Legal briefing | |

Nearly out of perg-atory – but not quite yet: good news as the FCA finalises PERG 18 on cryptoassets, but with even more legal changes to come

Overview

Cryptoasset firms are days away from the FCA opening its authorisation gateway on 30 September 2026. In an ideal world, the regulatory perimeter – enacted by Parliament in legislation, and (where appropriate) supplemented by interpretative Perimeter Guidance from the FCA – would have been finalised some time ago, allowing such firms to make strategic decisions about their commercial and regulatory objectives in the UK.

We are not living in that world. Cryptoasset firms, their investors and potential counterparties, as well as traditional financial institutions, financial market infrastructures, and asset managers looking to make innovative use of blockchain technology and tokenisation, are instead faced with an exceptionally fast-moving environment.

In April, we published an article The importance of paying attention: The FCA's consultation on cryptoassets perimeter guidance has been followed almost immediately by further legislative changes to the perimeter, which examined the FCA's consultation on cryptoassets Perimeter Guidance (PERG), as well as the evolving legislative position. This is very much the sequel to that article.

In the space of less than 24 hours, on 15 and 16 September 2026, there were two major developments affecting the perimeter:

The quotation marks around the word finalised are deliberate, because this is not the end of the matter. When firms ask, "Do we need authorisation, and if so, for what activities?" the answers, in some cases, remain unclear.

PERG 18 reflects the law as it is currently on the statute book. The Amending SI is not yet in force (although we believe that firms can be fairly confident that it will become the law in the near future), and it makes further changes to the cryptoassets regulatory perimeter. The single biggest change is the addition of a new exclusion which will help firms that want to facilitate payments using stablecoins, which we describe more fully below. These changes are not reflected in PERG 18 and, by definition, the FCA must reflect the law as it stands. The FCA has committed to consulting on additional Perimeter Guidance "in early Q4 2026". We read that to mean, in essence, as soon as the Amending SI becomes law. 

One point that comes across very strongly in PS26/18 is that a lot of the feedback given to the FCA related to the legislative design of the perimeter, and not, in fact, to the FCA's interpretation. The FCA must deal with the law as it stands and, as it notes in several places within its Policy Statement, it cannot use PERG to amend the law or create exclusions where none exist.    

This article focuses on, and highlights, the key changes to PERG the FCA has made following consultation; these are broadly welcome. We also pick out the key additional changes made by the Amending SI. We have said previously, more than once, that time is of the essence (including in the fintech section of our Financial Services End of Summer 2026 Postcard), but that is true now more than ever. The picture is sufficiently complex that we are not surprised that PS26/18 says in more than one place that firms should obtain legal advice - a sentiment with which (perhaps, unsurprisingly) we wholeheartedly agree.

Welcome clarity on the meaning of "solely a record"

Section 3 of our April article The importance of paying attention: The FCA's consultation on cryptoassets perimeter guidance has been followed almost immediately by further legislative changes to the perimeter described our concerns that the draft PERG was not sufficiently clear as to the proper regulatory treatment of "mere record/register" tokens that operate as part of a register of securities under the ultimate, unilateral control of the issuer, its registrar or other third party performing register maintenance functions (including, powers or rectification and amendment).

Under such arrangements, it is entry of the holder on the relevant register (and not control of the token itself) that confers (and is the root of) title to the contractual rights constituted by the security with which the token is associated; and the rights, privileges or other benefits attached to the relevant security (e.g. to vote or receive dividends) vest in the holder of the security as identified by their entry on the register of securities. Such a token is unlikely itself to be intended to be a separate object of personal property rights; and control of such a token will not give a present, unconditional and absolute right to the controller to be entered on the register of securities.

Specifically, we have supported the view that, as the definition of "qualifying cryptoasset" (and, by reference, "(relevant) specified investment cryptoasset") excludes a token that is "solely a record of value or contractual rights", safeguarding activities relating to such a "mere record/register" token should properly be considered to fall outside the scope of the new Article 9N safeguarding activity. 

On these points, the FCA has helpfully expanded its guidance (which is now found at PERG 18.4.4) in a way which we think will give issuers and central securities depositories, for example, greater assurance that the analysis we set out in our April article is indeed correct, and that it is likely shared by the FCA. The key text here is:

"Where the ability to exercise or transfer value or contractual rights relating to the underlying asset attaches, in practice, to the controller of the cryptoasset, rather than by reference to a separate register, record or other mechanism, the cryptoasset is unlikely to be solely a record.

By contrast, a cryptoasset that does not function as an asset in its own right may be solely a record where it simply serves to identify value or contractual rights in another asset, and any transfer of the relevant value or contractual rights in the underlying asset is effected by reference to something other than the transfer of control of the cryptoasset itself."

Helpfully, this is an area that is unaffected by the Amending SI, so these firms can proceed with greater confidence.

Some helpful news for pure data, communications, and technology providers

Many participants in the cryptoasset ecosystem consider themselves to be solely technology businesses, rather than providers of financial services. As is increasingly common in digital finance, that line is not always easy to draw. In the cryptoasset world, this is especially the case when looking at the wide scope of arranging deals in qualifying cryptoassets (Article 9Y of the Regulated Activities Order).

The current legislative perimeter includes specific exclusions for persons that merely provide the means for parties to communicate. These exclusions are from the regulated activities of making arrangements with a view to a person dealing in qualifying cryptoassets, and arranging qualifying cryptoasset staking. In the case of the latter, there is also a somewhat carefully-drawn exclusion that applies to technical services that allow a person to stake their qualifying cryptoassets, where the service provider does not hold itself out as offering staking.

The FCA has now given fuller guidance (see in particular PERG 18.8.4, 18.8.22, 18.10.2, 18.10.9, and part of 18.6.2 and 18.6.3 as this issue relates to safeguarding) on how firms should assess whether their service crosses the line from a "mere" technology/communications/information service to become a regulated activity. Key text is found in PERG 18.10.9 (although this is consistent with text found elsewhere):

"The fact that a service is useful, convenient, commercially valuable or designed specifically for the cryptoasset sector does not, of itself, mean that the person is carrying on a regulated activity. The relevant question is whether the person is merely providing information, communications or technical functionality, or whether the service forms part of the arrangements by which transactions in qualifying cryptoassets are facilitated, brought about or otherwise enabled.

The presence of one or more of these features does not necessarily determine the outcome. The assessment depends on the service as a whole and the role a person performs in the relevant arrangements. The assessment is not dependent on the way a person describes themselves or on the terminology used."

For many firms, however, this may not change the analysis of their activities. This is a particular concern among firms engaging with decentralised finance (DeFi). This is one area where HM Treasury has helped (and we expect this to be reflected in the next PERG consultation). The Amending SI will add a new "technical services exclusion" from Article 9Y. However, this exclusion (to be added as Article 9Z2A) is not a total panacea and will need careful application. It will apply to a person who is not an authorised person or a payment service provider, providing a technical service that allows another person to access services provided by a third person (or decentralised protocol), as long as that third person/protocol is providing a regulated activity and is authorised or exempt, and/or is a decentralised protocol.

What this means in practice is that purely providing the technology that allows someone to access a DeFi protocol will not be regarded as arranging deals in qualifying cryptoassets. We expect this to be widely welcomed – although PERG will remain relevant to establishing whether the service is, in fact, "merely providing a technical service".

New commentary on advising on cryptoassets

As the FCA notes at PERG 18.8.10, there is no regulated activity of giving investment advice relating to qualifying cryptoassets (which will doubtless be good news for the numerous influencers who appear to do so). The fact that the FCA has felt the need to add text expressing this (although noting the obvious pitfalls around "advice" moving into arrangements) suggests to us that they have had a lot of questions about this.

The Amending SI brings further good news for payments firms…

As we explained in our April article, we were slightly disappointed by the somewhat narrow and restrictive approach taken by the FCA to the existing exclusion from the dealing and arranging activities for services that were connected to a sale of goods or supply of services. In that context (see section 1 of that article), we welcomed the fact that an earlier version of the Amending SI proposed to introduce a wider "payments" exclusion, which would assist where the firm was carrying out an activity comprising either a transfer of certain qualifying stablecoins, or their exchange for another asset.

The final Amending SI not only implements that proposed exclusion (which will be Article 9Z10A), it over-delivers with an additional exclusion that also represents a policy U-turn by HMT. What will be Article 9QA includes an exclusion from the regulated activity of safeguarding qualifying cryptoassets, which will apply where a "UK qualifying stablecoin" (see below) is "held temporarily in connection with the execution of a payment transaction." 

As we wrote in section 3 of a different article (To modernity and beyond! HM Treasury's consultation on payments regulation gives a thrilling glimpse of a high-tech future – if executed well), HMT's previously-stated position was that firms wishing to help businesses accept stablecoin payments, and that sit in the flow of "funds", would need the safeguarding permission. The addition of this exclusion reverses this position (for "UK qualifying stablecoins") and will (subject to the next paragraph) be welcomed by the many payment service providers looking to do exactly this. We will have to wait and see, however, what the perimeter, and relevant regulatory segregation or other safeguarding obligations, look like at the conclusion of the Modernising Payment Services Regulation programme.   

The remaining issue with both of the exclusions for payments firms is that they apply only where the stablecoin in question is a "UK qualifying stablecoin". Bluntly, there is currently no such thing: UK qualifying stablecoins are those qualifying stablecoins issued by a person with FCA permission to issue a qualifying stablecoin, and doing so under the new regime. In other words, until the FCA authorises a stablecoin issuer and it goes live, no firm can actually rely on these exclusions. More immediately, many firms are (unsurprisingly) looking to use the likes of USDC and USDT in their operations, given their existing status and reach in the market. At the risk of stating the obvious, USDC and USDT are not UK qualifying stablecoins.

For stablecoin payments, the FCA's first authorisation of an issuer of a qualifying stablecoin cannot come soon enough.

Something we noted in our April article was that the promised perimeter guidance on the distinction between qualifying stablecoins and electronic money was not in the consultation paper. It is not in PERG 18 either, but the FCA has committed to including it in their forthcoming consultation.   

…And for stablecoin issuers

The Amending SI also introduces a new Article 9QB, which contains a new exclusion from the safeguarding activity. Where an authorised stablecoin issuer makes arrangements relating to the backing assets held for the purposes of maintaining the value of the qualifying stablecoin, this will not trigger the need to obtain a safeguarding permission from the FCA under Article 9N(1).

Actions

Determining whether you need authorisation (and if so, for what activities), or can rely on an exclusion, or structure your business in such a way as to stay outside the regulatory perimeter (perhaps by placing yourself outside the territorial scope of the regime) is now an immensely pressing strategic imperative.

Applying later than 28 February 2027 will put the continuity of the business at risk on 25 October 2027 – firms in this situation will not be permitted to onboard new customers after that date if the FCA has not determined their application, and may end up having to run off their businesses.

Please speak to any member of the Travers Smith Fintech, Market Infrastructure & Payments practice for help in this rapidly developing field.        

get in touch

Read Mark Evans Profile
Mark Evans
Read Matt Humphreys Profile
Matt Humphreys
Read Natalie Lewis Profile
Natalie Lewis
Read James Turner Profile
James Turner
Back To Top Back To Top chevron up