FCA Crypto Rules 2026: Capital, Trading & Custody Standards
FCA crypto rules 2026 explained: capital requirements, trading obligations, and custody standards every UK crypto firm must meet before the compliance deadlines.
FCA Crypto Rules 2026: Capital, Trading & Custody Standards
The FCA's Discussion Paper DP23/4 and the subsequent Consultation Papers CP24/10 and CP25/6 have collectively set the stage for the most comprehensive overhaul of UK crypto asset regulation since the Money Laundering Regulations 2017 first brought exchanges into scope. With the FCA's phased authorisation regime now live and the first tranche of Crypto Asset Service Provider (CASP) approvals being processed under the Financial Services and Markets Act 2023, firms that haven't stress-tested their capital buffers, trading controls, and custody arrangements against the new standards are already behind.
TL;DR
- UK CASPs must meet minimum own-funds requirements calibrated to business activity type, with trading venues facing the most demanding thresholds.
- Custody of client crypto assets is now subject to segregation, reconciliation, and sub-custodian due-diligence rules that mirror — but don't replicate — MiFID II's client asset protections.
- The FCA has signalled it will use its new Section 71H FSMA 2023 powers to impose requirements on unregistered overseas firms accessing UK retail clients.
- Firms operating under the Temporary Registration Regime (TRR) extension must have submitted a complete authorisation application; the TRR is not an indefinite safe harbour.
- Prudential, conduct, and market-integrity obligations are being introduced in tranches — the first tranche covering admissions and disclosures closed for comment in early 2025, with trading and custody rules following.
What This Regulation Actually Requires
Authorisation Scope and the FSMA 2023 Framework
The Financial Services and Markets Act 2023 designated a broad list of crypto asset activities as "specified activities" under a new regulated activity order. Operating a crypto trading venue, providing crypto custody, dealing in crypto assets as principal or agent, and arranging crypto asset transactions all now require FCA authorisation — not merely AML registration.
The distinction matters enormously. AML registration under the MLRs was a lighter-touch regime focused on KYC and transaction monitoring. Full FSMA authorisation brings prudential supervision, conduct rules, systems-and-controls obligations, and the Senior Managers and Certification Regime (SMCR) into play. Firms that were registered under the MLRs and assumed that registration carried forward are wrong. A fresh application is required.
Capital Requirements
The FCA's proposed prudential framework for CASPs draws on the Investment Firms Prudential Regime (IFPR) as a structural template but departs from it in several material respects.
Own-funds floor by activity type. The FCA has proposed tiered minimum own-funds requirements. Firms operating a crypto trading venue face the highest floor — currently proposed at £750,000 in Common Equity Tier 1 (CET1) equivalent capital. Custody-only firms face a lower floor, proposed at £150,000. Firms providing both services must meet the higher of the applicable floors, not an aggregate.
K-factor style variable requirements. Above the floor, firms must hold additional own funds calculated by reference to activity-based metrics: assets under custody (AUC), daily trading volume on the venue, and client money held. The AUC-based charge is proposed at 0.04% of the rolling 12-month average AUC. For a firm holding £500 million in client crypto, that's a £200,000 variable charge on top of the floor.
Liquidity. Separate from own funds, firms must hold liquid assets equivalent to at least one-third of their fixed overheads requirement (FOR), calculated annually. The FOR is the firm's total annual expenditure minus discretionary bonuses and certain one-off costs.
Trading Venue Obligations
Firms operating a crypto trading venue — essentially any multilateral system that brings together buyers and sellers of crypto assets — face a distinct set of market-integrity obligations.
Admission and disclosure standards. Before admitting a crypto asset to trading, venues must conduct due diligence on the issuer (where one exists), publish a crypto asset white paper meeting the FCA's prescribed content requirements, and maintain that white paper on an ongoing basis. The white paper requirements are modelled on the EU's MiCA Regulation but are not identical — UK firms cannot simply repurpose a MiCA-compliant white paper without checking the delta.
Market surveillance. Venues must implement real-time surveillance systems capable of detecting wash trading, spoofing, layering, and front-running. The FCA has been explicit that it expects surveillance to cover both on-venue and, where technically feasible, cross-venue manipulation patterns. This is a higher bar than many existing systems meet.
Halting and suspension powers. Venues must have documented procedures for halting trading in a crypto asset where there's evidence of disorderly market conditions or where the white paper contains a material inaccuracy. The FCA can also direct a halt under its new powers.
Custody Standards
Custody is where the FCA's rules diverge most sharply from what many firms currently do.
Segregation. Client crypto assets must be held separately from the firm's own assets at all times. This applies at the wallet level, not just the ledger level. Commingling client assets in an omnibus wallet that also holds proprietary assets is prohibited, even temporarily.
Sub-custodian due diligence. Where a firm delegates custody to a third-party sub-custodian (including a DeFi protocol or a smart contract), it remains fully liable for the sub-custodian's failures. The firm must conduct initial and ongoing due diligence on the sub-custodian's security practices, financial resilience, and regulatory status. Using an unregulated sub-custodian in a jurisdiction with no equivalent protections will require a documented risk assessment and board sign-off.
Reconciliation frequency. Daily reconciliation of client crypto asset positions is required. The reconciliation must compare the firm's internal records against the on-chain position and, where a sub-custodian is used, against the sub-custodian's records. Discrepancies must be investigated and resolved within one business day.
Insolvency protection. The FCA's rules are designed to ensure that client crypto assets are ring-fenced in an insolvency. Firms must obtain legal opinions confirming that their custody arrangements achieve this ring-fencing in all relevant jurisdictions where assets are held.
What This Means for Your Company
If you're running a UK-facing crypto exchange, custody provider, or broker-dealer, the practical implications are significant.
Capital adequacy is no longer a back-of-envelope exercise. Firms that have been operating on thin equity cushions — common in the early-stage crypto sector — will need to raise capital, reduce AUC, or restructure their business model. The variable AUC charge in particular can scale quickly as assets under custody grow.
The custody rules will force a technology rethink for many firms. Wallet architecture that was designed for operational convenience rather than regulatory compliance will need to be rebuilt. That takes time and money, and the FCA won't accept "we're working on it" as a defence once the rules are in force.
SMCR applies in full. Every firm will need to map its senior management functions, certify relevant employees, and ensure that the Conduct Rules are embedded in HR processes. The FCA has already used SMCR to pursue individuals at traditional financial firms; it will do the same in crypto.
How to Operationalize
Step 1: Confirm your regulated activity perimeter. Map every service you offer against the new specified activities list. If you're in scope, you need authorisation — not just AML registration.
Step 2: Calculate your own-funds requirement. Run the floor calculation and the variable K-factor equivalent for your current AUC and trading volumes. Identify the gap between your current CET1 equivalent capital and the requirement.
Step 3: Audit your wallet architecture. Engage a technical specialist to confirm that client assets are segregated at the wallet level. Document the architecture in a custody policy that the FCA can review.
Step 4: Implement daily reconciliation. Build or procure a reconciliation system that compares internal records, on-chain positions, and sub-custodian records daily. Assign a named individual (likely a Certified Function under SMCR) to own the process.
Step 5: Conduct sub-custodian due diligence. For every third party holding client assets on your behalf, complete a due-diligence questionnaire covering security, financial resilience, and regulatory status. Obtain legal opinions on insolvency ring-fencing.
Step 6: Build your white paper process. If you operate a trading venue, establish a documented admission process that includes white paper review, issuer due diligence, and ongoing monitoring. Assign responsibility to a named senior manager.
Step 7: Deploy market surveillance. Procure or build surveillance tooling capable of detecting the manipulation patterns the FCA has specified. Test it against historical data before go-live.
Step 8: Submit your authorisation application. Don't wait until the deadline. The FCA's authorisation queue is long, and an incomplete application resets the clock.
Common Mistakes and How to Avoid Them
Assuming AML registration equals authorisation. It doesn't. Firms that conflate the two risk operating without authorisation once the new regime is fully in force. Check your status now.
Treating the white paper as a one-time exercise. The FCA requires ongoing maintenance. A white paper that was accurate at admission can become misleading as the underlying protocol evolves. Build a review cadence into your compliance calendar.
Underestimating the custody technology lift. Many firms discover mid-project that their wallet infrastructure can't support wallet-level segregation without a full rebuild. Start the technical assessment early.
Ignoring the insolvency opinion requirement. Legal opinions on insolvency ring-fencing in multiple jurisdictions are expensive and time-consuming to obtain. Firms that leave this to the last minute will find themselves unable to meet the deadline.
Mapping the wrong senior managers to SMCR functions. The FCA expects the person holding a Senior Management Function to actually exercise that function. Assigning SMFs to figureheads rather than decision-makers is a red flag in supervisory visits.
Repurposing MiCA documentation without gap analysis. UK and EU requirements overlap but diverge in material respects. A MiCA-compliant white paper is a starting point, not a finished product, for UK purposes.
FAQ
Q: Does the new FCA authorisation regime apply to firms that only serve professional or institutional clients?
A: Yes. The specified activities under FSMA 2023 apply regardless of client type. There are some conduct-rule carve-outs for eligible counterparty business, but the prudential and custody requirements apply across the board. Institutional-only firms still need authorisation.
Q: Can a firm use a cold-storage sub-custodian that isn't FCA-authorised?
A: The FCA's rules don't require sub-custodians to be FCA-authorised, but they do require the appointing firm to conduct thorough due diligence and to remain fully liable for the sub-custodian's failures. Using an unregulated sub-custodian significantly increases the firm's risk exposure and will attract scrutiny in supervisory reviews.
Q: How does the FCA's custody regime interact with the existing CASS rules?
A: The FCA has confirmed that the new crypto custody rules are a standalone regime, not an extension of CASS 6 and 7. However, firms that also hold fiat client money in connection with crypto services remain subject to CASS 7 for the fiat component. Dual compliance is required.
Q: What's the timeline for the trading venue rules to come into force?
A: The FCA has indicated a phased implementation. Admissions and disclosures rules are expected to come into force first, with trading venue conduct and market-integrity rules following in a subsequent tranche. Firms should monitor the FCA's Policy Statements closely, as the exact dates are subject to change.
Q: Will overseas firms serving UK retail clients need FCA authorisation?
A: The FCA has signalled aggressive use of its Section 71H FSMA 2023 powers to require overseas firms to obtain authorisation or cease UK retail activity. The financial promotions restriction already bites on overseas firms communicating with UK retail clients. Authorisation is the only clean solution for firms with material UK retail exposure.
Sources
- Financial Services and Markets Act 2023, Part 5A (Crypto Assets), UK Parliament
- FCA Discussion Paper DP23/4, Regulating Cryptoassets: Phase 1 — Stablecoins, Financial Conduct Authority
- FCA Consultation Paper CP24/10, Crypto Asset Admissions and Disclosures, Financial Conduct Authority
- FCA Policy Statement PS23/6, Financial Promotion Rules for Cryptoassets, Financial Conduct Authority
Disclaimer
This article is produced by BizLegal-AI Intelligence Desk for general informational purposes only. It does not constitute legal advice and does not create a solicitor-client or adviser-client relationship. Regulatory requirements are subject to change; readers should verify current FCA rules and consult qualified legal counsel before taking or refraining from any action. BizLegal-AI makes no representations as to the completeness or accuracy of information derived from third-party regulatory sources.