriers, market abuse training, record-keeping and audit reviewed at least annually (sooner where controls prove weak), external communications monitoring, order book replay, and contractual powers to act on abuse, including off-boarding. Platforms also need rules to halt, restrict or suspend trading, warn users and remove assets. New and universal: every platform, whatever its size, must detect significant and persistent price discrepancies against other venues critical to price formation, and investigate them.
Two further obligations attach only to Large UK QCATPs—average revenue of at least £10m a year over the three previous years. The threshold drew 42% unsupportive responses and survived intact; it is total revenue—the FCA’s preferred indicator of compliance capacity—capturing roughly 95% of the current market. Boards near the line should establish now which side they fall, and when.
On-chain monitoring—narrowed to wallets linked to the platform—holding assets traded there, or identifiable as users’ through clustering or intelligence—and only where the firm’s arrangements identify abuse risk. The FCA’s view: these firms already run blockchain analytics.
Cross-platform information sharing—unchanged, live from day one. Large platforms must share information with other Large platforms on reasonable suspicion where necessary to prevent, detect or disrupt abuse, with ECCTA-modelled civil liability protection where conditions, including good faith, are met. No common data formats are prescribed—firms make their own data protection assessments—and notification may be required even where the user is unknown on the recipient platform. Transitional requests were refused.
On insider lists, the FCA dropped routine collection of employee wallet addresses—but systems and controls must enable the firm to require wallet information from employees on request. Hence, employment contracts and policies need updating.
8. What boards should do now
Decisions for the board itself:
Determine status under the £10m test and approve the resulting surveillance build—there is no transitional period to absorb a late start.
Approve admission criteria and conflicts architecture—the governing body owns the criteria and the separation between commercial listing decisions and the detriment assessment.
Set disclosure governance—who identifies inside information, who authorises delay, how the delay record, publication and repository upload operate.
Reassess reliance on the withdrawn “legitimate reasons” defence, and review burning and stabilisation against the finalised conditions.
Hold the timeline—application readiness for the gateway, operational readiness by 25 October 2027, without assuming the deferral consultation relieves pressure.
Infrastructure for management to commission: a CRYPTO 4 gap assessment, including price dislocation detection; the admission file—criteria, due diligence workflows, 5-to-7-year records, a rulebook imposing the required standards on applicants; QCDD production—regulation 13 templates, DTI and LEI acquisition, repository upload, SDD triggers, same-day withdrawal notifications; intermediary routing of suspicious reports to every relevant UK QCATP, with recalibrated Principle 11 escalation; and employment terms supporting investigations, including wallet addresses on request.



Comments