Back to Insights
    0September 7, 2026

    How Should Crypto Firms Prepare for the FCA's September 2026 Application Gateway?

    UK-facing crypto firms should use the September 2026 gateway to prove that their operating model can meet ongoing FCA standards before the new regime begins.

    How Should Crypto Firms Prepare for the FCA's September 2026 Application Gateway?

    UK-facing crypto firms should use the September 2026 gateway to prove that their operating model can meet ongoing FCA standards before the new regime begins.

    The dates set two separate deadlines

    The FCA crypto application window is scheduled to open on 30 September 2026 and close on 28 February 2027. The new UK cryptoasset regime is expected to commence on 25 October 2027.

    That timetable creates two jobs:

    1. Submit a complete application during the five-month gateway period.
    2. Complete the operational changes required to operate under the new regime by commencement.

    The FCA describes this as a pre-commencement authorisation process. It is not simply an administrative migration from the current anti-money laundering registration regime. Firms should expect the FCA to assess whether they can meet continuing standards around governance, financial resources, systems, customer treatment and supervision.

    The FCA has also encouraged early, high-quality applications and warned that incomplete or poor-quality submissions may be rejected, delayed or refused. Its preparation guidance for the new cryptoasset regime makes clear that firms need a realistic, board-agreed implementation plan before filing.

    Start with a permissions and perimeter assessment

    The first decision is which regulated cryptoasset activities the business actually conducts for UK customers.

    The new FSMA regime covers activities including:

    • Issuing qualifying stablecoins in the UK
    • Safeguarding cryptoassets and arranging safeguarding
    • Operating a qualifying cryptoasset trading platform
    • Dealing in cryptoassets as principal or agent
    • Arranging cryptoasset deals
    • Making arrangements with a view to cryptoasset transactions
    • Providing qualifying cryptoasset staking services

    The FCA’s summary of cryptoasset regulated activities uses an activity-based framework. Labels such as “exchange”, “wallet provider”, “tokenisation platform” or “DeFi interface” do not determine the required permissions by themselves.

    A firm may perform several regulated activities through a combination of group entities, smart-contract interfaces, third-party custodians, liquidity venues, validators and outsourced technology providers. The application must reflect what happens across the full service flow, including:

    • How a UK customer enters the service
    • Which entity contracts with that customer
    • Who controls assets, private keys or access credentials
    • How orders are arranged or executed
    • Where assets, reserves and transaction records sit
    • Which functions are performed by third parties
    • How the UK business is supervised and governed

    This exercise should cover current services and near-term commercial plans. Applying for a broad permission set may support future expansion, but it also increases the evidence required and raises questions about whether the firm has the operational maturity to conduct every requested activity. A narrower application may be easier to support, but can constrain product development until further permissions are obtained.

    Existing FCA status does not remove the authorisation task

    MLR registration does not convert automatically into FSMA authorisation.

    The current Money Laundering Regulations regime is focused on financial-crime supervision. The new framework involves a wider assessment of the firm, its business model, senior people, systems, financial resources and ability to meet conduct requirements.

    Firms already authorised under FSMA, including certain payment-services or e-money businesses, must apply for a variation of permission if they wish to conduct the new regulated cryptoasset activities. The FCA’s gateway operating guidance confirms both routes.

    Existing registration or authorisation can provide useful evidence. It may demonstrate established compliance capability, governance arrangements or financial-crime controls. It does not establish that the firm meets the requirements for each proposed cryptoasset permission.

    The FCA also states that its assessment of whether individuals are fit and proper under FSMA is broader than the equivalent MLR assessment. Founder-led firms, overseas-managed groups and businesses with informal decision rights should examine whether their UK governance model can show clear accountability, appropriate senior management and effective supervision.

    Build an evidence programme before the form is available

    The application form was still being finalised when the FCA published its July 2026 gateway update. The FCA did not expect its overall structure and content to change, but detailed wording and explanations may still change.

    That should not delay substantive preparation. The FCA’s application information document identifies a substantial evidence package, including:

    • Senior-management applications
    • Controller and close-link information
    • A group and organisational structure chart
    • A regulatory business plan
    • Projected income and financial forecasts
    • An IT self-assessment and control information
    • A financial-crime framework
    • A compliance monitoring plan
    • A complaints policy
    • A cryptoasset records-management policy

    The central challenge is consistency. A regulatory business plan must agree with the requested permissions, customer journeys, staffing model, systems architecture, outsourcing arrangements and financial forecasts. A policy that describes controls which engineering, operations or third-party providers cannot demonstrate will weaken the overall application.

    A board-approved programme should therefore assign accountable owners across legal, compliance, finance, technology, information security, operations and product. It should also set decision dates for unresolved issues, including entity structure, outsourcing changes, capital requirements and product constraints.

    The FCA’s optional Pre-Application Support Service can help firms explain their business model and understand process expectations. It requires meaningful supporting information and does not provide legal advice or guarantee authorisation.

    Activity-specific operations need activity-specific evidence

    Cryptoasset infrastructure becomes part of the regulatory case where it affects customer assets, execution, resilience or oversight.

    For safeguarding permissions, the FCA expects evidence on records and reconciliations, trust arrangements, third-party custodian oversight and the security of access to client cryptoassets. Firms should be able to explain their wallet architecture, key-management model, reconciliation process, blockchain-data dependencies and contingency arrangements.

    For qualifying stablecoin issuance, the FCA expects material on redemption, disclosures, backing assets and third-party arrangements. Reserve management, custody, valuation, contractual rights and operational access to data are therefore central to the application.

    Trading-platform, dealing and staking models require the same level of factual mapping. A staking service may involve validators, delegation arrangements, reward flows, slashing exposure and customer communications. A trading model may involve principal risk, agency execution, venue relationships or external liquidity. The required permission analysis cannot be completed from a product name or marketing description.

    The FCA has published final policy material for core requirements, prudential standards and several regulated activities. However, it has also identified further work in areas including DeFi, DLT, cryptoasset derivatives, audit requirements and certain stablecoin matters. Its stated approach to DeFi depends in part on whether there is an identifiable controlling entity, with some questions remaining subject to further consultation and case-by-case assessment. The FCA’s policy-statement overview should be monitored alongside facts-specific legal analysis.

    Treat continuity planning as a separate workstream

    A timely, complete application has important continuity consequences.

    The FCA expects firms applying during the gateway period to receive a decision before the regime commences. If the application remains unresolved, a saving provision may allow the firm to continue providing cryptoasset services while the FCA determines the application, subject to the relevant conditions and notifications.

    That provision does not amount to authorisation. It does not remove the risk of further information requests, extended assessment, restrictions or refusal. Firms should model the operational and commercial effects of each outcome.

    The alternative transitional provision is materially narrower. It supports orderly run-off of pre-existing contracts. It does not allow firms to enter new contracts with existing or new UK customers. The FCA states that firms which do not apply before commencement are not eligible, and rejected incomplete applications may be treated as if no application was made unless a later valid application is submitted.

    The FCA’s transitional-provision guidance means that late filing is not a workable plan for continuing normal UK growth. Contract renewals, new product terms, top-ups, migrations and partner arrangements may all require careful assessment where the business is limited to run-off.

    The September gateway is therefore a test of whether a crypto firm can evidence a durable UK operating model.