Introduction

Written for the person who now has to build a plan, not just understand the regime

Part 1 covered what counts as a cryptoasset, why owning and dealing are different questions, and why two regulatory regimes are live at once. That's the map. This part is the route, what's actually happening, in what order, and what a firm operating in this space needs to be doing right now, not eventually.

Two things have happened very recently that change the practical answer to "what do I do". On 30 June 2026, the FCA published its final rules and guidance for the new regime. And on 3 June 2026, the FCA published direct responses to firms' questions on exactly the interaction this guide is about, MLR registration versus FSMA authorisation.

๐Ÿ’ก
This reflects the settled position, not the earlier version of the timeline
Both the final rules (30 June 2026) and the FCA's direct responses on MLR versus FSMA (3 June 2026) landed within the last few weeks. If you read guidance on this topic from earlier in the year, treat it as superseded, the practical answer has moved.
Section 01

The timeline that actually matters

  • Now (from July 2026): The FCA's Pre-Application Support Service is open. Firms preparing for authorisation can engage directly with the FCA ahead of the formal window.
  • 30 September 2026: The FSMA cryptoasset authorisation gateway opens. This is when firms can formally submit applications.
  • 28 February 2027: The application window closes.
  • 25 October 2027: The new regime commences. From this date, cryptoasset activities move fully under FSMA authorisation.

The FCA has been explicit that applying inside the window matters. Submit during the application period and the FCA expects to determine the application before the regime commences. Miss it, and a saving provision allows continued operation while the application is pending, but that's a position of ongoing regulatory uncertainty, not a comfortable one to be running a business from.

Section 02

The fact that changes everything for MLR-registered firms

There is no automatic conversion from MLR registration to FSMA authorisation. The FCA has stated this plainly and repeatedly. A firm currently registered under the Money Laundering Regulations, and compliant, and operating without issue, does not carry that status forward. It has to apply for FSMA authorisation as a genuinely new process.

There is no automatic conversion from MLR registration to FSMA authorisation.

The FCA's own steer, published 3 June 2026, goes further: new firms are encouraged to focus on securing FSMA authorisation directly, rather than pursuing MLR registration in the meantime. If your firm is only now entering this space, MLR registration is increasingly a detour, not a stepping stone, given the transition already underway. Firms that still want to apply for MLR registration after 30 September 2026 are directed to contact the FCA's Pre-Application Support Service first to explain the rationale, that's not a formality, it's the FCA asking firms to justify why they're pursuing a route the regulator has already signalled is being phased out.

Section 03

What "good" actually looks like to the FCA

The FCA has set out, specifically, what separates a strong FSMA cryptoasset application from a weak one. This isn't generic authorisation guidance, it's stated in relation to this exact regime.

A financial crime assessment broader than MLR registration currently requires

Firms should expect the authorisation process to examine governance, systems and controls, resourcing, and overall readiness, not just whether AML policies exist on paper. Innovative or "pure on-chain" business models are expected to demonstrate a risk-based approach calibrated to their actual transaction flows, not a template lifted from a traditional payments firm.

Explicit governance and MLRO competency expectations

The FCA has directly referenced SYSC 3, its senior management arrangements, systems and controls sourcebook, in relation to crypto authorisation. Individuals in key AML roles, including the MLRO, need to be competent and appropriately experienced for the specific activities and risks the firm is running, with genuinely sufficient time and resource to do the job. If Part 1 of the MLRO Handbook sounded familiar reading this, that's not a coincidence, the same fit and proper bar that applies to any FCA authorised firm applies here, with crypto specific risk layered on top.

Travel Rule obligations continue to run alongside FSMA, not instead of it

The Travel Rule sits within the MLRs and operates concurrently with the new regime. Firms shouldn't assume that FSMA authorisation replaces MLR obligations wholesale, applicability is assessed firm by firm, based on the actual business and operating model.

Sanctions and fraud controls sit inside the same picture, not beside it

The FCA has been explicit that it expects AML, counter-terrorist financing, and counter-proliferation financing controls to be considered alongside sanctions and fraud risk, reflected end to end in governance, risk assessment, monitoring, and escalation, not run as separate, disconnected workstreams.

Existing
MLR Registration Expectations
+
  • Anti-money laundering and counter terrorist financing supervision only
  • Business wide risk assessment, CDD and EDD as currently required
  • In force and ongoing since 10 January 2020
  • Does not, on its own, satisfy the new authorisation bar
Legal source: Money Laundering Regulations 2017
New, broader
FSMA Authorisation Expectations
+
  • Full financial crime assessment: governance, systems and controls, resourcing, and readiness, not just policies on paper
  • Explicit SYSC 3 governance and MLRO competency, with sufficient time and experience for the firm's actual risk
  • Risk based approach calibrated to actual transaction flows, not a template from traditional payments
  • AML, CTF, CPF, sanctions, and fraud controls reflected end to end, not run as separate workstreams
Legal source: FSMA 2000 (Cryptoassets) Regulations 2026; SYSC 3
Put it into practice
Screen a director or beneficial owner name during your authorisation prep
Free, no login. Check sanctions and PEP exposure before it surfaces in the FCA's own review.
Screen a name โ†’
Section 04

A practical starting checklist

For a firm currently MLR registered, or actively preparing to enter the UK cryptoasset market, five things worth actioning now rather than in Q1 2027:

  1. Revisit your perimeter assessment. Not every MLR registered firm will be carrying out a regulated activity under the new framework, and some firms currently outside scope may find they're inside it. Don't assume last year's analysis still holds.
  2. Engage the Pre-Application Support Service early. It's open now. Early engagement, gap analysis, and operational planning are explicitly what the FCA has said it wants to see, not a completed application arriving cold.
  3. Stress test governance against SYSC 3, specifically for crypto risk. A generic AML governance structure inherited from a different regulated activity won't automatically satisfy this bar.
  4. Confirm your MLRO, or whoever will hold the equivalent function, genuinely has crypto specific competency and capacity. Not a general AML background stretched to cover a business model it wasn't built for.
  5. Map your Travel Rule exposure independently of the FSMA timeline. It's a live, current obligation regardless of where a firm sits in the authorisation process.
๐Ÿ“˜
Coming next in the series
This part covered the current timeline, why MLR registration doesn't carry over, and what the FCA says separates a strong application from a weak one. Part 3 turns to typologies, mixers, layering, and rug pulls, the patterns that show up once a crypto touching customer is actually on your desk.
Quick Reference
FSMA cryptoasset authorisation at a glance, cheat sheet summary Summary card covering key dates, the MLR to FSMA transition, what the FCA says good looks like, and the four milestone timeline, for the Crypto Guide Part 2 guide. FSMA Cryptoasset Authorisation AT A GLANCE โ€” CHEAT SHEET KEY DATES Gateway opens 30 Sep 2026 Window closes 28 Feb 2027 Regime starts 25 Oct 2027 Pre-Application Support Service open now MLR TO FSMA No automatic conversion, fresh application required New firms steered toward FSMA directly FCA position as of 3 Jun 2026 WHAT GOOD LOOKS LIKE Full financial crime assessment, not just policy SYSC 3 governance and MLRO competency Travel Rule runs alongside FSMA THE TIMELINE 1 PASS Service open, Jul 2026 2 Gateway opens 30 Sep 2026 3 Window closes 28 Feb 2027 4 Regime starts 25 Oct 2027 A summary aid, not a substitute for the full guide or professional advice. fincrimeradar.org