Purpose of the regime
PS26/13 (PS26/13) sets out the FCA’s final rules and guidance on how key cross-cutting FCA Handbook obligations will apply to firms carrying out regulated cryptoasset activities, including conduct, governance, resilience, redress and reporting standards. This is important because a lot of firms carrying on regulated cryptoasset activities will need to understand how existing FCA Handbook regimes – including the Consumer Duty, Conduct of Business Standards (COBS), Dispute Resolution and access to the Financial Ombudsman Service, Senior Management Arrangements, Systems and Controls (SYSC), the Senior Managers and Certification Regime (SM&CR), ESG, the Client Assets Sourcebook (CASS) and regulatory reporting – apply alongside new crypto-specific requirements. After receiving feedback on its three consultation papers published in December 2025, the FCA has largely maintained the proposed framework while making targeted refinements to improve clarity and proportionality.
Approach to International Cryptoasset firms
Building on the non-Handbook guidance consulted on in Consultation Paper 26/4 (CP26/4), Chapter 2 of PS26/13 sets out the minimum standards the FCA expects for international cryptoasset firms seeking UK authorisation, both at the time of their application and on an ongoing basis. Among other things, this relates to location of offices, effective supervision, appropriate resources, suitability and business model.
Given the broad support received at the consultation stage, the FCA’s core position remains that it will generally expect international cryptoasset firms to have a UK legal entity, reflecting its view that firms operating through UK branches may pose heightened risks to UK consumers and markets, particularly as retail customers may be less clear that the risk of harm could be higher where the firm they interact with is located overseas. Note that in some circumstances, firms may be able to operate in the UK by establishing an authorised UK legal entity together with a UK branch of an overseas qualifying cryptoasset trading platform (QCATP) which will also need to be authorised. In this scenario, there is no obligation for firms to carry out the activity of operating a QCATP via a UK branch, and the overseas UK QCATP could provide matched principal trading services on the platform, where they meet the relevant thresholds and permissions.
A key refinement introduced in PS26/13 is in the treatment of dual-regulated firms. The finalised guidance states that firms regulated by both the FCA and PRA will not necessarily be expected to carry on new cryptoasset activities through a UK legal entity if they can demonstrate, at authorisation and on an ongoing basis, that they can meet the threshold conditions by operating from a branch. This would require approval from the PRA as the lead regulator and would also be assessed by the FCA at the authorisations gateway and be reliant on the firm holding the relevant permission.
The Consumer Duty
The scope of the Consumer Duty (the Duty) in relation to cryptoasset firms has been consulted on in Consultation Paper 25/25 (CP25/25), CP26/4, and Guidance Consultation 26/2 (GC 26/2), non-Handbook Duty Guidance. Specifically, the FCA has looked at whether the Duty should apply to cryptoasset firms in the same way that it applies to other FSMA-authorised firms, whether all aspects of the Duty would apply, and how this would happen in practice. The Duty requires firms to put consumer needs first and act to deliver good outcomes, including by acting in good faith, avoiding foreseeable harm, and enabling and supporting retail customers to pursue their financial objectives.
After receiving positive feedback, the FCA has decided that Principle 12 and PRIN 2A will apply to cryptoasset firms, supplemented by non-Handbook guidance to clarify how the Duty applies to cryptoasset activities (See FG26/5 and FG22/5). This is subject to limited exceptions: some A&D activities in relation to qualifying cryptoassets (other than UK-issued qualifying stablecoins) and trading between participants on a UK QCATP are exempt. In the non-Handbook guidance, the FCA has emphasised that the Duty is designed to be outcomes-based, sufficiently flexible to incorporate a range of different sectors and business models, and applied proportionately.
Designated investment business
The FCA has confirmed that it will expand the concept of designated investment business (DIB) to cover qualifying cryptoasset activities, for the purpose of applying relevant sections of the Handbook. In CP25/25, the FCA proposed to expand the glossary definition of “designated investment business” in the Handbook to apply the majority of cross-cutting rules and guidance (including parts of SYSC, all of COBS and CASS 7) to cryptoasset firms in the same way as to traditional finance (TradFi) firms.
As a result, most existing rules and guidance in the Handbook will now apply to cryptoasset firms (including qualifying stablecoin) in the same way as to TradFi firms, establishing a base of compliance that is consistent. Some requirements will apply only in specific circumstances: for example, certain elements of SM&CR will apply only where firms meet the relevant criteria, and the TC Sourcebook will apply only to a subset of cryptoasset firms, where their employees carry out certain activities for retail clients.
Amendments to CASS 1, 7 and 8
In the final rules, the FCA has made amendments to CASS to address the expanded definition of DIB to include qualifying cryptoasset activities.
The FCA explains that, without further changes, the CASS 7 client money rules would apply, for example, to firms issuing qualifying stablecoins in the UK where they receive and hold client money, and to firms safeguarding client cryptoassets – including both qualifying cryptoassets and relevant specified investment cryptoassets – where money flows arise in connection with that safeguarding activity. The purpose of the proposed amendments is to ensure that CASS applies appropriately and to avoid duplication or unintended outcomes.
As such, a number of measures consulted on have been finalised, and some new provisions introduced. The most notable changes include:
- firms carrying on the activity of issuing qualifying stablecoins will now not be subject to CASS 7 at all, whether this relates to the money held as backing assets, or any other money arising from stablecoin issuance; and
- firms safeguarding relevant specified investment cryptoassets (RSICs) will be subject to CASS 6 for the time-being.
Note that the FCA is inviting industry feedback to inform CASS rules that may be applied to RSIC custody in the longer term through their call for input.
Senior Management Arrangements, Systems and Controls (SYSC)
In CP25/25 and CP26/4, the FCA proposed that cryptoasset firms must follow certain rules in SYSC and related sourcebooks to ensure a robust governance and compliance framework and to align with the rules applicable to FSMA-authorised TradFi firms. The proposals included that firms conducting new cryptoasset activities for retail clients would have to follow additional requirements in the TC Sourcebook.
These changes have been implemented in the final rules: SYSC 1, 4-7, 9-10 and 18 will apply in the same way as they do to existing FCA-regulated firms, as will provisions of the TC Sourcebook. The specific activities that will trigger the application of the TC Sourcebook are as follows:
- dealing in qualifying cryptoassets as principal or agent (including cryptoasset lending and borrowing);
- safeguarding a qualifying cryptoasset or a relevant specified investment cryptoasset (including arranging for a person to carry on that activity); and
- arranging qualifying cryptoasset staking.
Note that these new activities will be subject to the scope of the existing TC Sourcebook. As the cryptoasset industry develops, qualifications may be introduced into the regime.
SM&CR
As proposed in CP25/25, SM&CR will be applied in full to authorised cryptoasset firms, with some minor amendments. Given the Treasury, FCA and PRA are currently reviewing SM&CR rules, there will be a ‘modification by consent’ approach to avoid imposing requirements that may soon be amended. As such, the assessment of compliance will be deferred for a period of time during the gateway, until there is greater certainty and the changes to the regime have been finalised.
For firms with international management structures, the FCA may approve SMF applications for individuals based overseas, for example where an individual within the wider group is responsible for implementing the UK entity’s strategy. However, the FCA’s general expectation is that “mind and management” should be, and remain, located in the UK. Physical location will be a particularly important factor for SMF 17 and SMF 16 applications: the FCA expects persons holding these roles to work from the firm’s principal place of business in the UK.
The FCA has made two notable changes following feedback:
- it will not require individuals involved in the “backing asset management” element of stablecoin issuance to be certified under the “proprietary trader” certification function; and
- while the FCA will proceed with an Enhanced threshold of £100 billion in combined safe custody assets and client cryptoassets for cryptoasset safeguarding firms, it has revised the Enhanced threshold for UK qualified stablecoin issuers: a UK qualified stablecoin issuer will become subject to the Enhanced SM&CR regime when it holds £20 billion in backing assets, calculated as a three-year rolling average.
Operational resilience
In CP25/25, the FCA proposed extending the existing operational resilience framework under SYSC 15A (as supplemented by SYSC 4, 7 and 8) to cover all authorised cryptoasset firms, particularly given the technology-driven nature of the cryptoasset sector. The FCA also proposed creating additional non-Handbook guidance to help firms understand operational resilience requirements in relation to crypto, and treating cryptoasset firms’ use of permissionless distributed ledger technologies (DLTs) as an outsourcing arrangement under SYSC 8.1.1.
Given the overwhelmingly positive feedback received, the FCA has consolidated its proposals in the final rules. Only small amendments have been made to the proposals, for example various parts of the non-Handbook guidance (see FG 26/6) have been updated to provide additional clarity.
Later this year, the FCA will consult on non-Handbook guidance on operational resilience for DLT use. That future guidance is intended to support firms in managing DLT-specific operational and technological risks.
Financial crime
At the consultation stage, the FCA proposed to apply the financial crime elements of SYSC 6, the Financial Crime Guide (FCG) and Financial Crime Thematic Reviews (FCTR) to firms conducting cryptoasset regulated activities, in the same way as FSMA-authorised TradFi firms.
The FCA is proceeding to apply these provisions to cryptoasset firms in order to support them in building stronger policies and procedures and in monitoring and mitigating financial crime risks. The FCA places these changes in the context of the existing UK anti-money laundering framework for cryptoasset businesses. Since January 2020, cryptoasset businesses operating in the UK as cryptoasset exchange providers or custodian wallet providers have been required to register with the FCA and comply with the Money Laundering Regulations; since September 2023, they have also been required to comply with the Travel Rule.
COBS
COBS sets out core standards for how firms interact with clients. In CP26/4, the FCA consulted on how COBS will apply to firms carrying on regulated cryptoasset activities.
The FCA’s final position maintains much of the approach consulted on. COBS will apply to cryptoasset firms in key areas including conduct of business obligations, client categorisation, financial promotions, firm and service disclosures, client agreements and appropriateness assessments, while certain COBS provisions will be disapplied where crypto-specific rules in the CRYPTO Sourcebook apply instead. For overseas-incorporated QCATPs authorised in the UK via a branch, the FCA will disapply COBS for non-UK users based on habitual residence or, where applicable, country of business establishment.
For COBS 2-6, 8, 10-11, 15 and COBS 1 Annex 2, the FCA is maintaining its proposed approach with additional guidance being issued in the case of COBS 6 and 10. A few key provisions have been introduced in relation to the other provisions:
- COBS 1 (including Annex 1): The FCA will disapply COBS for non-UK users of overseas-incorporated QCATPs authorised in the UK via a branch, based on user habitual residence or (where applicable) country of establishment.
- COBS 16: This is being disapplied for staking activities, but the proposed approach will be maintained for other activities.
Environmental, Social and Governance (ESG)
After consulting on this issue, the FCA is rolling out the ESG Sourcebook (ESG 4.1.1R and ESG 4.3.1R) to all cryptoasset firms. This will prevent cryptoasset firms from using sustainability labels and require such firms to ensure any sustainability references they use are clear, fair and not misleading and are consistent with the sustainability characteristics of the product or service. Other ESG rules apply only to specific types of firms, so these will not be carried across to cryptoasset firms.
Dispute resolution and compensation
These provisions set out how the FCA’s complaints, redress and compensation framework will apply to regulated cryptoasset activities. In summary, the FCA will apply DISP rules and associated guidance to firms carrying out new regulated cryptoasset activities and will allow consumers of regulated cryptoasset firms access to the Financial Ombudsman, but it will not expand Financial Services Compensation Scheme protection to regulated cryptoasset activities.
Some key changes introduced in the final rules are as follows:
- The Financial Ombudsman’s compulsory jurisdiction will be extended to complaints relating to acts or omissions by firms in carrying on any new regulated cryptoasset activities, including acts or omissions for which a firm is responsible, such as those of third parties acting on its behalf. However, the FCA will introduce a carve-out for complaints by non-UK customers of overseas-incorporated QCATPs authorised via a UK branch, identifying non-UK customers as those not established or habitually resident in the UK.
- Following feedback, the FCA has changed the complaints-forwarding obligation from “immediately” to “promptly” to allow timely forwarding while recognising the need for third parties to triage complaints properly. The FCA will also add guidance to DISP 1 stating that firms should resolve complaints within eight weeks of a third party receiving them.
Regulatory reporting
Following consultation, all qualifying cryptoasset firms will be required to submit the applicable returns in SUP 16, and unless otherwise specified in the Handbook, these must be submitted via RegData within a specified time period. Note that the FCA is consulting on annual fees and levies for cryptoasset firms in CP26/17.
In most other areas consulted on, the FCA is also maintaining its proposed approach. A few small changes are as follows:
- the FCA has recognised that firms need time to design and embed reporting processes and controls so has introduced an indicative timeline (including the FCA’s intended approach to engagement in the post-implementation period);
- the questions in the UK-issued qualifying stablecoin issuance return are being amended to reflect feedback received. This includes requiring UK authorised stablecoin issuers to report information on the composition of the core backing assets (and the CASS rules have been amended to allow firms to make use of an excess in the backing pools);
- the requirement to report the total number of redemption suspension events has been removed (the firms will be required to notify the FCA of any such event immediately under CRYPTO 2.4.24R);
- clarification has been added to guidance on QCATP returns to note that where a firm is an overseas person operating through a UK establishment, references to client categories apply only to those clients who deal with the firm via that UK establishment; and
- guidance on safeguarding reporting has been updated to allow firms, where it is possible to do so, to provide the ISO 24165 Digital Token Identifier.
The FCA has indicated that it will monitor how initial reporting works in practice and may consult on refinements to the final form of the cryptoasset regulatory reporting requirements once the reporting framework has settled.
Next steps
Before these rules are implemented, firms will need to assess which provisions apply to them and update their understanding of the changes since the consultation papers were published. Do get in touch if you would like to discuss PS26/13 in more detail and what it means for your business.



.jpg?crop=300,495&format=webply&auto=webp)


_11zon.jpg?crop=300,495&format=webply&auto=webp)

_11zon.jpg?crop=300,495&format=webply&auto=webp)







_11zon.jpg?crop=300,495&format=webply&auto=webp)


_11zon.jpg?crop=300,495&format=webply&auto=webp)