Customer Event | MCO Customer Roadshow Europe 2026 – Registration is now open
Customer Event | MCO Customer Roadshow Europe 2026 – Registration is now open
Australian financial services firms are reaching the end of their runway to comply with digital asset regulation set by the Australian Securities and Investments Commission (ASIC). There’s little time left for firms that are sheltering under ASIC’s sector-wide no-action position, which applies to providers of digital asset-related financial products and services. On 02 September 2026, the regulator issued its final warning.1 Firms must apply for an Australian Financial Services (AFS) licence by 30 September, or widen the one you already hold.
After that date, the shelter disappears. From 1 October, any firm that needed a licence or a variation, but did not meet the terms ASIC set out, risks breaching financial services law and could face civil and criminal penalties with fines of up to 10% of annual turnover.
ASIC already shifted the cut-off date once, pushing back the original 30 June 2026 deadline by three months as a pragmatic answer to industry transition challenges.2 Firms should not risk holding out any longer.
For compliance professionals seeking broader context on how Australia’s digital assets regulatory landscape has evolved to reach this point, MCO's article Australia: Defining the Next Phase of Crypto Regulation provides a useful overview.
“From 1 October, firms that need a licence or variation to their existing authorisation but have not met the conditions of ASIC’s no-action position risk breaching financial services law and could face civil and criminal penalties. This includes potential fines reaching up to 10% of annual turnover.”
ASIC, May 2026
Since October 2025, ASIC has operated a class no-action position attached to Information Sheet 225 (INFO 225), Digital assets: Financial products and services3. The regulator asked the market about transitional arrangements the previous December, and accepted that firms would need time to read the guidance and shift across to licensing.4
Then on 25 June 2026, ASIC stretched the deadline and cast the net wider. It now includes digital asset businesses working under, or signing up to, authorised representative arrangements and intermediary authorisation arrangements with an AFS licence holder.
Trading venues and infrastructure operators face another challenge. Firms needing an Australian Market Licence or a Clearing and Settlement (CS) facility licence must tell ASIC in writing that they intend to apply, along with a pre-application meeting, both by the 30 September deadline.

The numbers tell their own story. In late June 2026, ASIC had logged roughly 30 licence applications from businesses wanting digital asset licensing authorisations.2 In its 02 September 2026 announcement, it put that revised total at over 45. Around fifteen firms took action within that ten-week window, indicating sizeable time and effort involved in making the transition.
An AFS licence application relies on responsible managers who can show they know the products, prove the firm holds enough capital, and provide evidence of appropriate compliance procedures and documentation.
Regardless of the effort involved, firms must act now if they have not already. Any further delay risks leaving the firm in a position where it is selling products its licence no longer covers. Waiting for the rules to settle is by no means a defensible play when regulators come knocking.
Firms assuming a product wrapper might sit outside the regulatory perimeter are making the wrong assumption. In June 2026, the High Court of Australia determined that a fixed-yield digital asset product sold by an Australian provider was a financial product, and it needed an AFS licence.5 ASIC brought the appeal, and the High Court overturned a 2025 Full Federal Court decision with a unanimous 7-0 ruling.
The Court looked at what the deal actually did with investor money rather than how the firm marketed it. It also agreed the product was a derivative, since the sum investors received back moved with the price of the digital asset and with exchange rates.
“This reinforces ASIC’s long-standing position that the definition of financial product is broad and technology neutral and so captures new and emerging products without the need to amend the legislation.”
ASIC Chair Sarah Court
The wholesale/retail distinction affects certain licence conditions and consumer protection obligations, but not the question of whether a licence is required at all. Wholesale-only digital asset service providers must still hold an AFS licence and must still apply by 30 September 2026.4

There are four actions a business may need to take before 30 September 2026, depending on its current position.

Paths 1 and 2 cover the great majority of digital asset firms. Paths 3 and 4 apply to a smaller set of trading venues and infrastructure operators. Firms uncertain about which path applies should engage legal counsel immediately.
Two regulatory regimes are converging, and firms need to plan for both. The current AFS licensing regime applies now. The Corporations Amendment (Digital Assets Framework) Act 2026 commences on 9 April 2027, creating new authorisations for digital asset platforms (DAPs) and tokenised custody platforms (TCPs).6
ASIC has confirmed that many existing authorisations will still be required once the new framework commences. Firms licensing now are building the foundation that the later regime will sit on.
ASIC’s implementation roadmap sets out what follows. Consultation on operational standards runs through late 2026, with regulatory guides for platform and custody operators expected in the first quarter of 2027. Licence applications for the new categories open from April 2027, and the transition window closes in October 2027.
The sequence may already appear familiar to firms operating across the APAC region. Regulators in Hong Kong and Singapore applied existing financial services law to digital assets first, then layered purpose-built regimes over the top. Firms with APAC-wide operations may want to plan now for comparable timelines and comparable demands for evidence.
The immediate question for compliance teams is a narrow one. Does the firm provide a financial service in relation to a digital asset? Where the answer is yes, or where it remains unsettled, the firm should lodge before 30 September.
Beyond that date, the obligation becomes an operational one. Firms must keep their authorisations aligned with what the business actually does, and evidence that alignment when ASIC asks. Digital asset activity now sits inside the regulated perimeter, and ASIC has signalled it will supervise and enforce accordingly.
The 30 September 2026 deadline brings a compliance programme management challenge. Compliance functions must determine licensing scope, document responsible managers, map services to authorisations, maintain financial resources evidence, and track the next phase of the DAF Act rollout. All of this sits alongside existing obligations across AML/CTF, conduct, and employee oversight.
Managing that workload can become manually intensive and time-consuming. Australia’s digital assets framework includes obligations across ASIC licensing and AUSTRAC’s expanded AML/CTF regime. Compliance teams need to track obligations across both regimes without relying on fragmented spreadsheets and siloed records.
Regulatory technology solutions such as MCO (MyComplianceOffice) provide a centralised system for managing compliance obligations across multiple jurisdictions and regulators. As a complete compliance management suite, MCO also gives compliance teams a single view of employee activity, regulatory obligations, licensing requirements and status, and much more as they evolve through each phase of ASIC’s implementation roadmap.
For firms whose employees hold or trade digital assets, MCO's Digital Asset Personal Trading solution provides a purpose-built workflow for managing employee personal trading in digital assets and cryptocurrency. This is a particularly relevant capability as AFS licence obligations bring greater scrutiny to conflicts of interest and employee conduct. With the Digital Asset Personal Trading solution, compliance teams can:
MCO's broader Know Your Employee Compliance Suite provides an integrated solution for monitoring, identifying, and addressing conflicts of interest and code of conduct issues. These obligations do not pause while a firm works through its AFS licensing requirements. The outcome is less time spent managing disparate compliance processes and more capacity for the substantive risk oversight that Australia’s evolving framework now demands.
Are you ready to help your firm meet evolving regulatory expectations? See the MCO complete compliance suite in action now.
Also, see our in-depth crypto regulation compliance article, which includes the latest updates across Singapore, Australia, the United States, the United Kingdom, and more.
Digital asset regulation in Australia runs through existing financial services law. Where a digital asset or a related service meets the definition of a financial product under the Corporations Act, the provider needs an AFS licence. ASIC's INFO 225 explains how those definitions apply. A purpose-built regime for digital asset platforms and tokenised custody platforms starts on 9 April 2027.
Firms relying on ASIC's no-action position must apply for an AFS licence, or vary an existing licence, by 30 September 2026. Firms needing an Australian Market Licence or a Clearing and Settlement facility licence face a further step. They must notify ASIC in writing of their intention to apply, and hold a pre-application meeting, by the same date.
From 1 October 2026, firms that need a licence or variation but have not met the conditions of the no-action position risk breaching financial services law. ASIC has confirmed the exposure. Civil and criminal penalties apply, including fines reaching up to 10% of annual turnover.
RegTech platforms pull the controls behind a licence into one place. For digital assets, the capabilities that matter include wallet discovery, blockchain activity capture, pre-clearance of employee trades, policy attestation, and audit-ready reporting. MCO's Digital Asset Compliance solution runs these through a single supervised workflow.