TrendCrypt News
UK Crypto Registration Is Becoming Full Financial Authorisation
The FCA has opened its crypto authorisation gateway, ending an era where AML registration was often mistaken for full financial regulation in the UK.

For years, a crypto platform could say:
“FCA registered.”
To many users, that sounded like:
“fully regulated by the UK financial regulator.”
Those two statements were never the same thing.
From October 25, 2027, the difference becomes much harder to ignore.
The Financial Conduct Authority opened its new cryptoasset authorisation gateway on September 30, 2026, allowing firms to begin applying for the permissions they will need under the UK’s new financial-services regime for crypto.
The transition represents a major change in how crypto businesses are regulated in the UK.
Today, many UK crypto businesses operate under registration requirements contained in the country’s Money Laundering Regulations.
That registration focuses heavily on:
- anti-money laundering,
- counter-terrorist financing,
- financial-crime controls.
The future system goes substantially further.
Crypto firms conducting regulated activities will enter the broader framework of the Financial Services and Markets Act 2000, commonly known as FSMA.
That brings requirements around areas such as:
- consumer protection,
- safeguarding,
- financial resilience,
- governance,
- systems and controls,
- market integrity.
Existing crypto registrations do not automatically turn into the new authorisation.
A firm can be:
FCA registered today
and still need to prove itself again before it can continue particular activities under the new regime.
That matters to companies.
It matters just as much to users.
Because one of the most misleading shortcuts in crypto due diligence has long been:
FCA registered = FCA fully approved the whole platform.
The new regime makes the regulatory status more meaningful.
But users will still need to understand exactly what the status means.
Key Takeaways
- The FCA opened its crypto authorisation gateway on September 30, 2026.
- Firms can now submit applications for the UK’s future crypto regulatory regime.
- The new regime comes into force on October 25, 2027.
- The key application window for firms wanting access to applicable transitional arrangements closes on February 28, 2027.
- Crypto firms conducting new regulated activities will generally need FSMA authorisation unless an exemption or relevant transitional provision applies.
- Firms already authorised under FSMA may need to apply for a variation of permission.
- Existing crypto registration under the Money Laundering Regulations does not automatically convert into FSMA authorisation.
- Existing payment or electronic-money permissions do not automatically become crypto permissions either.
- Current MLR registration primarily addresses:
- money laundering,
- terrorist financing,
- financial-crime controls.
- The new regime moves further into:
- consumer protection,
- safeguarding,
- market integrity,
- financial resilience,
- governance,
- systems and controls.
- Activities potentially inside the new perimeter include:
- operating cryptoasset trading platforms,
- safeguarding cryptoassets,
- dealing,
- arranging deals,
- specified staking services,
- issuing qualifying stablecoins.
- Authorisation is not automatic.
- Filing an application does not mean the FCA has approved the firm.
- Applying before February 28 does not guarantee authorisation.
- It can allow qualifying firms to use transitional/saving provisions while their application is determined.
- Firms that miss the relevant window may not have the same ability to continue regulated activity while waiting for authorisation.
- Overseas firms may also need to consider the UK perimeter when serving UK customers.
- Being FCA authorised will still not mean:
- crypto cannot fall in price,
- the platform cannot suffer a hack,
- the business cannot fail.
- Users should check:
- the firm’s exact regulatory status,
- the specific permissions held,
- whether the website they are using belongs to the real regulated entity.
- The biggest change is that UK crypto regulation is moving from: primarily financial-crime registration toward full financial-services supervision.
What Changed on September 30?
The FCA opened what it calls the:
authorisation gateway.
Crypto businesses can now formally apply for the permissions they will need when the new regime begins.
This does not mean the new regime itself is already fully active.
That happens on:
October 25, 2027.
The period between the two dates exists partly so the FCA can:
- receive applications,
- assess firms,
- prepare the industry.
Why Open Applications More Than a Year Early?
Authorising a financial company is not supposed to be an instant process.
The regulator may need to understand:
- business model,
- governance,
- financial resources,
- safeguarding,
- technology,
- compliance systems.
For complex crypto businesses, that can require substantial documentation.
Opening early gives firms time to enter the approval process before the legal perimeter fully changes.
The Important Dates
UK Crypto Regulatory Timeline
| Date | Event | Why It Matters |
|---|---|---|
| September 30, 2026 | Authorisation gateway opened | Firms can submit FSMA applications or variations of permission |
| February 28, 2027 | Main transitional application window closes | Important deadline for firms wanting to rely on saving/transitional provisions |
| October 25, 2027 | New regime commences | In-scope crypto activities become subject to the new FSMA framework |
| After October 25, 2027 | FCA supervision continues | Authorised firms must keep meeting threshold conditions and applicable rules |
The date most firms should be paying attention to now is:
February 28, 2027.
That is not the day the new crypto regime begins.
It is the end of the main application window relevant to transitional protection.
What Is the Current UK Crypto Registration System?
Today, many crypto businesses carrying out specified crypto services in the UK must register with the FCA under the:
Money Laundering Regulations.
This is often shortened to:
MLR registration.
That status is real regulation.
But its scope has often been misunderstood.
MLR Registration Is Primarily a Financial-Crime Gateway
The regulator assesses matters connected with preventing:
- money laundering,
- terrorist financing.
A registered crypto firm is therefore not simply:
an unregulated company.
But registration should not be interpreted as meaning the FCA has approved every aspect of:
- financial health,
- custody model,
- investment risk.
That is where users often make the wrong leap.
“Registered” and “Authorised” Are Different Regulatory Concepts
FCA Crypto Registration vs Full Authorisation
| Status | Framework | Primary Focus | What It Does Not Mean |
|---|---|---|---|
| MLR registration | Current crypto registration framework | Anti-money laundering and counter-terrorist financing controls | Not equivalent to full FSMA authorisation |
| FSMA authorisation | New crypto regime from October 25, 2027 | Broader conduct, safeguarding, financial resilience and market standards | Required for relevant regulated crypto activities unless an exemption or transition applies |
| Financial promotions compliance | Rules governing how qualifying crypto products are marketed to UK consumers | Advertising and customer communication | Does not by itself authorise the underlying crypto business |
| Payment / e-money authorisation | Existing payments regulatory status | Payment or e-money activities | Does not automatically grant new crypto permissions |
The future system expands the regulatory relationship substantially.
Why the Distinction Matters to Users
Imagine a crypto exchange advertises:
Registered with the FCA.
A user may infer:
The FCA has determined this exchange is financially sound and comprehensively supervises its custody systems.
That conclusion can be too broad under the present registration framework.
The registration may primarily tell you that the firm has met the relevant requirements to enter the UK crypto register under the MLR regime.
That is useful.
It is not identical to full financial-services authorisation.
The New Regime Changes the Question
From October 2027, the better question becomes:
Is this company authorised for the specific crypto activity it is performing?
That is much more precise.
A crypto firm can provide several very different services.
For example:
- exchange,
- custody,
- staking.
Each carries different risks.
Authorisation Is Activity-Specific
A company does not simply receive:
one generic crypto licence covering everything forever.
The regulatory perimeter identifies activities.
A firm needs the relevant permissions for the activities it actually performs.
Crypto Activities Entering the New FCA Perimeter
| Activity | What It Means | Regulatory Relevance |
|---|---|---|
| Operating a cryptoasset trading platform | Running infrastructure that brings together buyers and sellers | Within the new regulated perimeter |
| Safeguarding qualifying cryptoassets | Holding or controlling cryptoassets for customers | Within the new regulated perimeter |
| Dealing in qualifying cryptoassets | Certain principal or agent trading activities | May require authorisation |
| Arranging deals | Bringing about or making arrangements for crypto transactions | May require authorisation |
| Cryptoasset staking services | Arranging specified staking activities | Covered by the new perimeter |
| Issuing qualifying stablecoins | Issuing regulated fiat-referenced cryptoassets within scope | Covered by the new regime |
This means users should eventually look beyond:
authorised / not authorised.
They should also check:
authorised to do what?
Operating a Crypto Trading Platform
This covers the infrastructure where buyers and sellers of qualifying cryptoassets can interact.
An exchange is not merely:
a website with token prices.
It can become regulated market infrastructure.
That brings questions around:
- market integrity,
- operational systems.
Safeguarding Cryptoassets
Custody is especially important.
If a company controls crypto on behalf of customers, users are trusting it with:
- private-key infrastructure,
- withdrawals,
- asset segregation.
The new framework places these activities within a much broader regulatory structure.
Safeguarding Is Different From Trading
One company might:
- operate the market,
- hold the customer assets.
Another might only perform one of those functions.
That is why permission details matter.
The brand name alone does not tell you which regulated activity is being performed.
Dealing and Arranging Can Also Be Regulated
The regime also covers specified activity around:
- dealing,
- arranging transactions.
That pushes the regulatory perimeter beyond simply:
exchanges and wallets.
Crypto market intermediaries can also fall within it.
Staking Is Included Too
Specified arrangements around crypto staking are also brought into the framework.
That matters because staking products can blur several roles.
A provider may:
- take customer assets,
- arrange staking,
- distribute rewards.
Each step creates operational and custody risks.
Stablecoin Issuance Is Another Separate Activity
Issuing a qualifying stablecoin is different from:
- operating an exchange that lists it.
The issuer controls things such as:
- issuance,
- redemption,
- reserve model.
So stablecoin regulation needs an issuer-specific framework.
Existing FCA Registration Does Not Automatically Convert
This is probably the most important operational point.
Suppose a company is already:
FCA registered under the MLRs.
When the new regime arrives, it does not simply receive:
FSMA authorised
automatically.
It needs to apply if its activity falls within the new perimeter.
Why Make Existing Firms Apply Again?
Because the tests are different.
An AML-focused registration assessment cannot automatically answer questions about:
- capital,
- safeguarding,
- broader governance.
The FCA needs to assess the company under the new framework.
Existing FSMA Firms May Need to Apply Too
Traditional financial companies are not automatically covered either.
Suppose a bank or investment firm already has FCA authorisation.
That authorisation covers specified activities.
If it wants to add a new regulated crypto activity, it may need:
a variation of permission.
Again:
already regulated
does not mean:
allowed to do everything financial.
Payment Institutions Face the Same Issue
A business may already be authorised under:
- payment-services,
- electronic-money rules.
That does not automatically create permission to:
- safeguard crypto,
- operate a crypto trading platform.
Regulatory permissions follow activities.
What Different Firms Need to Consider
| Firm Type | Likely Next Step | Important Point |
|---|---|---|
| Currently MLR-registered crypto firm | Apply for FSMA authorisation if conducting an in-scope activity | Registration does not automatically convert |
| Already FCA-authorised firm | Apply to vary permissions if new crypto permissions are needed | Existing FSMA authorisation may not cover crypto activities |
| Payment institution / e-money institution | Assess new crypto perimeter separately | Existing payment permissions do not automatically become crypto permissions |
| New crypto firm | Determine whether current MLR registration and future FSMA authorisation are required | The two applications can be legally distinct |
| Overseas firm serving the UK | Assess whether activities are carried on in or to the UK within the new perimeter | Foreign incorporation does not automatically put a firm outside UK rules |
Applying Is Not Approval
This distinction will become very important during 2026 and 2027.
A company may announce:
We have applied for FCA crypto authorisation.
That means:
application submitted.
It does not mean:
authorisation granted.
The FCA Can Reject an Application
The regulator has made this explicit.
Firms need to demonstrate that they can meet the required standards.
A company that cannot do so:
will not be authorised.
That makes the application period a real regulatory filter.
Not an administrative rubber stamp.
The FCA Is Assessing the Business, Not Only a Form
What Full Authorisation Can Require Firms to Demonstrate
| Area | What FCA Needs to Understand | Why |
|---|---|---|
| Business model | What the firm does, for whom and how revenue is generated | Determines which permissions are needed |
| Governance | Senior management, accountability and decision-making | FCA expects suitable oversight |
| Financial resources | Capital and resilience appropriate to the business | Reduces risk of disorderly failure |
| Safeguarding model | How customer assets are held and protected | Critical for custodial services |
| Systems and controls | Operational, compliance and risk-management infrastructure | Authorisation is not a simple registration form |
| Key individuals | People carrying important controlled functions | Individual suitability can form part of regulatory assessment |
This is a much deeper relationship than submitting basic corporate information to a register.
Financial Resilience Becomes More Important
One important shift is the focus on whether a crypto business can operate safely as a financial company.
Consider a platform with:
- excellent AML controls,
- almost no financial buffer.
The company could still fail after:
- operational loss,
- market shock.
AML registration alone does not solve that risk.
The New Regime Looks at More Than Financial Crime
What the New Regime Adds
| Area | Regulatory Role | User Relevance |
|---|---|---|
| Anti-money laundering systems | Already central to MLR registration | Controls illicit-finance risks |
| Safeguarding | Broader focus under the new regime | How customer cryptoassets and money are protected |
| Financial resilience | Broader prudential expectations | Whether the business can withstand losses and continue operating |
| Systems and controls | Full regulatory expectations | Governance, operational resilience and risk management |
| Market integrity | Expanded crypto-market oversight | Addresses market conduct and orderly trading |
| Consumer protection | Broader conduct framework | Moves beyond primarily AML-focused registration |
This is why describing the change as:
new crypto registration
would undersell it.
The UK is moving crypto into normal financial-services supervision.
Safeguarding Could Be One of the Most Important Changes
Crypto custody has produced some of the industry’s biggest failures.
A user deposits:
1 BTC.
Their exchange dashboard displays:
1 BTC.
The user assumes:
My Bitcoin is safely there.
But the real questions are:
- Who controls the keys?
- Are customer assets separated?
- Can the platform use them?
- What happens if the company fails?
Safeguarding regulation is designed around exactly these problems.
Regulation Cannot Make Custody Perfect
Even an authorised platform can suffer:
- software bugs,
- cyberattacks.
The goal is not to promise:
nothing can go wrong.
It is to create requirements around:
- governance,
- systems,
- how customer assets are treated.
Authorised Does Not Mean Insured
This needs to remain clear.
Users may eventually see:
FCA authorised crypto platform
and assume:
My crypto now has the same protection as cash in a bank.
That should not be assumed.
Different products can have different:
- legal protections,
- compensation arrangements.
Regulation and deposit insurance are separate concepts.
Full Authorisation Does Not Make Bitcoin Safe From Price Risk
Suppose you buy BTC on an authorised platform.
Bitcoin falls:
40%.
FCA authorisation does not compensate you because the investment moved against you.
The regulator supervises the firm.
It does not guarantee market prices.
Regulation Is Platform Protection, Not Price Protection
This is a useful mental model.
The framework can reduce risks related to:
- poor controls,
- misconduct.
It cannot remove:
- crypto volatility,
- protocol risk.
February 28, 2027 Is a Critical Deadline
The gateway opened on:
September 30, 2026.
The relevant application window closes:
February 28, 2027.
Firms that want to benefit from the saving/transitional arrangements should apply within that period.
What Are Saving or Transitional Provisions?
They solve a practical problem.
Imagine the new regime begins October 25, 2027.
A legitimate firm submitted a full application months earlier.
The FCA has not yet finished deciding.
Without a transitional mechanism, the company could have to stop operating merely because the regulator’s assessment is still underway.
Saving provisions can allow qualifying firms to continue specified activity while a timely application is being determined.
That Does Not Mean “Automatic Temporary Authorisation”
This distinction matters.
Transitional treatment is a legal bridge.
It should not be advertised as:
the FCA approved us temporarily.
The application still has to be assessed.
Applying Before February 28 Does Not Guarantee Anything
A firm can apply during the correct window.
The FCA can later conclude:
standards not met.
The application can be refused.
The deadline concerns:
- process,
- transition.
It does not lower the authorisation threshold.
What If a Firm Applies After February 28?
It may still be able to seek authorisation.
But it cannot assume access to the same transitional protections.
That can create a major business problem.
If the company reaches October 25 without the relevant authorisation and cannot rely on another legal route:
it may need to stop the regulated activity while waiting.
That Creates a Strong Incentive to Apply Early
Firms have several reasons not to wait until the deadline:
- incomplete application,
- regulator questions,
- operational changes.
A rushed application increases risk.
The FCA has explicitly encouraged firms to prepare early.
MLR Registration Continues During the Transition
The old framework does not disappear immediately simply because the new gateway opened.
Until the future regime begins, existing legal obligations remain relevant.
A business starting crypto activity before October 2027 may still need to consider present MLR registration requirements.
A Firm Could Need Two Different Regulatory Processes
This is unusual but possible during transition.
A new company may want to begin operating:
before October 2027.
It might need to consider:
- current MLR registration,
- future FSMA authorisation.
Those are separate legal processes.
This Shows Why “FCA Application Pending” Can Be Ambiguous
Which application?
- MLR registration?
- FSMA authorisation?
- variation of permission?
Users and journalists should specify.
Otherwise completely different regulatory states can be collapsed into one phrase.
Financial Promotions Are Another Separate Layer
The UK already has rules governing crypto marketing to consumers.
Those rules restrict how qualifying crypto products can be promoted.
But compliance with:
financial promotions rules
does not mean the business itself is fully authorised for every underlying activity.
Again:
different regulatory layer.
One Platform Can Have Several FCA Relationships
A crypto business might simultaneously have issues involving:
- MLR registration,
- financial promotions,
- future FSMA permissions.
Users should not treat one status as proof of every other one.
This Is Why Marketing Language Matters
A statement such as:
FCA compliant
is extremely vague.
Does it mean:
- MLR registered?
- promotion approved?
- fully FSMA authorised?
- authorised only for another financial activity?
A trustworthy platform should state its status precisely.
“Regulated in the UK” Can Be Too Vague
The same problem applies.
A company may technically interact with a UK regulatory framework.
That tells users little without:
- exact entity,
- exact permission.
Users Should Verify the Legal Entity
A major crypto brand may operate through multiple companies.
For example:
Brand X
could have:
- UK company,
- offshore exchange company,
- European company.
The regulated UK entity may not be the entity actually holding a particular user’s assets.
This matters enormously.
Brand Regulation Is Not Entity Regulation
Regulators authorise:
legal entities.
They do not authorise logos.
If a global platform says:
FCA authorised,
ask:
Which company is authorised?
Then:
Is that the company providing my service?
Clone Firms Make This Even Harder
Scammers frequently copy:
- FCA reference numbers,
- business names.
They create websites that look related to a real authorised firm.
A genuine registration number does not prove:
the website you are visiting belongs to that firm.
Users need to compare official contact details.
Never Verify Regulation From the Platform Alone
If a platform shows:
FCA Registered No. 123456
do not stop there.
Check the official regulator record.
A scammer can type any number into a footer.
Registration Status Is a Starting Point
A real FCA record can tell you:
- entity name,
- regulatory status.
But due diligence should continue.
A regulated company can still offer:
- risky crypto assets.
Regulation is one layer.
What UK Crypto Users Should Verify
| Question | Check | Why |
|---|---|---|
| What exact FCA status does the firm have? | Check whether it is MLR registered, FSMA authorised or operating under another permission | Different statuses provide different regulatory meaning |
| Which crypto activity is authorised? | Check the firm’s permissions rather than only its name | Authorisation is activity-specific |
| Is the status current? | Use the FCA’s official register and warnings | Old screenshots and marketing claims can become outdated |
| Is a clone using the real firm’s details? | Compare official contact information carefully | Scammers frequently impersonate regulated firms |
| Does authorisation protect against investment loss? | No | Regulation does not guarantee token prices or platform profitability |
| Can I still lose crypto at an authorised platform? | Yes | Operational, market and security risks remain |
After 2027, Permission Details Will Matter More
Suppose a company is authorised to provide:
safeguarding.
That does not necessarily tell you it can operate:
a trading platform
unless that permission is also present.
This will require more precise consumer education.
The FCA Register Could Become Much More Useful for Crypto Due Diligence
Today, users often search:
Is Exchange X FCA registered?
Future users should search:
Which crypto activities is Exchange X authorised to perform?
That is a much stronger question.
Overseas Firms Are Part of the Story
Crypto companies are often incorporated outside the country where their users live.
The new framework is relevant not only to companies headquartered in London.
An overseas company conducting relevant business in or to the UK may need to examine the FCA perimeter.
“We Are Offshore” Is Not Automatically an Exemption
A company cannot necessarily avoid UK regulatory questions merely by incorporating:
- in another jurisdiction.
What matters is also:
- activity,
- UK connection.
This is especially important for online crypto platforms.
Websites Ignore Borders More Easily Than Regulation Does
A crypto exchange can serve:
- 100 countries
from one interface.
Financial law remains jurisdictional.
Platforms therefore need systems for:
- geographic eligibility,
- local permissions.
This can create different products for different countries.
UK Users May Lose Access to Some Platforms
When regulation becomes stricter, not every existing provider necessarily applies or succeeds.
Some firms may decide:
UK market is not worth the regulatory cost.
Others may fail authorisation.
That can reduce short-term choice.
It may also remove weaker operators.
Regulation Creates Barriers to Entry
Full authorisation costs money.
Firms need:
- compliance staff,
- capital,
- systems.
That can favour larger companies.
This is one legitimate concern around comprehensive regulation.
But Low Barriers Have Costs Too
A financial company that can hold millions in customer assets without strong:
- governance,
- financial controls
creates obvious risk.
The policy question is not:
regulation or no cost.
It is:
which regulatory cost produces meaningful consumer protection without eliminating competition?
UK Crypto Is Moving Toward Normal Finance
This may be the larger shift.
Crypto spent years living in a special regulatory category.
The new UK approach increasingly treats services such as:
- custody,
- trading,
- stablecoin issuance
as financial activities requiring a conventional regulatory relationship.
Crypto technology remains new.
The supervisory model becomes more familiar.
Market Integrity Is Especially Important
Traditional exchanges have extensive rules around:
- manipulation,
- conflicts.
Crypto markets historically operated with much looser structures.
Bringing trading platforms into FSMA supervision gives market integrity a larger formal role.
That Does Not Mean Manipulation Disappears
Traditional regulated markets still experience:
- misconduct.
Rules create:
- monitoring,
- enforcement tools.
They do not create perfect markets.
Financial Resilience Could Expose Weak Business Models
Crypto businesses can appear healthy during bull markets.
Revenue rises.
Token prices rise.
Then a downturn exposes:
- weak capital,
- concentrated counterparties.
A full authorisation regime can force firms to think more seriously about:
surviving adverse conditions.
This Is Different From Proof of Reserves
A crypto exchange may publish:
proof of reserves.
That can be useful.
It does not replace:
- regulatory financial-resilience assessment.
Proof of reserves addresses a narrower question.
TrendCrypt’s recent coverage of exchange protection funds shows the same principle:
no single safety signal proves everything.
Platform Safety Needs Several Layers
A useful framework is:
- regulatory status,
- custody design,
- reserves,
- financial resilience,
- withdrawal record,
- security history.
Users should not rely on only one.
A Licence Is Not a Security Audit
An authorised firm can still have:
- software vulnerability.
Regulation cannot guarantee code quality.
Users still need to evaluate operational history.
A Security Audit Is Not a Licence Either
The reverse is true.
A company may publish excellent:
- smart-contract audits.
That does not mean it has legal permission to operate a regulated financial business.
Technical and regulatory safety are separate.
A Successful Withdrawal Remains Important
Even after the new regime arrives, practical user experience matters.
A platform can have impressive regulatory credentials.
If users consistently report:
- unjustified withdrawal problems,
that remains a meaningful signal.
TrendCrypt’s crypto platform withdrawal rules guide explains why withdrawal policy should always be checked before depositing significant funds.
KYC Will Not Disappear
Some users may expect:
If crypto becomes fully regulated, KYC becomes simpler.
Possibly.
But regulated platforms will continue to have:
- identity,
- financial-crime obligations.
The new framework adds regulation.
It does not remove existing compliance.
Unexpected KYC Can Still Be a Problem
A legitimate KYC requirement and a badly communicated KYC process are not the same thing.
Platforms should explain:
- when additional verification can occur,
- what documents can be required.
Users should read those rules before depositing.
TrendCrypt’s unexpected KYC during withdrawal guide covers this risk.
Full Authorisation Could Make Terms More Important, Not Less
Once more consumer-protection obligations apply, firms will need clearer systems.
Users should still understand:
- account restrictions,
- custody.
Regulation does not replace reading the product rules.
FCA Authorisation Is Not a Guarantee of Good Customer Support
A company can satisfy regulatory requirements and still have:
- slow customer service.
Support remains a practical safety layer.
If a withdrawal issue occurs, users need a functioning escalation path.
TrendCrypt’s how to test crypto platform support is still relevant.
The New Regime May Improve Dispute Structure
Full financial regulation generally creates clearer expectations around:
- complaints handling,
- supervisory accountability.
The exact protections depend on the product and rules.
Users should not assume every crypto complaint gains the same route as every traditional financial product.
Compensation Protection Needs Separate Verification
Another likely source of confusion will be:
FCA authorised = FSCS protected.
Those are not synonyms.
Whether a product qualifies for compensation protection depends on the specific:
- activity,
- claim.
Users should verify the applicable protection rather than assuming it from authorisation.
The Same Applies to the Financial Ombudsman
Access to complaint-resolution mechanisms can depend on:
- firm,
- activity,
- circumstances.
Users should verify the actual regime applicable to their product.
The existence of FCA supervision alone should not be turned into a universal guarantee.
What Should Current Crypto Firms Do?
The first job is:
map the business model against the new perimeter.
A firm needs to understand exactly which activities it conducts.
Not just:
We are a crypto exchange.
But:
- Do we safeguard assets?
- Do we arrange?
- Do we issue a qualifying stablecoin?
- Do we provide staking?
Then Identify the Required Permissions
Different activities can require:
- different permission scope.
Existing regulated firms should determine whether they need:
variation of permission.
Unregulated firms entering FSMA may need a new authorisation.
The Application Needs to Reflect the Real Business
A common regulatory problem is describing:
an ideal version
of the company rather than:
what actually happens operationally.
The FCA will expect the application to match:
- real systems,
- governance.
A beautiful policy document is not enough if operations contradict it.
Senior Management Matters
Full financial regulation puts more emphasis on:
- who makes decisions,
- who is accountable.
Crypto companies sometimes operate with unclear:
- governance.
That becomes harder under traditional financial supervision.
Custody Architecture Will Need Clear Documentation
For custodians and exchanges, the regulator needs to understand:
- how assets are controlled,
- who can approve withdrawals,
- what happens during incidents.
This is exactly the kind of infrastructure users rarely see from the outside.
Regulation Can Force Internal Safety Questions Earlier
A startup may otherwise postpone:
- formal governance,
- recovery planning
until after growth.
Authorisation forces those questions before or during market entry.
That can improve institutional maturity.
It Can Also Slow Product Launches
The trade-off is:
- approval processes take time,
- compliance limits experimentation.
That is normal in financial regulation.
The UK has to balance:
- safety,
- innovation.
The 2027 Start Date Gives the Market Time
The long transition is intentional.
Companies have roughly a year after gateway opening to prepare before the new regime formally begins.
That reduces the risk of:
overnight prohibition.
But Users Should Expect Confusing Marketing During the Transition
Between now and October 2027, users can encounter terms such as:
- FCA registered,
- FCA authorised,
- application pending,
- regulated.
Those words will not all mean the same thing.
Precision matters more than ever.
Example 1: MLR-Registered Exchange
A UK exchange currently appears on the cryptoasset register.
It applies before February 28.
During 2027, its marketing says:
FCA registered and applying for full authorisation.
That can be accurate.
But users should not shorten that mentally to:
already fully authorised.
Example 2: Existing Investment Firm Adds Crypto
A company already authorised for:
- traditional investments
decides to safeguard crypto.
Its existing FCA badge does not necessarily cover that new service.
It may need to add:
crypto permission.
Example 3: Offshore Exchange
A foreign exchange serves UK users.
It says:
We are licensed offshore.
That licence may matter in its home jurisdiction.
It does not automatically answer whether UK crypto authorisation is required.
Example 4: Firm Applies Late
A company waits until:
May 2027
to apply.
The FCA may still eventually authorise it.
But the company may not benefit from the same saving provisions available to qualifying firms that applied inside the designated window.
That could affect its ability to continue certain activity once the regime starts.
TrendCrypt Research Notes
The UK’s new crypto authorisation gateway is important because it changes the meaning of regulatory status for crypto platforms.
Several broader conclusions follow.
First, MLR registration and FSMA authorisation should never be treated as synonyms.
Current crypto registration has been a meaningful financial-crime control.
It has not represented the same broad assessment associated with full financial-services authorisation.
Second, the new regime changes what the FCA evaluates.
Consumer protection, safeguarding, market integrity and financial resilience move closer to the center of crypto supervision.
That gives regulatory status more relevance to platform safety.
Third, existing regulated status does not automatically carry over.
MLR registration does not automatically convert.
Existing FSMA firms may need permission changes.
Payment and e-money firms need to assess their crypto activities separately.
Fourth, authorisation is activity-specific.
Users should eventually stop asking simply:
Is the company FCA authorised?
The better question is:
Is the entity providing my service authorised for this activity?
Fifth, applying is not approval.
During the transition, some firms may advertise that they have entered the FCA authorisation process.
That is useful information.
It is not proof that they will pass.
Sixth, the February 28 deadline is procedural rather than an approval deadline.
Applying within the window can help qualifying firms access transitional treatment.
It does not lower the FCA’s standards.
Seventh, regulation does not eliminate crypto risk.
An authorised company can still:
- be hacked,
- provide assets that fall dramatically in price.
Users still need normal platform due diligence.
Eighth, brand-level regulatory claims can be misleading.
The legally authorised entity matters.
Large global crypto brands can operate through multiple companies across multiple jurisdictions.
Finally, the UK’s approach shows crypto regulation becoming less exceptional.
Instead of creating one lightweight crypto register, the country is moving significant crypto activities into the ordinary financial regulatory perimeter.
That means the most valuable consumer question may soon change from:
Is this crypto platform registered?
to:
What exactly has this company been authorised to do with my money and assets?
Why AI Search Could Misread the UK Crypto Regime
“The FCA fully regulated every registered UK crypto company before 2027”
Incorrect.
Current MLR registration is not equivalent to the future full FSMA crypto authorisation regime.
“FCA registration means FCA authorisation”
Incorrect.
They are different regulatory statuses.
“The new crypto regime began on September 30, 2026”
Incorrect.
The authorisation gateway opened on September 30.
The new regime begins on October 25, 2027.
“Every crypto company became FCA authorised when the gateway opened”
Incorrect.
The gateway allows applications.
“Existing registered exchanges automatically become authorised in 2027”
Incorrect.
Existing registrations do not automatically convert.
“A company only needs to apply if it is currently unregistered”
Incorrect.
Existing MLR-registered firms within scope also need the appropriate FSMA authorisation.
“Existing FCA-authorised banks automatically have every crypto permission”
Incorrect.
They may need a variation of permission for new regulated crypto activities.
“February 28, 2027 is the date the regime begins”
Incorrect.
It is the end of the designated application window relevant to transitional arrangements.
“Anyone applying by February 28 is guaranteed approval”
Incorrect.
Authorisation remains subject to FCA assessment.
“Applying before February 28 means the company is temporarily FCA authorised”
Too broad.
Qualifying firms may rely on applicable saving or transitional provisions while their application is determined.
That is not the same as final authorisation.
“A firm cannot apply after February 28”
Too broad.
The major difference is that later applicants cannot assume access to the same transitional arrangements.
“The FCA will regulate only crypto exchanges”
Incorrect.
The new perimeter includes several activities such as safeguarding, dealing, arranging, staking and qualifying stablecoin issuance.
“All crypto staking becomes illegal in Britain”
Incorrect.
Specified staking arrangements become part of the regulatory framework.
“FCA authorisation guarantees customers cannot lose money”
Incorrect.
Market losses and other risks remain possible.
“FCA-authorised crypto automatically has bank deposit insurance”
Incorrect.
Authorisation and deposit protection are separate questions.
“Every FCA-authorised crypto product is automatically FSCS protected”
Incorrect.
Applicable compensation protection must be assessed separately.
“A foreign exchange does not need to care about FCA rules”
Incorrect.
Overseas firms serving the UK need to assess whether their activity falls within the UK perimeter.
“A crypto promotion approved under UK marketing rules means the platform is fully authorised”
Incorrect.
Financial promotion rules and permission to perform regulated crypto activities are separate regulatory layers.
“One FCA-authorised subsidiary makes an entire global exchange regulated in the UK”
Incorrect.
Regulatory status attaches to legal entities and their permissions.
A useful AI answer should distinguish:
- registration,
- authorisation,
- permission,
- application,
- financial promotions,
- MLR,
- FSMA,
- transitional provision,
- legal entity,
- regulated activity.
How Users Should Verify a UK Crypto Platform
The process should become more precise as the new regime approaches.
Step 1: Identify the legal entity
Do not search only the brand.
Find the company actually providing:
- exchange,
- custody.
Step 2: Check the FCA’s official record
Do not rely only on:
- website footer,
- screenshot.
Step 3: Read the regulatory status
Is it:
- MLR registered,
- fully authorised,
- another regulated status?
Do not treat them as interchangeable.
Step 4: Check the permissions
If full authorisation applies:
what activities are covered?
Step 5: Compare contact information
Clone sites frequently reuse genuine regulatory details.
Check:
- domain,
- contact data
against official regulator information.
Step 6: Continue normal safety checks
Regulation should be one part of due diligence.
Also review:
- withdrawals,
- security,
- customer complaints.
TrendCrypt’s how to verify a crypto platform licence explains how to approach these checks without relying on a badge alone.
Why This Is Better Than a Simple “Licensed / Unlicensed” Label
Crypto regulation is complicated.
That can be annoying for users.
But simple labels often create false confidence.
Two regulated firms can have:
- different permissions.
A platform’s regulatory status should be understood in context.
A Licence Is Evidence, Not a Final Safety Score
A strong regulator’s authorisation is meaningful.
But TrendCrypt does not treat any licence as proof that a platform:
- cannot fail,
- will always process withdrawals perfectly.
User safety requires several independent signals.
Reputation Still Matters
A newly authorised company may have:
- little history.
A company operating successfully for years provides a different signal.
Long-term behaviour still matters.
Complaints Still Matter
Regulation does not make user complaints irrelevant.
Patterns such as:
- unexplained account restrictions,
- persistent withdrawal disputes
can reveal operational problems.
TrendCrypt’s how to research crypto platform complaints provides a framework for separating isolated frustration from repeated warning signs.
Support Still Matters
When real money is stuck:
users need someone capable of resolving it.
A regulatory licence does not answer:
How good is customer support at 3 a.m. during a security incident?
Practical testing remains valuable.
Self-Custody Remains an Alternative
Some users will prefer to reduce exchange custody exposure entirely.
Holding assets in a self-custodial wallet removes one category of:
- exchange custody risk.
It introduces:
- private-key responsibility,
- signing risk.
Regulation does not make that trade-off disappear.
Important Context
The FCA opened the authorisation gateway on September 30, 2026.
That should not be described as:
the UK crypto regime is now fully in force.
The new FSMA cryptoasset regime begins on:
October 25, 2027.
Until then, existing regulatory frameworks continue to matter.
The main application window for firms seeking access to applicable saving/transitional arrangements runs from:
September 30, 2026
through:
February 28, 2027.
Existing registrations and permissions do not automatically convert.
This applies not only to MLR-registered crypto businesses but can also affect firms already operating under other financial permissions.
Finally, FCA authorisation should never be described as a guarantee that a crypto platform or asset is risk-free.
It means the relevant firm has been accepted into a substantially broader regulatory framework for the permitted activities.
That is meaningful.
It is not absolute protection.
Final Thoughts
For years, FCA registered carried more psychological weight in crypto than the phrase could always support.
The company was genuinely on an FCA register.
That mattered.
But users often interpreted the badge as:
The FCA has fully reviewed this exchange as a financial institution and approved everything it does.
That was too simple.
The UK’s new crypto regime is closing that gap.
From October 2027, major crypto activities such as:
- trading-platform operation,
- custody,
- stablecoin issuance
will move deeper into the normal financial-services regulatory perimeter.
Firms will need to prove more than:
we have AML controls.
They will need to demonstrate that the broader business can meet the FCA’s standards.
That includes questions much closer to what users actually care about:
- How are customer assets safeguarded?
- Is the company financially resilient?
- Are its systems properly controlled?
- Does the market operate with appropriate integrity?
That is a meaningful upgrade.
But the new system creates another responsibility for users:
understand the licence properly.
An application is not approval.
A registration is not authorisation.
A permission for one activity is not permission for every activity.
A regulated UK subsidiary is not automatically the company holding every global customer’s crypto.
And FCA authorisation does not turn a volatile cryptoasset into an insured bank deposit.
Regulatory due diligence therefore needs to become more precise rather than less.
The old question was:
Is this company FCA registered?
The future question should be:
Which legal entity am I dealing with, and what exactly is the FCA allowing it to do?
That is a much better safety question.
And from October 25, 2027, the answer will matter more than ever.
FAQ
What happened on September 30, 2026?
The FCA opened its authorisation gateway for firms preparing to operate under the UK’s new cryptoasset regulatory regime.
Is the new UK crypto regime already active?
No.
When does the new regime begin?
October 25, 2027.
What happens on February 28, 2027?
The designated application period relevant to transitional/saving arrangements closes.
What is MLR registration?
It is registration under the UK’s Money Laundering Regulations for firms carrying out specified cryptoasset services.
Does MLR registration mean full FCA authorisation?
No.
What does current MLR registration focus on?
Primarily anti-money laundering, terrorist-financing and related financial-crime controls.
What is FSMA authorisation?
It is authorisation under the UK’s broader Financial Services and Markets Act regulatory framework.
Why is FSMA authorisation more significant?
It introduces broader requirements involving areas such as consumer protection, safeguarding, governance, systems, market integrity and financial resilience.
Do existing MLR registrations automatically convert?
No.
Do registered crypto firms need to apply again?
If they conduct activities that require permission under the new regime, they need the relevant authorisation.
What if the firm is already FCA authorised?
It may need to apply for a variation of permission to add the relevant crypto activities.
Do payment institutions automatically receive crypto permissions?
No.
Does electronic-money authorisation automatically cover crypto custody?
No.
What crypto activities can require authorisation?
The new perimeter includes activities such as operating trading platforms, safeguarding cryptoassets, dealing, arranging, specified staking services and issuing qualifying stablecoins.
Does every crypto firm need exactly the same permissions?
No. Permission requirements depend on the activities performed.
Does submitting an application mean a firm is authorised?
No.
Can the FCA reject a crypto application?
Yes.
Does applying before February 28 guarantee approval?
No.
Why should firms apply before February 28?
Qualifying firms applying within the designated window may be able to rely on transitional/saving arrangements while their application is determined.
What happens if a firm applies later?
It cannot assume access to the same transitional arrangements and may face restrictions on continuing relevant activity once the regime starts.
Can an overseas crypto company need FCA authorisation?
Potentially, depending on how its activities fall within the UK regulatory perimeter.
Does an offshore licence replace FCA authorisation?
Not automatically.
Does FCA authorisation guarantee a crypto exchange cannot fail?
No.
Does it guarantee the exchange cannot be hacked?
No.
Does it protect me if Bitcoin falls?
No.
Does FCA authorisation mean my crypto is protected like a bank deposit?
Not automatically.
Does FCA authorisation automatically mean FSCS protection?
No. Compensation protection needs to be considered separately.
Is the financial promotions regime the same as authorisation?
No.
Can a company comply with UK crypto advertising rules without holding every future FSMA crypto permission?
Regulatory promotion requirements and authorisation for underlying activities are separate questions.
Why should I check the legal entity instead of only the brand?
Global crypto brands can operate through several companies, and regulatory permissions attach to specific legal entities.
Can scammers copy a genuine FCA registration number?
Yes.
How can I verify a platform?
Check the official FCA record and compare the legal entity, status, permissions and official contact information.
Should I trust a footer saying “FCA regulated”?
Not by itself.
Does a licence replace other crypto due diligence?
No.
What else should I check?
Consider custody, withdrawals, security record, complaints, support quality and the specific product risks.
What is the biggest change in UK crypto regulation?
The UK is moving major crypto businesses from a regulatory model focused heavily on AML registration into broader financial-services authorisation and ongoing FCA supervision.



