In June 2026, the FCA published final rules under its Cryptoasset Roadmap. Implementation begins October 2027, with some requirements deferred to January 2028 and a further proposed deferral to April 2028. Firms should assess how these rules apply and adapt accordingly.
This article considers the FCA's position on regulated cryptoasset activities in PS26/11, building on consultation papers CP25/40 (previously discussed) and CP26/4, and the finalised guidance on international cryptoasset firms (FG26/7) (the AICF Guidance). PS26/11 should be read alongside PS26/9 (admissions, disclosures and market abuse), PS26/12 (prudential requirements) and PS26/13 (cross-cutting Handbook requirements including Consumer Duty, COBS, SM&CR and regulatory reporting).
The key changes introduced or clarifications made in PS26/11 and the AICF Guidance are set out below:
Execution venue requirement: Orders for UK retail and elective professional clients must be executed on a UK-authorised execution venue. The final rules extend the requirement to all other arranging activities, where firms must take all reasonable steps to ensure client orders are executed on a UK-authorised execution venue.
Pre-trade transparency: Pre-trade transparency obligations apply to large UK QCATP operators but no longer extend to principal dealers, aligning with the SI regime reforms under PS24/14 and PS25/17.
Staking: Firms must provide retail clients with service information and obtain express prior consent to key terms each time a retail client instructs the firm to provide a staking service. For auto-staking arrangements, consent to the arrangement itself suffices and need not be repeated for each individual staking transaction under it. Firms need only keep records for clients whose identity is known, addressing challenges in liquid staking models.
Safeguarding: Requirements apply only where a firm has the necessary degree of control over client cryptoassets. A firm holding only part of a private key (e.g. a shard) is unlikely to meet the control threshold under article 9N(4) of the RAO.
The remainder of this article sets out at a high level the rules finalised by PS26/11 and the AICF Guidance for each regulated cryptoasset activity in turn.
Qualifying Cryptoasset Trading Platforms
Location, Incorporation and Authorisation of QCATPs
FCA authorisation: Mandatory for any firm operating a QCATP in the UK or serving UK consumers from overseas. A UK presence is required, but firms may combine a UK entity with branch authorisation where global liquidity access justifies it.
QCATP branch exception: A QCATP may be operated via a UK branch where this facilitates global liquidity pool access (no separate order book is required) and better execution outcomes. Conditions include:
Home regulator comparability - the FCA must determine the home regulator offers comparable protection; a letter of good standing is insufficient.
Application justification - firms must demonstrate why branch authorisation suits their model; only those with meaningful global liquidity pool access are expected to use this route.
COBS/DISP - apply to UK-based users only.
Safeguarding - a branch may be combined with a separate UK subsidiary for other regulated activities including safeguarding, assessed case-by-case.
Matched principal Trading (MPT): A QCATP operator may obtain restricted principal dealer permission solely to facilitate matched principal trading on its own platform. This does not cover proprietary or other non-matched trading.
Safeguarding: A QCATP operator may rely on a temporary settlement exclusion from the requirement to safeguard assets. Up to 2% of each client's cryptoassets (per client and per cryptoasset class) may be held outside the trust in a settlement wallet for settlement purposes; assets in the settlement wallet do not receive full CASS protection.
QCATP operation
- Platform rules (CRYPTO 6.2): Operators must define non-discriminatory rules and procedures for platform access and operation.
- Algorithmic trading (CRYPTO 6.4): A principles-based approach applies - firms set their own rules and controls, with no prescriptive minimum requirements.
- Market-making (CRYPTO 6.4): Firms must identify, document and monitor market-makers on their QCATP. Formal contracts are not required but incentive schemes must be documented and disclosed.
- Kill switches (CRYPTO 6.3.6): Requirements to halt trading in an emergency cover UK users only, not global activity.
- Settlement (CRYPTO 6.5): The FCA expects settlement to be initiated within 24 hours of a trade being executed on a UK QCATP.
- Matched principal trading (CRYPTO 6.6): Permitted for firms with appropriate permission, acting in accordance with non-discretionary QCATP rules.
- Own tokens and affiliates (CRYPTO 3): Firms may admit tokens in which they have a financial interest and permit affiliates to trade, subject to conflict mitigation under CRYPTO 3 and SYSC 10.
Retail Customer Focused Requirements
- Retail access (CRYPTO 6.2.3(1)): UK retail investors may only access qualifying cryptoassets admitted to trading on a UK QCATP with a compliant QCDD (except UK-issued qualifying stablecoins).
- Pre-order disclosure (CRYPTO 6.2.3(3)-(4)): QCATPs must direct UK retail customers to the relevant QCDD(s) and any SDDs before an order is placed.
- Withdrawal notification (CRYPTO 6.2.5-6): QCATPs must notify and disclose when a qualifying cryptoasset is withdrawn from trading.
- Disclosure (CRYPTO 6.5): Clear and timely disclosures on terms, fees, trading rules, settlement and conflicts of interest are required.
- QCDD deferral: A six-month deferral mechanism for the QCDD admission to trading requirement (extending to April 2028) is expected to be consulted on in September 2026. A separate three-month deferral for execution venue and execution policy requirements (extending to January 2028) is also proposed.
Cryptoasset Intermediaries
- Best execution (CRYPTO 5.4): Best execution applies but does not require transaction-by-transaction checks - effective overarching arrangements with periodic post-trade analysis suffice.
- Price checking (CRYPTO 5.4.40): Firms must check at least three reliable price sources from UK-authorised execution venues (where available) but need not execute on those venues. Non-UK venues may be used where outcomes are at least as good.
- Execution venue requirement (CRYPTO 5.2): Orders for UK retail and elective professional clients must be executed on a UK-authorised execution venue. For other arranging activities, firms must take all reasonable steps to ensure the same result.
- Meaning of "execution venue" (CRYPTO 5.2.5): A firm executing client orders on a matched principal basis is not deemed an execution venue when acting solely in that capacity. A firm otherwise acting in a principal capacity is considered the execution venue.
- Affiliated liquidity (CRYPTO 5.2.6): Affiliates of QCATP operators must not systematically or predominantly source liquidity from an affiliated overseas QCATP that is not UK-authorised.
- Asset restrictions for retail (CRYPTO 5.3.2): Cryptoassets offered to UK retail clients must be admitted to trading on at least one UK-authorised CATP with a compliant QCDD.
- Conflicts of interest (CRYPTO 5.7.2): Firms must have systems and controls to address conflicts between proprietary trading and client order execution, such as functional separation.
- Personal account dealing (CRYPTO 5.8): Similar to COBS 11.7 - firms must establish adequate arrangements to manage conflicts arising from personal account dealing.
- Payment for order flow (PFOF): Cryptoasset intermediaries engaging in PFOF are unlikely to meet the FCA's requirements on best execution, conflicts of interest and inducements when serving retail or professional clients. This aligns with the FCA's established approach to PFOF for other regulated investments.
- Deferrals: Execution venue and execution policy requirements are subject to a proposed three-month deferral (to January 2028), to be consulted on in September 2026. A separate six-month deferral for the QCDD admission to trading requirement (to April 2028) is also proposed (see above under Retail Customer Focused Requirements).
Pre- and post-trade transparency
- Pre-trade transparency (CRYPTO 7.2): Principal dealers are no longer subject to pre-trade transparency. Large QCATP operators (£10m+ average annual revenue across all activities, calculated on a three-year rolling basis) remain subject to it. Firms may develop their own waiver and deferral policies for large or sensitive orders.
- Post-trade transparency (CRYPTO 7.3): All UK QCATP operators and principal dealers must publish transaction data as close to real time as possible and within 1 minute of execution.
Record Keeping and Client Reporting
- Cryptoasset identifier (CRYPTO 8.2): Cryptoassets must be identified by DTI (ISO 24165) in transaction records and client reports.
- Client reporting (CRYPTO 8.3.1): Reports must be provided by the end of the same working day; if execution or data receipt occurs after end of day, reporting may roll to the next working day.
- Transaction history (CRYPTO 8.3.5): Clients must be given access to three years of transaction history on request.
- No size exemptions: Record-keeping and reporting standards are uniform and not reduced for smaller firms or particular business models.
Cryptoasset Lending and Borrowing
These rules primarily apply to retail clients, except for record-keeping and client reporting.
- Appropriateness testing: Required before providing L&B services to retail clients.
- Information and consent (CRYPTO 9.2-9.3): Firms must provide clear information on L&B risks and costs and obtain express prior consent to key terms each time - a one-time consent model is insufficient.
- Proprietary token prohibition (CRYPTO 9.5): Proprietary tokens are prohibited in retail L&B services.
- Over-collateralisation (CRYPTO 9.6): Mandatory for retail borrowing; structures must be modelled so that margin calls or liquidation are not expected within the first six months.
- Collateral top-up (CRYPTO 9.6.5): Firms may supplement retail collateral only with express consent and up to 50% of initial value; clients may top up above this threshold.
- Negative balance protection (CRYPTO 9.7): Retail clients cannot lose more than the collateral dedicated to the borrowing arrangement.
- Title transfer (CRYPTO 9.6.8): TTCAs are prohibited for retail client collateral; permitted for non-retail clients.
- CASS interaction: CASS 17 does not apply to assets transferred under a lending arrangement but does apply to qualifying cryptoasset collateral in retail borrowing (including when staked).
Safeguarding
- Scope of CASS 17 (CASS 17.1): Applies to all firms that can bring about a transfer of the benefit of client cryptoassets (the "control" test under Article 9N), whether or not they physically hold them. Also applies to qualifying cryptoasset collateral received from retail clients, including when staked.
- Trust requirement (CASS 17.3): Client cryptoassets must be held on a non-statutory trust, be separately identifiable and not co-mingled with the firm's own assets.
- Trust exceptions (CASS 17.3.4-17.3.13): Exemptions include lending arrangements, client-instructed transfers, discharge of client debt, the settlement float, and situations requiring absolute title transfer with client consent.
- RSIC custody: CASS 17 does not apply to RSIC custody at this stage; CASS 6 applies instead. The FCA has published a call for input ("The future of tokenisation") to inform what safeguarding requirements should apply to RSIC custody in the longer term, with further consultation expected.
- Third-party appointments (CASS 17.3.23): Permitted where they would not increase risk of loss, supported by written due diligence. Firms may not grant security interests, liens or rights of set-off to third parties.
- Backup key exception (CASS 17.3.12): A firm holding a backup key on behalf of a client is exempt from the trust requirement where the client retains full control and can act independently, whether the client is the cryptoasset owner or another safeguarding firm acting as trustee.
Staking
- Pre-commencement (CRYPTO 10.2): Firms must provide retail clients with information on the staking service and its risks (including slashing) before commencing.
- Express prior consent (CRYPTO 10.3): Firms must obtain a retail client's express prior consent to key terms each time the client instructs the firm to provide the service, before the client is bound or the service is provided.
- Auto-staking (CRYPTO 10.3.5): Key terms must explain that future holdings may be staked and how the service may be cancelled. Consent is needed each time a retail client instructs auto-staking, not for each individual transaction under the arrangement.
- Material changes (CRYPTO 10.3.8): Changes to key terms (e.g. fees, lock-up durations) must be notified to retail clients in good time.
- Annual notification (CRYPTO 10.4): Firms must notify retail clients at least every 12 months, covering amounts staked, rewards, fees, and current terms.
- Record-keeping (CRYPTO 10.5): Required only for clients whose identity is known to the firm.
Decentralised Finance (DeFi)
- When rules apply: Rules apply where there is a clear controlling person carrying on regulated cryptoasset activities. Truly decentralised activities fall outside the regulatory perimeter. Whether a person is in scope is assessed case-by-case; firms presenting as decentralised but acting as intermediaries will be caught.
- DeFi guidance: Separate guidance on operational resilience and financial crime risks in DeFi is expected to be consulted on later in 2026.
Next steps
With the first implementation deadline of October 2027 approaching, firms should now assess how they fit within the new regulatory perimeter. We are continuing to follow developments and would be happy to discuss what PS26/11 and the AICF Guidance mean for your business.






_11zon.jpg?crop=300,495&format=webply&auto=webp)
_11zon.jpg?crop=300,495&format=webply&auto=webp)
_11zon.jpg?crop=300,495&format=webply&auto=webp)
.jpg?crop=300,495&format=webply&auto=webp)



