PS26/9: Market Abuse Regime for Cryptoassets

The FCA’s Policy Statement 26/9 sets out the final rules for Admissions & Disclosures and the Market Abuse Regime for Cryptoassets

22 July 2026

Publication

Loading...

Listen to our publication

0:00 / 0:00

The FCA’s Policy Statement PS26/9 (PS26/9) follows the Consultation Paper CP25/41 (CP25/41) and sets out the final rules for Admissions & Disclosures (A&D) and the Market Abuse Regime for Cryptoassets (MARC) under the Designated Activities Regime (DAR).

The FCA’s Policy Statement PS26/9 is one of five policy statements recently published by the FCA relating to the new cryptoasset regime introduced by the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2025 (the Cryptoasset Regulations). These follow three consultation papers published 16 December 2025. Together, they are intended to promote market integrity and strengthen consumer protection while considering the unique structure and risks associated with cryptoassets.

Below, we look at the key MARC provisions finalised in PS26/9, particularly the changes introduced since CP25/41.

Purpose of the regime

MARC prohibits three types of market abuse: insider dealing, the unlawful disclosure of inside information and market manipulation – and requires firms to prevent and detect these behaviours should they arise. MARC applies where a qualifying cryptoasset has been admitted to trading, or is subject to an application seeking admission to trading on a UK qualifying cryptoasset trading platform (QCATP). In line with the UK Market Abuse Regulation (UK MAR), the prohibitions apply regardless of whether the activity takes place in the UK or overseas. There are two designated activities for the purposes of MARC: the use and disclosure of inside information and market manipulation.

In its final rules, the FCA states it has drawn on traditional finance (TradFi) principles, particularly UK MAR, and maintained the structure of this for MARC wherever possible to facilitate the adoption of this regime. However, the MARC framework gives UK QCATPs greater responsibility in the prevention, detection and disruption of market abuse than in UK MAR – in particular large UK QCATPs, defined as those with average revenue (calculated at 12-month intervals) of ≥£10m a year (for 3 previous years). For example, only large UK QCATPs will be subject to on-chain monitoring and cross-platform information sharing requirements, although these obligations have been narrowed in the final rules.

Consultation feedback

Given that consultation feedback was broadly supportive of the framework proposed in CP25/41, the FCA has largely maintained the overall approach consulted on (as set out in our CP25/41 Crypto View). Small, targeted changes have been made to improve the “proportionality, clarity and operability” of the regime.

Inside information disclosure responsibilities

Under the final rules, the rules on disclosure will be very similar to those consulted on in CP25/41. For example, issuers, offerors and cryptoasset trading platforms (CATPs) will be required to publicly disclose inside information that directly concerns them, as anticipated in CP25/41. In addition, inside information must generally be disclosed as soon as possible, unless immediate publication would harm legitimate interests (provided that the delay does not mislead the public and confidentiality is maintained).

However, the FCA has now clarified that:

  • the obligation to disclose information does not require a firm to proactively seek out information that is not already in its possession; and
  • a “legitimate interest” for delaying disclosure could include: (i) protecting the security of the issuer or token; or (ii) where disclosure of a code vulnerability would undermine efforts to contain and remediate that vulnerability.

In any event, however, delayed disclosure cannot be indefinite.

Disseminating inside information

In CP25/41, the FCA suggested that issuers, offerors and CATPs would need to publish inside information on their website, actively disseminate this and upload it to the FCA’s NSM. In the final rules, this explicit requirement to actively disseminate inside information has been removed. Note, however, that some form of active dissemination is likely to be required to meet the standard under the Cryptoasset Regulations.

There is also a new requirement that uploaded disclosures should include a DTI as metadata.

Legitimate market practices

As proposed under CP25/41, the FCA has introduced exemptions from UK MAR for legitimate market practices (LMPs) relating to cryptoassets. This goes beyond MiCA but is in line with the IOSCO standards. However, the scope of these exemptions have been narrowed and clarified in PS26/9:

Legitimate reasons

Under the final rules, carrying out actions for legitimate reasons will not be an exemption to MARC, as suggested in CP25/41. This decision has been taken to reduce the investigative burden for firms and minimise the potential for inconsistency.

Coin-burning and crypto-stabilisation

  • Coin burning (CRYPTO 4.11.3): Coin burning is the process whereby a cryptoasset is permanently removed from circulation on a blockchain. The rules around coin burning as an LMP have been amended slightly, so that it must be conducted in accordance with a defined framework or protocol – with the full details publicly disclosed – or alternatively, take place on an ad-hoc basis but meet a number of conditions. If burning takes place on an ad-hoc basis, full details of the burning process must be publicly disclosed before it starts, and relevant transactions / burns must be recorded (see CRYPTO 4.11.5). In any event, coin burning can only take place where the sole purpose of the activity is to support the effective functioning of the market in the relevant qualifying cryptoasset by reducing the amount of this cryptoasset in circulation.
  • Crypto-stabilisation (CRYPTO 4.11.7): Crypto-stabilisation still counts as an LMP, as long as it is carried out for no more than 30 calendar days after the public announcement of the offer of a coin distribution (with the rules varying slightly depending on whether this is an initial coin offer or a secondary coin offer). Transactions which form part of the crypto-stabilisation process must also be recorded (and retained for 5 years), subsequently disclosed to the public (even where the trade can be observed on the blockchain), and carried out in compliance with the applicable rules of the UK QCATP.

Note that the FCA will keep all LMPs under review as market practices evolve.

Market abuse systems and controls

As set out in CP25/41, CATPs and intermediaries are required to implement effective and proportionate systems to prevent, detect, and disrupt market abuse. These systems should be adapted from UK MAR, with adjustments to address the specific risks associated with cryptoassets.

A number of changes have been introduced in PS26/9 so that:

  • All UK QCATPs must now monitor price dislocations for signs of market abuse.
  • Firms must still notify the FCA of information of which they would reasonably expect notice, but this is not limited to activity that a firm cannot deal with itself (as was suggested in the consultation). As a result, the FCA would still expect to be notified of serious or repeated abuse, given this could have wider market implications.
  • Intermediaries may be required to submit suspicious transaction and order reports to all UK QCATPs that trade a cryptoasset, rather than solely to the UK QCATP on which the transaction or order was due to be placed.
  • Firms must be able to collect wallet addresses from employees.

New guidance has also been published to remind firms that the FCA has a general power under section 138A FSMA to waive or modify its rules, including the rules in CRYPTO 4.

On-chain monitoring

In cryptoasset markets, trading occurs both on the blockchain (on-chain) and outside it (off-chain). As a result, market abuse, such as wash trading, pump-and-dump schemes, and insider dealing, can take place directly on-chain, where traditional monitoring tools may not detect it.

To address this, the FCA initially proposed that large CATPs (with annual average revenue of £10 million or more) should conduct on-chain monitoring relevant to their operations to effectively detect and prevent market abuse. Smaller CATPs and intermediaries would only be required to maintain off-chain monitoring, but encouraged to adopt on-chain monitoring where possible.

However, the requirement for on-chain monitoring has been narrowed so that large UK QCATPs are not required to monitor the entire chain all the time. Instead, large UK QCATPs only need to monitor the on-chain activity of wallets that are linked to their platform. “Linked” wallet activity includes transactions involving wallets that are reasonably identifiable as being associated with platform users.

All UK QCATPs are now required to have the ability to detect material and persistent dislocations between (i) the price of a cryptoasset traded on their platform; and (ii) the price of the same cryptoasset that is publicly available and traded on other markets and trading venues which the UK QCATP reasonably considers to be material for price formation.

Other changes have been made to rules on on-chain monitoring to simplify them and clarify expectations, for instance removing the explicit requirement that on-chain monitoring should be “appropriate and proportionate in relation to the scale, size and nature of the business”.

Insider lists

In CP25/41, the FCA proposed that issuers, offerors, and CATPs must maintain accurate, up-to-date insider lists, including details like identity, reason for inclusion, and wallet addresses, using templates based on TradFi rules.

In the final rules, references to wallet addresses have been removed from insider list templates. The systems and controls of UK QCATP operators and intermediaries must instead include arrangements with employees to support investigations into whether that employee has complied with its internal controls or undertaken cryptoasset market abuse.

What this means

Although the final rules are largely similar to those proposed in CP25/41, firms now need to update their understanding of their obligations under the new regime – particularly where requirements have become more extensive or exemptions, such as the “legitimate reasons” LMP, have been removed.

Next steps

Now the final rules have been published, many cryptoasset firms will be considering submitting an authorisation application with the FCA. If you would like to discuss this process further, or how these new rules affect your firm, please do get in touch.

This document (and any information accessed through links in this document) is provided for information purposes only and does not constitute legal advice. Professional legal advice should be obtained before taking or refraining from any action as a result of the contents of this document.