We explore four questions regulated firms should consider as they prepare a VoP application to operate under the new FCA crypto and stablecoin regime: what permissions are needed, when to apply, which entity should hold the permissions, and how to get ready to operate.
Permissions scoping starts with two questions: what is the asset, and what activity will the firm perform?
A. What assets are in scope?
Digital assets do not all fall into the same regulatory category. As Figure 1 shows, unbacked cryptoassets like Bitcoin and fiat-backed stablecoins will generally fall within the new FCA regime, while others may remain subject to existing banking or capital markets rules instead – or outside UK financial services regulation altogether.
The FCA will look beyond labels and focus on each token’s substance: the rights it gives the holder, and how those rights are recorded and transferred. That analysis is critical for determining what regulatory permissions are required.
Tokenised securities show why this matters. The term is used broadly for equities, bonds, fund interests and other securities using distributed ledger technologies (DLT), but different tokenisation models can have different regulatory outcomes.
Where the security is issued directly in token form, often described as “issued natively on-chain”, the investor’s rights are linked to the token itself. The token is not just a record of the security; it is how the security exists and the mechanism through which ownership and rights are transferred. This token is likely to be treated as a specified investment cryptoasset (SIC) – and therefore remains subject to capital markets rules. The FCA is likely to take a broad view of what may constitute a SIC, with its authorisation information document listing a wide range of potentially in-scope investment types.
Harder cases arise with “digital twin” models, where the underlying security exists off-chain and the token acts as a representation of it. If the token is solely a record of value or contractual rights (often referred to as a “mere record”), it may not be a SIC and may also fall outside the new crypto regime. That creates important questions, particularly for custody models, about which regulatory obligations apply.
The FCA’s draft crypto perimeter guidance, released in April, gives some indicators for this analysis. Factors suggesting a token may be a “mere record” include the absence of an observable price or pricing mechanism. It is less likely to be a mere record where the token is traded as the object of exchange in markets, or where transferring control of the token is, in practice, how value or contractual rights transfer.
Some uncertainty remains. UK Finance and AFME have highlighted that broad references to tokenised debt and equity in the FCA’s draft guidance could create confusion over whether a token is a SIC or a “mere record”, calling for further clarity. The FCA’s final perimeter guidance, expected later in September 2026, will therefore be important for firms developing digital twin and other “mere record” models.
Firms should build a clear internal taxonomy for tokenised securities, developed with Front Office, Legal, and Compliance; mapped to products and services; and reflected in governance, policies and procedures. Even where a token may be considered to fall between regimes as a “mere record”, firms should be able to evidence their analysis and how they plan to treat the token for purposes of each service provided.
B. What activities are in-scope?
Firms should then map in-scope assets to current and planned activities over the next three years [Figure 2].
While priorities will vary by firm, regulated firms are currently tending to focus on three areas.1
A. Enabling stablecoins to support tokenised securities or fund tokenisation strategies
Stablecoins are likely to be an important enabler of tokenised securities and funds. Near-instant settlement, 24/7 transferability and automated payment flows all generally depend on having a DLT-based means of payment available alongside the security. Where clients need or want to hold, buy or sell stablecoins as part of that proposition, firms may require crypto permissions. For example, intermediary permissions will be relevant where the firm facilitates customer purchases or sales, while custody or arranging custody permissions may also be needed depending on how assets are held. Stablecoin permissions should therefore be built into tokenised securities strategies from the outset.
B. Stablecoins for retail and corporate payments
HMT’s July 2026 proposals to bring UK-issued stablecoins (and tokenised deposits) into the payments regulation regime should, over time, encourage the development of a UK stablecoin payments market. Clearer consumer rights and protections, including around refunds, redemptions and dispute resolution, should support adoption of UK-issued stablecoins in payments. However, this initiative is early stage, with significant policy work planned over 2027/28 and implementation unlikely before 2029.
For firms, the near-term question is how to proceed before that future payments regime is in place, and what permissions they may, or may not, need under the new crypto regime. Two issues stand out.
First, HMT is proposing an interim carve-out, ahead of the wider payments reforms, so firms exchanging UK-issued stablecoins for fiat or other UK-issued stablecoins would not need crypto intermediary permissions. But its use will be limited unless and until GBP stablecoins become available and are used at scale. USD stablecoins currently dominate market activity. As a result, in practice, firms enabling customers to buy, sell or transfer overseas stablecoins for payments are still likely to need crypto intermediary permissions.
Custody is another key permissions question. HMT intends stablecoin custody provided as part of payment services ultimately to sit within the future payments regime, rather than the crypto custody regime. But until the payments reforms are implemented, firms enabling customers to hold stablecoins for payments may still need crypto custody permissions. HMT has recognised industry concerns about permissions that may later become redundant, but for now, firms launching a wallet offering for stablecoin payments before the future regime is in place should build crypto custody permissions (CASS 17) into their authorisation plans.
More broadly, crypto and stablecoin permissions analysis, and the initial VoP, is unlikely to be a one-and-done exercise. Firms should expect further licensing work once the updated payments regime is finalised. HMT has indicated that firms already authorised for traditional payments may need a VoP to move into tokenised payments, including UK-issued stablecoins or tokenised deposits.
C. Custody of SICs: VoP required
Firms providing custody of SICs will be required to comply with CASS 6, which already applies to custody of traditional securities, although the FCA plans to adapt those rules to take account of DLT-based securities. Regardless, firms with custody permissions for traditional securities still need a VoP to custody SICs – including where they already do so and want to continue – and should therefore build this into authorisation plans.
This is because the legislation underpinning the new FCA crypto regime creates a regulated activity for safeguarding qualifying cryptoassets and SICs (Article 9N), explicitly bringing both asset types within scope.2 As a result, even if a firm only wants to provide custody of SICs that are subject to CASS 6, the firm will need a VoP to get the custody permission under the new regime.
The right route depends first on the firm’s current UK regulatory status. Banks, asset managers, investment firms and other FSMA-authorised firms can seek a VoP to add crypto or stablecoin activities to existing permissions. Crypto natives, payments firms and e-money firms without a UK FSMA licence will need to make a full application for authorisation. The same broad timelines apply, but the application route, preparation burden and evidence required will differ.
The next question is whether the firm is already active in crypto and stablecoin markets today, or if not, when it wants to launch [Figure 3].
A. Already active – apply by February 2027 to preserve continuity
B. Launching activity by October 2027 – apply by February 2027 to maximise launch certainty
C. Later entrant, launching activity after October 2027 – February 2027 is a less critical milestone, but no launch until permissions are obtained
Firms should also be alert to potential FCA scrutiny of tokenised securities business models, including on whether MLR registration is needed. Firms should assess their position, take external advice where required, document the rationale and Board approvals, and maintain a consistent position in regulatory engagement.
Legal entity options will vary by firm type and activity.
Banks now have clarity that regulated crypto activities can, in principle, be carried out from a UK branch. This should give banks greater confidence to progress UK strategies, although approval is not automatic. The FCA and PRA will assess applications case by case, with custody offerings likely to attract particular scrutiny. This reflects concerns that overseas insolvency regimes may not give clients equivalent protection if a firm fails. Custodians planning to use branch structures should expect questions on how client assets are ring-fenced and how protections are secured contractually. The CASS 17 contractual trust requirement could help here, if firms and their advisers can structure the trust appropriately.
Stablecoin issuance raises a separate structuring issue for banks. The PRA continues to expect retail issuance to sit in a separate, non-deposit-taking and insolvency-remote entity, increasing costs and complexity.
Solo-regulated investment firms using UK branches should engage the FCA early. The FCA’s baseline expectation is for crypto activity to sit in a UK legal entity, with only narrow flexibility for international crypto trading platforms to serve UK customers via a branch model. If a UK entity is required, firms will need to factor the additional cost, governance, capital, operational build and timing implications into the authorisation plan and commercial case.
For regulated firms, preparing a crypto VoP does not mean starting from scratch. Existing governance, risk, compliance, financial crime, cyber and operational resilience frameworks, together with established supervisory relationships, provide a strong foundation. But the regime is broad and multi-layered, spanning service-specific crypto rules, cross-cutting financial services requirements and firm-specific expectations [Figure 4].
In our experience, five areas are likely to require particular focus as firms prepare their VoP application:
Firms that want to compete in the UK’s regulated crypto and stablecoin market need to move quickly from product strategy to a credible authorisation plan, ready for submission by 28 February 2027, while maintaining momentum towards operational readiness ahead of go-live on 25 October 2027. Plans will need to consider the regulatory perimeter, define the permission scope, and demonstrate that governance, controls and senior oversight will credibly support the proposed activity.
References:
1. Not exhaustive; priorities will vary. For example, firms exploring crypto lending may also need intermediary permissions, particularly for dealing as principal.
2. Specifically, the new safeguarding activity introduced through the amendments to the Financial Services and Markets Act 2000 (Regulated Activities) Order 2001 (RAO) – see Article 9N.