On 30 June 2026 the FCA published their Policy Statement (PS26/13) titled ‘Application of FCA Handbook for Regulated Cryptoasset Activities’, setting out its final rules and guidance on how key cross-cutting Handbook obligations will apply to authorised Crypto Asset Service Providers (“CASP”).
The application of the FCA Handbook is a key component of the new cryptoasset regime that firms will need to build into their applications for authorisation. Once authorised as a CASP, your firm will be expected to meet applicable Handbook standards as per any other FSMA authorised firm – the days of operating in a regulatory space primarily defined by anti-money laundering registration will end on 25 October 2027 when the new authorisation regime commences.
Whilst this article summarises the key requirements discussed in PS26/13. It is not a substitute for reading the document itself. Firms that are preparing an application for authorisation as a CASP should work through the full text and the accompanying finalised non-Handbook guidance and incorporate the requirements in their gap analysis work.
Cryptoasset activities will be classified as Designated Investment Business
The foundational change confirmed in PS26/13 is the expansion of the Handbook definition of ‘Designated Investment Business’ to include all qualifying cryptoasset activities. This single change pulls most of the existing Handbook requirements into scope for CASPs. Subject to the specific scope and applicability of individual Sourcebooks (i.e. sections of the Handbook), most existing cross-cutting Handbook rules and guidance will now apply to cryptoasset firms in the same way as they already apply to traditional FSMA authorised firms.
Consumer Duty
The Consumer Duty (“the Duty”) will apply in full to cryptoasset firms, subject to two specific exemptions:
- It does not apply to trading between participants of a qualifying cryptoasset trading platform. The FCA’s view is that the dedicated CRYPTO 6 conduct rules provide equivalent protection for that activity and applying the Duty on top would be disproportionate.
- It also does not apply to public offers and admissions to trading for qualifying cryptoassets other than UK-issued qualifying stablecoins. For UK-issued qualifying stablecoins, the Duty applies in full, including to activities related to public offers and admissions to trading.
The FCA published FG26/5 ‘Guidance on the Application of the Consumer Duty to Cryptoasset Firms’ on 30 June 2026 which explains how the Duty’s four outcomes (products and services, price and value, consumer understanding and consumer support) translate to cryptoasset business models. As many firms will already know, the Duty is not a box-ticking obligation, it is a framework for assessing whether products, services and customer interactions deliver good consumer outcomes and has been a supervisory focus for the FCA in recent years. Firms are expected to exercise their own judgement in applying the outcomes to their specific cryptoasset models and consider the FCA’s guidance as illustrative rather than prescriptive.
Client money and assets
The Client Assets Sourcebook (“CASS”) framework will apply to cryptoasset firms that hold client money and client assets as part of their cryptoasset activities subject to several amendments. One of these amendments to CASS is in relation to the professional client opt-out from the client money rules – this lets a firm agree with a professional client (not a retail client) that money held by the firm on the client’s behalf will not be treated as “client money”. This opt-out will not apply to money held in connection with qualifying cryptoasset activities. Firms should specifically refer to CASS 7 which addresses the client money rules and the new CASS 17 which addresses cryptoassets. Firms conducting stablecoin issuance will also need to ensure they understand the distinct backing funds and asset requirements outlined in CASS 16.
Senior Management Arrangements, Systems and Controls
The Senior Management Arrangements, Systems and Controls (“SYSC”) Sourcebook will apply to cryptoasset firms in the same way as it applies to other FSMA-authorised firms. SYSC contains significant requirements which are foundational to the establishment and operation of firms. Key areas covered by SYSC include organisational requirements (SYSC 4), skills, knowledge and expertise (SYSC 5), compliance and risk management (SYSC 6 and 7), record-keeping (SYSC 9), conflicts of interest (SYSC 10) and whistleblowing (SYSC 18). The FCA has noted that its SYSC requirements are deliberately high-level and technology-neutral, and does not consider it necessary to tailor them specifically to cryptoasset business models.
Training and competence
The Training and Competence (“TC”) Sourcebook will apply where employees carry out certain activities for retail customers; the FCA specifically reference dealing in qualifying cryptoassets as principal or agent (including cryptoasset lending and borrowing), safeguarding a qualifying cryptoasset or a relevant specified investment cryptoasset (including arranging for a person to carry on that activity), and arranging qualifying cryptoasset staking. The FCA will not require formal qualifications for key individuals, given that the cryptoasset qualification market is still developing, but will keep this under review.
Senior managers and accountability
The FCA considers that the Senior Managers and Certification Regime (“SM&CR”) will have a beneficial effect for governance and accountability for firms in the cryptoasset sector in the same way as it has for other FSMA authorised firms. As such the FCA will apply it in full to all CASPs.
All relevant Senior Management Functions (“SMF”), requiring pre-approval by the FCA, certification functions (self-certified by the firm and not pre-approved by the FCA), prescribed responsibilities and conduct rules apply. Cryptoasset firms will therefore be brought into the same accountability framework as other FSMA-authorised firms with personal responsibility sitting with named senior managers for defined operational areas.
Under SM&CR there is an ‘Enhanced’ classification for larger firms which brings additional SMF functions into scope. However, the FCA believes that few, if any, firms will meet the thresholds at authorisation, although they may attain sufficient size in the long-term as the market grows.
Operational resilience
The FCA considers that the risks posed by the activities of the cryptoasset sector, and the reliance on technology in providing essential activities, makes applying SYSC 15A to cryptoasset firms appropriate and proportionate. SYSC 15A is the FCA’s operational resilience framework and includes requirements covering understanding and mapping the people, processes, technology, facilities and information needed to deliver each important business service, setting impact tolerances and testing in severe but plausible disruption scenarios. This should be familiar territory for payment and FSMA authorised firms but will be new for VASPs.
The FCA acknowledged the industry consensus that applying SYSC 8 (Outsourcing requirements) to the use of permissionless DLTs, given the absence of direct contractual relationships, is inappropriate. SYSC 8 will therefore not be applied to the use of permissionless DLTs.
The FCA have also published non-Handbook finalised guidance on operational resilience for cryptoasset firms (FG26/6) – this June 2026 document should be reviewed for additional helpful detail.
Financial crime
The FCA considers it proportionate for cryptoasset firms to be subject to the same financial crime rules that are already in place for other FSMA‑authorised firms. Firms carrying out cryptoasset activities will therefore need to comply with both the MLR and FSMA regimes. The FCA believes that this will support cryptoasset firms to build stronger policies and procedures, including systems and controls to identify, assess, monitor and manage financial crime risks. The financial crime requirements in SYSC 6 will apply in full, alongside the FCA’s Financial Crime Guide and Financial Crime Thematic Reviews.
Cryptoasset firms should establish risk-based policies, controls and procedures that are comprehensive and proportionate to the size and nature of the business. A financial crime risk assessment must underpin the development and operation of the framework.
The FCA have also stated that they will continue to engage with the JMLSG to ensure that guidance is updated and aligned with the Cryptoassets Regulations.
Conduct of Business Standards
The Conduct of Business Standards (“COBS”) Sourcebook sets out core standards governing how firms interact with clients. COBS will be applied to cryptoasset firms to ensure that firms develop conduct frameworks to address risks and ensure that firms act in the same way as other FSMA-authorised firms, i.e. honestly, fairly and professionally.
The application of COBS to cryptoasset firms is broadly in line with the FCA’s proposed approach described in their consultation, with some adjustments to reflect industry feedback.
With regard to financial promotions, the FCA decided to maintain their proposed approach and retain the current application of the financial promotions regime for qualifying cryptoassets, including the continued classification of qualifying cryptoassets (other than UK‑issued qualifying stablecoins on the basis that their risk profile is lower) as Restricted Mass Market Investments (“RMMI”). Classification of cryptoassets, including BTC and ETH, as RMMI triggers certain COBS 4.12A restrictions, in addition to financial promotions rules, including mandatory risk warnings on every promotion, a risk summary accompanying promotions, retail customer appropriateness assessments and restricted / high-net worth / sophisticated investor self-certifications. The FCA will keep the effectiveness and proportionality of the RMMI classification under review.
Key requirements include strengthening retail client understanding through the conduct of appropriateness assessments and the conduct of appropriateness tests. The FCA believes that appropriateness tests adds necessary friction and consumer protection in the consumer journey, helping to ensure that the consumer has the necessary experience and knowledge to understand the risks involved in relation to the specific cryptoasset activity.
Disclosure requirements regarding information on the safeguarding of cryptoassets are intended to complement the broader contractual and information obligations for cryptoasset firms. Required disclosures include explanations of crypto‑specific safeguarding arrangements and risks which, in the context of retail clients, should sit alongside the firms’ Consumer Duty obligations to support retail customer understanding by communicating information in a way that meets retail customers’ information needs and which is likely to be understood.
The FCA has published detailed COBS rules in the PS26/13 policy statement. Ensuring that your firm meets the requirements of COBS, including in its terms of use, approach to the Duty, information provided as part of the services and general website disclosures will be a significant piece of work to be undertaken by your legal function or advisors.
Dispute resolution and access to the Financial Ombudsman Service
Authorised CASPs will need to comply with the requirements of DISP to have appropriate and effective processes in place for the prompt and fair handling of complaints. Retail customers will have access to the Financial Ombudsman Service (“FOS”) for complaints about regulated cryptoasset activities. This represents a significant practical change for firms currently operating solely under the MLR regime – customer complaints are no longer purely a commercial matter.
Concerns had been raised during the consultation process that complaints might be raised in relation to periods of market volatility and that cryptoasset firms might be held liable for the associated losses of customers. However, the FCA has stated that the FOS will consider any complaints about investment losses in the usual manner, based on the application of the fair and reasonable test, which will include considering the nature of the investment product. It is therefore likely that complaints would be upheld if the FOS finds that the cryptoasset firm had acted in a way that caused the loss to the consumer rather than as a result of poor market performance.
What firms need to do now
The requirements confirmed in PS26/13 represent the core of what the FCA will assess at the authorisation gateway in terms of ongoing Handbook compliance. Firms preparing applications need to demonstrate not just that they understand these requirements but that they have the governance, people, systems and controls in place to meet them. That means conducting honest gap analyses against each area to identify gaps for resolution. Work to close the gaps should be reflected in the application and, where gaps still remain, a credible plan to address them should be in place. The FCA’s threshold for authorisation requires firms to be ready, willing and organised, and PS26/13 defines in considerable detail what “ready” looks like. Policy and procedural documents should be developed to reflect these requirements, operationalised as far as possible, service flows and user journeys mapped out.
The application window opens on 30 September 2026. For firms that are not yet working through these requirements systematically, the time available is shorter than it might appear.




