• Oct 01, 2026
  • 9 min read

How UK Crypto Regulations Work: FCA Rules Explained for 2026 

2026 guide to UK crypto regulations: FCA rules, AML/KYC duties, and how crypto firms stay compliant with the new FCA regime.

After several years of discussion papers and draft rules, the UK government and regulators have now finalized clear, comprehensive regulation of cryptoassets in the UK. 

The Financial Conduct Authority (FCA) published its final rules and guidance for the new UK cryptoasset regime on June 30, 2026. This follows on the heels of the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026, which were made on February 4, 2026. Several supporting regulations and policies also shape the new UK crypto regime.

With around 8% of UK adults owning cryptoassets, the potential market for crypto businesses is already substantial. Interestingly, 1 in 4 UK crypto users say they would be more likely to invest if the sector were more regulated, suggesting the incoming regime could boost consumer confidence and create new opportunities for crypto firms.

However, to take advantage of those opportunities, businesses will need to comply with the new rules, including authorization requirements. Penalties for non-compliance can be severe: restrictions on or loss of registration or authorization, financial penalties, and prison sentences.

Below, we explain how crypto is regulated in the UK, what changed in 2026, and what firms need to do to stay compliant.

Who regulates crypto in the UK?

The Financial Conduct Authority (FCA) is the UK's main crypto regulator. It requires crypto firms to have effective anti-money laundering and counter-terrorist financing (AML/CTF) controls and to follow strict UK rules on advertising and promotions.

The FCA maintains a register of crypto firms that fall under UK money laundering regulations (MLR 2017 with amendments) and issues guidelines.

Other UK institutions that regulate crypto include:

  • HM Treasury designs the underlying legislative framework and decides, under the Banking Act 2009, whether a payment system or service provider, such as a stablecoin issuer, should be recognized as systemic (i.e., whether deficiencies or disruption would be likely to threaten the stability of, or confidence in, the UK financial system, or seriously affect UK businesses).
  • The Bank of England will regulate systemic stablecoin issuers jointly with the FCA. On June 30, 2026, the two regulators published a joint paper explaining how they will supervise systemic issuers together, with the Bank handling prudential and financial-stability oversight and the FCA covering conduct and consumer protection.

Key UK crypto regulations

Crypto companies in the UK must comply with the following where applicable:

Which crypto businesses are affected?

Under the current MLR regime, two categories of firms must register with the FCA: 

  • cryptoasset exchange providers (roughly equivalent to cryptoasset service providers, or CASPs, in EU terms) – businesses exchanging crypto for fiat, crypto for crypto, or operating crypto ATMs
  • custodian wallet providers – firms safeguarding cryptoassets or private keys for customers

However, the new Cryptoassets Regulations will bring a far broader range of businesses under crypto regulation in the UK. These include firms:

  • Operating a qualifying cryptoasset trading platform (QCATP)
  • Dealing in qualifying cryptoassets as principal or agent
  • Arranging deals in qualifying cryptoassets
  • Safeguarding qualifying cryptoassets or "relevant specified investment cryptoassets"
  • Arranging qualifying cryptoasset lending, borrowing, or staking
  • Issuing qualifying stablecoins in the UK

This change affects exchanges, custodians, brokers, staking-as-a-service providers, DeFi services with an identifiable controlling entity, and stablecoin issuers. It applies both to firms headquartered in the UK and overseas firms serving UK consumers directly.

Suggested challenge: Crypto Crossword: Decrypt & Win!

Who needs to register with the FCA? 

Currently, under the MLR 2017, any business acting as a cryptoasset exchange provider or custodian wallet provider in the UK must register with the Financial Conduct Authority before starting operations. Additionally, under the financial promotions regime, any firm that communicates crypto marketing to UK consumers must be authorized by the FCA, registered under the MLR 2017, or use one of the FCA's approved routes, even if it has no other UK presence.

Under the Cryptoassets Regulations, firms carrying out any of the newly regulated activities described above will need FSMA Part 4A authorization (or a variation of existing permission) once the regime takes effect on October 25, 2027. Existing MLR registrations will not convert automatically.

FCA registration and authorization process for crypto firms

There are two routes to FCA approval: MLR registration and FSMA authorization, depending on timing and the activities a business will conduct.

Until October 25, 2027, firms providing cryptoasset exchange or custody services must register with the FCA under the MLR 2017 and demonstrate adequate AML/CTF controls before the FCA approves the application. From that date, firms carrying on the newly regulated activities need FSMA authorization instead.

For authorization under the Cryptoassets Regulations, the process is as follows:

  • Firms can apply for FCA authorization since September 30, 2026.
  • Firms that apply by February 28, 2027, benefit from a "saving provision" allowing them to continue their existing activities for up to two years if their application is still being determined when the regime goes live on October 25, 2027.
  • Firms that apply after the window closes (but before go-live), or whose applications are refused or withdrawn, can at most run off existing contracts under a separate transitional provision.

Applicants will need to meet FSMA's Threshold Conditions, identify individuals for Senior Managers and Certification Regime (SM&CR) roles, and show they can meet capital and liquidity requirements under the prudential rules in PS26/12. 

The FCA explains how the authorization gateway will operate and how MLR registration works during the transition.

AML/KYC requirements for crypto firms

To stay compliant with the AML requirements of the MLRs and related UK legislation, companies have to implement a clear set of procedures. This includes at least the following:

When carrying out KYC checks at onboarding, firms should collect at least each user's full name, date of birth, and address, according to guidance from the Joint Money Laundering Steering Group.

Firms usually verify this information against government-issued documents or reliable, independent electronic sources. Acceptable proof of address includes utility bills and current bank or credit/debit card statements from a regulated UK financial firm.

UK crypto Travel Rule

Like many other jurisdictions, the UK applies the Financial Action Task Force (FATF) Travel Rule to cryptoasset businesses. The Travel Rule requires crypto companies to collect information on the originator and beneficiary of a cryptoasset transfer and share it with the counterparty cryptoasset business. 

Suggested read: Crypto Travel Rule Explained: FATF Requirements for VASPs

Part 7A of the MLRs, inserted by the Money Laundering and Terrorist Financing (Amendment) (No. 2) Regulations 2022, sets out the specifics of the Travel Rule in the UK. It does not specify a de minimis threshold, meaning certain information must be transferred regardless of the transaction amount. 

Additional originator information must accompany cross-border transfers of £800 or more; where every business in the chain, including any intermediary, carries on business in the UK in respect of the transfer, it must be provided on request.

As a rule, cryptoasset exchange providers and custodian wallet providers (‘cryptoasset businesses’) in the UK have to take the following steps to comply with the Travel Rule:

1) For transfers between two cryptoasset businesses, the originating business must ensure, before making the transfer, that it is accompanied by the following information: 

  1. the names of the originator and the beneficiary
  2. if the originator or beneficiary is a firm, the registered name of the originator or beneficiary (as the case may be), or, if there is no registered name, the trading name
  3. the account number of the originator and the beneficiary, or, if there is no account number, the unique transaction identifier

2) The beneficiary cryptoasset business must check that the required information has been received before making the cryptoasset available, and report to the FCA any counterparties that repeatedly fail to provide it.

How Sumsub simplifies Travel Rule compliance

Manually collecting, verifying, and exchanging originator and beneficiary data across multiple counterparties is one of the most operationally demanding parts of UK crypto compliance. Sumsub's Travel Rule Solution automates this exchange between cryptoasset businesses, screens counterparties, and helps firms detect and resolve missing or mismatched data before funds are released, reducing manual back-and-forth and transaction drop-offs.

It works with Sumsub's identity verification and transaction monitoring tools, so crypto firms can manage Travel Rule data in the same place as their KYC checks and AML processes. Compliance teams work in one system instead of switching between several.

The new UK cryptoasset regime: What changed in 2026

2026 has brought significant changes to the UK’s FCA cryptoasset regime:

  • February 4, 2026 – The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 were made, bringing a broad range of cryptoasset activities within the FCA's authorization regime.
  • June 30, 2026 – The FCA published five final policy statements:
    • PS26/9 (Admissions & Disclosures and the Market Abuse Regime for Cryptoassets, or MARC) 
    • PS26/10 (stablecoin issuance)
    • PS26/11 (regulated cryptoasset activities, covering trading platforms, intermediaries, custody, lending, staking, and DeFi)
    • PS26/12 (the prudential regime)
    • PS26/13 (application of the wider FCA Handbook, including the Consumer Duty and operational resilience)
  • September 30, 2026 – The FCA’s authorization gateway opened for firms wishing to carry out regulated cryptoasset activities.

The new regime will take full effect from October 25, 2027.

UK stablecoin rules and the Bank of England's role

Under the new regime, stablecoin regulation in the UK will be split between the FCA and the Bank of England as follows:

Non-systemic UK stablecoin issuance, custody, and admission to trading will be regulated solely by the FCA, with issuer rules in PS26/10, custody rules in PS26/11, and admission rules in PS26/9. Requirements include full reserve backing, redemption at par, and restrictions on paying interest to coin-holders, supporting stablecoin use as money-like instruments.

Systemic stablecoins (i.e., those HM Treasury recognizes as systemic under the Banking Act 2009) will be jointly regulated by the Bank of England and the FCA.

On June 22, 2026, the Bank published a policy statement and draft Code of Practice for sterling-denominated systemic stablecoins. This includes a temporary issuance guardrail of £40 billion per product, permission for issuers to hold up to 70% of backing assets in short-term UK government debt (with the remainder in unremunerated accounts at the Bank of England), and a ban on paying coin-holders interest.

Suggested read: Global Stablecoin Compliance: GENIUS Act, MiCA, Hong Kong, Singapore, and More Key Rules

Market abuse and disclosure rules for cryptoassets

For the first time, the UK is introducing a dedicated Market Abuse Regime for Cryptoassets (MARC). Created by the Cryptoassets Regulations, with FCA rules in PS26/9, it sits alongside a new Admissions and Disclosures (A&D) regime. The goal is to raise the quality of information available to investors and tackle manipulation through UK trading platforms.

Under the A&D regime, UK QCATPs act as gatekeepers. They decide which tokens can be admitted to trading and, for tokens accessible to retail investors, must ensure a Qualifying Cryptoasset Disclosure Document has been published. Ongoing disclosure obligations then apply after admission."

Meanwhile, MARC prohibits insider dealing, unlawful disclosure of inside information, and market manipulation involving qualifying cryptoassets. It also imposes systems-and-controls obligations on QCATPs and intermediaries, with heightened requirements, such as on-chain monitoring and cross-platform information sharing, for larger platforms.

The FCA has also consulted on extending its penalty framework (the Decision Procedure and Penalties Manual, or DEPP) to cryptoasset market abuse. This would align MARC penalties with those applicable to traditional markets.

Classifying the legal status of cryptoassets has long been a challenge. They do not easily fit into either of the two traditional categories of personal property, i.e., ‘things in possession’ (physical, tangible objects) or ‘things in action’ (rights enforceable through litigation, like a debt). 

However, this issue has now been clarified. Following a 2023 final report from the Law Commission, the Property (Digital Assets etc) Act 2025 became law on December 2, 2025, and took effect immediately. The Act confirms that something can be the object of personal property rights even if it doesn't fall into either traditional category, including if it is digital or electronic in nature. This effectively creates a third category of personal property, leaving courts to decide which digital assets fall within it.

The Act extends to England, Wales, and Northern Ireland, while Scotland addresses the issue with its own Digital Assets (Scotland) Act 2026.

Penalties for non-compliance with UK crypto rules

Non-compliance with UK crypto rules carries both criminal and civil consequences, and the FCA has been increasingly active in enforcing them.

Promoting cryptoassets to UK consumers without using one of the FCA's approved routes breaches the restriction in section 21 of FSMA 2000 and is a criminal offense under section 25. It is punishable by up to two years' imprisonment, an unlimited fine, or both. 

Once MARC takes effect, cryptoasset firms and individuals will face the same category of market abuse penalties currently used in securities markets.

There are also strict penalties for failure to comply with AML and KYC requirements (e.g., identity verification and sanctions screening) and for failing to submit Suspicious Activity Reports to the National Crime Agency when required. 

Compliance breaches can lead to unlimited fines for businesses and up to 2 years’ imprisonment for those involved under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017.

UK crypto regulation in 2027 – Sumsub’s vision

By October 2027, the UK will have moved from a patchwork of AML registration and financial promotions rules to a full-scope, activity-based authorization regime covering trading, custody, staking, and stablecoin issuance, with specific rules for crypto lending and borrowing and a dedicated market abuse regime. This will arguably be one of the most comprehensive crypto frameworks among major international financial centers.

We expect the next 12 months to bring further detail rather than a change of direction. This could involve additional FCA consultations on DeFi, the failure of cryptoasset firms and financial crime guidance, a finalized Bank of England Code of Practice for systemic stablecoins, and continued work on tokenized funds.

For compliance teams, the direction of travel is clear. They will need to prioritize identity verification, transaction monitoring, and Travel Rule compliance to achieve and maintain authorization. 

Sumsub expects increased demand for integrated AML, KYC, and Travel Rule infrastructure as firms prepare evidence for FCA authorization ahead of the February 2027 saving provision deadline.

UK crypto regulations FAQ

  • Is crypto legal in the UK?

    Cryptocurrency is legal in the UK, but it is not legal tender. Anyone can buy cryptoassets and store them in digital wallets.

  • Is cryptocurrency regulated in the UK?

    Yes, and regulation is expanding. Today, cryptoasset exchange providers and custodian wallet providers must register with the FCA under the Money Laundering Regulations 2017, and firms marketing crypto to UK consumers must comply with the financial promotions regime. From October 25, 2027, a broader set of activities (operating trading platforms, dealing, arranging, custody, staking, and stablecoin issuance) will require full FCA authorization under FSMA, with systemic stablecoins jointly overseen by the Bank of England.

  • How do you use identity verification in business?

    For businesses subject to AML regulations, identity verification is a legal requirement under customer due diligence. For businesses not subject to AML requirements, identity verification isn't generally mandatory, but it can be good practice to reduce fraud, build trust, and understand who they are doing business with. Regardless of the regulatory requirement, businesses can lose customers during onboarding if applicants are overwhelmed by the number of documents and details they’re asked to provide. That’s why it’s important to design a user journey that requests information step by step, rather than all at once, while completing the necessary checks before the business relationship begins.

  • How is the FATF Travel Rule applied in the UK?

    The UK applies the FATF Travel Rule (Recommendation 16) through Part 7A of the Money Laundering Regulations 2017. There is no de minimis threshold for domestic transfers, so every transfer must include basic originator and beneficiary information, regardless of value. For cross-border transfers of £800 or more, additional originator information requirements are triggered. Beneficiary firms must check received information, verify beneficiary details against their own CDD records, and report repeated non-compliance by counterparties to the FCA.

  • What is the FATF Travel Rule threshold for transfer of personal data?

    FATF Recommendations allow jurisdictions to set a de minimis threshold of up to USD/EUR 1,000, below which a reduced data set applies (names plus wallet addresses or unique transaction reference numbers). Jurisdictions may set a lower threshold or forgo one altogether. For example, the UK has no de minimis threshold. Additional originator information is required for cross-border transfers of £800 or more.

  • What is the FCA cryptoasset regime?

    The FCA cryptoasset regime is the new framework created by the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026. It brings trading platforms, intermediaries, custodians, stablecoin issuers, and lending/staking providers within the FCA's regulatory scope, with specific rules for crypto lending and borrowing. The regime introduces authorization requirements, prudential capital standards, a market abuse regime (MARC), admissions and disclosure standards, and applies the Consumer Duty to cryptoasset firms. The regime will take full effect on October 25, 2027.