Crypto businesses in Australia that have been operating under a temporary safety net from the regulator ASIC now have a real deadline. Any business that needs a proper financial services license, or needs to update an existing one, must submit their application by 30 September 2026. Starting from 1 October, any company that keeps offering these services without meeting the conditions of that temporary protection could be treated as operating illegally under Australian company law. This can lead to both civil and criminal penalties, with fines going as high as 10 percent of a company’s yearly revenue.
This is not a brand new crypto law being introduced. It is actually the end of a transition period that ASIC started after it updated its guidance document, known as Information Sheet 225, back in October 2025. In simple terms, ASIC said that many crypto products already fall under Australia’s existing financial services laws, so companies need to follow those same rules.
What the temporary protection actually covered
After that guidance was rewritten, ASIC gave the entire industry a kind of grace period, officially called a no action letter. This allowed eligible companies to keep running their business while they prepared their license application, instead of being forced to shut down immediately.
The original deadline for this was 30 June 2026. But in late June, ASIC pushed it back to 30 September 2026, and also expanded who could use this protection to include companies working through authorized representative arrangements with a licensed firm, and companies working through intermediary arrangements with a licensed firm.
Companies that might need a market license or a clearing and settlement license were told to write to ASIC to say they intend to apply, and to set up a meeting with ASIC before applying, all by the same deadline.
This protection was never something companies could take for granted. To qualify, companies generally needed to have already been operating in Australia by the end of 2025, needed to be a member of the financial complaints authority if dealing with everyday customers, and foreign companies needed to have a local agent in Australia. Applying on time can keep a company protected while ASIC reviews their application, but it does not automatically make every crypto product legal. Brokers and other middlemen still need to check each individual product and service separately.
Who this actually applies to
The businesses ASIC is targeting are not just crypto exchanges in the traditional sense. This covers any business providing financial services related to digital assets that count as financial products under the existing law. This includes crypto trading platforms, brokers, middlemen, and even financial advisors who work with these businesses.
ASIC’s approach is based on what a business actually does, not what it calls itself. If a token or service functions like a financial product under company law, then the normal licensing requirement applies to it, regardless of the fact that it involves blockchain technology.
How many companies have applied so far
Since the guidance update in October 2025, ASIC says it has received more than 45 crypto related license applications. This is up from about 30 applications when the deadline was first extended back in June.
Forty five applications shows some level of engagement, but it is still a small number compared to how many crypto businesses are believed to be operating in Australia. This suggests there will likely be a rush of last minute applications before 30 September, and there will probably be a mix of outcomes, some companies will apply and continue operating, some will partner with an already licensed company, and some will simply reduce their presence in Australia or leave the market entirely.
There are actually two deadlines to worry about
Missing the 30 September deadline is the immediate danger. But there is a second deadline already approaching after that.
A law called the Corporations Amendment Digital Assets Framework Act 2026 officially became law on 8 April 2026, but it will not actually take effect until 9 April 2027. This law will bring digital asset platforms and tokenized custody platforms fully into the financial services licensing system, with specific ASIC rules covering how customer assets are held, how transactions are settled, financial requirements for the platform, platform operating rules, and a dedicated guide for how these platforms should treat their clients.
ASIC has made it clear that many of the approvals companies get now under the current system will still be required even after April 2027. So companies applying now are not done once they get approved. They are simply securing their place in the current system so that later they can add the additional approvals required once the new law takes effect.
To summarize the two deadlines simply, the current temporary protection ends on 30 September 2026, meaning companies need to apply for or update their license by then, or use a qualifying representative or intermediary setup. Starting 1 October 2026, operating without meeting these conditions could mean being treated as unlicensed, which comes with civil and criminal penalties, including fines up to 10 percent of yearly revenue. Then on 9 April 2027, the new platform specific law begins, meaning platforms handling digital assets or custody services will face extra licensing requirements and new ASIC rules.
What the 10 percent revenue fine is meant to achieve
The 10 percent of revenue figure is meant to scare companies into compliance, it is not necessarily what every company will actually be charged. ASIC is sending a message that unlicensed crypto businesses will be treated exactly like any other unlicensed financial business, not treated leniently just because their product runs on blockchain technology.
For a medium sized crypto exchange or custody provider, a fine like this could seriously threaten the survival of the business. For a smaller broker, even a small fraction of that fine, combined with the legal costs of fighting a civil case, could be enough to shut them down completely. That is exactly the point of issuing this kind of final warning weeks before the actual deadline.
What responsible companies are doing right now
The practical steps companies need to take are fairly straightforward. First, they need to go through every single product and service they offer and check it against the ASIC guidance to figure out which ones count as financial products. Second, they need to submit their license application or update by 30 September, or make sure they have a proper authorized representative or intermediary arrangement that actually qualifies for the protection. Third, if they think they might need a market license or clearing and settlement license, they need to write to ASIC and schedule the required meeting. Fourth, they need to already be thinking ahead to the April 2027 rules for digital asset platforms and custody platforms, so that the license they get now does not become outdated just a few months later.
Companies that treat the 30 September deadline as just paperwork, and treat the April 2027 changes as someone else’s problem to deal with later, will likely end up doing the same work twice, under much more time pressure, and with far less patience from the regulator.
Australia is not banning crypto. It is closing the gap between simply running a digital asset business and actually being recognized as providing financial services. After 30 September, that gap is no longer a grace period companies can rely on. It becomes a real legal risk.
To bring it all together, Australia is essentially folding crypto businesses into its existing financial services laws, and then adding an extra layer of rules specifically for platforms starting in April 2027. The 30 September cutoff marks the end of the temporary grace period. After that date, operating without proper filing is not simply a legal gray area anymore, it becomes unlicensed activity with a fine attached that scales with how much revenue the company makes.
