The FCA FSMA cryptoasset gateway (opens 30 September 2026)
The FCA has fixed the dates for the UK cryptoasset authorisation regime, and the sequencing is unusual: the application gateway opens more than a year before the rules it leads to take effect. Getting the order of work right matters more than getting any single document perfect.
Three dates
- 30 September 2026 — the application period opens.
- 28 February 2027 — the application period closes.
- 25 October 2027 — the regime begins, applying to cryptoasset firms granted permission under FSMA on or after that date.
The five-month window between the first two dates is what constrains planning. It is not a rolling queue that stays open until commencement. The FCA has set both ends of it, and applications submitted inside the window are the ones assessed on the intended timetable.
Your MLR registration does not carry over
This is the point most often misread. The FCA has said that being registered under the Money Laundering Regulations does not guarantee authorisation under FSMA, and that an application form for MLR registration cannot be treated as an application form for FSMA authorisation. There is no automatic conversion. A registered firm that does nothing will not be authorised when the regime starts.
The traffic runs the other way, though. Once the FSMA gateway is open, the FCA will accept information contained in a firm application for FSMA authorisation as relevant to an application for MLR registration. Work done for FSMA can support an MLR file; the reverse does not hold.
On whether to register under the MLRs in the meantime, the FCA position is conditional: apply only if you are confident the registration can be completed early enough to be worth having before the new regime starts. After 30 September 2026 the FCA will encourage firms to focus on securing FSMA authorisation instead, and a firm that still wants to register after that date is expected to go through the pre-application support service first.
What happens if you are late
The regime has two different landing places for firms that are not authorised at commencement, and they are not equivalent:
- Apply within the application period but not yet be authorised at commencement, and a saving provision allows you to continue operating while the application is assessed.
- Apply after the period closes but before commencement, and you enter the transitional provision by operation of law. Firms in that position may only service pre-existing contracts. They cannot take on new UK customers.
That difference is the entire commercial case for applying inside the window. A firm in the transitional provision is not shut down, but it is frozen — running off a book it is not allowed to add to, for as long as assessment takes.
What the FCA expects to see
The FCA has asked firms to develop a clear and credible plan, and has been specific about what that involves:
- Work out which of the new cryptoasset regulated activities you carry on, and therefore which permissions you need.
- Run a gap analysis against the expected FSMA requirements.
- Produce a board-level implementation plan naming who is accountable, what has to change, how it will be delivered and by when.
- Assess the resourcing and the cost of compliance honestly.
- Take specialist legal and regulatory advice where the perimeter question is not obvious.
For MLR-registered firms, the FCA accepts that existing systems will demonstrate part of what FSMA requires, but flags market conduct, treatment of customers and senior leadership as areas where more will be expected. Those are not things the MLR regime tested, so a strong financial-crime record does not translate into readiness across the board.
Sequencing the next twelve months
The FCA runs a Pre-Application Support Service, and it is better used early than as a rescue. The FCA has also warned that applying outside the application period, or submitting an inadequate application, risks rejection, delays in assessment, refusal of authorisation, or being unable to continue operating when the regime launches.
A workable order of play: settle the perimeter question first, because it determines everything downstream; then build the governance, systems and control evidence, because that is what consumes calendar time; then draft the application itself. Firms that leave the perimeter analysis until the gateway opens tend to discover they have spent months preparing for the wrong permission — and by then the window is already running.
The checklist behind this article
The working document behind this: an 11-page readiness checklist for the FCA cryptoasset gateway, with the rule, article number or published FCA statement cited behind every item, and the open questions marked as open rather than guessed at. Seven activity heads with RAO article numbers, permanent minimum requirement by activity, the application pack, SM&CR, and the eight failure modes the FCA has published. USD 149, with the updated edition free when the September 2026 fee notice and the autumn perimeter guidance land.