FCA Cryptoasset Authorisation Gateway Analysis: Date vs Architecture
articleVerifyo Editorial TeamJuly 1, 2026

FCA Cryptoasset Authorisation Gateway Analysis: Date vs Architecture

Any FCA cryptoasset authorisation gateway analysis worth its name has to read the regime as more than a calendar. We read it as the front door to an evidence pipeline authorised firms will use for every customer onboarded from commencement. The 30 September 2026 window is the licensing test; the per-customer evidence pipeline is the operating cost across UK cryptoasset markets.

The four hard dates in the new cryptoasset regime

The new UK cryptoasset regulatory regime is built on four dated anchors. The FCA published the gateway operating model on its Cryptoassets webpage: PASS meetings for cryptoasset firms open 11 May 2026; the entry point opens 30 September 2026 and closes 28 February 2027 (1). The new cryptoasset regime is expected to commence and is effective from 25 October 2027 (2).

SI 2026/102 — the FSMA 2000 (Cryptoassets) Regulations 2026 — was made 4 February 2026 (3). The FCA has run AML supervision of registered cryptoasset firms since 10 January 2020 under MLR 2017 (6). The new layer adds FSMA regulation and consumer protection requirements over the existing registration framework.

The FCA's consultation papers shape the regulatory layer across UK markets. CP25/40, published 16 December 2025, covers regulated cryptoasset activities; CP25/41 and CP25/42 followed (2, 4). HMT shapes the perimeter via the policy note published 21 April 2026, amending SI 2026/102 before the regime takes effect (7).

The gateway is a four-anchor arc from 11 May 2026 to the new regime's start, not a single deadline.

Per-customer evidence pipeline an authorised cryptoasset firm runs from 25 October 2027: customer onboards, identity document collection, sanctions and PEP screening, evidence retention, ongoing CDD.

What authorised cryptoasset firms will operate from commencement

The new rules cover trading platforms, intermediation services, lending services, staking, custody services, market abuse, prudential standards, operational resilience, and financial promotions across regulated cryptoasset activities in domestic markets (2, 4). The FCA describes the shift as a move "to a more comprehensive crypto regime" (4), layering FSMA rules and consumer-protection requirements on the money laundering regulations. Existing cryptoasset firms apply these regulatory requirements as controls and systems across the activities offered. Authorised firms hold the FCA permission required for each set of regulated cryptoasset services they intend to carry on.

FATF Recommendation 10 names the four-part CDD process every authorised firm is required to use at onboarding: identify and verify the customer; identify the ultimate beneficial owner; understand the business relationship; and conduct ongoing customer due diligence (9). Under MLR 2017, registered cryptoasset firms have used real-time transaction monitoring under FCA supervision since 10 January 2020 (6).

From commencement, every customer onboarded by authorised firms triggers fresh collection, screening, retention, and refresh required across the regulated activities (3). The consumer duty applies to in-scope cryptoasset services; the market abuse regime under SI 2026/102 Part 2 Chapter 2 sets the market manipulation, insider-dealing, and surveillance disclosures firms provide to the FCA; money laundering regulation governs CDD compliance obligations (5); SI 2026/102 governs safeguarding (3).

The EU has run the equivalent arc one year ahead. MiCA's Title V regime entered application 30 December 2024; CASPs operating under national law have until 1 July 2026 to meet MiCA authorisation (8). The per-customer evidence pipeline is the global pattern across crypto markets.

The gateway is the licence test. The pipeline behind it is the operating cost.

Inside the application period: PASS, FCA announces, and the gateway timetable

The Pre Application Support Service opens 11 May 2026, before the entry point opens (1). The pre application meeting is the FCA's pre-authorisation support for firms preparing to apply during the application period.

The application period opens on the September 2026 start and closes on 28 February 2027 (1). Firms that submit and apply during this period are considered for authorisation under the new regime, provided they meet the FCA's threshold. Firms that apply for authorisation, or variation of an existing permission, must meet FCA expectations on business model, risk profile, and the regulated activities they intend to run. The pre application support service serves applicants seeking new permissions and authorisation or variation; the regulator expects firms to use the pre application meeting to provide the information that determines application quality and the required controls. The Latham & Watkins UK Cryptoasset Regulatory Tracker, last published 27 February 2026, documents the FCA's Q&A on the Authorisations workstream (11).

The service signals that the pre application route is part of the authorisation plan, not optional. Firms that submit cold carry an application-quality risk the FCA's published support, information sessions and webinars cannot offset; the FCA expect firms to engage early and prepare complete materials before they are considered. The FCA's guidance on the new regime and on authorisation or variation are published on its Cryptoassets webpage section.

The pre application meeting is the FCA's window into application quality before the period closes.

Verifier-private attestation architecture - issuer signs once, holder selectively presents, verifier checks proof; documents stay, only the proof crosses.

Where verifier-private attestations cut the application process

Every customer onboarded by authorised firms from commencement triggers fresh collection, screening, and retention. Firms on one-time-per-customer document flows carry the recurring compliance cost the traditional KYC market built in — Sumsub, Onfido, Jumio, Veriff, Persona, Socure, and Trulioo all transfer raw PII to every integrating firm.

The architectural alternative is verifier-private attestation. The W3C Verifiable Credentials Data Model 2.0, published 15 May 2025, defines a three-party topology — issuer, holder, verifier — where holders "can generate verifiable presentations and then share these verifiable presentations with verifiers to prove they possess verifiable credentials" (10).

Authorised firms receive proof of identity, age, and AML-screening controls without documents crossing the firm's compliance perimeter. The per-customer evidence pipeline collapses from "collect, screen, store, re-verify" to "check the attestation". Storage cost, retention liability, refresh cost, and breach exposure collapse with the documents that never crossed.

This is the approach we take at Verifyo. Verifyo provides a single Zero-Knowledge KYC attestation that proves the customer is identity-verified, sanctions-clear, PEP-clear, age-confirmed, and document-country-known — without the receiving firm holding the underlying documents. Verifyo's scope is Level 1 — Standard KYC. We do not offer address verification, KYB, transaction monitoring, source-of-funds or source-of-wealth, Travel Rule, or EDD as captured 11 June 2026. The attestation refreshes on a fixed expiry cadence. Authorised firms apply separate stacks for those regulatory requirements; what Verifyo cuts is the customer-identity step in the application process.

The traditional KYC pipeline collects, screens, stores, re-verifies for firms. The attestation does not.

Pre-application preparation: how cryptoasset firms prepare for the cryptoasset regime

Between 11 May 2026 and the application period opening, firms that apply for authorisation have a defined runway. PASS is the support vehicle: firms prepare to meet FCA expectations on regulated cryptoasset activities by using the pre application meeting to test business model, governance, and risk management (1).

Firms that apply for authorisation face an architectural choice: design what's required before authorisation, or retrofit afterwards. One-time-per-customer document flows carry the recurring compliance cost the traditional KYC market embedded. Reusable verifier-private attestations operate a smaller compliance surface.

Practical items as firms prepare the application plan: scope the data perimeter; decide on document-vs-attestation controls; complete a verification-provider assessment honestly; determine required permissions; submit a credible plan including the information the FCA uses to assess the application. Verifyo's Level 1 covers the customer-identity step — identity, document country, age (18 / 21), sanctions, PEP, adverse-media, criminal, barred, and military screening, plus wallet-binding. It does not cover address verification, KYB, transaction monitoring, source-of-funds or source-of-wealth, Travel Rule, or EDD — authorised firms address those regulatory requirements through other stacks.

The FCA expects firms to demonstrate a credible plan and risk management before the application closes 28 February 2027 (11). Architecture chosen before authorisation meets the regime's data-perimeter expectations without retrofit, and is cheaper than architecture retrofitted afterwards.

Verdict: the gateway is a deadline; the architecture is the operating surface

The FCA's application closes 28 February 2027. The per-customer evidence pipeline starts at scale from 25 October 2027 (1, 2). The licensing test is the entry door; the architecture behind it is the operating cost surface firms carry through the regime's life.

Verifier-private attestation is the structural answer (10). It does not change what the FCA requires. It changes what crosses the firm's data perimeter.

The gateway is a date. The architecture is the surface. Architecture locked into the firm's application plan before the new regime begins is cheaper than retrofit after.

Sources

  1. S1 — FCA. "Cryptoassets: how the gateway will operate." Updated 30 April 2026. URL.
  2. S2 — FCA. "A new regime for cryptoasset regulation." Updated 2 June 2026. URL.
  3. S3 — UK SI. "FSMA 2000 (Cryptoassets) Regulations 2026 (SI 2026/102)." Made 4 February 2026. URL.
  4. S4 — FCA. "CP25/40: Regulating cryptoasset activities." Published 16 December 2025. URL.
  5. S5 — FCA. "Cryptoassets: AML / CTF regime." Updated 12 February 2026. URL.
  6. S6 — FCA. "FCA becomes AML and CTF supervisor of UK cryptoasset activities." Published 10 January 2020. URL.
  7. S7 — HM Treasury. "Draft SI amending the FSMA 2000 (Cryptoassets) Regulations 2026: Policy Note." Published 21 April 2026. URL.
  8. S8 — EU. "Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA)." Adopted 31 May 2023; Title V in force 30 December 2024. URL.
  9. S9 — FATF. "Recommendation 10 (Customer Due Diligence)." Updated October 2025. URL.
  10. S10 — W3C. "Verifiable Credentials Data Model v2.0 — W3C Recommendation." Published 15 May 2025. URL.
  11. S11 — Latham & Watkins LLP. "UK Cryptoasset Regulatory Tracker." Updated 27 February 2026. URL.
Tags:fca cryptoasset authorisation gatewaycasp authorisationfca pass pre-applicationcryptoasset regulatory regimefca regulatory analysisverifier-private attestation

Want to learn more?

Explore our other articles and stay up to date with the latest in zero-knowledge KYC and identity verification.

Browse all articles