FCA Crypto Authorisation: UK Firms Face 2027 FSMA Deadline
Key Takeaways
- •From 25 October 2027, firms carrying on in-scope cryptoasset activities in or to the UK must hold relevant FCA permissions under FSMA, as MLR registration alone will no longer be sufficient.
- •The FCA has set a fixed application gateway for FSMA authorisation running from 30 September 2026 to 28 February 2027, during which applicants may qualify for transitional or savings provisions while their submissions are under review.
- •The FCA's finalised guidance FG26/7 establishes a baseline expectation that most firms seeking cryptoasset authorisation should operate through a UK legal entity with genuine local mind and management, subject to only limited exceptions.
- •Firms requiring MLR registration should apply before 30 September 2026 to avoid being blocked when the FSMA gateway opens, as weaknesses in AML controls can undermine the broader authorisation process.
- •The UK regime differs structurally from the EU's MiCA regulation, as it requires FCA permission and a UK-entity presence rather than offering passporting across member states under a directly applicable regulation.

The UK’s full cryptoasset regulatory regime is moving toward a firm 2027 start date, with businesses that operate in or serve the UK required to prepare for Financial Conduct Authority authorisation under the Financial Services and Markets Act, or FSMA. The new regime marks a step change from the UK’s existing cryptoasset oversight, which since January 2020 has been limited to anti-money-laundering registration under the MLRs. FSMA authorisation will for the first time bring crypto firms into the same prudential, conduct and consumer-protection framework that applies to traditional financial services in the UK.
From 25 October 2027, firms will not be able to carry on in-scope cryptoasset activities in or to the UK unless they hold the relevant FCA permissions. The FCA has set a fixed application gateway for crypto FSMA authorisation from 30 September 2026 to 28 February 2027. Firms that submit during that window may be able to use transitional or savings provisions while the regulator considers their applications.
The FCA’s published materials also state that most firms seeking authorisation should expect to conduct the relevant activities through a UK legal entity. Separately, firms that require registration under the UK Money Laundering Regulations, or MLRs, should address that status before filing an FSMA application.
Key dates include the FCA’s final policy package on 30 June 2026, the gateway window from 30 September 2026 to 28 February 2027, and the regime’s start date on 25 October 2027. The FCA’s policy statements are available at its press release is at and its guidance for firms is at
What changes under the FCA’s 2027 crypto regime
On 30 June 2026, the FCA published its final package of policy statements, PS26/9 to PS26/13, completing the roadmap for the UK’s cryptoasset authorisation framework. Those policy statements set out the core rules and guidance against which firms will be assessed. The package follows a series of consultation papers and discussion papers through 2024 and 2025, through which the FCA tested its approach on market abuse, custody, admissions, disclosures and stablecoin-related activities.
The mandatory FSMA-based regime begins on 25 October 2027. From that date, firms carrying on in-scope cryptoasset activities in or to the UK must hold the relevant FCA permissions. An MLR registration alone will not be sufficient once the FSMA regime starts.
The UK framework arrives as comparable regimes take effect in other major markets. The EU’s Markets in Crypto-Assets Regulation, or MiCA, began applying to crypto-asset service providers across the European Economic Area from December 2024. While the UK and EU regimes share objectives around consumer protection and market integrity, they differ in structure: MiCA operates as a directly applicable regulation with passporting across member states, whereas the UK regime requires FCA permission and a UK-entity presence subject to limited exceptions.
The FCA’s materials set out both the activities covered and the standards expected. In practice, firms should prepare for a full authorisation assessment covering senior management accountability, prudential resources where required, custody and safeguarding controls, market abuse and surveillance where relevant, operational resilience, complaints and redress processes, and a credible wind-down plan. The process is a whole-firm assessment rather than a limited registration exercise.
Application timing and the gateway process
The FCA has confirmed a fixed gateway window for crypto FSMA authorisation applications running from 30 September 2026 to 28 February 2027. Submitting during that period may make a firm eligible for transitional or savings provisions while the FCA processes its application. The FCA has said those arrangements are intended to support continuity where applications are under review.
Firms should not treat the gateway as a last-minute filing period. Complex groups may need months to document governance arrangements, technology architecture, risk frameworks, third-party dependencies and operational controls. External readiness reviews and wind-down planning can also take significant time.
The hard start date remains 25 October 2027. Firms will need either an authorisation in place or a valid transitional position arising from a gateway-period submission if they intend to continue carrying on in-scope activities in or to the UK after that date.
UK legal entity expectations
Finalised guidance FG26/7 sets out the FCA’s baseline expectation that firms requiring FCA authorisation for cryptoasset activities should carry on those activities from a UK legal entity. The guidance is available at
The guidance identifies limited exceptions, including for some qualifying overseas trading platforms. However, firms should generally plan on establishing a UK company with real mind and management in the UK if they require authorisation.
That expectation affects a firm’s operating model. Senior managers must have defined responsibilities. Risk, compliance and internal audit functions need appropriate scope and authority. Outsourced technology and group services must be subject to oversight, contractual controls and exit planning. Boards also need UK-appropriate composition and management information.
Firms currently serving UK users from an overseas hub should assess whether any narrow exception applies. For many firms, planning a UK entity early will be central to preparing an FSMA application.
MLR registration before FSMA authorisation
MLR registration is separate from FSMA authorisation. The FCA reminds firms to be registered under the UK Money Laundering Regulations where applicable and to resolve that position ahead of the FSMA regime. The FCA’s MLR guidance is available at
The FCA has signalled practical cut-offs, including applying for MLR registration before 30 September 2026 where relevant, so firms are not blocked when the FSMA gateway opens.
MLR registration should be treated as a prerequisite for many firms’ wider regulatory plans. Weaknesses in anti-money-laundering governance, customer risk assessment, blockchain analytics coverage, transaction monitoring and suspicious activity reporting processes can create issues before an FSMA application is considered.
Firms should check their MLR status, align their AML target operating model with the FSMA application they intend to submit, and avoid relying on last-minute remediation.
MLR registration, FSMA authorisation and transitional status
The three concepts serve different purposes.
| Item | What it is | Timing | Who needs it | Practical outcome |
|---|---|---|---|---|
| MLR registration | Registration under the UK Money Laundering Regulations | Apply early; the FCA signals applying before 30 September 2026 if relevant | Firms carrying on relevant cryptoasset AML-regulated activity | Allows lawful operation for AML purposes; it is not an FSMA licence |
| FSMA authorisation | Core permissions to carry on in-scope cryptoasset activities | Apply during the gateway from 30 September 2026 to 28 February 2027 | Firms in or to the UK carrying on in-scope crypto activities | Required to operate from 25 October 2027 |
| Transitional or savings provisions | Temporary arrangements connected to a gateway-window filing | Dependent on a valid submission in the gateway window | Applicants that meet FCA conditions | May support continuity pending a decision; not guaranteed |
Firms should consult the FCA’s current materials for the latest details and scope clarifications.
Contents of a strong FSMA application
An FSMA application should read like an operating manual rather than a marketing presentation. The FCA will expect evidence that the business can operate safely, identify and manage risks, treat customers fairly, and wind down in an orderly way if required.
A strong file should include a corporate map and rationale covering group structure, ownership, roles and the reason the UK entity sits where it does. It should also include governance materials, such as board and committee terms, management information packs, senior management function responsibilities and handover plans.
Financial crime materials should cover customer risk assessment, blockchain analytics, know-your-transaction controls, politically exposed person and sanctions controls, transaction monitoring, and suspicious activity reporting procedures. Custody and safeguarding materials should address wallet design, key management, reconciliation, segregation logic, recovery drills and third-party due diligence.
Operational resilience documentation should set out impact tolerances, severe-but-plausible scenarios, runbooks and supplier exit plans. Technology materials should include architecture diagrams, change control, security policies, incident response processes and data retention procedures.
Where relevant, market integrity controls should cover surveillance, abuse prevention and conflicts management. Customer outcome materials should address disclosures, complaints handling, financial promotions governance and vulnerable customer policies. A wind-down plan should include triggers, liquidity and resource estimates, customer communications and data retention. The application should also disclose regulatory history, including MLR status, overseas licences and remediation logs.
Controls need to be documented in a way that is understandable to a reader who does not know the firm’s technology stack. If a control exists only informally, such as in an engineer’s knowledge or an internal ticket, it is unlikely to be adequate evidence for authorisation.
Before filing, firms should conduct a challenge review of their application pack to identify gaps and prepare for FCA follow-up questions.
Transitional and savings provisions
The FCA’s press materials and guidance state that firms filing a complete application during the 30 September 2026 to 28 February 2027 gateway may benefit from transitional or savings provisions. Those provisions may provide time while the FCA reviews applications, but they are not a permission to operate without meeting regulatory standards.
Eligibility and conditions will matter. The FCA can be expected to consider a firm’s current controls, MLR status and the credibility of its submitted plans. A minimal or incomplete application should not be assumed to qualify.
The more prudent approach is to submit early in the gateway, maintain and improve live controls, and respond quickly to FCA requests for further information.
Board approvals for H2 2026 and 2027
Boards and founders will have a significant role in managing the authorisation timeline. Several decisions can reduce execution risk.
First, firms should approve a UK entity plan with real mind and management, consistent with FG26/7 expectations. Second, they should lock down the MLR registration pathway and resources, aiming to apply before 30 September 2026 if in scope. Third, they should identify and appoint senior managers who meet fitness and propriety standards and have clear role profiles.
Boards should also approve internal audit or external readiness reviews focused on AML, custody and resilience. Budget approvals should cover headcount and vendor spending through 2027 so the application build does not stall.
If those decisions cannot be completed in Q3 2026, firms should reassess whether they can submit a credible application during the gateway. Filing late in Q1 2027 may compress the time available to respond to FCA questions before the regime starts.
Common preparation risks
A frequent risk is leaving MLR registration until the end of the process. The FCA has flagged practical cut-offs, and delays can undermine an FSMA filing.
Another risk is assuming an overseas entity will be sufficient. FG26/7 establishes an expectation for a UK entity, subject to limited exceptions. Firms should not design their operating model around an exception unless they clearly fall within it.
Wind-down planning is also often underestimated. A credible plan requires triggers, costed steps, customer communications and data plans, and should be tested through a dry run or tabletop exercise.
Firms should avoid relying on paper-only controls. If custody, monitoring or resilience claims do not match live systems and processes, the FCA is likely to identify the gap. Evidence will matter more than future promises.
Outsourcing oversight is another key area. Firms that depend heavily on vendors should be able to show exit plans, performance management information and contractual rights. Submitting at the end of the gateway also creates pressure and reduces the time available to answer follow-up questions before 25 October 2027.
Frequently asked questions
Does the regime apply to overseas firms with UK users through an app store?
If a firm carries on in-scope cryptoasset activities in or to the UK, the FCA framework applies. FG26/7 sets a baseline expectation for a UK legal entity, with limited exceptions for some qualifying overseas trading platforms. Many firms serving UK users should plan around a UK entity.
What happens if a firm submits during the gateway but has no decision by 25 October 2027?
The FCA has indicated that applicants filing between 30 September 2026 and 28 February 2027 may benefit from transitional or savings provisions. Those provisions are not automatic or universal. Firms should keep controls operating and respond to FCA queries to support any transitional position.
Can a firm operate with only MLR registration after the regime starts?
No. From 25 October 2027, firms carrying on in-scope cryptoasset activities in or to the UK must hold the relevant FSMA permissions. MLR registration remains separate and important, but it is not a substitute for FSMA authorisation.
Do DeFi teams building open-source software need authorisation?
That depends on the actual activities and who is carrying them on in or to the UK. If a team does not carry on in-scope activities, it may fall outside the regime. If it does carry on in-scope activities, the regime applies. Firms should assess the question against their actual operating model.
How much time is needed for a wind-down plan?
A wind-down plan should be budgeted in weeks rather than days. It needs costed steps, triggers, communications templates and a data plan. A tabletop test before filing can help identify gaps.
Can a group-level risk team outside the UK satisfy the FCA?
Only if UK oversight is real and effective. The guidance points to UK mind and management. Group services may be used, but the UK entity needs clear accountability and the ability to challenge or exit arrangements where needed.
What if a firm misses the gateway window?
A firm can still seek authorisation, but it may not have access to the same transitional or savings provisions that support the cutover to 25 October 2027. Firms targeting the UK should plan to file within the gateway window.
This article is for informational purposes only and is not legal, tax, investment, financial or other advice.