Blog
Insights

The FCA cryptoasset regime is here: what it means for institutional blockchains

Peter Bidewell
August 14, 2026
2
min read

On 30 June 2026 the FCA published the core of its cryptoasset regime, a set of five policy statements that move digital asset activity in the United Kingdom into full authorisation under the Financial Services and Markets Act. For anyone building or relying on institutional blockchain infrastructure, this is the most consequential UK regulatory milestone of the year, and it rewards a careful read rather than a headline skim. The full package sits behind the FCA's overview of its cryptoasset regime policy statements.

The regime rests on the FSMA 2000 (Cryptoassets) Regulations 2026, which Parliament passed on 4 February 2026. The authorisation gateway opens on 30 September 2026, and the full scope of regulated activities takes effect from 25 October 2027, so firms have a defined and fairly short window to prepare. This is the moment the United Kingdom stops treating cryptoassets mainly as a financial promotions and anti-money-laundering question and starts treating them as regulated financial services, with the Consumer Duty, the senior managers regime, operational resilience, safeguarding, and a bespoke prudential framework all attached.

Key takeaways

The package is large, so it helps to isolate the points most relevant to institutional infrastructure.

  • Five policy statements, one direction. PS26/9 sets the admissions, disclosures, and market abuse regime for cryptoassets. PS26/10 covers stablecoin issuance and sits alongside a joint Bank of England publication on systemic stablecoins. PS26/11 covers the regulated activities, including custody, staking, and lending. PS26/12 sets the prudential regime through the new COREPRU and CRYPTOPRU sourcebooks. PS26/13 applies the wider FCA Handbook, with finalised guidance on the Consumer Duty (FG26/5), operational resilience (FG26/6), and international firms (FG26/7).
  • Obligations attach to identifiable, accountable actors. The regime is built around authorised firms, and for decentralised finance it attaches where there is an identifiable controlling entity, with tailored guidance and objective indicators of decentralisation still to be consulted on. The consistent principle is that where there is someone accountable, the rules apply to them.
  • Staking and custody become regulated activities. Staking now carries disclosure, consent, and record-keeping obligations, with sensible allowances for automatic staking. Custody applies the new CASS 17 safeguarding rules to client cryptoassets, using a deliberately technology-agnostic approach to private-key management, while custody of tokenised securities continues under the existing CASS 6 rules.
  • Operational resilience is the quiet centrepiece. Authorised firms must manage and evidence their dependence on the infrastructure they use, including third-party and technology risk. This is the mechanism through which a regulated firm's obligations reach the blockchains it relies on.
  • Stablecoins gain a settlement role. The Digital Securities Sandbox guidance has been updated to allow qualifying stablecoins to be used as a settlement asset, and the prudential treatment of stablecoin issuance has been eased, with the relevant capital coefficient reduced from 2% to 1%.

What still needs to be clarified

The reaction from industry has been broadly warm, and in places genuinely enthusiastic. The Payments Association welcomed the fact that the FCA had listened to feedback, singling out the decision to halve the stablecoin issuance capital coefficient from 2% to 1% as a win for proportionality and describing the wider changes as replacing rigid complexity with commercial workability (industry reaction). Law firms and payments commentators have read the package, alongside the Bank of England's stablecoin work, as the foundation of a more integrated UK digital assets and payments ecosystem. That is the right headline, and we share it.

The more useful question for anyone planning around the regime is what it does not yet settle. The FCA is candid that several components are still to come, listing decentralised finance, distributed ledger technology, cryptoasset derivatives, further stablecoin policy, audit requirements, and the saving and transitional provisions as areas to be progressed through later policy development and consultation (FCA overview). A few of these are more consequential than others for institutional infrastructure.

  • The prudential detail is not final. The capital and liquidity rules are set at the level of the policy statement, but the supporting COREPRU and CRYPTOPRU guidance remains in consultation, with feedback due by 30 July 2026, so firms cannot yet model their capital position with full confidence.
  • DeFi is deferred. The identifiable controlling entity test gives the perimeter a sensible anchor, but the FCA has said it will consult separately on DeFi guidance and on the objective indicators of decentralisation, which leaves the most contested boundary in the regime unresolved for now.
  • The stablecoin perimeter is still moving. A draft statutory instrument published in April 2026 proposes to remove UK-issued qualifying stablecoins from arranging and dealing and bring them under a future payments regime, and the Government has separately proposed folding the Payment Systems Regulator into the FCA, so the treatment of stablecoin activity could shift again before the regime goes live.
  • The compliance bar is high, and its cost is real. Alongside the welcome, firms have noted the weight of the obligations, from demonstrating redemption at par under stress, to holding capital against staking losses such as slashing, to the operational-resilience evidence expected of anyone relying on third-party infrastructure. These are reasonable requirements, but they are not cheap, and the industry will judge the regime partly on whether supervision applies them proportionately.

None of this undermines the direction, and we would rather have a regime that is open about its unfinished sections than one that pretends to completeness. The areas still open, namely DeFi, operational resilience for distributed ledgers, the financial crime guidance, and the final prudential rules, are precisely the areas that most shape infrastructure choices, which is why we will keep engaging with each consultation as it lands.

What this means for the industry, and for Rayls

The headline for the blockchain industry is that the United Kingdom now has a full authorisation regime aligned with international standards, and the competitive question shifts from whether institutions can use digital assets to which infrastructure lets them do so while staying compliant. The regime does not name validators or tell a public chain how to run its consensus. What it does, repeatedly, is concentrate accountability on identifiable, authorised entities and require regulated firms to govern the infrastructure they depend on. Read together, those two features push regulated activity towards networks whose operators are identifiable and accountable, and whose compliance controls can be supervised.

This is the environment we designed Rayls for, and it is worth being precise about how the design choices map to the guidance.

  • Identifiable, governed infrastructure. We run the Rayls Public Chain as a Layer 1 with a permissioned, identifiable validator set rather than an anonymous, permissionless one. For a regulated firm that has to evidence operational resilience and manage third-party risk, an accountable validator set is far easier to stand behind than a set of unknown participants.
  • Compliance by design. We embed compliance at the level of the network and the token, using identity-aware and permissioned token standards rather than adding checks after the fact. That maps directly to a regime which attaches obligations to identifiable controlling entities and expects compliance to be demonstrable.
  • Privacy with auditability. Rayls Enygma provides transaction privacy while preserving the auditability that supervisors and firms require. Institutions need confidentiality of commercially sensitive flows and the ability to satisfy market abuse and financial-crime obligations at the same time, and the two stop being in tension once privacy is designed for oversight rather than against it.
  • Settlement and safeguarding. With the Digital Securities Sandbox now permitting stablecoins as a settlement asset, an institutional Layer 1 that supports regulated settlement instruments and integrates institutional-grade custody fits the direction of travel rather than working around it.

We should be careful not to overstate the point, because it is stronger for being accurate. The FCA has not mandated permissioned validators, and it has not written a rule that favours one network architecture over another. What it has done is make identifiability, accountability, and operational resilience the price of admission for regulated activity, and those have been our design goals from the start. That is why the regime reads to us less like a constraint to adapt to and more like a confirmation of the approach.

The firms that settle their compliant infrastructure position before the October 2027 deadline will have a meaningful head start on those that begin once the rules bite. The regime is published, the direction is clear, and the infrastructure question is the one worth getting right.

Share this post

Subscribe to our newsletter