Skip to content
UK MarketsIndependent UK news, policy and video briefings from @OneGenMedia
OGM OneGeneration News | OGMUK news, policy, and video briefings powered by @OneGenMedia Subscribe @OneGenMedia

FCA Outlines Compliance Pathways for UK Cryptoasset and Custody Providers

FCA cryptoasset compliance pathways and UK custody editorial illustration

The Financial Conduct Authority (FCA) has published a set of final rules, guidance and explanatory material that set out the regulatory architecture and expectations for firms engaging in a range of cryptoasset activities. The FCA says these changes — articulated across a set of policy statements, consultation papers and guidance — form the basis of FCA cryptoasset compliance pathways that firms and advisers will need to understand as the regime expands under the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 (the 2026 Regulations). (The FCA’s published overview of the regime is available from the FCA.)1

According to the FCA, the 2026 Regulations passed Parliament on 4 February 2026 and enlarge the perimeter of regulated activity; the FCA says the full scope of regulated activities under the new framework is due to come into effect from 25 October 2027. The FCA has published final rules and guidance, including activity-specific material, core requirement documents and material on custody and stablecoins, which the FCA says firms authorised under FSMA on or after 25 October 2027 will need to follow. Those materials together form the practical FCA cryptoasset compliance pathways described in the documents the FCA has issued.2

FCA cryptoasset compliance pathways

The FCA says the package of final material it published sets out “the rules and guidance firms will need to follow” and that firms providing cryptoasset services, including custody, should read its policy statement PS26/11 alongside core requirement documents. The FCA describes this body of work as the set of documents that firms will use to understand FCA cryptoasset compliance pathways for regulated activity under the new FSMA-based perimeter.1,2

Those documents are presented by the FCA as a mapped set of policy statements, consultation materials and supporting guidance. The FCA says they include activity-specific requirements, a prudential framework, Handbook application material, and custody and stablecoin-specific material. The FCA also emphasises the continuation of the Money Laundering Regulations (MLR) and financial-promotion standards in the recent past and clarifies that prior registration under the MLR or a firm’s use of the financial-promotions mechanisms should not be used as a proxy to infer regulatory status under the new FSMA regime.1,2

Snapshot: what the FCA has published

  • The FCA says the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 passed Parliament on 4 February 2026 and expand the regulatory perimeter, with the full regulated scope expanding from 25 October 2027.1
  • The FCA says it published final rules and guidance for cryptoasset firms, and identifies a set of core documents and activity-specific policy statements that firms should read (PS26/11, PS26/12, PS26/13 and associated material).1
  • The FCA says it is proceeding with a client-asset-style regime for cryptoassets (CASS 17), identifying protections around ownership rights, record keeping, reconciliation and private-key management, and states it adopted a technology-agnostic private-key approach.1
  • The FCA’s CP25/14 consultation paper on stablecoin issuance and cryptoasset custody was first published on 28 May 2025 and updated on 30 June 2026; the FCA says final rules and guidance from that work were published on 30 June 2026 and will apply to firms authorised under FSMA on or after 25 October 2027.2

Dated policy timeline (key dates from the FCA documents)

The FCA’s two published materials provide the principal dates the regulator highlights. The following table sets those dates out succinctly as the FCA presents them.

Date FCA statement (as presented in FCA documents)
28 May 2025 CP25/14 first published (stablecoin issuance and cryptoasset custody).2
4 Feb 2026 Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 passed Parliament, according to the FCA.1
30 June 2026 FCA published final rules and guidance across its cryptoasset regime policy statements and updated CP25/14; FCA says final rules and guidance were published on this date.1,2
25 Oct 2027 The FCA says the full scope of regulated activities will expand from this date and final rules will apply to firms authorised under FSMA on or after this date.1,2

How the current MLR/financial-promotion context differs from the future FSMA regime

The FCA’s materials stress a clear distinction between the prior regulatory context the FCA applied to parts of the crypto market and the future FSMA-based regime. According to the FCA:

  • Historically, the FCA’s role in the crypto market was framed by the Money Laundering Regulations and by its financial-promotion standards.1,2
  • The FCA says the future framework represents an expansion from that prior MLR and financial-promotion footing to a more comprehensive crypto regime under FSMA.2
  • The FCA explicitly cautions against inferring a firm’s regulatory status from previous MLR registration or from a firm’s use of financial-promotion mechanisms; such facts do not establish whether a firm is authorised or falls within the FSMA-based perimeter.1

FCA cryptoasset compliance pathways: document map

The FCA presents a multi-document map for the regime. The FCA says firms providing cryptoasset services, including custody, should read PS26/11 and related documents. The FCA also identifies core requirements (PS26/13, PS26/12) and associated materials, and describes the custody and stablecoin material that was set out in CP25/14 and later finalised.1,2

Below is a compact mapping, prepared from the FCA’s text, of the principal document identifiers the FCA names and the topics the FCA associates with each.

Document identifier (FCA label) Topic(s) the FCA associates with the document (FCA description)
PS26/11 Activity-specific rules for trading platforms and intermediaries; safeguarding client cryptoassets; lending and borrowing; staking (FCA directs firms to read PS26/11).1
PS26/12 Prudential requirements (identified by the FCA as a core requirement).1
PS26/13 FCA Handbook application (identified by the FCA as a core requirement).1
CP25/14 Stablecoin issuance and cryptoasset custody; consultation first published 28 May 2025 and updated 30 June 2026; final rules and guidance published 30 June 2026 and applying from 25 Oct 2027 (FCA description).2
CASS 17 (proceeding) Client-asset-style protections for client cryptoassets — ownership, record keeping, reconciliation, private-key management; the FCA is proceeding with CASS 17 and has adopted a technology-agnostic private-key approach.1

Core requirement: PS26/13 — FCA Handbook application (summary of FCA description)

The FCA says PS26/13 sets out how the FCA Handbook will apply to firms carrying on regulated cryptoasset activities. According to the FCA, PS26/13 is one of the core documents firms will need to read to understand how existing statutory and Handbook obligations will interact with the new cryptoasset regime.1

The FCA’s description highlights that PS26/13 is designed to clarify application rather than to create standalone novel obligations beyond the Handbook where the FCA has not stated them. The FCA places PS26/13 alongside prudential material and activity-specific requirements as part of the core set firms should consult.1

Core requirement: PS26/12 — Prudential requirements (summary of FCA description)

The FCA says PS26/12 contains prudential requirements that form another core strand of the regime. The FCA identifies prudential requirements as a core part of the FCA cryptoasset compliance pathways and lists PS26/12 as the relevant material to understand prudential expectations.1

The FCA’s materials place PS26/12 in close relation to PS26/13 (Handbook application) and to activity-specific rules set out in PS26/11. The FCA describes PS26/12 as the locus of prudential rules and guidance the FCA expects firms to consult as part of preparing to operate under the FSMA-based perimeter.1

Activity-specific rules: PS26/11 — trading platforms, intermediaries, lending, borrowing, staking

The FCA says PS26/11 contains activity-specific rules, and it explicitly directs firms providing cryptoasset services — including custody providers — to read PS26/11. The FCA states that PS26/11 covers trading platforms and intermediaries and contains rules on safeguarding client cryptoassets, as well as rules on lending and borrowing, and staking.1

The FCA describes PS26/11 as the place where firms will find the specific activity-oriented obligations and guidance that will sit alongside the core Handbook and prudential material. According to the FCA, firms providing those services should read PS26/11 together with the other documents in the policy set.1

Custody and safeguarding: CP25/14 and CASS 17 proceeding (what the FCA says)

The FCA’s consultation CP25/14 — first published on 28 May 2025 and updated on 30 June 2026 — addressed stablecoin issuance and cryptoasset custody. The FCA says final rules and guidance from that work were published on 30 June 2026 and that the final rules will apply to firms authorised under FSMA on or after 25 October 2027.2

Separately, the FCA says it is proceeding with a client-asset-style regime called CASS 17 for client cryptoassets. The FCA identifies in its PS material that CASS 17 will include protections around ownership rights, record keeping, reconciliation and private-key management.1

CASS 17 protections: ownership rights, record keeping, reconciliation and private-key management

According to the FCA, the protections it intends for client cryptoassets in CASS 17 include defined elements the FCA lists as ownership rights, record keeping, reconciliation and private-key management. The FCA says it is proceeding with this set of protections and that these will form part of the custody and safeguarding approach under the FSMA-based framework.1

The FCA also states that it has adopted a technology-agnostic private-key approach within this CASS 17 workstream. That is, the FCA describes the private-key method as not being tied to a single technology approach in the rules it presented. The FCA sets out these elements as part of the safeguarding and custody protections it is moving forward with.1

The FCA’s technology-agnostic private-key approach (what the FCA describes)

The FCA says it adopted a technology-agnostic position on private-key management within the CASS 17 framework, and it lists private-key management as a specific protection area under CASS 17.1

Technology-agnostic in the FCA’s description means that the FCA’s approach to private-key treatment in CASS 17 does not presuppose a single technological design; the FCA presents private-key management as a set of protections and expectations rather than as a prescription of one technical implementation. The FCA also signals in its materials that further engagement is planned on tokenised asset custody and potential CASS amendments.1

Tokenised asset custody and FCA engagement on potential future CASS amendments

The FCA says it plans further engagement on tokenised asset custody and potential future amendments to CASS. The FCA’s language describes tokenised asset custody as an area that may require additional work and interaction between the regulator and market participants, and the FCA presents it as part of its forward-looking engagement rather than as already-determined rules.1

Stablecoins: CP25/14 — qualifying stablecoin issuance and safeguarding qualifying cryptoassets

The FCA’s CP25/14 paper, first published 28 May 2025 and updated 30 June 2026, concerns the issuance of qualifying stablecoins and the safeguarding of qualifying cryptoassets, including qualifying stablecoins. The FCA says that final rules and guidance from the CP25/14 work were published on 30 June 2026 and that they will apply to firms authorised under FSMA on or after 25 October 2027.2

The FCA describes CP25/14 as constituting an extension from the regulator’s prior role under the MLR and financial-promotion regimes into a more comprehensive FSMA-based framework addressing stablecoin issuance and custody of qualifying cryptoassets.2

Operational resilience, Consumer Duty and international guidance (what the FCA cites)

In describing the core documents, the FCA places operational resilience, the Consumer Duty and international cryptoasset-firm guidance alongside the core requirements and PS26/11 activity-specific material. The FCA lists Consumer Duty, operational-resilience and international cryptoasset-firm guidance as associated elements of the overall package of material that firms should consider as part of the regulatory framework.1

The FCA’s combined presentation treats these items as cross-cutting elements that accompany the prudential, custody and activity-specific material. The FCA identifies them as part of the set of considerations firms will need to address once operating under the FSMA-based perimeter.1

Application date and practical read-across (what the FCA has said about timing)

The FCA states that the 2026 Regulations passed Parliament on 4 February 2026 and that the full scope of regulated activities will expand from 25 October 2027. The FCA further says the final rules and guidance published on 30 June 2026 will apply to firms authorised under FSMA on or after 25 October 2027.1,2

The FCA’s materials therefore present a read-across in which the legislative change (the 2026 Regulations) has been made and the regulator’s published rules and guidance are timed to apply in connection with the expansion of regulated activities from the October 2027 date the FCA set out.1,2

Which firms should read which documents: an FCA-directed checklist

The FCA’s own guidance language highlights documents firms “should read”. The following checklist is derived from the FCA’s phrasing and is an organisational rendering of the FCA’s direction about which documents are relevant to which types of activity; it does not assess or characterise any particular firm.

  • Firms providing cryptoasset services, including custody: the FCA says they should read PS26/11.1
  • Firms concerned with prudential requirements: the FCA says they should read PS26/12.1
  • Firms and advisers seeking to understand how the Handbook applies: the FCA says they should read PS26/13.1
  • Firms involved in stablecoin issuance or custody of qualifying stablecoins/qualifying cryptoassets: the FCA says they should read CP25/14.2
  • Firms that will hold or control client cryptoassets: the FCA says to note CASS 17 protections on ownership rights, record keeping, reconciliation and private-key management.1
  • Firms with cross-border operations or that need to consider international practice: the FCA lists international cryptoasset-firm guidance as an associated consideration.1

Four compact tables to help navigate the regime (documents, safeguards, dates, scope)

Table A — Principal FCA documents and their FCA-described focus

FCA document FCA-described focus (directly from FCA materials)
PS26/11 Activity-specific rules for trading platforms and intermediaries; safeguarding client cryptoassets; lending and borrowing; staking.1
PS26/12 Prudential requirements.1
PS26/13 FCA Handbook application.1
CP25/14 Stablecoin issuance and cryptoasset custody; final rules and guidance published 30 June 2026.2
CASS 17 (proceeding) Client cryptoasset protections: ownership, record keeping, reconciliation, private-key management.1

Table B — CASS 17 protections (as identified by the FCA)

Protection area FCA description
Ownership rights Included by the FCA as a protection area for client cryptoassets under CASS 17.1
Record keeping Included by the FCA as a protection area for client cryptoassets under CASS 17.1
Reconciliation Included by the FCA as a protection area for client cryptoassets under CASS 17.1
Private-key management Included by the FCA as a protection area for client cryptoassets; FCA adopted a technology-agnostic private-key approach.1

Table C — Key dates (summary from FCA documents)

Date Significance (as described by the FCA)
28 May 2025 CP25/14 first published (stablecoins and custody).2
4 Feb 2026 2026 Regulations passed Parliament (FCA statement).1
30 June 2026 FCA published final rules and guidance in the policy statements and updated CP25/14; FCA says final rules and guidance were published on 30 June 2026.1,2
25 Oct 2027 Full scope of regulated activities expands from this date; final rules apply to firms authorised under FSMA on or after this date.1,2

Table D — Current MLR/financial-promotion context vs future FSMA regime (as the FCA frames them)

Aspect FCA description of prior context FCA description of FSMA-based regime
Regulatory framing Money Laundering Regulations and financial-promotion standards framed the FCA’s prior role in the market.1,2 The FCA says the future FSMA-based framework expands beyond MLR/financial-promotion to a more comprehensive crypto regime.2
Inference about firm status The FCA warns not to infer a firm’s status from prior MLR registration or financial-promotion facts.1 Undergoing authorisation under FSMA and final rules applying from 25 Oct 2027 are the FCA’s stated points of application.1,2

Document-by-document source detail

PS26/11: PS26/11 is the activity-specific strand the FCA highlights in its overview. According to the FCA, PS26/11 covers trading platforms and intermediaries and contains rules for safeguarding client cryptoassets. The FCA says PS26/11 also addresses lending and borrowing and staking. The FCA’s overview directs firms providing cryptoasset services, including custody providers, to read PS26/11 as part of the set of materials that comprise the FCA cryptoasset compliance pathways.1

PS26/12: The FCA presents PS26/12 as the prudential component of the regime. The FCA identifies prudential requirements as a core requirement and lists PS26/12 among the materials firms should consult to understand prudential expectations. The FCA’s overview presents PS26/12 alongside the Handbook application material and activity-specific policy statements.1

PS26/13: The FCA presents PS26/13 as the document that addresses how the FCA Handbook will apply to firms carrying on regulated cryptoasset activity. The FCA lists PS26/13 as a core requirement and suggests firms consult it to understand the operation of the Handbook in the cryptoasset context.1

CASS 17 (proceeding): The FCA says it is proceeding with a CASS-style regime for client cryptoassets, referred to as CASS 17, and identifies specific protections the FCA is taking forward: ownership rights, record keeping, reconciliation and private-key management. The FCA describes the private-key approach within CASS 17 as technology-agnostic and signals that further engagement will take place on tokenised asset custody and potential future CASS amendments.1

CP25/14: The FCA’s CP25/14 consultation covered stablecoin issuance and cryptoasset custody. The FCA notes that CP25/14 was first published on 28 May 2025 and that it was updated on 30 June 2026. The FCA says final rules and guidance resulting from CP25/14 were published on 30 June 2026 and that those final rules and guidance will apply to firms authorised under FSMA on or after 25 October 2027. The FCA characterises the CP25/14 work as an extension of its prior role under MLR and financial-promotion frameworks into a more comprehensive FSMA-based regime for stablecoins and custody.2

Operational resilience, Consumer Duty, international guidance: The FCA lists operational resilience, Consumer Duty and international cryptoasset-firm guidance as associated elements to be considered in the overall package that comprises the FCA’s published policy statements and guidance. These items are presented by the FCA as cross-cutting topics in addition to the prudential, custody and activity-specific rules and guidance.1

Further engagement and tokenised asset custody: The FCA says it plans further engagement on tokenised asset custody and on potential amendments to CASS in the future. The FCA presents this as planned engagement and potential future work rather than as completed or finalised rules for tokenised assets.1

Practical note on interpreting the FCA material: the FCA’s published overview and CP25/14 set out what the FCA says the rules and guidance will cover, the intended areas of protection and the application dates. The FCA’s documents are presented as rules, guidance and explanatory material; they describe the regulator’s intentions and the documents firms should read. The FCA also explicitly cautions that previous MLR registration or a firm’s use of financial-promotion mechanisms should not be taken as determinative of regulatory status under the new FSMA-based perimeter.1,2

How the FCA frames compliance pathways in its own words

The FCA’s overview materials repeatedly direct firms to consult particular policy statements and describe those statements as the materials firms need to understand the regulatory expectations that will apply from the stated dates. The FCA identifies PS26/11 as the primary activity-specific resource for custody providers and other service providers.1 The FCA describes the package of documents — activity-specific, prudential, Handbook-application, and custody/stablecoin material — collectively as the material that sets out the pathway into compliance for cryptoasset activities under the FSMA-based regime.1,2

A final checklist derived from the FCA’s language

  • Read PS26/11 for activity-specific rules on trading, intermediaries, safeguarding client cryptoassets, lending and borrowing, and staking.1
  • Read PS26/12 for prudential requirements.1
  • Read PS26/13 for how the FCA Handbook will apply.1
  • Read CP25/14 for rules and guidance on qualifying stablecoins and safeguarding qualifying cryptoassets; note the publication and application dates the FCA states.2
  • Note the FCA’s CASS 17 protections statement: ownership rights, record keeping, reconciliation and private-key management, and that the FCA adopted a technology-agnostic private-key approach.1
  • Be aware of the FCA’s caution not to infer regulatory status from prior MLR registration or financial-promotion facts.1

Reading the FCA’s document map without treating it as an individual-firm assessment

The FCA says its “Overview of our cryptoassets regime policy statements”, published on 30 June 2026, presents an organised map of the materials that together form the UK’s cryptoasset regime (the FCA). The FCA says the Cryptoassets Regulations 2026 passed Parliament on 4 February 2026 and that the full scope of regulated activities expands from 25 October 2027 (the FCA). The FCA says the overview lists PS26/11 for activity‑specific regulated cryptoasset rules, PS26/12 for prudential requirements, PS26/13 for Handbook application and associated guidance such as Consumer Duty, operational resilience and international‑firm guidance (the FCA).

The FCA says firms providing cryptoasset services, including custody, should read PS26/11 together with the core materials identified in the overview (the FCA). The FCA says CASS 17 for client cryptoassets covers ownership rights, record keeping, reconciliation and private‑key management, using a technology‑agnostic private‑key approach, and that further engagement is planned on tokenised‑asset custody and potential future CASS amendments (the FCA). The FCA says CP25/14 concerns issuance of qualifying stablecoins and safeguarding qualifying cryptoassets and that final rules and guidance were published on 30 June 2026 and apply to firms authorised under FSMA on or after 25 October 2027 (the FCA).

This section does not reproduce the article’s existing tables; instead it sets out how the FCA itself frames the documents. The FCA says the materials are intended to be read together rather than to serve as a firm‑by‑firm compliance checklist (the FCA). Readers should therefore treat the FCA’s map as an index and contextual guide to the policy statements and rules, rather than as an individual assessment of any firm’s arrangements.

FCA cryptoasset compliance pathways: why activity-specific and core materials sit together

The FCA says PS26/11 is the activity‑specific set of rules for regulated cryptoasset activities, covering areas such as trading platforms and intermediaries, safeguarding client cryptoassets, and activities including lending/borrowing and staking (the FCA). The FCA says PS26/12 sets out prudential requirements and PS26/13 addresses how existing Handbook rules apply to cryptoasset activities (the FCA). The FCA says the overview also links to cross‑cutting materials that include Consumer Duty considerations, operational resilience expectations and guidance for international firms (the FCA).

The FCA says firms providing cryptoasset services, including custody, should read PS26/11 together with the core materials listed in the overview, because the activity‑specific obligations are positioned alongside prudential and Handbook‑application materials to reflect how these strands interact in practice (the FCA). This combined reading is the path the FCA sets out for firms seeking to understand the complete regulatory picture, according to the FCA (the FCA). The FCA says CP25/14 addresses qualifying stablecoin issuance and safeguarding and that its final rules and guidance were published on 30 June 2026, applying to firms authorised under FSMA on or after 25 October 2027 (the FCA).

This framing is central to how the FCA cryptoasset compliance pathways are presented in the FCA’s materials: activity definitions and operational obligations appear in PS26/11, while capital, liquidity and prudential expectations are set out in PS26/12 and the application of existing Handbook rules is clarified in PS26/13 (the FCA). The FCA says the combined structure is designed so that an activity‑specific requirement cannot be read in isolation from prudential and Handbook implications (the FCA). The FCA says that cross‑cutting guidance such as Consumer Duty and operational resilience should be considered alongside these statements to form a complete view of regulatory expectations (the FCA).

Custody safeguards as published: separating stated protections from implementation claims

The FCA says CASS 17 sets out requirements for client cryptoassets that cover ownership rights, record keeping and reconciliation, and private‑key management, and that CASS 17 takes a technology‑agnostic private‑key approach (the FCA). The FCA says this wording is intended to focus on outcomes and controls rather than mandating particular technologies or architectures (the FCA). The FCA says further engagement is planned on tokenised‑asset custody and potential future CASS amendments, indicating that the regime may be adapted in response to developments and consultation (the FCA).

The FCA says CP25/14 is concerned with the issuance of qualifying stablecoins and the safeguarding of qualifying cryptoassets, and that its final rules and guidance were published on 30 June 2026 (the FCA). The FCA says those rules and guidance apply to firms authorised under FSMA on or after 25 October 2027 (the FCA). The FCA says the CP25/14 materials form part of the broader set of safeguards and obligations that the FCA places on activities involving custody and issuance (the FCA).

The FCA’s published protections can therefore be read in two separate dimensions in the FCA’s own materials. First, the FCA says it sets out stated protections in the form of rules and guidance: ownership protections, record‑keeping and reconciliation requirements, and private‑key management expectations are described as components of CASS 17 and CP25/14 (the FCA). Second, the FCA says the materials distinguish those protections from any claims by providers about how they implement them; the FCA’s documentation is the reference point for the content and scope of protections, while implementation details are left to firms subject to the rules and to future supervisory assessment (the FCA).

The FCA says CASS 17’s technology‑agnostic private‑key approach is deliberate, leaving room for different technical architectures while imposing outcome‑focused obligations on custody arrangements (the FCA). The FCA says further engagement is planned on tokenised‑asset custody and potential future amendments to CASS, which signals that the FCA expects to refine how custodial safeguards apply as market practices and token types evolve (the FCA). The FCA says readers should consult PS26/11 alongside the core materials to understand how custody obligations fit into the activity‑specific and prudential frameworks (the FCA).

The 2026–2027 timing sequence and the limits of a public explainer

The FCA says its overview was published on 30 June 2026 and that the Cryptoassets Regulations 2026 passed Parliament on 4 February 2026 (the FCA). The FCA says the full scope of regulated activities expands from 25 October 2027 and that the CP25/14 final rules and guidance were published on 30 June 2026 with application to firms authorised under FSMA on or after 25 October 2027 (the FCA). The FCA says these dates define a staged timetable in which statutory change has been enacted in 2026 and the broader operational scope becomes effective in late 2027 (the FCA).

The FCA says PS26/11, PS26/12 and PS26/13, together with related Consumer Duty, operational resilience and international‑firm guidance, form the set of materials that firms are advised to read together in preparation for the change in scope that becomes effective from 25 October 2027 (the FCA). The FCA says further engagement is planned on areas such as tokenised‑asset custody and potential CASS amendments, indicating that the regime’s implementation will be an ongoing process rather than a single‑event change (the FCA).

A public explainer can describe the sequence the FCA has published, but the FCA says that firms and readers should treat the primary documents as the authoritative source of rules, timing and scope (the FCA). The FCA says the overview is an index to materials rather than a substitute for the detailed policy statements and rule texts themselves (the FCA). The FCA says the interaction between activity‑specific requirements, prudential rules and Handbook application means that timing matters for when particular obligations take effect and for which types of firms they apply under FSMA after 25 October 2027 (the FCA).

The FCA says the combined publication of final rules and guidance for CP25/14 on 30 June 2026 is part of that sequencing and that those specific provisions apply to firms authorised under FSMA from 25 October 2027 (the FCA). The FCA says the staged timetable and the plan for continued engagement make clear that rule text, practical guidance and supervisory expectations will evolve as the FCA engages with the market and considers token‑specific or technology‑specific issues (the FCA). This constrains what a single article can authoritatively assert about firm readiness or specific implementation choices: the FCA’s materials are the baseline reference and the timing in those materials determines when obligations become operationally relevant (the FCA).

Questions a reader can take back to the primary FCA documents

  • How does PS26/11 describe the scope of activity‑specific obligations for trading platforms and intermediaries, relative to the core materials identified in the FCA overview? (FCA materials to consult: PS26/11 and the overview, according to the FCA.)

  • In what ways does PS26/12 set out prudential requirements that interact with the obligations in PS26/11, and where do the PS26/12 texts point to Handbook expectations identified in PS26/13? (See PS26/12, PS26/11 and PS26/13 as listed in the FCA’s overview, according to the FCA.)

  • Which parts of CASS 17, as described in the FCA’s overview, are explicitly framed around ownership rights, record keeping and reconciliation, and how does the FCA’s technology‑agnostic private‑key approach appear in the CASS 17 text? (FCA reference: CASS 17 summary in the FCA overview and full CASS 17 text, per the FCA.)

  • Where does the FCA explain differences between safeguarding obligations for qualifying stablecoins and broader safeguarding requirements for other qualifying cryptoassets in CP25/14 and the overview? (FCA reference: CP25/14 final rules and guidance, and the FCA’s overview, according to the FCA.)

  • How does the FCA set out the effective dates and transitional expectations for obligations that arise from the Cryptoassets Regulations 2026 and for the CP25/14 final rules and guidance, particularly with regard to the 25 October 2027 date noted in the FCA overview? (FCA materials: Cryptoassets Regulations 2026 timing and the CP25/14 publication and application dates, as stated by the FCA.)

  • Where does the FCA identify Consumer Duty, operational resilience and international‑firm guidance as cross‑cutting considerations, and how are these materials referenced alongside PS26/11, PS26/12 and PS26/13 in the FCA’s overview? (FCA reference: the overview’s list of associated guidance, according to the FCA.)

  • What language does the FCA use to describe the intended relationship between PS26/11 and the “core materials” it says firms should read together, and what practical examples (if any) does the FCA provide in the published statements? (FCA reference: the FCA’s instruction that firms should read PS26/11 with core materials, in the FCA overview.)

  • Where does the FCA set out its plan for further engagement on tokenised‑asset custody and potential amendments to CASS, and what scope or timeline does the FCA describe for that engagement? (FCA reference: the FCA’s statement on planned further engagement, as noted in the FCA overview.)

  • How are private‑key management expectations described across PS26/11, CASS 17 and CP25/14, and how does the FCA’s technology‑agnostic approach appear across those documents? (FCA reference: the FCA’s overview statements on CASS 17 and CP25/14, according to the FCA.)

  • Which parts of the FCA materials explicitly address the distinction between the rules and guidance the FCA has published and claims by service providers about how they implement custody or safeguarding controls? (FCA reference: the FCA overview and the texts of PS26/11, PS26/12, PS26/13 and CP25/14, as published by the FCA.)

These prompts are framed to encourage direct reading of the FCA’s published statements and rule texts rather than to substitute for them; the documents cited above are those the FCA lists in its overview and related publications (the FCA). The phrase FCA cryptoasset compliance pathways appears across the FCA’s overview as the way the materials are organised and should be read together, according to the FCA.

What the FCA’s publications do not establish (explicit limits from the FCA)

The FCA’s two documents set out rules, guidance and the regulator’s description of protections and timings. The FCA materials themselves contain statements about what they are and what they do not establish. Derived from the FCA text, the following points summarise explicit limits the FCA has set out:

  • The FCA’s mention of prior MLR registration or use of financial-promotion mechanisms does not establish whether a given firm is authorised under the FSMA-based perimeter. The FCA cautions against inferring a firm’s status from those facts.1
  • The FCA’s materials set out rules and guidance the FCA says will apply from 25 October 2027 to firms authorised from that date; they do not make determinations in the public documents about the compliant status of any named firm.1,2
  • Where the FCA indicates it will proceed with CASS 17 or further engagement on tokenised asset custody, the FCA’s documents describe intended protections and planned engagement rather than asserting final operational detail for every conceivable custody technology.1

What this does not tell a reader

  • This article summarises and explains FCA-published documents. It is based solely on the FCA materials cited in the Sources section below. It is general information only and does not constitute legal, tax, investment or compliance advice.
  • This article does not assess or state whether any particular firm is authorised, compliant, in breach of rules, exempt from rules, regulated, unregulated, safe or unsafe.
  • The article does not attempt to predict future enforcement outcomes or to interpret the FCA’s materials beyond the direct descriptions the FCA provides.
  • For firm-specific or transaction-specific matters, the FCA materials should be read in full and, where necessary, professional legal or regulatory advice should be sought. The FCA’s documents themselves state the intended scope and application dates for the rules the FCA has published.1,2

FAQ — short answers based only on the FCA documents

Q: What are the FCA cryptoasset compliance pathways?
A: The FCA uses that language in its overview to describe the package of final rules, guidance and policy statements firms should read to understand regulatory expectations under the FSMA-based crypto regime. The FCA lists PS26/11, PS26/12, PS26/13 and associated guidance, and it identifies CP25/14 for stablecoins and custody material.1,2

Q: When do the FCA’s published final rules and guidance apply?
A: The FCA says the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 passed Parliament on 4 February 2026 and that the full scope of regulated activities expands from 25 October 2027. The FCA says final rules and guidance published on 30 June 2026 will apply to firms authorised under FSMA on or after 25 October 2027.1,2

Q: What custody protections does the FCA describe?
A: The FCA says it is proceeding with CASS 17 for client cryptoassets and identifies protections around ownership rights, record keeping, reconciliation and private-key management, noting a technology-agnostic private-key approach.1

Q: Does the FCA set out prudential rules?
A: The FCA says PS26/12 covers prudential requirements and lists it as a core requirement firms should read.1

Q: Are stablecoins covered?
A: The FCA says CP25/14 covers stablecoin issuance and safeguarding qualifying cryptoassets. The FCA says CP25/14 was first published on 28 May 2025, updated on 30 June 2026, and that final rules and guidance were published on 30 June 2026 and will apply from 25 October 2027 for firms authorised under FSMA from that date.2

Q: Can I infer a firm’s status from MLR registration or financial promotions?
A: The FCA explicitly warns not to infer an individual firm’s status from prior MLR registration or from financial-promotion evidence.1

Date-based source timeline (concise, document-led)

  • 28 May 2025 — The FCA first published CP25/14 (stablecoin issuance and cryptoasset custody).2
  • 4 February 2026 — The FCA states the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 passed Parliament.1
  • 30 June 2026 — The FCA published final rules and guidance across its cryptoasset regime policy statements and updated CP25/14; the FCA says final rules and guidance were published on this date.1,2
  • 25 October 2027 — The FCA says the full scope of regulated activities expands from this date and that the final rules and guidance will apply to firms authorised under FSMA on or after this date.1,2
  • https://onegenerationnews.com/crypto/uk-crypto-regulation-2026/
  • https://onegenerationnews.com/crypto/crypto-custody-uk/
  • https://onegenerationnews.com/crypto/uk-crypto-financial-promotions/
  • https://onegenerationnews.com/crypto/defi-uk-regulation/

Conclusion — explicit no-advice statement

This article summarises and explains material published by the FCA. It is based exclusively on the FCA sources listed in the Sources section below. It is intended as neutral reporting and general explanation only and does not constitute legal, tax, investment or regulatory advice. The material does not assess or determine the status or conduct of any particular firm. For any firm- or transaction-specific questions, readers should consult the FCA documents and, if needed, seek professional advice.1,2

Sources

1) FCA, “Overview of our cryptoassets regime policy statements”, published 30 June 2026: FCA: overview of cryptoassets regime policy statements

2) FCA, “CP25/14: Stablecoin issuance and cryptoasset custody”, first published 28 May 2025, updated 30 June 2026: FCA CP25/14: stablecoin issuance and cryptoasset custody