Skip to main content

Crypto authorisation opens 30 September: the gateway is now the strategy

The FCA has published perimeter guidance for the UK's cryptoasset regime, with the authorisation gateway opening on 30 September 2026 and the regime taking effect on 25 October 2027. For senior leaders at crypto firms and the banks, custodians and asset managers adjacent to them, the thirteen-month window between gateway opening and regime commencement is now the defining planning horizon.

The FCA has fired the starting gun on UK crypto authorisation. Guidance published on 16 September 2026 sets out how the new perimeter applies to stablecoin issuance, trading platforms, dealing and arranging, safeguarding and staking, with the authorisation gateway opening on 30 September 2026 and the regime taking effect on 25 October 2027 (FCA). Firms that assumed they had until late 2027 to decide their UK posture no longer do.

Key Executive Takeaways

  • The FCA's authorisation gateway for UK cryptoasset firms opens on 30 September 2026, with the full regime commencing on 25 October 2027, giving firms roughly thirteen months to secure permissions.
  • The perimeter covers stablecoin issuance, trading platforms, dealing and arranging, safeguarding and staking, meaning banks and asset managers with adjacent exposure need to reassess counterparty and custody arrangements now.
  • A further FCA consultation in October 2026 will refine the perimeter around stablecoins, proprietary trading, technology providers and decentralised protocols, so any authorisation strategy filed early may need revisiting.

The gateway is the strategy

The sequencing matters. Rules were finalised in June 2026, the government legislated in February 2026 and has since introduced targeted exclusions and clarifications, and the FCA will consult in October on further changes covering qualifying stablecoins, proprietary trading and market making, certain technology providers, decentralised protocols, safeguarding arrangements involving central securities depositaries, and financial promotions (FCA). Firms filing in the first quarter of the gateway will be doing so against a perimeter that is still being refined. That creates a genuine dilemma: file early and risk resubmission, or wait and risk queueing behind competitors for scarce supervisory attention.

David Geale, the FCA's executive director of consumers, payments and competition, framed the guidance as delivering "the clarity they've asked for so they can prepare with confidence" (FCA). The subtext is that the regulator wants substantive applications, not placeholders. Pre-application meetings and webinars on the handbook, authorisation process and prudential framework are being run precisely to filter out unready firms before they consume gateway capacity.

Second-order effects for regulated incumbents

The more consequential audience is not the crypto-native firms but the banks, custodians, asset managers and payment institutions that touch them. Any UK-facing institution providing banking rails, custody, or trading infrastructure to a crypto firm will need to know, by mid-2027, whether its counterparty holds or will hold Part 4A permissions. Onboarding, credit and outsourcing frameworks will need refreshing on a timetable set by the gateway, not by internal planning cycles.

The fragility of unauthorised or lightly regulated payment firms is a live reminder. Premier Payment Solutions Ltd, a small payment institution under the Payment Services Regulations 2017, entered liquidation on 10 September 2026, and the FCA has confirmed that small payment institutions are not required to safeguard customer funds and that the FSCS does not cover payment services (FCA). Boards should expect the same questions about crypto counterparties: where are client assets held, under what permission, and with what recourse.

What to do before 30 September

The practical implication is narrow and urgent. Firms in scope need a filed view on whether they intend to seek authorisation, a mapped inventory of activities against the perimeter categories, and a decision on whether to file in the October window or wait for the post-consultation guidance. Firms out of scope but exposed as counterparties need to run the same exercise on their book. The gateway opens in less than two weeks. The strategic choices being made this month will define UK crypto market structure for the rest of the decade.

What this reveals

The FCA's compressed thirteen-month window exposes a common failure mode: leadership teams treat regulatory perimeters as fixed inputs to plan against, when they are in fact moving targets shaped by ongoing consultation, supervisory capacity and peer behaviour. Firms that assumed the 2027 commencement date gave them planning latitude are discovering that the real decision point is now, and that adjacent regulated firms (banks, custodians, asset managers) who assumed this was a 'crypto problem' are equally exposed through counterparty and custody arrangements. The broader issue is that regulatory timelines are almost always read as later than they actually bite, and perimeter guidance is almost always read as more stable than it actually is.

Questions accountable leaders should ask

  • 01Have we mapped every counterparty, custody arrangement and service relationship that touches the new perimeter, or only assessed our own direct authorisation position?
  • 02What is our filing sequencing logic, and have we tested whether filing early against a still-moving perimeter is riskier than queueing later behind competitors for scarce supervisory attention?
  • 03How will we know if the October 2026 consultation materially changes the assumptions underpinning our authorisation strategy, and who owns that monitoring?
  • 04If a key counterparty fails to secure Part 4A permissions by mid-2027, what is our fallback, and have we stress-tested the commercial and operational consequences?
  • 05Are we treating the FCA's pre-application meetings as procedural, or as substantive intelligence-gathering opportunities that shape our filing?

What accountable leaders should do now

  1. 1Commission a perimeter exposure map within 30 days that captures both direct authorisation requirements and every adjacent relationship (banking rails, custody, trading infrastructure, staking arrangements) where a counterparty's authorisation status will affect your operating model.
  2. 2Establish a decision framework for filing sequencing that explicitly weighs the resubmission risk of early filing against the supervisory-capacity risk of later filing, and record the reasoning so it can be revisited when the October consultation lands.
  3. 3Assign a named owner to monitor the October 2026 consultation and subsequent FCA communications, with a standing brief to flag any perimeter shifts that would require the authorisation strategy to be reopened.
  4. 4Engage counterparties now on their intended authorisation posture, and build contractual and operational contingencies for the scenario where key counterparties do not secure permissions in time.
  5. 5Treat pre-application meetings and webinars as intelligence exercises: brief attendees to capture supervisory tone, expectations on evidence, and signals about how the FCA is prioritising applications, then feed findings back into the filing strategy.

Explore the practical guide

A practical guide for senior leaders on integrating stakeholder risk assessment into a regulatory filing so it reads as evidence of genuine control, not compliance theatre. After reading, you will know how to sequence the work, what to include, and where filings typically fall short under supervisory review.

Read the guide

Where the operating environment may be moving faster than internal reporting reflects

Polar Insight's Signal Briefings translate emerging regulatory, stakeholder, and market developments into a clear implication for accountable leaders.

Explore Signal Briefings

Stakeholder Signals

Consequential developments in financial services and other regulated markets, with one implication for accountable leaders.