UK FCA warns crypto firms old registrations won’t carry into new regime

Daily Feed
UK FCA warns crypto firms old registrations won’t carry into new regime

The UK’s crypto rulebook is getting a proper teeth-and-claws update. The Financial Conduct Authority has told firms not to assume old registrations or permissions will carry into the new regime, because they won’t.

  • Fresh FCA authorization may be needed for crypto firms, including some overseas businesses serving UK customers.
  • Existing registrations do not automatically roll over into the new framework.
  • Stablecoins, custody, staking, and trading activity are all in the regulator’s sights.
  • The FCA will look at what a firm actually does, not the shiny label it slaps on the front door.

The FCA issued final guidance on Sep. 16, telling firms to reassess what permissions they need before applications open on Sep. 30 for the new authorization process. The framework is scheduled to take effect on Oct. 25, 2027, and firms seeking transitional arrangements must apply by Feb. 28, 2027.

The key point is brutally simple: current FCA registrations and permissions will not automatically transfer into the new system. If a firm is relying on its existing anti-money laundering registration, or another FCA permission, it may still need fresh authorization or a variation of permission once the new rules kick in.

That distinction matters. Authorization means formal FCA approval to carry out regulated activities. A variation of permission is what an already authorized firm may need if it wants to add crypto-related business to its existing permissions. In plain English: one is a new gate, the other is a bigger key for a door you already opened.

David Geale, the FCA’s executive director of consumers, payments and competition, said:

“Getting ready for regulation starts with understanding how the regime applies to your business.”

“This guidance gives firms the clarity they’ve asked for so they can prepare with confidence.”

That is the regulator’s polite way of saying: stop guessing, stop winging it, and stop pretending a compliance sticker makes the problem disappear.

What the FCA is actually asking firms to do

The guidance tells firms to examine the functions they perform, not just the way they market themselves. That sounds obvious, but crypto has spent years making “we’re not a financial firm, we’re a protocol/platform/tech layer” into a favorite dodge.

The FCA’s approach cuts through that. If a business is dealing in digital assets, arranging transactions, safeguarding customer cryptoassets, running a trading platform, issuing qualifying stablecoins, or providing staking services, the regulator wants a hard look at whether that activity falls inside the perimeter.

The term perimeter simply means the boundary between regulated and unregulated activity. Regulators care about the boundary because crypto firms often try to blur it. The FCA is saying that if the business walks like a regulated firm and quacks like a regulated firm, it does not get to hide behind a slick website and a white paper full of vapor.

Firms already holding other regulatory permissions may not need to start from scratch, but they may need a variation of permission. That is especially relevant for banks, brokers, payments firms, and other incumbents that want to offer crypto services without building a brand-new regulated entity.

Companies registered under the UK’s anti-money laundering rules also need to go through the new authorization process. That is a big deal because AML registration has never been the same thing as being fully authorized for regulated financial activity. It’s a narrower check, not a blank cheque.

What sits in scope

The FCA’s guidance and rule package point to a fairly broad crypto perimeter. The activities highlighted include:

  • qualifying stablecoins
  • crypto trading platforms
  • dealing in digital assets
  • arranging transactions
  • safeguarding cryptoassets
  • staking services

The package also includes rules on cryptoassets regime policy statements, stablecoin reserves and redemptions, crypto custody, operational resilience, consumer treatment, capital requirements, token admissions, and misconduct on trading platforms.

A few of those terms deserve plain English.

Safeguarding cryptoassets means holding customer crypto on their behalf and protecting it from loss, theft, commingling, or operational mess. In other words: custody, but with more cyber risk and fewer excuses when things go wrong.

Operational resilience is the ability to keep functioning through outages, hacks, failures, and other disruptions. In crypto, where “the platform is down” can become a lifestyle, this is not a decorative requirement.

Token admissions refers to the rules around letting tokens onto trading venues. That matters because listing a token is not the same as rubber-stamping it as safe, liquid, or suitable for ordinary users.

Misconduct on trading platforms covers bad behavior on venues, including market abuse-type conduct. That is the sort of thing that happens when a market is treated like a casino with better graphics and worse consequences.

Stablecoins and staking are the pressure points

Stablecoins are crypto assets designed to hold a stable value, usually by being backed by reserves. That reserve backing is the whole point: if the issuer claims a token is worth one unit of fiat, users want confidence that the backing assets are actually there, segregated, liquid, and redeemable when needed.

That is why regulators care so much about reserve management and redemption rules. If the “stable” part of a stablecoin turns out to be mostly branding, the market finds out the hard way.

Staking is another tricky area. At a basic level, staking means locking up crypto to help secure a network, often in exchange for rewards. But the regulatory treatment can change depending on how the service is structured. A direct protocol function, a custodial staking service, and a packaged yield product are not the same thing, even if the marketing team tries to blur the lines.

That distinction matters because the FCA is looking at the real function being performed. If a firm controls customer assets, intermediates the staking process, or markets a return in a way that looks and feels like a financial product, it may have a very different regulatory position than a bare protocol participant.

Why the UK is doing this

The UK has been building a dedicated crypto framework instead of relying only on anti-money laundering registration. Parliament approved the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 in February, and the wider package is meant to bring more digital asset activity under FCA oversight.

That shift is not subtle. The message is that crypto is no longer being treated as a side alley where firms can improvise forever. If a business handles customer assets, issues stablecoins, or runs market infrastructure, the UK wants it inside a proper supervisory framework.

The FCA is not doing this alone. The Treasury, Parliament, and the Bank of England all have a hand in the broader policy direction. That matters because crypto regulation in the UK is becoming an institutional project, not just a single-regulator mood swing.

The House of Lords also voted 194-138 in September for an amendment requiring the Treasury to prepare a national digital asset strategy within 12 months of the Financial Services and Markets Bill becoming law. Whether that survives in final form is a separate question, but the vote shows there is still political appetite to keep pushing the issue.

What firms should do now

The practical next step is boring but necessary: map the business properly.

Firms need to review what they actually do, identify which activities may fall inside the FCA perimeter, and decide whether they need full authorization, a variation of permission, or transitional arrangements. That means looking at custody models, transaction flows, stablecoin handling, staking structures, marketing claims, and who controls what at each stage.

For firms seeking transitional arrangements, the deadline is Feb. 28, 2027. That gives some runway, but not much if the legal and operational work starts late. In regulated markets, “we’ll sort it out later” is how companies end up in a very expensive meeting with lawyers.

Overseas firms should pay close attention too. Serving UK customers does not automatically exempt a business from UK regulation. If a foreign company is performing regulated crypto activities for the UK market, the FCA may still expect authorization.

The same point applies to firms that have already cleared some regulatory hurdle elsewhere. Approval from the SEC, the CFTC, a state regulator, or another foreign authority is not a substitute for FCA permission if the UK regime applies.

What is still not settled

Even with final guidance in place, not everything is nailed down. The FCA said it will consult further in October on qualifying UK stablecoins, proprietary trading, market making, some technology providers, decentralized protocols, custody arrangements involving central securities depositories, and financial promotion rules.

That means parts of the perimeter are still being drawn. For firms working in more crypto-native models, that uncertainty matters. A business can prepare now, but the final shape of some requirements may still shift.

The Bank of England is also considering whether eligible tokenized assets, including stablecoins, could serve as collateral under its FedNow Service Overview and Features. The FCA and the Bank of England plan to publish a roadmap for tokenization in wholesale financial markets as well.

If those pieces come together, the UK will not just be regulating crypto. It will also be trying to wire tokenized assets into the machinery of mainstream finance. That is the real prize, and the real test.

Handled well, that could make the UK a serious home for regulated crypto and tokenized financial infrastructure. Handled badly, it could become a maze of compliance burdens that only the biggest incumbents can stomach while everyone else gets squeezed out. There is a fine line between sensible oversight and bureaucratic sludge.

Key takeaways

  • Will old crypto permissions still work under the new regime?
    No. The FCA says existing registrations and permissions will not automatically carry over, so firms may need fresh authorization or a variation of permission.
  • What crypto activities are in scope?
    The guidance points to stablecoins, trading platforms, dealing, arranging transactions, safeguarding cryptoassets, and staking services, with more detail still coming in consultation.
  • What is the difference between authorization and AML registration?
    AML registration is narrower and focused on money-laundering controls. FCA authorization is a broader approval to carry out regulated activities.
  • Do overseas firms need to care?
    Yes, if they serve UK customers and perform regulated activities. Being based abroad is not a free pass.
  • Why is the FCA focusing on what firms do rather than what they call themselves?
    Because regulators look at substance, not branding. A business does not escape regulation just by calling itself a technology platform.
  • What should firms do first?
    Map their activities, review custody and transaction flows, assess whether they need authorization or a variation of permission, and prepare for any transitional deadline well before the clock runs out.

The message from the UK is clear enough: crypto firms are being pulled into a real regulatory framework, not a vibes-based registration scheme. The final perimeter is still evolving, but the days of assuming yesterday’s paperwork covers tomorrow’s business are over.

Further reading

A few useful sources for the regulatory and market context behind this UK crypto crackdown:

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog