The UK’s cryptoasset regime is moving from consultation to implementation. With the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 made on 4 February 2026, the FCA’s authorisation gateway opening on 30 September 2026, and the regime coming into full force on 25 October 2027, firms now have a timetable to work towards.
Rather than creating a standalone regime with a standalone rulebook, the UK is bringing cryptoassets inside its existing regulatory framework based on the principle of ‘same risk, same regulatory outcome’.
For cryptoasset firms that means authorisation will bring more than new requirements for the business itself. The people who run those businesses will also become subject to the Senior Managers and Certification Regime (SM&CR) and its framework for individual accountability.
For firms that have never operated under SM&CR before, this could require a significant shift in how responsibilities, conduct and accountability are managed and evidenced.
The practical question is: what will SM&CR mean for cryptoasset firms, and what should they be doing now to prepare?
Why will SM&CR apply to cryptoasset firms?
Until now, most crypto activity in the UK has sat outside the full regulatory perimeter, captured mainly through anti-money laundering registration and the financial promotions regime.
From 25 October 2027, specified cryptoasset activities fall within the FSMA regulatory perimeter. These include issuing qualifying stablecoins in the UK, safeguarding or arranging safeguarding of qualifying cryptoassets and relevant specified investment cryptoassets, operating a qualifying cryptoasset trading platform, dealing as principal or agent, arranging deals in qualifying cryptoassets, and arranging qualifying cryptoasset staking.
Money Laundering Regulations (MLRs) registration will not convert automatically into FSMA authorisation. Firms already registered under the MLRs will need to apply for Part 4A authorisation if they want to continue carrying on regulated cryptoasset activities. Existing authorised firms will need a variation of permission if they wish to carry on regulated cryptoasset activities.
With authorisation comes a continuing set of regulatory obligations, including the Threshold Conditions, Consumer Duty and SM&CR.
For many cryptoasset firms, SM&CR will be one of the most significant changes because it places clear regulatory accountability on the individuals responsible for running the business.
What will SM&CR mean for cryptoasset firms?
Many cryptoasset firms are likely to fall within the core SM&CR regime. The FCA does not anticipate that many, if any, firms conducting only cryptoasset activities will meet the enhanced threshold when the regime commences: its final rules set the thresholds at £20bn in backing assets, on a three-year rolling average, for UK qualifying stablecoin issuers, and £100bn in custody assets for custodians. The limited scope tier is not expected to apply to firms authorised solely for cryptoasset activities.
SM&CR will therefore introduce a framework already familiar to other regulated financial services firms, including:
- Senior Management Functions (SMF): the most senior decision-makers must be approved by the FCA, with their responsibilities documented in a Statement of Responsibilities.
- Prescribed Responsibilities: specific, non-delegable accountabilities that must be allocated to named senior managers.
- The Certification Regime: staff who are not SMFs but whose role could cause significant harm must be assessed as fit and proper, at least annually.
- Fitness and propriety: senior and certified staff must meet, and continue to meet, standards of honesty and integrity, competence and capability, and financial soundness.
- The Conduct Rules: a baseline set of conduct standards applying to almost all employees.
These requirements mean firms will need to think carefully about who is responsible for what, how those responsibilities are documented and how individual accountability is embedded in day-to-day operations.
Why could SM&CR be challenging for cryptoasset firms?
Several challenges are already foreseeable, particularly for firms coming into full FCA regulation for the first time.
Founder-led firms may find formal fitness and propriety assessments of their own senior team unfamiliar, but they will be unavoidable. Responsibilities that have historically been shared informally will need to be allocated to named individuals, without material gaps or unnecessary overlaps.
Firms will also need to identify their certification population and establish processes to assess fitness and propriety on appointment and at least annually.
Conduct culture is straightforward to assert but harder to evidence. Firms will need to demonstrate that employees understand the Conduct Rules and how they apply to their specific roles, rather than relying on generic training.
Record-keeping will matter too. Standards that may have been adequate for a business outside the full regulatory perimeter may not meet FCA expectations once the firm becomes authorised.
None of these challenges are unique to cryptoassets. Other sectors worked through similar adjustments when SM&CR was introduced. Cryptoasset firms have the advantage of that experience – but only if they use the time before the new regime takes effect to prepare.
What do the Conduct Rules mean for cryptoasset firms?
The Conduct Rules sit at the centre of individual accountability under SM&CR. There are five individual rules: acting with integrity; acting with due skill, care and diligence; being open and co-operative with the regulators; paying due regard to the interests of customers and treating them fairly; and observing proper standards of market conduct. Alongside these sit four further rules for senior managers, covering effective control, regulatory compliance, delegation and disclosure.
Firms must make staff aware of the rules and train them on how the rules apply in their specific roles.
Separately, the Conduct Rules are being extended to cover serious non-financial misconduct, such as bullying, harassment and violence towards colleagues, where it relates to the individual’s role and there is a sufficient work-related link. This change takes effect for firms already within the SM&CR from 1 September 2026.
Cryptoasset firms will not enter the new regime until 25 October 2027, so they should factor the extended requirements into their SM&CR frameworks from the outset, including staff policies, Conduct Rules breach reporting, fitness and propriety assessments, regulatory references and training.
What does good SM&CR readiness look like?
For firms preparing for authorisation, SM&CR readiness is not simply about producing the required documentation.
By the time the regime takes effect, firms should be able to demonstrate:
- clear ownership of senior management responsibilities;
- appropriate SMFs and prescribed responsibilities have been identified;
- responsibilities are mapped without material gaps or unnecessary overlaps;
- the certification population has been identified;
- a robust process exists for initial and ongoing fitness and propriety assessments;
- Conduct Rules training is tailored to relevant roles; and
- appropriate records, management information and governance evidence are maintained.
The key is being able to demonstrate that the framework works in practice, rather than simply showing that the right policies exist.
Is your firm ready for SM&CR?
Boards and founders should be asking:
☐ Do we know who our SMF holders are likely to be?
☐ Have responsibilities been mapped without material gaps or unnecessary overlaps?
☐ Have prescribed responsibilities been allocated to appropriate individuals?
☐ Have we identified our certification population?
☐ Do we have a process for assessing and documenting fitness and propriety?
☐ Is our Conduct Rules training tailored to the roles people actually perform?
☐ Could we evidence our SM&CR arrangements to the FCA if asked?
Where firms cannot yet answer these questions confidently, there is still work to do before SM&CR becomes part of their regulatory framework.
Key dates for cryptoasset firms
- 4 February 2026: the Cryptoassets Regulations 2026 were made, confirming the legislative framework.
- 1 September 2026: the extension of the Conduct Rules to non-financial misconduct takes effect for in-scope firms.
- 30 September 2026 to 28 February 2027: the FCA’s authorisation gateway is open for applications.
- 25 October 2027: the FCA’s cryptoasset Handbook rules come into force and the regime commences.
What should cryptoasset firms do now?
With the authorisation gateway opening in September 2026, firms should be moving from awareness into planning and execution.
- Assess your current governance arrangements Review how responsibilities are allocated today and identify where accountability is unclear, shared or undocumented.
- Identify your SM&CR population Identify likely SMFs and the certification population, allocate prescribed responsibilities and begin preparing Statements of Responsibilities.
- Establish fitness and propriety processes Put in place a robust process for assessing senior and certified staff on appointment and on an ongoing basis.
- Prepare for the Conduct Rules Develop a role-specific Conduct Rules training plan and ensure wider policies and processes reflect the requirements that will apply when the firm becomes authorised.
- Build the evidence Establish the records, registers and management information needed to demonstrate that the framework is operating effectively from day one.
The key takeaway
Authorisation should be treated as the start line, not the finish line.
For cryptoasset firms, entering the FCA regulatory perimeter will change not only what the business must do, but also how responsibility and accountability are allocated to the people running it.
Firms that start identifying their SM&CR population, mapping responsibilities and establishing fitness and propriety and Conduct Rules frameworks now will be better placed to demonstrate that those requirements are embedded when the new regime takes effect.
How fscom can help
At fscom Compliance Maturity Specialists™, we help firms prepare for and implement SM&CR in a way that reflects how their business actually operates.
For cryptoasset firms, this can include SM&CR readiness assessments, responsibility mapping, identifying SMF and certification populations, developing fitness and propriety frameworks, preparing Statements of Responsibilities, establishing management information and delivering role-specific Conduct Rules training.
If you would like an independent view of your firm’s SM&CR readiness ahead of the new cryptoasset regime, get in touch with our team.
This post contains a general summary of advice and is not a complete or definitive statement of the law. Specific advice should be obtained where appropriate.