By 25 October 2027, no firm can carry on in-scope cryptoasset activities in or to the UK without proper FCA permissions under FSMA. That deadline is fixed. The FCA published its final policy package on 30 June 2026, covering five policy statements (PS26/9 through PS26/13), and the application gateway opened on 30 September 2026 and closes 28 February 2027. Miss the window, and you lose access to transitional provisions that could keep your business running while the regulator works through the queue.
This is a hard cutover, not a soft landing. An MLR registration alone will not be sufficient from 25 October 2027 onwards. Firms that are currently operating in the UK on that basis need to treat the FSMA authorisation process as a separate, more demanding exercise.
What the FCA actually expects from your application
The FCA's guidance makes clear that this is a whole-firm test, not a tick-box exercise. Applications need to demonstrate substance across a broad range of areas:
- Senior management accountability and governance structures
- Prudential resources where required by the rules
- Custody and safeguarding controls
- Market abuse monitoring and surveillance systems
- Operational resilience and IT mapping
- Complaints and redress processes
- A credible wind-down plan
The FCA's FG26/7 guidance also expects most firms to operate through a UK legal entity. Narrow exceptions exist for overseas platforms, but the bar for qualifying is genuinely narrow. Sort your corporate structure before you start building the application pack, not after.
The gateway window and why timing matters
Filing between 30 September 2026 and 28 February 2027 gives you access to transitional or savings provisions while the FCA processes your file. For complex groups, that buffer is not optional, it is the only realistic way to stay operational if the review runs past October 2027. The FCA has also signalled practical cut-off points for MLR registration ahead of FSMA filings, so get that piece sorted first.
Complex groups will spend months documenting governance arrangements, IT infrastructure, risk frameworks, third-party outsourcing arrangements, and financial crime controls before a file is even ready to submit. Boards should be signing off on project timelines and resourcing now, not in Q3 2026. The firms that struggle will be the ones that underestimate how much internal documentation the FCA will want to interrogate.
This article is for informational purposes only and does not constitute financial or legal advice. Always consult a qualified professional before making regulatory or investment decisions.



