Cryptoassets

FCA Crypto Prudential Requirements 2026: Capital and Financial Resource Rules Explained

Regulatory Counsel · July 2026 · 14 min read

Key Takeaways

  • Permanent minimum capital requirements range from £75,000 for dealing as agent to £750,000 for dealing as principal, with £150,000 for custody, staking and trading-platform activities and £350,000 for stablecoin issuance.
  • The permanent minimum is a floor — the actual own funds requirement depends on the higher of the fixed overheads requirement, K-factor requirements and the overall risk assessment.
  • K-RCS (0.04% of relevant cryptoassets safeguarded), K-SII (1% of stablecoins in issuance), K-CTF, K-CCO, K-CCS, K-NCP, K-CCD and K-CON make capital scale with activity.
  • At least 56% of own funds must be CET1 and at least 75% CET1 plus AT1 — shareholder loans and informal funding do not automatically qualify.
  • Basic liquid assets requirement is one-third of fixed overheads plus 1.6% of qualifying guarantees, with additional issuer liquid assets requirements for qualifying stablecoin issuers.

The FCA’s new prudential regime introduces formal capital and liquidity requirements for cryptoasset firms entering full FSMA regulation in the UK.

Under the new framework, firms will not simply need to meet a single fixed minimum capital figure. The actual requirement depends on the permissions held, operating costs, transaction volumes, cryptoassets safeguarded, market exposures and the wider risk profile of the business.

The FCA published its final prudential rules in June 2026 through COREPRU and CRYPTOPRU. These rules will apply to authorised cryptoasset firms when the new regime commences on 25 October 2027 and are a central part of the FCA authorisation assessment.

For applicants, capital planning should therefore begin well before submission. A firm that meets the headline permanent minimum requirement but cannot satisfy its fixed overheads, K-factor, liquidity or overall financial adequacy requirements will not have sufficient regulatory resources.

Crypto permanent minimum capital requirements

The FCA has set different permanent minimum requirements according to the activities a firm is authorised to carry on.

Regulated cryptoasset activityPermanent minimum capital requirement
Dealing in qualifying cryptoassets as principal£750,000
Issuing a qualifying stablecoin£350,000
Safeguarding cryptoassets£150,000
Operating a qualifying cryptoasset trading platform£150,000
Arranging qualifying cryptoasset staking£150,000
Dealing in qualifying cryptoassets as agent£75,000
Arranging deals in qualifying cryptoassets£75,000

Where a firm holds several permissions, the permanent minimum requirement is generally the highest applicable amount rather than the sum of every minimum.

A firm authorised for both custody and dealing as agent, for example, would start with the higher £150,000 custody minimum rather than adding £150,000 and £75,000 together.

This figure is only the starting point.

The permanent minimum is not the final capital requirement

One of the most important points for applicants is that the permanent minimum requirement is not necessarily the amount of capital the firm must hold.

The firm must calculate its own funds requirement under the wider COREPRU and CRYPTOPRU framework.

This can include the permanent minimum requirement, fixed overheads requirement and applicable K-factor requirements. Depending on the firm’s activities and scale, the formulaic requirement can rise substantially above the headline minimum.

The FCA then requires the firm to assess whether even that amount is sufficient in light of its specific risks and wind-down needs.

A business plan that simply states “minimum capital is £150,000” without modelling the wider prudential framework is therefore incomplete.

Fixed overheads requirement

The fixed overheads requirement is designed to ensure that the firm holds sufficient capital relative to the cost base required to operate and, where necessary, wind down.

The standard calculation is one quarter of the firm’s relevant expenditure during the preceding year, subject to the detailed COREPRU rules and adjustments.

For a new business without a full year of historical expenditure, the calculation is based on the relevant forecast information under the applicable rules.

This can materially increase the required capital for businesses with substantial staffing, technology, compliance and infrastructure costs.

For example, a crypto custodian may have a £150,000 permanent minimum requirement but annual relevant expenditure that produces a fixed overheads requirement of £600,000. The firm must then consider the higher applicable figure rather than assuming the £150,000 floor is sufficient.

Financial forecasts therefore directly affect regulatory capital planning.

K-factors make capital scale with regulated activity

The FCA has introduced K-factors to link capital more closely to the volume and risk of specific cryptoasset activities.

These are designed so that a growing firm generally holds more capital as the scale of regulated activity increases.

Relevant K-factors include:

  • K-SII for stablecoins in issuance.
  • K-RCS for relevant cryptoassets safeguarded.
  • K-CCS for client cryptoassets staked.
  • K-CCO for cryptoasset client orders.
  • K-CTF for cryptoasset trading flow.
  • K-NCP for net cryptoasset positions.
  • K-CCD for cryptoasset counterparty default.
  • K-CON for concentration risk.

Not every K-factor applies to every firm.

A custody business may be particularly affected by K-RCS, while a trading platform or intermediary can have different operational and exposure-based requirements.

The application should therefore identify precisely which K-factors apply to the proposed activities and model them using realistic forecast volumes.

K-RCS for [cryptoasset custody](/insights/crypto-custody-fca-authorisation-2026)

A firm safeguarding cryptoassets is subject to the K-RCS requirement.

The requirement is equal to 0.04% of the firm’s average relevant cryptoassets safeguarded, calculated in accordance with CRYPTOPRU.

This means capital can rise significantly as assets under custody grow.

A custodian safeguarding £1 billion of relevant cryptoassets would have a K-RCS amount of approximately £400,000 before considering the permanent minimum, fixed overheads and any other applicable requirements.

The FCA also prevents firms from avoiding this exposure simply by appointing a third-party custodian where the authorised firm has undertaken to safeguard the assets for its clients. Relevant assets can still be included in the K-RCS calculation.

The prudential model must therefore reflect the true scale of custody responsibility.

K-SII for [qualifying stablecoin issuers](/insights/fca-stablecoin-authorisation-2026)

Qualifying stablecoin issuers are subject to a K-factor based on stablecoins in issuance.

The final K-SII requirement is 1% of average qualifying stablecoins in issuance, calculated under the detailed CRYPTOPRU methodology.

This can become a significant capital driver for a large issuer.

A stablecoin business should therefore model capital requirements against the expected value of tokens in circulation rather than focusing only on the £350,000 permanent minimum.

The regulatory capital requirement also sits alongside the separate backing-asset and liquidity framework applying to the stablecoin itself.

This distinction matters because backing assets protect tokenholders and support redemption, while the issuer’s own funds provide loss-absorbing capacity for the business.

K-CCS for staking

Firms arranging qualifying cryptoasset staking can be subject to K-CCS.

The requirement is calculated at 0.04% of average client cryptoassets staked, subject to rules designed to prevent inappropriate double-counting where the same assets are already included within custody K-factors.

A staking provider that also safeguards the underlying client assets therefore needs to understand how K-RCS and K-CCS interact.

The FCA’s framework recognises that the same cryptoassets should not necessarily generate duplicate operational-risk capital where the relevant exposure is already captured.

However, the firm’s overall risk assessment must still consider material staking risks that may not be reflected fully by the formulaic K-factors.

Protocol risk, slashing, validator failure, liquidity restrictions and third-party dependencies may all require additional consideration.

K-CCO and K-CTF for trading and intermediary businesses

K-CCO applies to relevant cryptoasset client orders, while K-CTF relates to cryptoasset trading flow.

The FCA has aligned these concepts broadly with prudential approaches used in traditional investment markets while adapting them to cryptoasset activities.

K-CCO is based on average client order activity and applies to relevant order-handling services.

K-CTF is calculated at 0.1% of average cryptoasset trading flow and captures relevant transactions entered into in the firm’s own name.

These requirements can become important for high-volume exchanges, brokers and intermediaries even where the firm’s permanent minimum capital is comparatively modest.

Forecast volumes used in the FCA application should therefore be credible. An applicant cannot reasonably project rapid growth in trading activity while assuming capital remains permanently at the initial minimum.

Dealing as principal carries the highest permanent minimum

The permanent minimum requirement for dealing in qualifying cryptoassets as principal is £750,000.

This reflects the additional balance-sheet, market and counterparty risks created where the firm trades in its own name and assumes direct exposure.

Principal trading firms may also be subject to exposure-based K-factors, including requirements linked to net cryptoasset positions, counterparty default and concentration.

The prudential framework therefore becomes more complex than the headline £750,000 floor.

Businesses combining principal dealing with exchange, brokerage or other activities should model each component carefully.

The authorisation strategy should also consider whether principal activity is genuinely required within the business model, because it can materially change both the permission profile and capital burden.

Own funds quality matters

Not every source of funding automatically qualifies as regulatory capital.

COREPRU sets requirements governing the quality and composition of own funds. Regulatory capital can include Common Equity Tier 1, Additional Tier 1 and Tier 2 instruments subject to the relevant criteria and limits.

The FCA places greatest reliance on Common Equity Tier 1 capital because it provides the strongest form of loss absorption.

At least 56% of the firm’s own funds requirement must generally be met with CET1 capital, while CET1 plus Additional Tier 1 must represent at least 75% of the requirement. The full own funds requirement must be met with eligible regulatory capital.

Shareholder loans, informal funding commitments or ordinary commercial debt therefore cannot automatically be treated as regulatory capital.

Applicants should confirm the regulatory treatment of proposed funding instruments before relying on them in the application.

Deductions and prudential adjustments

A firm’s accounting equity is not necessarily the same as its regulatory own funds.

COREPRU requires deductions and adjustments to ensure that capital genuinely provides loss-absorbing capacity.

Certain intangible assets, losses, holdings or other balance-sheet items can reduce the amount recognised for regulatory purposes.

This means a company can appear well capitalised in its statutory accounts while having materially less eligible regulatory capital.

The prudential calculation should therefore be based on FCA definitions rather than simply copying the balance-sheet equity figure.

Applicants should reconcile financial forecasts, accounting treatment and regulatory capital calculations carefully.

Basic liquid assets requirement

Cryptoasset firms must also maintain liquid resources.

Under COREPRU, the basic liquid assets requirement is generally equal to one-third of the firm’s fixed overheads requirement plus 1.6% of any qualifying guarantees provided to clients, subject to the detailed rules.

This requirement is separate from the own funds calculation.

Capital may absorb losses, but a firm can still fail if it does not have enough liquid resources to meet obligations as they fall due.

The FCA therefore requires firms to maintain appropriate core liquid assets and assess whether additional liquidity is needed for business operations, stress and wind-down.

Applicants should not assume that money used to satisfy regulatory capital automatically solves all liquidity requirements.

Stablecoin issuers have additional liquidity requirements

Qualifying stablecoin issuers face an additional sector-specific liquidity framework.

This reflects the need to support redemption and manage liquidity risk within the stablecoin backing asset pool.

The issuer must assess the liquidity characteristics of backing assets and calculate its issuer liquid assets requirement under CRYPTOPRU.

Longer-dated or less liquid assets can generate higher liquidity charges than cash or highly liquid instruments.

The stablecoin issuer must therefore manage several separate concepts simultaneously: fully backing the stablecoin, maintaining sufficient liquidity to redeem it and holding adequate regulatory own funds for the issuing business.

These requirements should be modelled together rather than in isolation.

Overall risk assessment

Formulaic capital requirements are not the end of the prudential process.

Cryptoasset firms must carry out an overall risk assessment under COREPRU and CRYPTOPRU.

The purpose is to determine whether the minimum own funds and liquidity amounts produced by the standard calculations are actually sufficient for the firm’s specific risks.

The assessment should consider both ongoing operations and an orderly wind-down.

A firm may therefore conclude that it needs more resources than the permanent minimum, fixed overhead and K-factor calculations suggest.

The FCA can also assess whether the firm’s conclusions are credible and whether its resources remain adequate under the threshold conditions and Principle 4.

For applicants, the overall risk assessment should be integrated into the business plan, financial forecasts and wind-down framework.

Wind-down resources

The FCA expects cryptoasset firms to be capable of exiting the market without causing material harm.

Wind-down planning therefore has a direct prudential dimension.

The firm should estimate the costs of ceasing regulated activities, maintaining essential staff and systems, communicating with customers, closing contracts, returning client assets and meeting regulatory obligations during the exit period.

A crypto custodian may need to maintain wallets and key infrastructure until all assets have been returned or transferred.

A trading platform may need to manage open positions, customer withdrawals and market communications.

The resources needed for wind-down can exceed the simplistic assumption that the business can simply stop trading and dismiss staff immediately.

Prudential planning for new applicants

New applicants face an additional challenge because they do not have long operating histories from which to calculate expenditure or activity volumes.

The FCA therefore relies heavily on forecasts.

Those forecasts should be realistic, internally consistent and supported by the business plan.

If the application projects rapid customer growth, billions in assets under custody or substantial trading volume, the prudential calculations should reflect the capital and liquidity consequences of that growth.

Applicants should model regulatory capital throughout the forecast period, not simply at the date of authorisation.

The funding plan should also explain when additional capital will be raised and how the firm will remain above regulatory requirements as the business scales.

Multi-permission firms

Many cryptoasset firms will hold more than one regulated permission.

An exchange may operate a trading platform, safeguard customer cryptoassets, arrange transactions and deal as agent. A stablecoin business may issue tokens and also provide custody or intermediary services.

The permanent minimum requirement is generally based on the highest applicable activity-specific minimum, but K-factors and other prudential requirements can accumulate according to the activities carried on.

The prudential framework should therefore be modelled across the whole firm rather than one permission at a time.

Groups also need to consider whether other prudential regimes apply to the same legal entity.

Where a firm is already subject to MIFIDPRU or another FCA prudential sourcebook, COREPRU and CRYPTOPRU contain interaction rules that need to be considered carefully.

Overseas firms and UK authorisation

International crypto firms carrying on regulated activities in the UK may also become subject to UK prudential requirements.

The FCA’s approach to international firms considers whether an overseas applicant has sufficient UK presence, governance and financial resources to be supervised effectively.

The prudential analysis should therefore consider both the local UK entity and wider group dependencies.

A UK business that relies entirely on parent-company funding should have clear and credible arrangements demonstrating how resources will remain available when needed.

Group guarantees or informal commitments do not necessarily replace eligible own funds held by the authorised firm.

International applicants should therefore structure capital and liquidity arrangements specifically around the UK regulatory entity.

Common prudential application mistakes

A frequent mistake is treating the permanent minimum requirement as the total capital required.

Another is preparing financial forecasts without calculating how growth affects fixed overheads, K-factors and liquidity.

Applicants can also rely on funding instruments that do not qualify fully as own funds or assume that parent-company support automatically satisfies UK regulatory capital requirements.

Inconsistency between forecasts and prudential calculations is another common weakness. Transaction volumes, assets under custody, staffing and expenditure assumptions should match across the application.

The prudential section should therefore be built from the same operating assumptions as the wider business plan.

The FCA should not receive one growth story in the commercial forecast and a completely different risk profile in the capital calculations.

What should firms do now?

Firms preparing for authorisation should identify all proposed permissions and map the applicable prudential requirements.

They should then build a forecast model covering permanent minimum capital, fixed overheads, relevant K-factors, basic liquidity, sector-specific liquidity and the wider overall risk assessment.

The model should run through the full forecast period and include credible downside scenarios.

The board should understand how much capital the business needs at launch and how that requirement changes as the business grows.

Existing MLR-registered firms should complete this work early because the prudential framework may require substantial additional funding compared with their current regulatory arrangements.

Capital raising completed after the application has been submitted can create delay if the FCA is not satisfied that the firm has secure resources.

How Regulatory Counsel can help

Regulatory Counsel supports cryptoasset applicants with the full prudential workstream required for FCA authorisation.

We identify the applicable COREPRU and CRYPTOPRU requirements based on the permissions sought and develop the capital and liquidity framework alongside the wider regulatory business plan.

Our work can include permanent minimum capital analysis, fixed overhead calculations, K-factor modelling, financial forecasts, liquidity requirements, overall risk assessment, wind-down resources and regulatory capital planning.

We also ensure that prudential assumptions align with the firm’s customer forecasts, transaction volumes, custody assets, staffing, technology expenditure and growth strategy.

Where the applicant requires several cryptoasset permissions, we model the combined prudential impact rather than considering each activity in isolation.

The objective is to demonstrate to the FCA that the business has sufficient financial resources not only to obtain authorisation but to remain compliant as it grows.

Contact Regulatory Counsel to discuss CRYPTOPRU, FCA crypto capital requirements or the prudential workstream for a cryptoasset authorisation application.

Frequently Asked Questions

It depends on the regulated activities carried on. Permanent minimum requirements range from £75,000 for dealing as agent or arranging deals, to £150,000 for custody, staking and trading-platform activities, £350,000 for qualifying stablecoin issuance and £750,000 for dealing as principal.

No. The firm must also consider its fixed overheads requirement, applicable K-factor requirements and the outcome of its overall risk assessment. The actual requirement can therefore be materially higher than the headline permanent minimum.

The standard fixed overheads requirement is generally one quarter of the firm’s relevant annual expenditure, calculated under the detailed COREPRU rules. For a growing or cost-intensive business, this can exceed the permanent minimum capital requirement.

K-RCS is the capital requirement linked to relevant cryptoassets safeguarded. It is calculated at 0.04% of average relevant cryptoassets safeguarded under the CRYPTOPRU methodology.

Yes. Cryptoasset firms are subject to liquid asset requirements in addition to own funds requirements. They must also assess whether additional liquidity is required for ongoing operations, stress scenarios and an orderly wind-down.

Need Expert Advice?

Free initial consultation. No obligation.

Speak to an Expert