COREPRU / CRYPTOPRU scoping
The UK cryptoasset regime is not in one instrument. Activity rules sit in CRYPTO across three policy statements, prudential rules in two new sourcebooks, and cross-cutting requirements somewhere else again. Tick the activities and see which rulebooks reach you, and which modules your authorisation application will need.
PS26/12 final rules · COREPRU and CRYPTOPRU · gateway opens September 2026 · perimeter expands 25 October 2027
Which rulebooks apply to this entity?
Runs in your browser · nothing uploadedAnswer for one legal entity. The FCA's own framing is that firms need an activity-by-activity rules map for each legal entity and service — no single policy statement is a complete compliance manual, and a group will not get one answer.
Step 1 — Regulated cryptoasset activities
Cryptoassets Regulations 2026Select every activity this entity will carry on. More than one is normal, and the combination is what decides the shape of both the rulebook map and the application.
Step 2 — Two questions that change the map
PS26/11 · PS26/13The gateway opens in September 2026. The UK capital module models the three-way own funds test and keeps it current as permissions change — with free monitoring to start.
Create free account →Four rulebooks, one firm
The regime is deliberately layered rather than consolidated. Knowing which layer a requirement lives in is most of the work of finding it.
CRYPTO — activity rules
Split across three policy statements: admissions, disclosures and market abuse in PS26/9; stablecoin issuance in PS26/10; and the regulated activities themselves, including trading platforms, intermediaries, safeguarding, staking and lending, in PS26/11.
COREPRU — common prudential
Core prudential requirements common across the different types of firm the FCA prudentially regulates. Not crypto-specific: it is the integrated base that sector sourcebooks sit on top of, and it applies to every in-scope firm.
CRYPTOPRU — sector specific
Supplements COREPRU with the requirements specific to regulated cryptoasset activities. Own funds are the higher of the permanent minimum requirement, the fixed overheads requirement, and an activity-based requirement built from K-factors — the same architecture as MIFIDPRU.
The rest of the Handbook
PS26/13 applies cross-cutting requirements with adjustments: Consumer Duty, COBS, SM&CR, systems and controls, operational resilience, safeguarding and regulatory reporting. Easy to overlook precisely because it is not in a crypto-named sourcebook.
Rules reviewed 21 August 2026 · PS26/12 published 30 June 2026 · Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026, passed 4 February 2026
Final rules, not yet in force
Three dates, and they are far apart. Firms are preparing applications now against rules that commence more than a year later.
SettledThe prudential rules
- PS26/12 confirms the finalised prudential rules for COREPRU and CRYPTOPRU. These are not proposals.
- The proposals were taken forward in the main, with targeted changes and clarifications after consultation feedback.
- Three substantive changes were made to the CP25/15 and CP25/42 proposals: the K-factors for issuing qualifying stablecoins, for net cryptoasset position, and consequentially for cryptoasset counterparty default.
- The operational risk K-factor for stablecoin issuance, K-SII, was reduced from the proposed 2% to 1%.
- The safeguarding K-factor was renamed, reflecting the perimeter extension to safeguarding both qualifying cryptoassets and specified investment cryptoassets.
- The permanent minimum requirement for issuers of qualifying stablecoins is £350,000.
Still movingGuidance and later work
- Non-Handbook guidance on the overall risk assessment in Chapter 7 of both sourcebooks — GC26/4 for COREPRU and GC26/5 for CRYPTOPRU. Consultation closed 30 July 2026.
- Further consultations are expected on financial crime requirements through the Financial Crime Guide, on the resolution of crypto custodians, and on tailored DeFi guidance.
- Tokenised asset custody and potential future CASS amendments remain under engagement.
- The ICARA terminology was replaced by the overall risk assessment before the rules were finalised. Material still using ICARA for crypto firms is out of date.
September 2026, then October 2027
The FCA plans to open its gateway for cryptoasset permission applications in September 2026, while the full scope of regulated activities expands from 25 October 2027. The final rules apply to firms authorised under FSMA on or after that date. The gap is deliberate preparation time — and it means an application is being written now against a rulebook that binds later.
Nothing you enter here leaves your browser
Every answer is evaluated on your own machine. Nothing is sent to REGREP, written to a log, saved to a database, or passed to any analytics tool.
That is deliberate. Your intended permissions are not something we want to hold.
About the two sourcebooks
What is the difference between COREPRU and CRYPTOPRU?
COREPRU is an integrated sourcebook covering the core prudential requirements common across the different types of firm the FCA prudentially regulates. Where necessary it is supplemented by sector-specific sourcebooks, of which CRYPTOPRU is one. A regulated cryptoasset firm is therefore reading both: the common base and the crypto-specific layer on top of it.
How is the own funds requirement structured?
As the higher of three measures: a permanent minimum requirement, a fixed overheads requirement, and an activity-based requirement built from a set of K-factors that scale with the risks the business actually generates. That is the same three-way test as the investment firm regime, which is why firms already inside MIFIDPRU find the architecture familiar even though the K-factors differ.
Are staking and lending separate authorisations?
They are business models rather than standalone firm categories. In its own analysis the FCA assumes firms conducting lending, borrowing or staking are authorised as either a trading platform or an intermediary firm. They still carry their own activity rules in PS26/11 — staking was amended to permit auto-staking with annual notification — and the authorisation form has modules for both.
Does CASS 17 apply to everything we hold?
No. CASS 17 was taken forward broadly as consulted, but the FCA decided not to apply it to the custody of relevant specified investment cryptoassets at this stage. RSIC custody remains subject to the existing CASS 6 requirements for now, so a firm holding both is operating under two custody regimes at once.
Can we still rely on our reading of the consultation papers?
Only with care. The rules were finalised on 30 June 2026 with targeted changes, and at least three are substantive enough to change a number: the stablecoin issuance K-factor halved from 2% to 1%, the net cryptoasset position K-factor changed with a consequential change to cryptoasset counterparty default, and the safeguarding K-factor was renamed. A model built from CP25/15 or CP25/42 will look structurally right and be numerically wrong.
What does an application actually require?
The FCA published a preview of the application form in July 2026. It combines the standard information required from most FSMA applicants with activity-specific modules for stablecoin issuance, safeguarding, staking, lending and borrowing, intermediation, and operating a qualifying cryptoasset trading platform. The activity mix therefore drives the shape of the application as well as the rulebook map.
Final rules. A gateway opening. Fourteen months to commencement.
Create a free account and model the three-way own funds test now, so the capital position is not discovered during the application.
No card required · free tier on core modules · nothing stored from this tool