Skip to main content
Welcome to Deloitte
If we have selected the wrong experience for you, please change it above.

The FCA’s crypto and stablecoin regulatory regime is final: what should firms do now?

Key takeaways:

  • The FCA policy statements and guidance, published on 30 June, set out the regulatory position for firms looking to offer digital assets products and services. Banks, asset managers, investment firms and other firms authorised under the Financial Services and Markets Act 2000 (FSMA) can launch or continue crypto and stablecoin offerings by seeking a variation of their regulatory permissions (VoP), rather than a new authorisation. Crypto natives and payments or e-money firms without a UK FSMA licence will need to apply for full authorisation to undertake in-scope activities.
  • Stablecoin permissions are likely to be a key focus for regulated institutions. Firms enabling customers to hold, buy, sell or transfer stablecoins are likely to need new regulatory permissions, including intermediary and possibly custody-related permissions. This will be relevant both for firms developing retail and corporate payment offerings and for those pursuing tokenised securities and fund tokenisation strategies, where stablecoins can enable 24/7 settlement and automated payment flows, either from launch or as those offerings scale.
  • Custody of tokenised securities can create new permissions requirements. "Tokenised securities" is an umbrella term covering a range of structures with potentially different regulatory outcomes. Providing custody of certain types of tokenised securities, particularly where the token itself constitutes the security, will require a VoP even where firms already hold traditional securities custody permissions.
  • Timing is critical. The FCA authorisation and VoP gateway opens on 30 September 2026 and closes on 28 February 2027. Firms who have already mobilised, or plan to start crypto activity before the regime goes live on 25 October 2027, need to apply by the February deadline to preserve business continuity and keep business launch and growth plans on track.
  • A credible VoP will reflect the digital assets strategy behind it. Firms need to decide which products and services to offer, when to launch, and what permissions they need. That depends on operating model choices – including infrastructure buy vs. build, vendors and partners – and will take time to develop into a regulatory business plan (including a 3-year strategy) they can justify with the regulator.
  • The final FCA regime is a major milestone, but not the endpoint. Firms pursuing broader digital assets strategies should expect further regulatory change – and potentially licensing – work over the coming years. This includes an updated payments regulatory framework to accommodate UK-issued stablecoins and tokenised deposits, and possible reforms to support scaling tokenised capital markets activity.

We explore four questions regulated firms should consider as they prepare a VoP application to operate under the new FCA crypto and stablecoin regime: what permissions are needed, when to apply, which entity should hold the permissions, and how to get ready to operate.

1. What permissions does the firm need?

Permissions scoping starts with two questions: what is the asset, and what activity will the firm perform?

A. What assets are in scope?

Digital assets do not all fall into the same regulatory category. As Figure 1 shows, unbacked cryptoassets like Bitcoin and fiat-backed stablecoins will generally fall within the new FCA regime, while others may remain subject to existing banking or capital markets rules instead – or outside UK financial services regulation altogether.

Skip to description

Figure 1: The UK approach to different types of digital assets

The FCA will look beyond labels and focus on each token’s substance: the rights it gives the holder, and how those rights are recorded and transferred. That analysis is critical for determining what regulatory permissions are required.

Tokenised securities show why this matters. The term is used broadly for equities, bonds, fund interests and other securities using distributed ledger technologies (DLT), but different tokenisation models can have different regulatory outcomes.

Where the security is issued directly in token form, often described as “issued natively on-chain”, the investor’s rights are linked to the token itself. The token is not just a record of the security; it is how the security exists and the mechanism through which ownership and rights are transferred. This token is likely to be treated as a specified investment cryptoasset (SIC) – and therefore remains subject to capital markets rules. The FCA is likely to take a broad view of what may constitute a SIC, with its authorisation information document listing a wide range of potentially in-scope investment types.

Harder cases arise with “digital twin” models, where the underlying security exists off-chain and the token acts as a representation of it. If the token is solely a record of value or contractual rights (often referred to as a “mere record”), it may not be a SIC and may also fall outside the new crypto regime. That creates important questions, particularly for custody models, about which regulatory obligations apply.

The FCA’s draft crypto perimeter guidance, released in April, gives some indicators for this analysis. Factors suggesting a token may be a “mere record” include the absence of an observable price or pricing mechanism. It is less likely to be a mere record where the token is traded as the object of exchange in markets, or where transferring control of the token is, in practice, how value or contractual rights transfer.

Some uncertainty remains. UK Finance and AFME have highlighted that broad references to tokenised debt and equity in the FCA’s draft guidance could create confusion over whether a token is a SIC or a “mere record”, calling for further clarity. The FCA’s final perimeter guidance, expected later in September 2026, will therefore be important for firms developing digital twin and other “mere record” models.

Firms should build a clear internal taxonomy for tokenised securities, developed with Front Office, Legal, and Compliance; mapped to products and services; and reflected in governance, policies and procedures. Even where a token may be considered to fall between regimes as a “mere record”, firms should be able to evidence their analysis and how they plan to treat the token for purposes of each service provided.

B. What activities are in-scope?

Firms should then map in-scope assets to current and planned activities over the next three years [Figure 2].

Skip to description

Figure 2: Mapping planned activities to FCA permissions

While priorities will vary by firm, regulated firms are currently tending to focus on three areas.1

A. Enabling stablecoins to support tokenised securities or fund tokenisation strategies

Stablecoins are likely to be an important enabler of tokenised securities and funds. Near-instant settlement, 24/7 transferability and automated payment flows all generally depend on having a DLT-based means of payment available alongside the security. Where clients need or want to hold, buy or sell stablecoins as part of that proposition, firms may require crypto permissions. For example, intermediary permissions will be relevant where the firm facilitates customer purchases or sales, while custody or arranging custody permissions may also be needed depending on how assets are held. Stablecoin permissions should therefore be built into tokenised securities strategies from the outset.

B. Stablecoins for retail and corporate payments 

HMT’s July 2026 proposals to bring UK-issued stablecoins (and tokenised deposits) into the payments regulation regime should, over time, encourage the development of a UK stablecoin payments market. Clearer consumer rights and protections, including around refunds, redemptions and dispute resolution, should support adoption of UK-issued stablecoins in payments. However, this initiative is early stage, with significant policy work planned over 2027/28 and implementation unlikely before 2029.

For firms, the near-term question is how to proceed before that future payments regime is in place, and what permissions they may, or may not, need under the new crypto regime. Two issues stand out.

First, HMT is proposing an interim carve-out, ahead of the wider payments reforms, so firms exchanging UK-issued stablecoins for fiat or other UK-issued stablecoins would not need crypto intermediary permissions. But its use will be limited unless and until GBP stablecoins become available and are used at scale. USD stablecoins currently dominate market activity. As a result, in practice, firms enabling customers to buy, sell or transfer overseas stablecoins for payments are still likely to need crypto intermediary permissions.

Custody is another key permissions question. HMT intends stablecoin custody provided as part of payment services ultimately to sit within the future payments regime, rather than the crypto custody regime. But until the payments reforms are implemented, firms enabling customers to hold stablecoins for payments may still need crypto custody permissions. HMT has recognised industry concerns about permissions that may later become redundant, but for now, firms launching a wallet offering for stablecoin payments before the future regime is in place should build crypto custody permissions (CASS 17) into their authorisation plans.

More broadly, crypto and stablecoin permissions analysis, and the initial VoP, is unlikely to be a one-and-done exercise. Firms should expect further licensing work once the updated payments regime is finalised. HMT has indicated that firms already authorised for traditional payments may need a VoP to move into tokenised payments, including UK-issued stablecoins or tokenised deposits.

C. Custody of SICs: VoP required

Firms providing custody of SICs will be required to comply with CASS 6, which already applies to custody of traditional securities, although the FCA plans to adapt those rules to take account of DLT-based securities. Regardless, firms with custody permissions for traditional securities still need a VoP to custody SICs – including where they already do so and want to continue – and should therefore build this into authorisation plans.

This is because the legislation underpinning the new FCA crypto regime creates a regulated activity for safeguarding qualifying cryptoassets and SICs (Article 9N), explicitly bringing both asset types within scope.As a result, even if a firm only wants to provide custody of SICs that are subject to CASS 6, the firm will need a VoP to get the custody permission under the new regime.

2. When should we submit our VoP application?

The right route depends first on the firm’s current UK regulatory status. Banks, asset managers, investment firms and other FSMA-authorised firms can seek a VoP to add crypto or stablecoin activities to existing permissions. Crypto natives, payments firms and e-money firms without a UK FSMA licence will need to make a full application for authorisation. The same broad timelines apply, but the application route, preparation burden and evidence required will differ.

The next question is whether the firm is already active in crypto and stablecoin markets today, or if not, when it wants to launch [Figure 3].

Skip to description

Figure 3: Milestones and market entry routes for firms seeking a VoP

Market entry routes for firms seeking a VoP

A. Already active – apply by February 2027 to preserve continuity

  • The FCA expects to determine applications submitted during the gateway before the regime goes live in October 2027.
  • If the application remains pending at go-live (October 2027), firms are allowed to continue providing crypto services, including taking on new clients, pending the FCA’s final decision.
  • Missing the February 2027 deadline risks a more restrictive transitional route: service pre-existing contracts only, with no new UK business.

B. Launching activity by October 2027 – apply by February 2027 to maximise launch certainty

  • The FCA will not expedite applications submitted after February 2027. This may leave the firm without the necessary permissions at go-live, delaying launch plans.
  • Firms launching activity before October 2027 may also need to register with the FCA under the money laundering regime.

C. Later entrant, launching activity after October 2027 – February 2027 is a less critical milestone, but no launch until permissions are obtained

  • Later entrants can apply after the gateway closes but must wait for FCA approval before starting in-scope crypto activity.

Firms should also be alert to potential FCA scrutiny of tokenised securities business models, including on whether MLR registration is needed. Firms should assess their position, take external advice where required, document the rationale and Board approvals, and maintain a consistent position in regulatory engagement.

3. Which entity should (or can) hold the crypto permissions?

Legal entity options will vary by firm type and activity.

Banks now have clarity that regulated crypto activities can, in principle, be carried out from a UK branch. This should give banks greater confidence to progress UK strategies, although approval is not automatic. The FCA and PRA will assess applications case by case, with custody offerings likely to attract particular scrutiny. This reflects concerns that overseas insolvency regimes may not give clients equivalent protection if a firm fails. Custodians planning to use branch structures should expect questions on how client assets are ring-fenced and how protections are secured contractually. The CASS 17 contractual trust requirement could help here, if firms and their advisers can structure the trust appropriately.

Stablecoin issuance raises a separate structuring issue for banks. The PRA continues to expect retail issuance to sit in a separate, non-deposit-taking and insolvency-remote entity, increasing costs and complexity.

Solo-regulated investment firms using UK branches should engage the FCA early. The FCA’s baseline expectation is for crypto activity to sit in a UK legal entity, with only narrow flexibility for international crypto trading platforms to serve UK customers via a branch model. If a UK entity is required, firms will need to factor the additional cost, governance, capital, operational build and timing implications into the authorisation plan and commercial case.

4. How do you prepare to operate under the new regime?

For regulated firms, preparing a crypto VoP does not mean starting from scratch. Existing governance, risk, compliance, financial crime, cyber and operational resilience frameworks, together with established supervisory relationships, provide a strong foundation. But the regime is broad and multi-layered, spanning service-specific crypto rules, cross-cutting financial services requirements and firm-specific expectations [Figure 4].

Skip to description

Figure 4: Crypto regulation is multi-layered

In our experience, five areas are likely to require particular focus as firms prepare their VoP application:

  • Explain the business model and growth story clearly. Firms should set out what they plan to launch on day one, how the proposition will evolve over the following three years and – where stablecoin permissions support a tokenised securities strategy – the interdependencies, fund flows, and the role of group entities or third-party vendors.
  • Make operating model and partner decisions early. A VoP needs to reflect key choices on infrastructure (buy vs. build), trading venue access, custodians, exchange and liquidity provider relationships, and other vendor dependencies, including wallet infrastructure. Firms need to progress these decisions quickly to develop an operating model they can credibly discuss with the FCA and explain in the application.
  • Tailor policies and procedures to the UK crypto activity. Group-level policies, procedures and frameworks, including those developed for regimes like EU MiCA, may be a good starting point, but they must reflect UK-specific requirements and the UK offering. The FCA’s operational resilience and Consumer Duty guidance also includes crypto-specific expectations and good practice examples that firms should embed into operating model design, controls and customer journeys. Firms should also critically assess the suitability of existing financial crime and market surveillance frameworks. While many will have existing controls covering bribery and corruption, sanctions, fraud, money laundering, terrorist financing, and market abuse, they will need to be reviewed and potentially enhanced. Controls should be specifically designed and operationally effective to detect and mitigate the specific risks posed by the crypto and stablecoin offering.
  • Evidence senior management review, challenge and oversight. Senior leaders need to understand the proposed crypto activity, risks and wider business implications before making go/no-go decisions. The PRA has made this explicit for banks’ Boards and Executive teams, and the FCA will expect similar evidence from VoP applicants.
  • Build flexibility into implementation plans. Further policy detail will be published over time, but this should not delay preparations. Final perimeter guidance, further DLT operational resilience guidance and targeted deferral or transitional measures will need to be embedded into compliance strategies as they emerge from September 2026 onwards.

Taking things forward

Firms that want to compete in the UK’s regulated crypto and stablecoin market need to move quickly from product strategy to a credible authorisation plan, ready for submission by 28 February 2027, while maintaining momentum towards operational readiness ahead of go-live on 25 October 2027. Plans will need to consider the regulatory perimeter, define the permission scope, and demonstrate that governance, controls and senior oversight will credibly support the proposed activity.

References:

1. Not exhaustive; priorities will vary. For example, firms exploring crypto lending may also need intermediary permissions, particularly for dealing as principal.
2. Specifically, the new safeguarding activity introduced through the amendments to the Financial Services and Markets Act 2000 (Regulated Activities) Order 2001 (RAO) – see Article 9N.