The Financial Conduct Authority published its final cryptoasset perimeter guidance, giving firms two weeks to determine which permissions they need before the authorisation gateway opens.
The publication date corrects an error in some secondary coverage that placed the release on September 17. The bigger consequence is unchanged: firms registered under the Money Laundering Regulations will not convert automatically into authorised firms under the Financial Services and Markets Act.
The guidance follows FinanceFeeds’ September 9 report, “FCA Crypto Gateway Opens 30 September: What Firms Must File by February”, which covered the application timetable. PS26/18 now explains the perimeter that determines who must enter that process.
The FCA Lists Seven Regulated Crypto Activities
The final policy statement identifies seven activities introduced by the Cryptoassets Regulations. They are issuing qualifying stablecoins in the UK, safeguarding or arranging the safeguarding of qualifying cryptoassets, operating a qualifying cryptoasset trading platform, dealing as principal, dealing as agent, arranging deals and arranging qualifying cryptoasset staking.
Some summaries group principal and agency dealing together and describe six categories. The FCA’s policy statement lists them separately, producing seven legally stated activities. Crypto lending and borrowing can also fall within dealing or arranging, depending on how the business operates.
The assessment does not stop at a company’s label. Firms must examine what they do, whether they carry it on by way of business, whether it occurs in the UK and whether an exclusion or exemption applies. Overseas firms can be caught when their services have the required UK connection.
The FCA also distinguishes qualifying cryptoassets from tokens that are already specified investments. Electronic money, fiat currency, central bank digital currencies and some limited-network tokens sit outside the new qualifying-cryptoasset definition. Hybrid structures require analysis of the rights represented by the token rather than its marketing name.
MLR Registration Does Not Become FSMA Authorisation
The FCA states that existing registrations and permissions will not convert automatically. A crypto business already registered for anti-money-laundering supervision must apply for FSMA authorisation if it intends to conduct an in-scope regulated activity after the new regime begins.
That turns the transition into a fresh authorisation project rather than an administrative transfer. The application asks firms to document their business model, governance, financial resources, controllers, systems and controls and the specific crypto permissions they require.
MLR registration and FSMA authorisation serve different purposes. The first focuses on anti-money-laundering supervision, while the second tests whether the firm meets the regulator’s wider threshold conditions and can comply with conduct, prudential, governance and reporting rules.
Firms already authorised under FSMA for other financial services are not exempt. They will need to apply for a variation of permission when their planned crypto activities are outside their current permissions.
The FCA received 78 responses to its April consultation. Sixty percent generally supported the proposed perimeter guidance, while respondents asked for more clarity on territorial scope, technical infrastructure, decentralised arrangements and the relationship with other regulatory frameworks.
The result is not a licence checklist that can be completed by job title or website description. A firm may need several permissions where it combines exchange, custody, dealing and staking services, and each permission must match the activities described in its regulatory business plan.
The Gateway Runs From 30 September to 28 February
The FCA’s gateway operating page and its formal gateway direction state that the application period begins at 9:00am on 30 September 2026 and ends at 11:59pm on 28 February 2027. These are the regulator’s stated times, not dates calculated from the regime’s commencement.
The wider FSMA crypto regime takes effect on 25 October 2027. The FCA says it expects to decide applications submitted within the window before that date. If an in-window application remains unresolved, a statutory saving provision may allow the firm to continue providing services until a final decision is made.
That protection is one reason the February deadline matters. A firm that applies after the window cannot assume it will receive the same ability to continue operating while the FCA assesses its case.
The gateway is therefore a capacity-management tool as well as a legal deadline. The FCA is asking firms to submit within a fixed period so it can sequence assessments before commencement, while saving provisions prevent an unresolved in-window application from creating an automatic cliff edge.
Missing the Window Can Mean an Orderly Exit
Existing firms that do not apply during the gateway period must assess whether they can use a transitional run-off provision or whether they need to stop the regulated activity before commencement. The route is designed to allow existing business to be wound down, not to provide an indefinite alternative to authorisation.
The perimeter guidance itself is not the final word on every model. The FCA says only the courts can provide an authoritative interpretation of legislation, and it plans another consultation after a government statutory instrument changes parts of the underlying framework.
For firms already on the MLR register, however, the operational decision is immediate. They must map each product and service to the seven activities, identify exclusions, choose the permissions needed and prepare an FSMA-standard application before the gateway closes.
The perimeter work should come first because it controls the rest of the application. Governance charts, financial forecasts, systems descriptions and wind-down planning all depend on the regulated activities the applicant says it will conduct.
