FCA Crypto Authorisation: What UK Firms Must Do Before the 2027 Regime

FCA Crypto Authorisation: What UK Firms Must Do Before the 2027 Regime

The UK’s crypto rules are finally landing in full. If you run a crypto business with any UK reach, the clock’s already ticking toward a hard 2027 cutover. This guide gets straight to what to file, when to file it, and the gotchas that trip teams up.

We’ll walk through the FCA’s dates, the expectation to use a UK entity, how MLR registration fits, what your application needs to prove, and what boards should greenlight now. No fluff. Just the steps and the risks.

By 25 October 2027, you can’t carry on in-scope cryptoasset activities in or to the UK without the right FCA permissions under FSMA. The FCA opened a fixed application gateway from 30 September 2026 to 28 February 2027, and filings in that window may benefit from transitional or savings provisions while decisions are made. The FCA’s guidance expects most firms to operate through a UK legal entity, and you should sort MLR registration ahead of any FSMA application. Start building your pack now and assume real lead times.

  • Key dates: policy package landed 30 June 2026; gateway runs 30 Sep 2026–28 Feb 2027; regime starts 25 Oct 2027 (FCA, FCA — press, FCA).
  • Use a UK legal entity unless you fall into narrow overseas platform exceptions (FCA FG26/7).
  • Get MLR registration in hand early; the FCA signposts practical cut-offs ahead of FSMA filings (FCA).
  • Expect deep checks on governance, financial crime, custody, outsourcing, resilience, and wind-down.

What exactly changes under the FCA’s 2027 crypto regime?

On 30 June 2026 the FCA published its final package of policy statements (PS26/9–PS26/13), which completes the roadmap and sets the core rules and guidance for cryptoauthorisation in the UK. That’s the framework you’ll be judged against going forward (Financial Conduct Authority (FCA)).

The mandatory FSMA-based regime starts on 25 October 2027. From that date, firms carrying on in-scope cryptoasset activities in or to the UK must hold the relevant FCA permissions. If you’re operating here on just an MLR registration, that won’t be enough from the start date (FCA).

The FCA’s materials lay out the activities and standards. In practice, expect a full-scope authorisation ask: senior management accountability, prudential resources where required, custody and safeguarding controls, market abuse and surveillance where relevant, operational resilience, complaints and redress processes, and a credible wind-down plan. It’s a whole-firm test, not a light-touch badge.

When should UK crypto firms apply, and how does the gateway work?

The FCA confirmed a fixed gateway window for crypto FSMA authorisation applications running from 30 September 2026 to 28 February 2027. Submitting during that period can make you eligible for transitional or savings provisions while the FCA processes your file, which helps with business continuity if the queue runs long (FCA — press release).

Translation: don’t leave it to the last week. Complex groups will spend months documenting governance, IT maps, risk, third-party dependencies, and controls. Booking external reviews and drafting a wind-down plan alone can take a quarter. Build in time for inevitable follow-up questions.

It’s worth repeating that the hard start date for the FSMA regime is 25 October 2027. You want a clean path to that date with either an authorisation already in hand or a transitional position because you filed in the gateway window. Anything else is a cliff edge (FCA).

Do you need a UK entity to be authorised?

Finalised guidance FG26/7 is clear about the FCA’s baseline expectation: if you require FCA authorisation for cryptoasset activities, you should carry them on from a UK legal entity. There are limited exceptions, specifically flagged for some qualifying overseas trading platforms, but the message is to plan on a UK company set up with real mind and management here (FCA — FG26/7).

Why this matters: a UK entity drives a bunch of design choices. Senior managers need to sit in clearly defined roles. Risk, compliance, and internal audit can’t be shadows on a group chart; they need scope and authority. Outsourced tech and group services must be governed with proper oversight and exit plans. And your board needs UK-appropriate composition and MI.

If you’re currently serving UK users from an overseas hub, assess whether you fit any of those narrow exceptions. Most firms won’t. The earlier you map a UK entity plan, the smoother your FSMA build will be.

Where does MLR registration fit into all this?

Separate to FSMA authorisation, the FCA reminds firms to be registered under the UK Money Laundering Regulations (MLRs) where applicable, and to sort this ahead of the FSMA regime. The FCA even signals practical cut-offs, including applying for MLR registration before 30 September 2026 if you need it, so you’re not blocked when the gateway opens (FCA).

Think of MLR as table stakes. If your AML registration isn’t squared away, your FSMA application track can stall. And the MLR review is often where weak firms get found out. Governance gaps, flaky customer risk assessment, poor blockchain analytics coverage, and thin SAR processes all show fast.

In short: check your MLR status now, align your AML target operating model with what you intend to file under FSMA, and don’t rely on last-minute triage.

How do MLR registration, FSMA authorisation, and transitional status compare?

Here’s a quick side-by-side to ground the conversation.

Item What it is Timing Who needs it Practical outcome
MLR registration Registration under UK Money Laundering Regulations Apply early; FCA signals applying before 30 Sep 2026 if relevant Firms carrying on relevant cryptoasset AML-regulated activity Allows you to lawfully operate for AML purposes; not a FSMA licence
FSMA authorisation Core permissions to carry on in-scope cryptoasset activities Apply during gateway: 30 Sep 2026–28 Feb 2027 Firms in or to the UK carrying on in-scope crypto activities Required to operate from 25 Oct 2027
Transitional/savings provisions Temporary arrangements if you file in the gateway window Dependent on a valid submission in the window Applicants that meet FCA conditions May support continuity pending a decision; not guaranteed

Always read the FCA’s page for the most current details and any scope nuance (FCA).

Crossing the compliance scanner before 2027

What should go into a strong FSMA application file?

Treat the application like a real operating manual, not a pitch deck. The FCA wants to see that your business can run safely, spot and manage risks, treat customers fairly, and wind down without chaos if needed.

  • Corporate map and rationale: group structure, ownership, roles, and why the UK entity sits where it does.
  • Governance: board and committee terms, MI packs, SMF responsibilities, and handover plans.
  • Financial crime: customer risk assessment, blockchain analytics coverage, KYT, PEP/sanctions controls, transaction monitoring, SAR playbooks.
  • Custody and safeguarding: wallet design, key management, reconciliation, segregation logic, recovery drills, and third-party diligence.
  • Operational resilience: impact tolerances, severe-but-plausible scenarios, runbooks, and supplier exit plans.
  • Technology: architecture diagrams, change control, security policy, incident response, and data retention.
  • Market integrity where relevant: surveillance, abuse prevention, and conflicts management.
  • Customer outcomes: disclosures, complaints handling, financial promotions governance, vulnerable customer policies.
  • Wind-down plan: triggers, liquidity and resource estimates, communications, and data retention.
  • Regulatory history: MLR status, any overseas licences, and remediation logs.
Pro tip: write for a reader who doesn’t know your stack. If a control only exists in an engineer’s head or in a Jira thread, it doesn’t exist for authorisation.

Before you submit, run a red-team style challenge of your own pack. Ask a fresh pair of eyes to spot the gaps. You’ll be grateful when the first round of FCA questions lands and you have answers ready.

How do the transitional and savings provisions really work?

The FCA’s press and guidance indicate that if you file a complete application during the 30 September 2026 to 28 February 2027 gateway, you may benefit from transitional or savings provisions. That language means potential breathing room while the FCA reviews applications, rather than a free pass to operate without standards (FCA — press release).

Eligibility and conditions matter. Expect the FCA to look at your current controls, your MLR status, and whether your submitted plans are credible. Don’t assume coverage if you file a shell of an application. Transitional help is there to prevent cliff effects, not to reward incomplete files.

The safest posture is simple: submit early in the gateway, keep your controls live and improving, and be ready to answer follow-ups quickly. Time kills momentum.

What should boards actually approve in H2 2026 and 2027?

Boards and founders can make or break the timeline. A few concrete approvals de-risk the whole journey.

  • Entity decision: approve the UK entity plan with real mind and management, per FG26/7 expectations (FCA — FG26/7).
  • MLR pathway: lock the registration plan and resourcing; aim to apply before 30 Sep 2026 if in scope (FCA).
  • SMF hiring: identify and contract senior managers who meet fitness and propriety standards, with clear role profiles.
  • Control testing: approve an internal audit or external readiness review focused on AML, custody, and resilience.
  • Budget and roadmap: allocate headcount and vendor spend through 2027 so the application build doesn’t stall.

If you can’t get those decisions through in Q3 2026, be honest about whether you can submit during the gateway. Slipping into late Q1 2027 compresses everything.

Common Mistakes

  1. Leaving MLR to the end. The FCA flags practical cut-offs. If you wait, your FSMA file can’t get traction. Start AML gap work now and lock your registration plan.
  2. Assuming an overseas entity will pass. FG26/7 sets the expectation for a UK entity with limited exceptions. Don’t architect around a loophole that isn’t yours.
  3. Underestimating wind-down. It’s not a paragraph. You need triggers, costed steps, customer communications, and data plans. Dry-run it.
  4. Paper-only controls. If your custody, monitoring, or resilience claims don’t match what your systems do today, the FCA will spot it. Evidence beats promises.
  5. Poor outsourcing oversight. If your whole stack runs on vendors, show exit plans, performance MI, and contract rights. Hope is not a control.
  6. Submitting at the cliff. Files that land at the end of the gateway create pressure and reduce your ability to answer follow-ups before the 2027 start date.

For ongoing coverage of UK crypto policy and the market knock-ons, visit Crypto Daily.

Frequently Asked Questions

Does this apply if my firm is overseas and we only have UK users through the app store?

If you’re carrying on in-scope cryptoasset activities in or to the UK, the FCA framework still bites. FG26/7 sets a baseline expectation for a UK legal entity, with limited exceptions for some qualifying overseas trading platforms. Most firms serving UK users should plan on a UK entity.

What if we submit in the gateway but don’t have a decision by 25 October 2027?

The FCA indicates applicants in the 30 Sep 2026–28 Feb 2027 window may benefit from transitional or savings provisions. It isn’t automatic or universal. Keep your controls live and be responsive to FCA queries to maintain any transitional position.

Can we operate with just an MLR registration after the regime starts?

No. From 25 October 2027, firms carrying on in-scope cryptoasset activities in or to the UK must hold the relevant FSMA permissions. MLR registration is separate and still important, but it’s not a substitute for FSMA authorisation.

We’re a DeFi team building open-source software. Do we need authorisation?

It depends on the actual activities and who is carrying them on in or to the UK. If you don’t carry on in-scope activities, you may fall outside. If you do, the regime applies. This is one to discuss with counsel using your real operating model.

How much time should we budget for drafting the wind-down plan?

Weeks, not days. You need costed steps, triggers, communications templates, and a data plan. Testing it with a tabletop exercise before you file helps surface gaps.

Will a group-level risk team outside the UK satisfy the FCA?

Only if UK oversight is real and effective. The guidance points to UK mind and management. You can use group services, but the UK entity needs clear accountability and the ability to challenge and exit if needed.

What happens if we miss the gateway window?

You can still seek authorisation, but you may not access the same transitional or savings provisions that help manage the cutover to 25 October 2027. That increases business risk. If you’re targeting the UK, plan to file in the window.

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

Related Stories