The UK’s Financial Conduct Authority is opening its crypto authorisation gateway on Wednesday, but the easy part is the calendar. The hard part is proving a firm actually fits the new rules, activity by activity, without assuming old anti-money laundering registration buys a free pass.
- Gateway opens: 7 a.m. UK time on Sept. 30, 2026
- Main window closes: Feb. 28, 2027
- Regime expected to start: Oct. 25, 2027
- No automatic conversion: AML registration does not become FSMA authorisation
- Timing matters: valid, complete filings get far better treatment than late or incomplete ones
According to the FCA’s final perimeter guidance published on Sept. 16, the UK is moving into a new authorisation framework for specific cryptoasset activities under the Financial Services and Markets Act 2000. That matters because this is not a single, all-purpose “crypto licence.” It is a permissions regime, and the regulator wants firms to map what they actually do to the right legal category.
On Sept. 17, the FCA also published an information-only preview of the application form, alongside a 73-page preview that gives firms a clear look at what the regulator expects to see. The message is not subtle: start now, because the paperwork is where optimism goes to die if the controls are weak.
“The door opens Wednesday, but entering it is not an approval.”
What the FCA is actually opening
The application gateway opens at 7 a.m. UK time on Sept. 30, 2026, with the main application period closing on Feb. 28, 2027. The regime itself is expected to begin on Oct. 25, 2027, according to the FCA materials described in the guidance preview.
That gap between opening and commencement is the critical part. Firms that submit a valid application during the main window may be able to keep serving customers while the FCA is still deciding the application, under a saving provision. That is not a blank cheque. It is a conditional bridge, and it only helps firms that filed properly and on time.
Late filings are a different animal. The FCA’s position, as described in the guidance preview, is that firms can still submit after Feb. 28, but they should not expect special treatment simply because they were late. If approval is still pending when the regime starts, a late applicant may be pushed into a more limited route focused on pre-existing contracts and orderly run-off rather than normal business expansion.
In regulator-speak, that is the difference between continuing a business and being allowed to wind one down without blowing up the market on the way out.
AML registration is not authorisation
One of the biggest misconceptions is also one of the most dangerous: existing anti-money laundering registration does not automatically convert into FSMA authorisation.
That distinction matters because AML registration and authorisation are not the same thing. AML registration is focused on financial crime controls. FSMA authorisation is broader and asks whether the firm is permitted to carry on regulated cryptoasset activity at all, under the right conditions, with the right governance and controls in place.
So if a firm already appears to be in good standing on the AML side, that is a start, not a finish line. It may show the business has at least met one regulatory hurdle. It does not mean the FCA will rubber-stamp the new one.
The practical takeaway is simple: if the firm is building on the assumption that past registration equals future permission, that assumption is rubbish.
The real task: map the business, not the branding
The source materials point to the real challenge with blunt clarity: the hard part starts with a map of the actual business: order flow, wallets, contracts, control of keys, customer residency and the people responsible for each.
That is where many crypto firms get exposed. A company may talk about one brand, one app, and one user experience, but regulators care about the legal and operational plumbing underneath it. Who controls customer assets? Who handles the orders? Which entity is dealing with the customer? Which team is responsible for the UK branch? What happens when systems fail?
Those are not abstract questions. They decide which permission a firm needs, whether it needs more than one, and whether the application tells a coherent story or a compliance fairy tale.
The FCA’s map of regulated crypto activities includes nine activity descriptions, covering:
- UK issuance of qualifying stablecoins
- safeguarding qualifying crypto assets
- arranging for another party to safeguard them
- operating a qualifying trading platform
- dealing as principal or agent
- two kinds of arranging deals
- qualifying crypto asset staking
In plain English, safeguarding means holding or protecting customer crypto assets or the keys that control them. Arranging means facilitating or intermediating a deal or custody arrangement without necessarily being the one actually holding the bag. A trading platform is the venue where matching or order execution happens. And staking is the process of locking up qualifying crypto assets to support network operations or earn rewards, which the FCA has now brought into the permission map for the relevant activity.
These categories are not cosmetic. A custodian is not an exchange. A stablecoin issuer is not a broker. A staking provider is not just “another crypto company.” Each one can trigger different permissions and different obligations.
Why timing matters so much
The distinction between a timely, valid application and a late or incomplete one is the whole game here.
A firm that submits within the Sept. 30 to Feb. 28 window may benefit from transitional protection if the application is still pending when the new regime begins. That protection is what keeps the business from being forced off a cliff on day one.
But there are conditions. The filing must be valid. If the application is rejected as incomplete, the firm does not get the same status as a complete filing. Pressing submit at the last minute without proper controls, disclosures, and permissions does not magically secure the same position as doing the job properly.
The FCA also says the transitional route has a maximum duration of two years after commencement. So this is not a forever bridge. It is a limited runway, and firms that need more than that will need to be fully authorised or out.
That is the kind of detail compliance teams obsess over for a reason. It can decide whether a firm keeps operating, starts shrinking, or ends up in orderly run-off while everyone pretends that was the plan all along.
What firms are likely to be asked for
The preview materials suggest the FCA will want much more than a polished policy deck and a reassuring tone of voice. Firms may need to disclose their close links and controllers, submit a board-approved implementation plan, explain operational resilience, and address retail appropriateness where relevant.
Close links and controllers means ownership and control relationships the regulator wants to see clearly. Who owns the firm? Who controls it? Who sits behind it? A web of entities with vague responsibility lines is exactly the kind of structure regulators dislike, and with good reason.
Operational resilience means the firm’s ability to keep running when something goes wrong, cyber incidents, wallet failures, vendor outages, key-management problems, broken internal controls, all the usual crypto party tricks. The FCA wants evidence that the business can survive stress, not just look impressive in a pitch deck.
Retail appropriateness is the question of whether a product or service is suitable for ordinary customers. That is especially relevant in a market where a lot of products are sold with more hype than substance and more slogans than safeguards.
Overseas firms applying through a UK branch will also need to explain how UK standards are met in practice, not merely in theory. “The group handles it” is not a compliance strategy. It is a sentence that tends to annoy regulators and worry lawyers.
Who feels this most
Well-run firms with mature compliance and operations teams should be able to treat this as a serious but manageable reset. The regime gives legal clarity, and serious firms usually prefer clarity to a vague regulatory shrug.
Smaller firms, or businesses that grew fast without building real controls, may struggle. That is not a bug in the system. It is the point of the system. If a company is touching custody, trading, payment rails, or customer assets, then the bar should not be “we made a nice website and sent a newsletter.”
Crypto.news has also reported that Binance is planning a UK licence bid, while UK banks can retain crypto payment restrictions even as the wider framework approaches. That matters because authorisation does not automatically mean banking access. A firm can be legally in the game and still be blocked by conservative payment rails if counterparties decide the risk is not worth the hassle.
That is the quiet choke point in this market: regulation can open a door, but it cannot force banks to smile while they hold it open.
Why this is bigger than a filing deadline
The UK is drawing a cleaner line between legitimate crypto businesses and the sort of half-baked operators that survive on marketing, offshore opacity, and optimism taken intravenously. That is good for market integrity, even if it is painful for firms that never bothered to build proper controls.
For decentralization-minded people, there is a fair tension here. Centralized gatekeepers can overreach. Bureaucracy can be slow, expensive, and occasionally ridiculous. But a serious market also needs basic standards that separate infrastructure from fraud. Nobody needs another “revolutionary” platform that turns out to be a flimsy wrapper around someone else’s chaos.
Bitcoin does not need a regulator’s blessing to exist. But firms that custody assets, run trading venues, issue stablecoins, or touch customer funds absolutely need clear rules if they want to operate in a major financial center like the UK.
That is the real shift here. The FCA is not just opening a portal. It is demanding that firms prove they are actual businesses with actual controls, not just branding exercises with a compliance folder taped to the side.
Key questions and takeaways
-
Does AML registration automatically become FSMA authorisation?
No. The FCA has made clear that anti-money laundering registration does not convert into the new permission automatically. -
What is the biggest thing firms need to get right?
They need to match their real activities to the correct permissions and submit a complete, valid application. -
Does filing on time guarantee continued operations?
No. A timely valid filing may help preserve continuity while the FCA reviews it, but approval is not automatic. -
What happens if a firm applies late?
The FCA may still accept the filing, but late applicants should not expect faster treatment and may face only limited transitional rights. -
What if the application is incomplete?
An incomplete filing does not get the same protection as a valid application, which can leave the firm in a much weaker position. -
How long can transitional arrangements last?
The source materials say the transitional route can last up to two years after commencement. -
Why does this matter for the wider crypto market?
It raises the bar for UK firms and should push out sloppy operators while rewarding businesses with real controls, real governance, and real accountability.
The FCA has opened the gate. Now firms have to show they know what door they are walking through, what permission they need, and whether their business is actually built to survive scrutiny. The clock is ticking, and the regulator is not in the mood for vague answers.
Further reading
A few useful threads on UK crypto rules, custody, and market plumbing worth keeping on hand.
- Bank Activities: Crypto-Asset Safekeeping Services
- Cloud Mining: A Comprehensive Review of Top Platforms
- FCA finalises the UK Crypto Regime
- UK FCA Finalizes Crypto Rules for Firms, Stablecoins and Market Abuse Controls
- UK Pulls Crypto Into FSMA Rulebook With Broad FCA Oversight
- Tether and Circle Mint $1.75B in Stablecoins to Counter