Pitchsd

Home  /  Cryptoasset authorisation

Digital assets

Cryptoasset authorisation

Authorisation for cryptoasset firms — the UK's incoming FCA regime, the EU's MiCA framework, and the digital-asset regimes established across the Gulf and Asia.

Crypto is moving from the edge of regulation into the perimeter. We help cryptoasset firms prepare for authorisation under the new regimes — analysing which activities fall in scope, building the financial-crime and custody controls regulators concentrate on, and producing the application itself.

The UK timetable is the immediate pressure. The FCA's cryptoasset authorisation gateway opens on 30 September 2026, applications close on 28 February 2027, and the regime takes effect in October 2027. Firms that miss the window have no guarantee their application will be processed before the regime goes live, and a firm cannot begin regulated activity until authorisation is granted. Pre-application meetings with the regulator are already available, and for anything beyond a simple permission profile the preparation work needs to start well before the gateway opens.

Who we do this for

  • Exchanges and trading venues
  • Custodians and safeguarding providers
  • Brokers, dealers and OTC desks
  • Stablecoin issuers and payment firms with crypto rails
  • Staking, lending and yield propositions
  • Tokenisation platforms and digital-asset infrastructure

Perimeter analysis comes first

The new regimes are activity-based, and most firms perform more than one regulated activity without having framed the business that way. Operating a trading platform, dealing as principal or agent, arranging, custody, and stablecoin issuance are separate activities with separate consequences. Firms that describe themselves by product rather than by activity typically discover a second or third permission requirement late, when the application is already drafted. We start by mapping the flow of assets and money and working out which activities that flow actually constitutes.

Financial crime and the Travel Rule

Financial crime remains the area where crypto applications are examined most closely. A business-wide risk assessment that engages with the specific typologies of your asset mix and counterparties. Blockchain analytics with thresholds you can justify. Travel Rule compliance operating across counterparties who may not themselves be compliant, with a documented approach to what happens when data is missing. And a sanctions position that covers wallet screening as well as customer screening.

Custody and safeguarding of client assets

Where client assets are held, regulators will want segregation, key management with documented procedures for generation, storage and recovery, an insurance or loss-allocation position, and a clear answer on what happens to client assets on insolvency. Hot and cold wallet architecture should be described operationally, including who can move assets, under what authorisation, and how that is logged and reviewed.

Prudential, resilience and the wind-down question

Capital and liquidity requirements appropriate to the activities, an operational resilience position covering the technology stack and third-party dependencies, and a wind-down plan that explains how client assets are returned in a stressed market. The wind-down analysis matters more here than in most sectors, because the assets are volatile and the return mechanics are not straightforward.

Where we authorise

United Kingdom

The FCA's new cryptoasset regime, with the authorisation gateway opening on 30 September 2026.

FCA
Gateway opens 30 September 2026 · regime effective October 2027

European Union

A single authorisation for crypto-asset service providers across the EU.

National regulators
Markets in Crypto-Assets (MiCA)

Middle East & Asia

Established and developing digital-asset regimes.

VARA (Dubai)FSRA (ADGM)MAS (Singapore)SFC (Hong Kong)
Among the most advanced digital-asset frameworks
The FCA cryptoasset authorisation gateway opens on 30 September 2026.

Applications close on 28 February 2027 and the regime takes effect in October 2027. Pre-application meetings with the regulator are already available. If you will need UK authorisation, the time to start the application is now.

How the process runs

Perimeter and jurisdiction

Which activities you perform, which regimes catch them, and whether the UK, the EU or a Gulf or Asian jurisdiction is the right first authorisation for your business.

Building the pack

Regulatory business plan, financial-crime and Travel Rule frameworks, custody and key-management controls, prudential position, resilience and wind-down analysis.

Submission and case officer

Pre-application engagement where it is available, then submission and management of the information requests. UK applicants should work backwards from the 28 February 2027 closing date.

Getting operational

Controls live and tested, analytics calibrated, Travel Rule operating with real counterparties, and reporting obligations diarised.

Common questions

When does the FCA cryptoasset authorisation gateway open?

It opens on 30 September 2026. Applications close on 28 February 2027 and the regime takes effect in October 2027. Pre-application meetings with the FCA are available before the gateway opens.

What happens if I miss the application window?

The FCA has indicated it cannot guarantee that applications submitted after the window closes will be determined before the regime goes live. Since a firm cannot carry on regulated activity without authorisation, missing the window creates a real risk of having to stop trading in the UK.

Do I still need registration under the money laundering regulations?

The existing anti-money-laundering registration regime for cryptoasset businesses is separate from, and narrower than, the incoming authorisation regime — it covers financial crime only. Firms currently registered should not assume that registration carries across; plan for the full authorisation application.

Can I use a MiCA authorisation to operate in the UK?

No. MiCA provides a passport across the EU, and the UK regime is separate. Firms serving both markets need to plan for two authorisations, though much of the underlying documentation — financial crime, custody, resilience — can be built once and adapted.

What do regulators focus on most in crypto applications?

Financial-crime controls calibrated to the actual asset mix and counterparty base, custody and key management, and the wind-down analysis. Business model viability is also examined closely, because the regulator has to be satisfied the firm can meet its obligations on an ongoing basis.

More on how we work, fees and timelines is on the FAQ page, and the regimes we cover are set out under jurisdictions.

Why firms use Pitchsd

Crypto authorisation is being written as it is applied, which means the firms that succeed are the ones whose applications engage with the regulator's actual concerns rather than reciting the rules back. We have built financial-crime and custody frameworks that had to work in production, and we track the UK and EU regimes as they develop.

We also build the technology the business runs on, so the platform and the permission arrive together rather than being someone else's problem. And we can put senior people into the business — a fractional MLRO, non-executive directors, a CFO — through our network. Get in touch to talk through where your application stands.