regulatory

FCA Crypto Rules 2026: Capital, Resilience & Trading Standards

FCA crypto rules 2026 explained: capital requirements, stress testing, and trading standards your UK crypto firm must meet before the compliance deadlines hit.

FCA Crypto Rules 2026: Capital, Resilience & Trading Standards

The FCA's Consultation Paper CP24/20, published in November 2024, set out the most detailed prudential and conduct framework ever proposed for UK cryptoasset firms — and the first wave of rules under the resulting Policy Statement are now live or imminent. Firms that treated FCA registration as a finish line are about to discover it was only the starting gun.

TL;DR

  • The FCA's 2026 cryptoasset regime introduces explicit own-funds requirements, liquidity buffers, and wind-down planning obligations for registered VASPs.
  • Trading standards rules — covering market abuse, best execution, and disclosure — apply to cryptoasset exchange providers and custodian wallet providers from the relevant commencement dates.
  • Stress testing is no longer optional guidance; it's a supervisory expectation with documented methodology and board sign-off.
  • Firms that registered under the MLRs alone are not automatically compliant — a separate cryptoasset firm authorisation process is underway.
  • Non-compliance triggers supervisory intervention, public censure, and potential cancellation of registration.

What This Regulation Actually Requires

The Authorisation Regime Replacing MLR Registration

Since January 2020, UK cryptoasset firms have operated under anti-money laundering registration with the FCA under the Money Laundering Regulations 2017 (as amended). That regime was never designed to address prudential soundness or consumer protection. The Financial Services and Markets Act 2000 (as amended by the Financial Services and Markets Act 2023) now brings cryptoasset activities within the regulated activities framework.

The FCA has designated cryptoasset exchange activity and custodian wallet provision as specified activities. Firms carrying on these activities in or from the UK need full FCA authorisation — not just MLR registration — by the applicable transitional deadline. The FCA confirmed in its March 2025 update that firms relying on the transitional period must have submitted a complete application to benefit from continued permission to operate.

Own-Funds and Capital Requirements

CP24/20 proposed a tiered capital framework. The core obligation is a minimum own-funds requirement calculated as the higher of:

  • A fixed floor (proposed at £150,000 for smaller exchange providers, scaling to £750,000 for firms holding client assets above defined thresholds), or
  • A variable requirement equal to a percentage of relevant annual expenditure (the "FOR" or Fixed Overhead Requirement approach borrowed from MiFID II).

Firms must hold own funds in the form of Common Equity Tier 1 instruments — retained earnings, paid-up share capital. Subordinated loans and hybrid instruments don't count toward the minimum. The FCA's rationale is explicit: cryptoasset firms have failed precisely because they commingled client assets with operational capital and had no genuine buffer when markets moved against them.

Liquidity and Wind-Down Planning

Separate from capital, firms must maintain a liquidity buffer sufficient to cover at least three months of projected wind-down costs. This isn't a theoretical exercise. The FCA expects a documented Wind-Down Plan (WDP) that:

  1. Identifies the trigger events that would initiate wind-down.
  2. Maps the operational steps, timelines, and responsible individuals.
  3. Quantifies the costs of an orderly wind-down, including staff redundancy, technology decommissioning, and client asset return.
  4. Is reviewed and approved by the board at least annually.

The WDP must be submitted to the FCA as part of the authorisation application and updated whenever material changes occur.

Stress Testing Requirements

The FCA's supervisory expectations — set out in its 2025 Dear CEO letter to cryptoasset firms — require firms to conduct and document stress tests covering at least:

  • A 90-day sustained market downturn scenario (calibrated to the 2022 crypto market conditions as a baseline).
  • A sudden operational failure scenario (e.g., key third-party technology provider outage).
  • A client redemption stress scenario modelling simultaneous withdrawal requests from the top 10% of clients by asset value.

Results must be presented to the board with a clear narrative on capital adequacy under each scenario. The FCA has indicated it will request stress test outputs during supervisory visits and as part of the Section 165 information-gathering process.

Trading Standards: Market Abuse and Best Execution

The trading standards component is where many firms are least prepared. The regime introduces:

Market Abuse Prohibitions. Insider dealing and market manipulation in cryptoassets become criminal offences under the extended scope of the Market Abuse Regulation (UK MAR) as applied to admitted cryptoassets. Firms must implement surveillance systems capable of detecting layering, spoofing, wash trading, and pump-and-dump patterns.

Best Execution. Exchange providers must take all sufficient steps to obtain the best possible result for clients when executing orders, considering price, costs, speed, and likelihood of execution. A written Best Execution Policy is mandatory, reviewed at least annually, and disclosed to clients.

Disclosure Obligations. Pre-trade and post-trade transparency requirements apply to trading venues. Firms must publish bid/ask spreads, last-traded prices, and order book depth in a standardised format. The FCA has not yet mandated a consolidated tape for crypto, but firms should design their disclosure infrastructure with that eventuality in mind.

Custody and Client Asset Segregation

Custodian wallet providers face the most operationally demanding requirements. Client cryptoassets must be:

  • Held in segregated wallets, clearly distinguished from the firm's own assets on-chain and in internal records.
  • Reconciled daily against the firm's internal ledger.
  • Covered by a written custody agreement specifying the firm's obligations, the client's rights on insolvency, and the fee structure.

The FCA has explicitly stated that omnibus wallet arrangements are permissible only where the firm can demonstrate, at any point in time, each client's individual entitlement — and where the custody agreement discloses the omnibus structure and its risks.

What This Means for Your Company

If you're a crypto exchange, OTC desk, or custody provider operating in the UK, the compliance gap between where most firms are today and where the FCA expects them to be is significant.

Firms that built their compliance programmes around AML/KYC alone will need to rebuild. Capital adequacy, liquidity management, stress testing, and trading surveillance are not add-ons — they're core supervisory expectations that will be tested during authorisation review and ongoing supervision.

The FCA has already demonstrated willingness to act. In 2024 it cancelled the registration of several firms for AML failures and issued public censures. The new regime gives it sharper tools: it can impose capital add-ons, restrict activities, and require remediation plans on a much faster timeline than the MLR framework allowed.

Smaller firms face a genuine viability question. The fixed capital floor, combined with wind-down planning costs and the investment required in surveillance and reporting infrastructure, may push some business models below the economic threshold. Early modelling of the capital impact is not optional — it's a board-level decision.

How to Operationalize

Step 1: Gap Analysis Against CP24/20 and the Final Policy Statement. Map your current capital structure, liquidity position, and compliance infrastructure against each proposed requirement. Assign RAG ratings and owners.

Step 2: Engage Legal and Regulatory Counsel on Authorisation Timing. Determine whether you're in scope for the transitional period and whether your existing MLR registration covers your current activities. Submit your authorisation application early — the FCA's processing queue is long.

Step 3: Calculate Your Own-Funds Requirement. Run both the fixed floor and the FOR calculation. Identify the higher figure. Assess whether your current capital structure meets it and, if not, model the fundraising or restructuring required.

Step 4: Draft Your Wind-Down Plan. Use the FCA's published guidance as a template. Quantify wind-down costs with input from finance, operations, and HR. Get board approval and build a calendar reminder for the annual review.

Step 5: Commission Your First Stress Test. Define the three mandatory scenarios. Run the numbers. Present results to the board with a written narrative. Document the methodology so you can reproduce it for the FCA on request.

Step 6: Implement Trading Surveillance. Select a surveillance vendor or build internal tooling capable of detecting the manipulation patterns listed in UK MAR. Define alert thresholds, escalation procedures, and investigation workflows.

Step 7: Audit Your Custody Arrangements. Confirm wallet segregation on-chain. Reconcile your internal ledger against on-chain balances. Update custody agreements to meet the new disclosure requirements.

Step 8: Train Your Board and Senior Management. The FCA's Senior Managers and Certification Regime (SM&CR) applies to authorised cryptoasset firms. Each Senior Manager must understand their individual accountability for the areas they oversee.

Common Mistakes and How to Avoid Them

Treating MLR registration as sufficient. It isn't. MLR registration addresses financial crime risk only. Full FCA authorisation under the FSMA framework is a separate, more demanding process. Start the application process now.

Underestimating the capital calculation. Many firms calculate only the fixed floor and stop there. The FOR calculation — based on annual expenditure — can produce a higher figure for firms with significant cost bases. Run both.

Wind-down plans that exist on paper only. The FCA will probe whether your WDP is operational. If the plan names individuals who've left the firm, references systems that no longer exist, or hasn't been updated since the initial application, it will fail supervisory scrutiny.

Surveillance systems calibrated for equities, not crypto. Off-the-shelf market surveillance tools designed for traditional securities often miss crypto-specific manipulation patterns like wash trading across related wallets or cross-exchange layering. Validate your tooling against crypto-specific scenarios before going live.

Ignoring the disclosure obligations. Best execution policies that are copied from MiFID II templates without adaptation to crypto market microstructure will not satisfy the FCA. The policy must reflect how your specific trading venue or OTC desk actually executes orders.

FAQ

Q: Does the new FCA authorisation regime apply to firms that only serve professional or institutional clients?

A: Yes. The activity-based scope of the regime doesn't distinguish between retail and professional clients for the purposes of authorisation. Prudential requirements apply regardless of client type, though some conduct obligations are calibrated differently for professional clients.

Q: We're a DeFi protocol with no UK legal entity. Are we in scope?

A: Potentially. The FCA applies a "by way of business" and "in the UK" nexus test. If your protocol actively markets to UK users, has UK-based developers making governance decisions, or routes transactions through UK infrastructure, you may be in scope. Take legal advice specific to your architecture before concluding you're outside the perimeter.

Q: What's the timeline for the stress testing requirement to become mandatory?

A: The FCA's Dear CEO letter issued in 2025 framed stress testing as an immediate supervisory expectation for firms already registered. For newly authorised firms, it's a condition of authorisation. There's no grace period for firms that are already operating.

Q: Can we use a third-party custodian to meet the segregation requirements?

A: Yes, but you remain responsible for ensuring the third-party custodian meets the FCA's standards. You must conduct due diligence on the custodian, document it, and include appropriate contractual protections. Outsourcing the function doesn't outsource the regulatory obligation.

Q: How does the UK regime interact with MiCA for firms operating in both the UK and EU?

A: There's no mutual recognition between the UK FCA regime and EU MiCA. Firms operating in both jurisdictions need separate authorisations and must comply with each regime independently. Where requirements conflict — for example, on capital calculation methodology — the more demanding standard applies in each jurisdiction.


Sources

  • Financial Conduct Authority, Consultation Paper CP24/20, Regulating cryptoassets: admissions and disclosures, market abuse and operating a cryptoasset trading venue (November 2024)
  • Financial Conduct Authority, Dear CEO Letter, Cryptoasset firms: supervisory expectations on financial resilience (2025)
  • Financial Services and Markets Act 2023, Part 5 (Cryptoassets), UK Parliament
  • HM Treasury, Future Financial Services Regulatory Regime for Cryptoassets: Response to the Consultation and Call for Evidence (October 2023)

Disclaimer

This article is produced by BizLegal-AI Intelligence Desk for informational purposes only. It does not constitute legal advice and does not create a solicitor-client or attorney-client relationship. Regulatory requirements change frequently; verify all information against current FCA publications and applicable legislation before relying on it. Consult qualified legal counsel for advice specific to your firm's circumstances and jurisdiction.

Stop reading. Start checking.

Scan your actual contract for hidden risk in 60 seconds

DocAI reads your agreement, flags every clause-level risk with cited evidence, and gives you an attorney-ready fix path. $97, refund if we cite an issue your document doesn't support.

Scan my contract →

Used by founders & counsel across 50+ jurisdictions · Not legal advice

Related

Regulatory changes, before they cost you

One email when a rule that affects crypto, fintech, or cross-border deals actually changes. No noise. Unsubscribe anytime.

Disclaimer: BizLegal-AI produces regulatory intelligence and working drafts. It is not legal, financial, or tax advice. Consult qualified counsel for specific situations.