On 30 September 2026 the FCA opens the authorisation window for the new UK cryptoasset regime. You do not need to file an application on 30 September. You do need to know, before that date, whether you will require one.
From that day, firms that are in scope can apply and, if they apply before 28 February 2027, generally keep serving UK customers while the FCA determines the application. Firms that miss the window lose that protection. After 25 October 2027, carrying on a regulated cryptoasset activity in the UK without authorisation is a criminal offence.
If your business touches cryptoassets and has UK consumers, from London, Dubai, Singapore or a laptop, this is no longer a watching brief.
The two dates that decide how you plan
30 September 2026 to 28 February 2027 is the application window. It is not a hard stop. It is the period in which an application preserves continuity.
25 October 2027 is the commencement date. From then, the activity is either authorised or unlawful.
That distinction should govern the next six months. A firm that is in scope and files inside the window is buying time. A firm that is in scope and files after 28 February 2027 may have to pause the UK-facing activity until permission comes through. Preparing a credible application takes months, not a fortnight. The firms that will file in October are scoping now.
Do not wait for PERG 19. The FCA's interpretive perimeter guidance remains in draft and is expected this autumn. It will refine edge cases. It will not unwrite the Regulations, and it will not move the dates.
The rulebook is already final
On 30 June 2026 the FCA published the rules that will govern authorised cryptoasset firms: prudential requirements, the Consumer Duty, operational resilience, and the Senior Managers and Certification Regime. Safeguarding of client cryptoassets is now subject to dedicated custody rules. Admissions, disclosures and market abuse controls apply to firms that issue or trade cryptoassets on UK platforms.
If you operate an exchange, issue a token, hold client assets, run a trading venue, arrange staking, or sit behind a DeFi interface with an identifiable controlling person, this is the rulebook that will apply to you. The remaining work is not to wait for more paper. It is to establish whether you are inside the perimeter, and if so which permissions you need.
For the detail of the June package, see our earlier insight: The FCA Finalises the UK Cryptoasset Regime: Final Rules Published.
Most firms guess their scope. Most guess wrong.
The regulated activities are wider than the labels founders use. Issuing a qualifying stablecoin. Safeguarding cryptoassets, or arranging safeguarding. Operating a trading platform. Dealing as principal or as agent. Arranging deals. Arranging staking. A single business can be caught more than once. The activity that surprises people is rarely the one on the homepage. It is the one in the product flow: the widget that lets a user place an order, the arrangement that moves someone else's assets, the interface that completes a stake.
Distance from London does not save you. If you deal with, safeguard assets for, or arrange transactions for individual consumers in the UK, you can be in scope with no UK office and no UK staff. For some activities the FCA's working assumption is a UK presence: a UK legal entity, or a branch of an authorised group, not a .co.uk domain and a terms-of-use clause. That is the point international platforms most often miss.
Nor do yesterday's permissions carry you across. Registration under the Money Laundering Regulations is not FCA authorisation. A payment-services or e-money permission does not cover cryptoasset activities. Approval of a financial promotion under section 21 of FSMA does not either. Each of those is a different regime. None of them is a substitute for an activity-by-activity perimeter analysis.
Start with five minutes. Then get a formal answer.
We built the UK Cryptoasset Perimeter Scanner for this fortnight. It turns the legislation and the FCA's final rules into six questions and gives you a preliminary, confidential view of where you stand. It is free. Your answers do not leave your device.
It is a first reading, not advice, and you should not take a decision on it. If the result is “likely in scope”, or “formal analysis needed”, or if you serve UK consumers from overseas, instruct a proper assessment.
LawBEAM's fixed-fee UK Perimeter Analysis tells you which regulated activities apply, whether any exclusion is real on your facts, and how the territorial rules bite if part of the business sits outside the UK. You have the written position within seven days of instruction. From there we sequence the application: the permissions you actually need, the gaps the FCA will test, and a filing plan timed to the window.
If you already know you are in scope, do not spend September rereading the policy statements. Spend it closing the gaps.
Contact us
Contact us to instruct a UK Perimeter Analysis, or to talk through your authorisation plans.

Roshi Sharma
Founding Partner
Email: roshi@lawbeam.io
Tel: +44 (0) 7815 610 474
LinkedIn: linkedin.com/in/roshi-sharma-lawbeam
This insight is provided for general information only and does not constitute legal advice. It reflects our understanding of the UK cryptoasset regime as at 1 September 2026, including FCA policy statements and finalised guidance published on 30 June 2026. The FCA's perimeter guidance (PERG 19) remains in draft, expected to be finalised this autumn, and the position described above may change when it is. For advice on your specific circumstances, please contact us.



