The sandbox in brief
Operated jointly by the Bank of England and FCA, the Digital Securities Sandbox (established under SI 2023/1398) lets firms test DLT-based market infrastructure — trading venues and Digital Securities Depositories — for securities using a modified regulatory rulebook. Scope covers equities, bonds, money-market instruments and fund units. Entrants pass through gates: initial admission, then progression as live activity demonstrates control. As of September 2026 the entrant cohort includes major banks and market-infrastructure firms, with at least one having reached live Gate-2 business — and the sandbox runs into January 2029.
What entrants must demonstrate
- Participant standards under modified MLRs: admission and identification regimes the venue enforces for its participants — tiered, evidenced, and readable from the outside.
- Firm-specific limits: volume and exposure limits set at each gate, per firm — not industry-wide constants. When your limits are negotiated, your software treats them as data.
- Records and reporting: complete, explainable records of every action and the venue's responses — the evidence base for gate progression.
- Technology resilience: deterministic behavior, fail-closed dependencies, replayable decision-making — the operational qualities supervisors probe in a sandbox.
- Exit expectations: a credible path off sandbox rules onto permanent ones without re-platforming.
Settlement assets
DSS venues can settle in central-bank money via the Bank's infrastructure, and — since mid-2026 — in qualifying stablecoins that meet the authorities' criteria. The criteria will evolve; the architecture should not. Settlement-asset eligibility is a rulebook dimension in clarivyx: per-deployment, versioned, updatable as the qualifying standards develop.
Limits as configuration — the DSS use case
The defining property of a sandbox is that its rules are firm-specific and temporary. A venue whose limits, admission tiers, reporting formats and settlement-asset policy live in a schema-validated rulebook can absorb a gate renegotiation as a config change with an audit trail. A venue whose limits are compiled into its code re-engineers, re-tests and re-deploys — in a sandbox whose entire premise is that the rules will change. The permissioned-AMM core and operator layer are identical to the EU and US deployments; the DSS rulebook is what varies.
Gate evidence from the test suite
Gate reviews ask "show that your controls work." The strongest answer is a test matrix mapping each of your conditions to the invariant or property test that proves enforcement — admission tests over the choke point, cap-math property tests, halt-sync replays, feed-loss fail-closed tests, records-integrity checks. clarivyx ships that mapping as part of the deployment; it doubles as authorization-file support.
After the sandbox
The FCA's consultation program points toward permanent rules for digital-securities trading — with secondary trading and DeFi-adjacent models explicitly in view. Entrants who arrive at permanent rules with configuration-driven venues re-point the rulebook; entrants with bespoke systems face the rebuild they hoped to avoid. The sandbox is a dress rehearsal for the regime, and the software decision is the same in both acts.
Frequently asked questions
Who can apply to the Digital Securities Sandbox?
How long does the Digital Securities Sandbox run?
What can a DSS venue settle in?
Entering the sandbox?
Bring your gate conditions and target instruments. We'll return the DSS rulebook draft and the test matrix mapping each condition to the test that proves enforcement — the gate-evidence artifact before you need it.