Five Weeks to the FCA Cryptoasset Window — What "Ready" Looks Like
The FCA Cryptoasset Window Opens in Five Weeks — What “Ready” Actually Looks Like
Five weeks.
That's what's left before the FCA's cryptoasset authorisation application window opens — 30 September 2026, closing 28 February 2027, ahead of the regime commencing 25 October 2027. For a firm that already knows it will need to apply, that's a fixed window, not a distant deadline, and five weeks isn't long to get an application into genuinely defensible shape.
I've spent the last several years on both sides of this: as a registered Data Protection Officer working directly with the FCA and ICO, and grounded in Travel Rule and crypto-compliance work through Omnia DeFi and Validitum. Most advisors in this space cover one side — data protection or crypto regulation — not both. The gap between them is usually where applications fall down.
What “ready” actually looks like, in practice:
● Governance mapped to a level the FCA can actually follow — who decides what, and on what authority.
● AML/KYC and Travel Rule processes documented, not just implemented.
● Data protection built in from the start, not retrofitted once someone asks.
● A record of all of the above that would hold up under scrutiny, not just under normal operating conditions.
None of that gets fixed in the week before the window opens. It gets fixed now, while there's still time to do it properly rather than defensively.
If your firm is preparing an application, or isn't yet sure what “ready” looks like, I'm happy to talk it through.