From consultation to final rules: what the FCA’s crypto prudential regime means for firms.

What does the FCA's crypto prudential regime mean, and how can it affect your firm?
Crypto Prudential Regime

PS26/12: A Prudential Regime for Cryptoasset Firms finalises the proposals consulted on in CP25/15 and CP25/42, establishing the new COREPRU and CRYPTOPRU sourcebooks. The FCA’s final rules now bring an important part of the UK’s future cryptoasset regulatory framework into sharper focus.

This is an important development for firms preparing for FCA authorisation. As we noted in our earlier analysis, CP25/15: A regime for Cryptoasset Firms – current developments and subsequently in CP25/42: Completing the FCA’s Prudential Framework for Cryptoasset Firms, the FCA’s direction of travel was already clear: cryptoasset firms would be expected to demonstrate financial resilience, appropriate liquidity and effective risk management, with requirements tailored to the risks inherent in their business models.

The final rules do not change that fundamental direction. Instead, they refine the framework in a number of important areas, particularly around capital requirements, the treatment of cryptoasset exposures and public disclosure.

The result is a prudential regime that is both more proportionate in some respects and clearly embedded in the FCA’s wider supervisory approach.

FROM PROPOSED FRAMEWORK TO FINAL REGIME.

CP25/15 established the initial prudential architecture for stablecoin issuers and cryptoasset custodians. CP25/42 subsequently extended the framework to a much broader range of activities, including trading platforms, dealing, arranging and staking.

The final rules bring those strands together.

At the centre of the framework remains the minimum requirement for firms to hold sufficient own funds and liquidity to meet formulaic requirements

A firm’s own funds must be at least equal to the highest of:

  • the Permanent Minimum Requirement (PMR);
  • the Fixed Overhead Requirement (FOR); and
  • the applicable K-Factor Requirement (KFR).

From a liquidity perspective, a Firm must hold sufficient liquid assets that are at lest equal to:

  • The Basic Liquid Assets Requirement (BLAR) which is the sum of one-third of the FOR and 1.6% of client guarantees

This is familiar territory for firms operating under MIFIDPRU, but its application to cryptoasset businesses reflects the FCA’s view that the risks generated by cryptoasset activities require a tailored prudential framework.

Importantly, however, the FCA has not moved to a purely formulaic regime.

As we highlighted in our CP25/42 analysis, the Overall Risk Assessment (ORA) is a central part of the framework. The FCA has now confirmed that firms cannot assume that satisfying their PMR, FOR and KFR automatically means that they are adequately capitalised. The ORA must identify risks which may not be fully captured by the minimum requirements and firms must hold additional financial resources where necessary.

WHAT HAS CHANGED?

The final rules retain much of the framework proposed in CP25/42. The more significant changes are concentrated in three areas.

Summary of Main Structural Changes

AREA / REQUIREMENT
CONSULTATION PROPOSAL (CP25/42)
FINAL RULES (PS26/12)
K-SII (STABLECOIN ISSUANCE)
2% capital requirement on average qualifying stablecoins in issuance.Halved to 1% due to embedded risk mitigants like the 1:1 backing pool.
K-NCP (NET CRYPTOASSET POSITION)
Rigid, complex asset-by-asset market risk framework.Simplified to a flat 40% net risk position requirement for prudently valued assets.
K-CCD (COUNTERPARTY CREDIT DEFAULT)
Standardised traditional volatility calculations.Adjusted to a 40% volatility adjustment matching the K-NCP baseline.
PUBLIC DISCLOSURES
Broad disclosure requirements for all Firms.A more proportionate approach for Firms whose OFR is driven by there PMR.

A more proportionate approach to stablecoin issuance

One of the clearest changes concerns the capital requirement for stablecoin issuance.

The FCA has reduced the coefficient for the K-SII requirement from 2% to 1%. This responds directly to industry feedback and is intended to make the framework more proportionate, particularly for larger stablecoin issuers.

The change does not remove the prudential requirement. Rather, it recognises that the original calibration could produce increasingly significant capital requirements as issuance volumes grew. In addition, the FCA recognised through the consultation process that issuing stablecoins will be, under the broader regime, subject to a comprehensive set of requirements (as set out under PS26/10) that will reduce the residual operational risk that K-SII is intended to cover.

For firms considering stablecoin issuance, this is therefore a meaningful reduction in the potential capital burden, but it should not be interpreted as a weakening of the FCA’s overall expectations around financial resilience.

The broader framework for stablecoin issuers remains demanding, particularly when the capital requirements are considered alongside the separate requirements concerning backing assets, the redemption regime and safeguarding.

Simplification of the treatment of cryptoasset market risk

Perhaps the most technically significant change is the FCA’s decision to simplify its proposed approach to cryptoasset market and counterparty risk.

CP25/42 proposed a two-tier categorisation of cryptoassets for capital purposes. The final rules move away from that more complex Category A/Category B framework. The feedback from the industry was clear; the monitoring of assets under the Category A/Category B framework was likely to be unwieldy and would create ‘cliff edge’ effects when a cryptoasset moved from Category A to Category B.

Instead, qualifying cryptoassets that can be prudently valued and are admitted to a UK qualifying cryptoasset trading platform will be subject to:

  • a 40% net risk position requirement under K-NCP; and
  • a 40% volatility adjustment under K-CCD

Cryptoassets that do not meet those conditions will be subject to more conservative treatment, a deduction from regulatory capital and a 100% volatility adjustment for K-CCD. The impact of this adjustment is to avoid those outcomes where the capital requirement arising from holding a position is greater than the value of the exposure itself.

The FCA’s objective is to retain the underlying distinction between assets with different risk characteristics without imposing a framework that is unnecessarily complex. This is an important example of the FCA responding to industry feedback without abandoning the prudential objective.

It also demonstrates the regulator’s broader approach to cryptoasset regulation: where the risks are sufficiently understood, the framework can be proportionate, but firms should not expect crypto-native characteristics to remove the need for conventional prudential protections.

Public disclosure requirements have been made more proportionate

The FCA has also changed its approach to public prudential disclosures.

The proposed requirement to publicly disclose the Own Funds Threshold Requirement (OFTR) and Liquid Asset Threshold Requirement (LATR) has been removed.

Instead, the FCA has introduced a proportionality mechanism based on which component of the firm’s Own Funds Requirement is binding.

Where the PMR is the binding requirement, the firm will not generally be subject to the CRYPTOPRU public disclosure requirements.

Where the FOR or KFR is the binding component, the full disclosure requirements will apply.

This is a useful distinction. A small or simple firm whose prudential requirement is essentially a fixed minimum should not face the same disclosure burden as a firm whose capital requirement is being driven by the scale or complexity of its activities.

The change therefore supports the FCA’s stated objective of creating a proportionate regime while retaining transparency for firms where their risk and activity levels make that information more meaningful.

WHAT HAS NOT CHANGED?

It is just as important to understand what the FCA has not changed.

The final rules continue to place significant emphasis on:

  • adequate own funds;
  • liquidity and liquid asset requirements;
  • operational risk;
  • market and counterparty risk;
  • concentration risk;
  • group risks;
  • orderly wind-down; and
  • the firm’s overall risk assessment.

The FCA has also retained a number of operational risk K-factors. These are designed to provide simple, activity-based minimum requirements and are broadly aligned with equivalent concepts in MIFIDPRU.

For example, the FCA has retained K-factors relating to client orders, trading flow, safeguarding and staking. The regulator acknowledges that there is limited historical loss data from which to calibrate crypto-specific prudential requirements and has therefore adopted a broadly technology-agnostic approach based on the principle of same risk, same regulatory outcome.

The FCA is not attempting to create an entirely separate set of principles of prudential regulation for crypto. Instead, it is adapting established financial-services concepts where they can be applied appropriately, while introducing crypto-specific requirements where the risks demand them.

Of all the elements of the final framework, the Overall Risk Assessment may prove to be one of the most important in practice.

THE OVERALL RISK ASSESSMENT (ORA).

As we noted in our article CP25/42: Completing the FCA’s Prudential Framework for Cryptoasset Firms, the formulaic requirements provide the starting point but the ORA is where firms assess their actual risk profile.

A firm’s ORA will need to consider the risks arising from its business model, including operational and technology risks, custody and safeguarding, market and counterparty exposures, liquidity and funding, and the risks associated with an orderly wind-down.

The FCA has now consulted separately on non-Handbook guidance for both COREPRU and CRYPTOPRU to help firms undertake their ORAs. This is particularly relevant for firms approaching authorisation because it gives greater insight into how the FCA expects firms to demonstrate that their financial resources are appropriate to their individual risk profile.

The practical message is clear: firms should not design their capital framework backwards from the minimum regulatory number. The starting point should instead be the business model, the risks it creates and the resources required to withstand those risks.

WHAT DOES THIS MEAN FOR FIRMS?

For firms preparing for authorisation, the finalisation of PS26/12 changes the nature of the exercise.

The question is no longer simply what the FCA might require. Firms now have a substantially clearer picture of the prudential framework against which they will need to operate.

BUSINESS MODELS NEED TO BE TESTED AGAINST THE FINAL RULES.

Firms should revisit their proposed permissions and business models and calculate the likely impact of the final prudential requirements. The capital impact will differ significantly depending on the activities undertaken.

A firm focused on arranging or agency activities may find that the PMR remains the principal constraint. A firm operating a trading platform, dealing as principal or undertaking activities that generate significant client or trading flows may instead find that K-factors become increasingly important as the business grows.

For firms with trading books, the treatment of cryptoasset positions and counterparty exposures will be particularly important.

CAPITAL PLANNING NEEDS TO BE DYNAMIC.

The final framework is not simply a requirement to demonstrate sufficient capital on the proposed date of authorisation. Firms will need to understand how their capital requirements could evolve as volumes, client assets, trading activity and costs change.

This is particularly relevant to high-growth businesses. A business model that appears comfortably capitalised at launch may produce a materially different prudential position once trading volumes or client assets increase.

Firms must prioritise accurate and realistic financial forecasting that is closely aligned to the Firm’s strategic objectives and business model. Boards and senior management therefore need visibility over the relationship between commercial growth and regulatory capital.

LIQUIDITY SHOULD NOT BE TREATED AS AN AFTERTHOUGHT.

The same applies to liquidity. A firm can be adequately capitalised while still being vulnerable to a liquidity event.

For cryptoasset businesses, this distinction is particularly important given the speed at which market conditions can change and the potential mismatch between the liquidity of assets held and the firm’s obligations.

Liquidity assumptions should therefore be tested under stressed conditions rather than simply based on normal-market convertibility.

This will also need to connect with the firm’s wind-down planning. The FCA’s prudential framework is designed not only to reduce the likelihood of failure, but to ensure that a firm has sufficient resources to manage an orderly exit where failure does occur.

BALANCING COMMERCIAL OBJECTIVES WITH PRUDENTIAL COMMITMENTS.

There is a tendency to view prudential regulation principally as an additional cost of authorisation. That risks missing the wider commercial implications. The final framework is likely to influence which cryptoasset business models are economically attractive in the UK.

Firms with relatively low-risk, capital-light models may find that the PMR provides a manageable entry requirement. Firms with substantial balance-sheet exposure, significant trading activity or high operational volumes may need to commit considerably more capital and liquidity as they scale.

This could influence decisions about:

  • which permissions to seek;
  • whether activities should be undertaken within the same legal entity;
  • the level of balance-sheet exposure to retain;
  • the pace of growth;
  • group structures and intra-group dependencies;
  • liquidity management; and
  • where capital should be deployed across an international group.

In that sense, prudential regulation becomes part of business strategy, rather than simply regulatory compliance.

POLICY TO PRACTICE: WHAT FIRMS SHOULD DO NOW?

With the authorisation gateway scheduled to open on 30 September 2026, firms should now be moving from policy interpretation to implementation. The FCA has confirmed that the priority application window is expected to run from 30 September 2026 to 28 February 2027 – with all applicants to be provided with a final decision by 25 October 2027.

Firms should consider, at a minimum:

  • Mapping permissions to prudential requirements – identify which PMR, FOR and K-factors will apply to the proposed business model.
  • Recalculating capital requirements – update financial models using the final rules rather than the CP25/42 assumptions.
  • Assessing liquidity – identify liquid assets, liquidity needs and stress scenarios, including the resources required for an orderly wind-down.
  • Developing the ORA – ensure the assessment is genuinely linked to the firm’s risks and financial-resources framework.
  • Reviewing group structures – identify intra-group dependencies, upstreaming arrangements and risks that may need to be reflected in the prudential assessment.
  • Testing growth scenarios – consider how changes in trading volumes, client assets, staking activity or other business metrics could affect K-factor requirements and capital commitments.
  • Embedding board oversight – ensure senior management and the board understand the firm’s prudential position and the assumptions underpinning it.
  • Aligning the wider authorisation programme – prudential work should be integrated with governance, operational resilience, safeguarding, financial crime and conduct workstreams rather than treated as a standalone exercise.
  • Establish Capital Management and Liquidity Risk Management policies –  to demonstrate the Firm has a robust prudential risk management framework.

CONCLUSION.

While the framework has in some aspect been simplified and made more proportionate, the regime still requires Firms significant attention to detail to demonstrate financial resource adequacy.

The FCA’s final prudential framework is not a wholesale departure from the proposals set out in CP25/15 and CP25/42. In many respects, it confirms the direction that was already visible in those consultations which we have highlighted in our previous articles

The FCA has responded to industry feedback by simplifying the treatment of cryptoasset exposures, reducing the K-SII calibration, and introducing a more proportionate approach to public disclosures. At the same time, it has retained the central features of the framework: minimum capital requirements, liquidity requirements, K-factors and, critically, the Overall Risk Assessment.

The final rules are indeed more proportionate than some of the proposals initially suggested but this should not be mistaken for a lighter-touch regime.

The FCA is establishing a prudential framework in which firms will need to demonstrate that they have sufficient financial resources for the risks they actually run, not simply that they can satisfy a regulatory formula.

For firms preparing for authorisation, the priority now should be to turn the final rules into a firm-specific financial resilience framework – one that links capital, liquidity, risk management, governance and wind-down planning to the realities of the business model.

The firms that approach prudential requirements in this way are likely to be better placed not only to meet the FCA’s authorisation expectations, but also to scale sustainably once the new regime is fully operational.

GET IN TOUCH.

Preparing for FCA authorisation under the new cryptoasset prudential regime? Our Financial Resilience team can help you understand how the final rules apply to your business model, from capital and liquidity requirements to the Overall Risk Assessment and wider prudential framework.

Get in touch with our experts to discuss your requirements and how to prepare for the new regime.

Table of Contents

Speak to a sector expert

Article Post

"*" indicates required fields

Full name*

Need something else?

Tell us what you’re working on and we’ll point you to the right support, or build a plan around your firm.

Share:

Featured Resources

Book a Personalised Demo

Tell us a little about your firm and what you're looking to achieve. We'll arrange a personalised demo with the right product specialist and show you how our solution can meet your needs.

"*" indicates required fields

Terms*

Fill in your details below to download your free checklist

Enter your details below to access the checklist.

"*" indicates required fields

Terms*