The FCA crypto gateway is open and MiCA grandfathering has ended. Which senior roles to hire, in what order and where, before you apply.
Before you apply for FCA authorisation or a MiCA CASP licence, you need named, credible people in four seats: a chief executive who runs the regulated entity, a compliance oversight lead, a money laundering reporting officer (MLRO), and a board with the collective knowledge to challenge them. In the UK those people become approved senior managers under SM&CR. In the EU they form a management body that must be of sufficiently good repute and genuinely located in the Union. Hire them before you write the application, not after.
This guide is for founders and CEOs of exchanges, custodians, brokers and stablecoin issuers.
The UK window is open now. The FCA opened its authorisation gateway on 30 September 2026. The application period closes on 28 February 2027, and the new regime comes into force on 25 October 2027. From that date, carrying on a regulated cryptoasset activity in the UK without authorisation is unlawful.
Three points matter for planning:
In the EU, the grandfathering period has already ended. Article 143(3) of MiCA allowed CASPs operating under national law before 30 December 2024 to continue until 1 July 2026 at the latest, and member states could shorten or remove that window. As of today, any firm serving EU clients without MiCA authorisation (or a valid Article 60 notification as an existing financial entity) has no transitional cover.
The FCA confirmed in PS26/13, published on 30 June 2026, that it will apply SM&CR in full to authorised cryptoasset firms: senior management functions (SMFs), certification functions, prescribed responsibilities and the conduct rules.
Most crypto firms will be Core firms. The FCA's guide for solo-regulated firms lists the Core SMFs:
Core firms must also allocate prescribed responsibilities to those senior managers, including responsibility for financial crime policies and, where relevant, compliance with CASS. PS26/13 confirms custodians must give that CASS responsibility (PRz) to an individual SMF, covering both traditional and crypto safe custody.
Enhanced status will be rare at launch. The FCA set the threshold at £100bn in client cryptoassets and safe custody assets for custodians, and £20bn in backing assets (three-year rolling average) for UK qualifying stablecoin issuers. It does not expect many, if any, crypto-only firms to hit Enhanced when the regime starts.
On certification, the FCA will use a "modification by consent" waiver during the gateway, deferring assessment of Certification Regime compliance while the wider SM&CR review runs. In April 2026 the FCA and PRA noted the Government's proposal to remove the Certification Regime from legislation. Staff in significant roles still need to be fit and proper; just do not over-engineer a process that may be dismantled.
MiCA sets the standard in Article 68. Members of the management body must be of sufficiently good repute and have the appropriate knowledge, skills and experience, individually and collectively. They must not have convictions for money laundering, terrorist financing or other offences affecting good repute, and must show they can commit sufficient time. The CASP must also employ personnel with the expertise its services require.
The suitability test is set out in the joint EBA and ESMA guidelines on management body members and qualifying holders under MiCA. The sharper practical guidance is in ESMA's supervisory briefing on CASP authorisation (January 2025), which tells national authorities what to look for. Its people expectations include:
Article 59(2) requires a registered office in a member state where the CASP provides services, a place of effective management in the Union, and at least one director resident in the Union. ESMA's briefing goes further: the EU entity must be able to take decisions autonomously, meet its regulator without a group representative in the room, and keep key roles predominantly in the home jurisdiction. Outsourcing that turns the entity into a letter-box is grounds for rejection.
Stablecoin issuers face a separate route. Issuers of e-money tokens must be authorised as a credit institution or electronic money institution under Article 48, while asset-referenced token issuers face the same good repute and competence test for their management body under Article 34.
Hire in the order the regulator will test you. A sensible sequence:
For trading-venue operating roles, see our exchanges and venues practice.
Partly, but the key control functions should not be. In PS26/13 the FCA says it may approve overseas-based SMFs, for example a group executive responsible for UK strategy. Its general expectation, though, is that "mind and management" sits in the UK. It particularly considers physical location for SMF16 and SMF17 and expects those holders to work from the firm's UK principal place of business. Firms that are part of a global group should also read the FCA's guidance on its approach to international cryptoasset firms.
MiCA is stricter on paper. ESMA's briefing says staff outside the country of authorisation are acceptable in supporting roles such as non-management IT and HR, but key roles should be predominantly in the home jurisdiction and management must remain accessible to the national authority.
Use interim where it buys you time, not where it signals a gap. Interim compliance professionals can build the policy suite and draft the application, but the people named in your application are the people the regulator assesses. If your SMF16 or MLRO is an interim who leaves after authorisation, you are back to finding, onboarding and seeking approval for a replacement while live.
A practical model: interim to build, permanent to apply. Bring in interim support early to prepare the documentation, and run the permanent search in parallel so the permanent holder is in place, and ideally has reviewed the application, before it goes in.
Work backwards from your filing date. Three clocks stack up:
With the UK window closing on 28 February 2027, a firm that has not yet started its SMF16 or MLRO search is already tight. Respondents to the FCA's consultation flagged the cost of recruiting UK-based SMF holders and questioned whether a 6 to 12 month implementation period was realistic, suggesting some requirements could take 12 to 18 months.
The people problems that hold applications back are predictable:
The last point is not theoretical. Austria's FMA granted KuCoin EU Exchange GmbH MiCA authorisation on 27 November 2025, then banned it from new business from 19 February 2026 because key functions, including the AML officer and sanctions compliance officer, were not properly filled. The FMA lifted the new business ban on 18 May 2026 once those roles were filled, but said commencement of business remained prohibited pending governance requirements and additional senior management key functions. Succession planning for named control functions belongs in your application plan, not your post-licence to-do list.
Start with a gap analysis of people, not policies: list every SMF or key function the regime requires, name who will hold it, where they will sit, and whether they would pass a fit and proper interview today. Then hire into the gaps in order of regulatory scrutiny.
Spearpoint Search runs retained searches for digital asset and crypto leadership, including compliance, MLRO and regulated-entity CEO roles, and will tell you plainly if your compensation or structure will not attract the people a regulator expects. For benchmarks, see our compensation guide. For Sam's deeper take on how licences are lost through people rather than capital, read Who killed the licence? in Talent Before Capital.
This article is general information, not legal or regulatory advice. Requirements vary by firm, activity and jurisdiction, and regulators update their rules and guidance. Take advice from qualified counsel before applying.
The FCA's application window runs from 30 September 2026 to 28 February 2027, and the new cryptoasset regime comes into force on 25 October 2027. Existing firms that apply within the window can keep operating while their application is determined. Firms that miss it and are not authorised by go-live can only perform pre-existing contracts. MLR registration does not convert automatically.
Yes. In PS26/13 the FCA confirmed it will apply the Senior Managers and Certification Regime in full to authorised cryptoasset firms. Most will be Core firms needing an approved Chief Executive (SMF1), executive directors (SMF3), a Chair (SMF9), Compliance Oversight (SMF16) and an MLRO (SMF17). Enhanced status applies only above high custody or stablecoin backing-asset thresholds.
In the UK, one person can hold both SMF16 and SMF17 if they are approved for each, and this is common in smaller firms. Only do it where the capacity is genuine. Under MiCA, ESMA expects at least one dedicated compliance lead, and the AML/CFT compliance officer must meet EBA guidelines, so check expectations with your national authority.
Article 59 of MiCA requires a CASP's place of effective management to be in the Union and at least one director to be resident in the Union. ESMA's supervisory briefing goes further, expecting at least one executive board member resident in the member state granting authorisation, key roles mainly based there, and a CEO who, as a rule, works full time for the CASP.
No. Article 143 allowed crypto-asset service providers operating under national law before 30 December 2024 to continue until 1 July 2026 at the latest, and some member states set shorter periods. That window has now closed, so a firm serving EU clients needs MiCA authorisation, or a valid notification if it is an existing regulated financial entity.