Quick Answer: Three announcements this week point to the same shift in digital-asset infrastructure. UK authorization is becoming a defined operational project, Circle has put Arc into public mainnet, and S&P Global has moved to acquire smart-contract security firm OpenZeppelin. Treasury teams now have better infrastructure choices, but provider diligence must cover regulatory permissions, settlement design, and technology risk as separate questions.
1. The FCA turns crypto authorization into a dated workstream
The UK Financial Conduct Authority published final perimeter guidance on September 16. The guidance explains which cryptoasset activities may require authorization under the country's future regime. The application window opens on September 30, 2026 and closes on February 28, 2027. The regime takes effect on October 25, 2027.
The timing creates a practical divide. Firms that apply during the window may qualify for transitional arrangements while the FCA assesses their applications. Existing registrations and permissions do not convert automatically. A firm registered under the Money Laundering Regulations, or already authorized for payment or electronic-money services, still has to determine whether its cryptoasset activities require a new permission or a variation of permission.
The perimeter covers activities such as issuing qualifying stablecoins, safeguarding cryptoassets, operating a trading platform, arranging deals, and staking. It can also apply to overseas firms serving UK consumers. Each business therefore needs a map of its actual role in the payment chain. Marketing a crypto-enabled service, controlling customer assets, arranging a transaction, and supplying software can produce different regulatory outcomes.
For a corporate buyer, an FCA registration number or a general statement about compliance is no longer enough. Procurement should ask which legal entity performs each regulated activity, which permissions it expects to hold, and what happens if its application is pending or refused. Contract language should then match that responsibility map.
2. Circle moves Arc from test environment to public mainnet
Circle launched the public mainnet of Arc on September 16. The company describes Arc as a Layer 1 network built for financial markets and real-time money movement. Its founding validator group includes BlackRock, DTCC, ICE, Mastercard, MoneyGram, Standard Chartered, Visa, and other financial and payment institutions. Circle also reported more than 100 applications and more than 100 institutional and ecosystem builders at launch.
The validator list is commercially relevant because it shows established institutions taking direct roles in a new settlement network. It does not prove that Arc is suitable for every treasury flow. A mainnet launch begins the operating record that risk teams need to examine.
Finance and payment teams should test the network at the level of a specific use case. They need to know which asset settles the obligation, when settlement becomes final, who pays network fees, and how a failed or delayed transaction is reconciled. They also need a recovery process for incorrect addresses, screening holds, smart-contract faults, and chain outages. A fast network can shorten transfer time while leaving funding cutoffs, conversion spreads, banking hours, or manual compliance reviews unchanged.
That makes end-to-end evidence more useful than headline throughput. A controlled pilot should record the complete path from payment instruction to bank-account reconciliation, including timestamps, fees, counterparties, exception handling, and the accounting entry.
3. S&P Global adds smart-contract security to its risk stack
S&P Global announced on September 17 that it had agreed to acquire OpenZeppelin. OpenZeppelin develops widely used open-source smart-contract libraries and provides security assessments and development services. S&P Global said the acquisition would extend its risk-assessment capabilities into onchain technology risk. The transaction still has to pass customary closing conditions.
The proposed acquisition says something specific about institutional demand. Asset, issuer, and counterparty analysis cannot cover every failure mode in tokenized finance. The code governing issuance, custody, permissions, transfers, and upgrades creates another source of exposure.
A treasury team does not need to audit source code itself. It does need evidence that qualified specialists have reviewed the contracts involved, along with the scope and date of that review. Buyers should also ask who can upgrade a contract, pause transfers, change allowlists, or move reserve assets. An audit report becomes stale when the deployed code or its administrative controls change.
This diligence belongs beside legal and financial review. A regulated provider can still depend on vulnerable software. Audited code can still sit inside a weak operating model. The controls address different risks and should remain visible as separate lines in a provider assessment.
4. What treasury teams should change now
This week's news gives finance leaders a useful sequence for provider review.
- Confirm the legal perimeter. Identify the contracting entity, the entity holding customer assets, the entity executing conversion, and the permissions required in every material jurisdiction.
- Test the settlement path. Measure funding time, execution time, finality, conversion cost, bank payout time, and reconciliation effort under normal and exception scenarios.
- Request technology evidence. Review smart-contract audit scope, deployment versions, administrative keys, upgrade rights, incident response, and business-continuity arrangements.
- Write the exit plan before launch. Define how balances, transaction records, and customer obligations will be handled if a provider loses permission, a network is suspended, or an integration is retired.
The strongest counterpoint is that this level of review can slow a pilot and raise implementation cost. That is true. A proportionate review can narrow the work to the assets, jurisdictions, transaction sizes, and customer types in scope. The answer is a smaller, controlled pilot with explicit limits, followed by expansion when the evidence supports it.
5. The operational takeaway
Crypto payment infrastructure is becoming easier to buy and harder to assess with a single label. The FCA's timetable makes authorization status time-sensitive. Arc's launch adds another live settlement option. S&P Global's OpenZeppelin agreement brings code risk further into mainstream financial analysis.
A CFO comparing providers should keep three files open: a permissions map, a settlement and reconciliation test, and a technology-control record. None substitutes for the others. Together, they show whether a proposed payment route can operate within the company's legal boundaries, cash-management requirements, and risk tolerance.
Disclaimer: This article is for informational purposes only and does not constitute legal, financial, or investment advice.
Sources
- https://www.fca.org.uk/news/press-releases/crypto-firms-get-guidance-how-new-regime-applies
- https://www.circle.com/pressroom/circle-launches-arc-mainnet-an-economic-operating-system-for-the-internet
- https://investor.spglobal.com/news-releases/news-details/2026/SP-Global-Announces-Agreement-to-Acquire-OpenZeppelin/default.aspx
