On 16 September, the FCA published PS26/18, its final cryptoasset perimeter guidance, introducing a new PERG 18 into the Perimeter Guidance Manual. With the authorisation gateway now open, it provides clarity on a number of key areas:
TOKENISED ASSETS AND THE “SOLELY A RECORD” TEST.
A cryptoasset that is solely a record of value or contractual rights, and does not function in practice as an asset in its own right, is not a qualifying cryptoasset. The FCA has expanded its guidance on where that line falls, and the test it applies is functional rather than technical.
Broadly, if transferring the token is the mechanism by which the underlying entitlement moves, it is likely to be more than a record. If entitlement continues to be determined by a separate register and the token merely identifies it, it is likely to fall outside the definition.
For firms tokenising existing assets this is worth working through carefully. The answer rests on the legal definition rather than the technology, and it determines whether cryptoasset permissions are required.
QUALIFYING CRYPTOASSETS AND SPECIFIED INVESTMENT CRYPTOASSETS.
A specified investment cryptoasset (SIC) is a qualifying cryptoasset that is also a specified investment – that is, something already regulated under FSMA, such as a share or a bond. Activities relating to SICs are largely already within the existing FSMA perimeter, so this boundary determines whether a firm needs new cryptoasset permissions or its existing ones.
Tokenised debt securities and tokenised shares are the FCA’s examples. A token representing a bond or a share is still a bond or a share for regulatory purposes, whether the instrument it represents already exists in the traditional market or was created on a blockchain from the outset.
That matters because two tokens can look much the same and sit on opposite sides of the line. Where a token is a SIC, a firm dealing in it is largely working within the existing investment rules. Where it is a qualifying cryptoasset but not a SIC, the new cryptoasset regime applies instead.
SAFEGUARDING AND ARRANGING SAFEGUARDING.
The FCA has set out the control test in detail. A firm safeguards cryptoassets only where it has the requisite degree of control, meaning the ability, through any means, to bring about the transfer of the benefit of the cryptoasset to another person, including to itself. The legislation gives two common examples: holding the means of access, usually the private key, and operating an arrangement in which others are appointed to hold that means of access or any part of it, including key sharding arrangements.
Negative control is not enough. A firm that can only prevent a transfer, such as one holding a single shard below the signing threshold, does not have the requisite degree of control. But if it can reach the threshold by other means – for example by requiring other parties to act in relation to shards they hold – it does. The threshold is case-specific, and whether a service is online or offline is not, of itself, conclusive. The central question is whether the firm is, or could put itself, in a position to initiate a transfer that could prejudice a person with a claim to the asset.
There is no express exclusion for technical, infrastructure, connectivity or security services. Providers of those services need to work through the control test on their own facts, with the holding out exclusion potentially available where its conditions are met. Genuine self-custody solutions, where the customer exercises control and the firm has no means of bringing about a transfer, fall outside the activity.
DEALING AS A PRINCIPAL OR AGENT, AND ARRANGING DEALS.
Arranging remains broadly drawn, and the FCA has declined to narrow it, on the basis that scope is set by legislation rather than guidance. What it has done is clarify the boundary.
The provision of information, analytics, research, market data or dashboard services does not, of itself, amount to arranging. The test is not whether a service provides information useful to a trading decision, but whether it forms part of the arrangements by which transactions are facilitated or entered into. Services limited to collecting, displaying, analysing or transmitting information – price feeds, blockchain analytics, research, screening, filtering or search functionality – are less likely to be in scope. The label is not determinative: a service crosses the line where it enables users to identify counterparties or execution venues, transmit or route orders, access trading functionality, or otherwise participate in the transaction process. Merely influencing a decision to buy, sell or hold does not on its own make a person an arranger.
Firms in this space should check their financial promotions position separately, as the two perimeters differ.
THE EXCLUSION FOR AIFMs AND UCITS MANAGERS.
Only a limited number of the general exclusions that apply elsewhere in the Handbook have been carried across to the new cryptoasset activities. One of them matters a great deal to fund managers.
Where a firm holds a Part 4A permission to manage an AIF or a UK UCITS, activities carried on in connection with, or for the purposes of, managing that fund are excluded from the new regulated cryptoasset activities. In practice, an authorised AIFM whose fund takes cryptoasset exposure should not need separate cryptoasset permissions for what it does in managing that fund.
INTERACTION WITH THE MONEY LAUNDERING REGULATIONS.
The new FSMA regime does not replace the Money Laundering Regulations. The two operate side by side, they are not identical in scope, and the MLR registration requirement continues to apply beyond 25 October 2027.
What that means depends on where a firm lands:
| # | POSITION | KEY REQUIREMENT |
|---|---|---|
| 1 | FSMA-AUTHORISED FIRMS | A firm authorised under FSMA for cryptoasset activities that also acts as a cryptoasset exchange provider or custodian wallet provider must still comply with the MLRs in full. It will not need a separate MLR registration, but it must notify the FCA that it intends, or has begun, to act in that capacity, either before doing so or within 28 days. |
| 2 | FIRMS OUTSIDE THE FSMA PERIMETER | A firm that concludes it does not need FSMA authorisation because its activity falls outside the new perimeter, or because an exclusion applies, may still need to be registered under the MLRs if it acts as a cryptoasset exchange provider or custodian wallet provider. Benefitting from an FSMA exclusion does not take a firm outside the MLRs. |
The two perimeters are drawn differently and must be assessed independently. Reaching the FSMA answer does not give you the MLR answer.
WHAT TO DO NOW.
The gateway is now open and closes on 28 February 2027 for firms relying on the savings provisions. Existing registrations and permissions will not convert automatically. Firms should complete a documented perimeter assessment against PERG 18, assess the MLR position separately, and use the FCA’s pre-application support service where the position is genuinely borderline.
PERG 18 does not yet reflect the Government’s recent amending regulations, which introduce further exclusions, including for certain stablecoin payment activity, and the FCA has said it will consult on updated guidance later this year, so assessments completed now may need revisiting.
At Cosegic we are supporting firms through perimeter assessments and authorisation applications. Book a conversation with the Cosegic team to discuss how the new regime applies to your business.