UK cryptoasset regime · rules final 30 Jun 2026 · application window 30 Sep 2026 – 28 Feb 2027 · fully in force 25 Oct 2027
Is your firm ready for the FCA's cryptoasset gateway?
Every MLR-registered cryptoasset firm must apply for full FSMA authorisation in one window — and overseas firms reaching UK customers through a s.21 approver are caught by the same deadline. The FCA has said poor-quality applications will be rejected without assessment — and at its last gateway, over 87% of crypto registrations were rejected, withdrawn or refused (FCA Annual Report 2023/24). Permora screens your readiness against the final rulebook, in minutes, in your browser.
Readiness triage · recommended
26 checks across the five things the FCA will actually test
1
Window & timing — saving vs frozen-book mechanics, submission quality
2
Threshold conditions — UK mind-and-management, close links, resources, disclosure, business model
3
Application pack — RBP, forecasts, Form A, fincrime framework, policy uploads
4
Governance & prudential — SM&CR, capital floors, ORA, wind-down
Perimeter check · if you're not sure you're in scope
Do you need FSMA authorisation at all?
The FCA's own statutory decision trees: is your token a qualifying cryptoasset, is your activity in scope, and what permissions and minimum capital follow.
Read this first. Permora produces an indicative screening, not legal advice and not a regulatory determination. Readiness checks are verified against the FCA's final rules and application materials; perimeter results rest on draft PERG 19 (final guidance expected September 2026). Permora is an independent tool: it is not affiliated with, endorsed by, or acting for the Financial Conduct Authority. Answers stay in this browser tab — nothing is stored or sent anywhere. Professional review is required before relying on any output.
Readiness triage · your current status
Routing · how you reach UK customers today
Which best describes the firm right now?
This shapes how the window mechanics apply to you — the saving provision, the frozen-book risk and the s.21 cliff-edge work differently for each.
SI 2026/102 Part 7 · Webinar Q&A (Feb 2026) Q9, Q11, Q13
Readiness triage · your activities
Activities → permission set, capital floor & upload packs
Which of these does the firm do (or plan to do in the first 12 months)?
Tick everything that applies — this determines your permission set, your permanent minimum capital and which activity-specific document packs your application must include.
Perimeter check · Part 1 of 4 · Asset test · step 1 of 6
Tree 1 · qualifying cryptoasset
Is your token a cryptoasset within the FSMA s417 definition?
A cryptographically secured digital representation of value or contractual rights that can be transferred, stored or traded electronically, using technology supporting the recording or storage of data.
Draft PERG 19.4.1(1) · s417 FSMA
Perimeter check · Part 1 of 4 · Asset test · step 2 of 6
Tree 1 · qualifying cryptoasset
Is the token a tokenised share, debt security or other specified investment?
Substance over label: look at the rights conferred and how holders obtain returns — whether off-chain-backed or digitally native.
Draft PERG 19.4.6–19.4.7 · PERG 2.6
Perimeter check · Part 1 of 4 · Asset test · step 3 of 6
Tree 1 · qualifying cryptoasset
Is each unit fungible — freely interchangeable with any other unit?
A question of fact, not labels: a token marketed as an "NFT" can still be fungible, and vice versa.
Draft PERG 19.4.2
Perimeter check · Part 1 of 4 · Asset test · step 4 of 6
Tree 1 · qualifying cryptoasset
Is the token — or the rights it confers — transferable between persons?
Contractual lock-ups do not negate transferability; burn-and-mint mechanisms count; rights transferable off-chain count even where the token itself cannot move on-chain.
Draft PERG 19.4.3 · art 88F(3)
Perimeter check · Part 1 of 4 · Asset test · step 5 of 6
Tree 1 · qualifying cryptoasset
Is the token solely a record of value or contractual rights?
Functional test: if it is traded as an object of exchange and transferring it is how value moves, it is more than a mere record. Liquid staking tokens and wrapped tokens are "unlikely to constitute mere records" — usually in scope.
Draft PERG 19.4.4
Perimeter check · Part 1 of 4 · Asset test · step 6 of 6
Tree 1 · qualifying cryptoasset
Is the token excluded from the QCA definition by art 88F(4)?
E-money; UK or foreign currency (including CBDC); tokens redeemable only with the issuer; tokens usable only within a limited network of providers with direct commercial agreements with the issuer; or cryptoassets falling within another specified investment category.
Draft PERG 19.4.1(3) · art 88F(4)
Perimeter check · Part 1 of 4 · Asset test · stablecoin check
Tree 1 · qualifying stablecoin
Does the token seek to maintain a stable value against a single fiat currency, backed by held assets?
Algorithmic stablecoins (no backing assets) and multi-currency-basket tokens are not qualifying stablecoins — they remain plain QCAs.
Draft PERG 19.4.5 · art 88G
Perimeter check · Part 2 of 4 · Scope test · step 1 of 5
Tree 2 · do you need authorisation?
Are you carrying on any activity in relation to qualifying cryptoassets, qualifying stablecoin or specified investment cryptoassets?
Draft PERG 19 Annex 2 · CP26/13 para 2.17
Perimeter check · Part 2 of 4 · Scope test · step 2 of 5
Tree 2 · do you need authorisation?
Will the activity be carried on in the UK?
Careful — this is wider than where your office is. Selling to (or buying from) a UK consumer is deemed carried on in the UK even for a wholly overseas firm (s418(6C)); the Overseas Persons Exclusion does not apply to the new cryptoasset activities; and an interposed UK agent or arranger does not take an overseas firm out of scope — only a principal dealer or QCATP does.
Draft PERG 19.3.1, 19.3.5 · s418(6C) FSMA
Perimeter check · Part 2 of 4 · Scope test · step 3 of 5
Tree 2 · do you need authorisation?
Will the activity be carried on by way of business?
Deliberately narrower than the general FSMA business test: is the activity offered to customers as part of the business model? Occasional own-account trading as an end-user is out — but note the MLR business tests are different and assessed separately.
Draft PERG 19.2.1 · CP26/13 para 2.19
Perimeter check · Part 2 of 4 · Scope test · step 4 of 5
Tree 2 · do you need authorisation?
Does a tailored exclusion clearly apply to everything you do?
The crypto exclusions are narrow and activity-specific: intra-group transactions; genuine no-consideration airdrops; merchants accepting crypto for goods/services; DPB professional firms' incidental activity; pure technical provision. Familiar RAO exclusions (OPE, art 15) do not carry over.
Draft PERG 19.11 · art 9Z10–9Z11
Perimeter check · Part 2 of 4 · Scope test · step 5 of 5
Tree 2 · do you need authorisation?
Does a PERG 2.10 exemption apply (e.g. appointed representative, exempt person)?
Draft PERG 19 Annex 2 · PERG 2.10
Perimeter check · Part 3 of 4 · Activities & capital
Permission mapping · CRYPTOPRU 4.2.1R
Which of these does the firm do (or plan to do)?
Tick everything that applies — permissions stack, capital doesn't: the permanent minimum requirement is the highest single figure, not the sum.
Perimeter check · Part 4 of 4 · Transition position