SEC crypto custody rule 2026 gives advisors and funds a clear compliant pathway and audit guidance.
The SEC crypto custody rule 2026 sets a clear path for investment advisers and funds to hold digital assets, naming qualified custodians, tightening records, and allowing limited adviser self-custody when no custodian exists. Use this guide to map requirements, build controls, and prepare audits before the final rule lands.
The U.S. Securities and Exchange Commission has proposed new guardrails for how advisers and funds hold client crypto. The plan clarifies who can custody assets, how firms must keep books, and what disclosures and audits are expected. It also creates a narrow path for adviser self-custody if no qualified custodian will take a specific asset, with strict checks and quarterly reviews. A 60-day comment window is open, so firms should prepare now.
What the SEC crypto custody rule 2026 changes
Clear lanes for qualified custodians
The proposal explains which entities can hold client crypto. It leans on “qualified custodians” and opens the door to state-chartered trust companies that meet high standards. Firms should expect stronger expectations for asset segregation, safekeeping, and access controls that match digital asset risks.
Books, records, and disclosures
Advisers and registered funds must keep accurate, timely records of wallet balances, movements, and approvals. The rule pushes firms to reconcile on-chain data with internal ledgers and to disclose arrangements, risks, and service providers to the SEC and clients.
Audit and oversight expectations
The proposal tightens independent verification. Expect enhanced auditor procedures, surprise exams for advisers, and greater reliance on third-party assurance reports from custodians (for example, SOC reports). The focus is proof that the assets exist, are controlled, and are segregated.
Limited adviser self-custody
The rule uses “self-custody” in an asset management sense. Advisers may hold client crypto themselves only if:
No qualified custodian is reasonably available for that asset.
The adviser has proven expertise, security, and segregation controls.
The firm reevaluates at least quarterly to see if a custodian is now available.
This pathway could apply to a new token that custodians do not yet support. It is meant to be rare, monitored, and temporary.
Who must comply and by when
The proposal targets:
SEC-registered investment advisers (RIAs) that invest in crypto for clients.
Registered funds that hold digital assets directly or indirectly.
Service partners, including custodians, administrators, and auditors supporting those firms.
The SEC opened a 60-day public comment period. A final rule would follow after review. You should expect a phase-in timeline once adopted, but the safe approach is to design controls now, align vendors, and prepare disclosures ahead of the final text.
How to comply: a practical checklist
1) Inventory exposure and map flows
List every token, network, and wallet you use (trading, cold storage, staking, settlement).
Document how assets move, who approves moves, and what systems log them.
Identify assets that currently lack a qualified custodian and flag them for special treatment.
2) Confirm your qualified custodian
Validate that your custodian meets the proposal’s criteria, including for state-chartered trusts.
Review segregation, omnibus vs. segregated wallets, and bankruptcy-remote structures.
Update service agreements to reflect control responsibilities, reporting, SLAs, and incident notice.
3) Strengthen safekeeping controls
Use defense-in-depth: cold storage for long-term assets; MPC/HSM for controlled access; role-based approvals.
Enforce least privilege. Separate initiation, approval, and release of transactions.
Run periodic key ceremonies, keep tamper-evident logs, and test emergency procedures.
Maintain chain-specific security baselines (Bitcoin, Ethereum, and other networks have different risks).
4) Build books and records that match the chain
Maintain a crypto subledger that ties each address to an account and strategy.
Reconcile on-chain balances daily (or more often for active strategies) against your ledger.
Use independent node infrastructure or trusted indexers; validate data sources.
Retain cryptographic evidence of ownership (signing challenges where appropriate).
5) Upgrade disclosures and filings
Update Form ADV and client materials to describe custody arrangements, service providers, insurance limits, and key risks.
Disclose conflicts, such as staking, lending, or rehypothecation policies, if applicable.
Document valuation methods for thinly traded tokens and the use of pricing oracles or vendors.
6) Get audit-ready
Coordinate with your auditor on existence testing, address confirmations, and cutoff procedures.
Obtain and review custodian SOC reports and bridge any control gaps in-house.
Prepare for surprise exams and walkthroughs of transaction approvals and incident response.
Do not rely on “proof of reserves” alone; align with traditional audit evidence standards.
7) Plan for the self-custody exception
Define criteria to show that no qualified custodian is available for a specific asset.
Seek board or risk committee approval with clear documentation and timelines.
Implement strict cold storage, dual/multi-approval, and physical security for seed materials.
Review availability of custodians every quarter and move assets promptly once support exists.
Assess insurance and legal opinions regarding control, title, and loss events.
8) Monitor state-chartered trust custodians
Verify the trust’s charter, permissible activities, capital, and regulatory supervision.
Evaluate segregation, client ownership clarity, and bankruptcy protections.
Set measurable SLAs for reconciliations, reporting, and incident notifications.
Operational impacts and opportunities
Token support and launch playbooks
The proposal’s limited self-custody path can help you gain exposure to new tokens before custodians support them. Build a token-onboarding process with risk scoring, legal review, and an exit plan to migrate to a qualified custodian when available.
Vendor management and costs
Expect higher due diligence and reporting workloads for custodians and data providers. Review vendor capacity, security certifications, and uptime. Budget for compliance tooling, expanded audits, and possibly higher custody fees linked to enhanced controls.
Insurance and risk transfer
Revisit crime, cyber, and specie insurance. Map limits and exclusions to actual wallet types. If you self-custody under the exception, confirm that your controls meet insurers’ underwriting standards.
Investor communication
Clear custody and audit practices can reduce perceived risk and support fundraising. Use simple language to explain how client assets are kept safe, how segregation works, and how independent verification protects investors.
Common pitfalls to avoid
Keeping client assets on exchange accounts and assuming they count as qualified custody.
Letting traders or portfolio managers control private keys or hot wallets directly.
Using one-size-fits-all controls across chains with different attack surfaces.
Forgetting the quarterly review for the self-custody exception.
Weak incident escalation and late regulator or client notifications.
Unrehearsed disaster recovery for key loss, custodian outages, or chain halts.
What comes next under the proposal
The SEC will review public comments submitted during the 60-day window. Expect refinements on definitions, documentation, and audit expectations. The agency has also moved on other digital asset items, including tokenized securities paths and capital formation rules, signaling a coordinated framework. Use this period to submit comments, close control gaps, and align your vendors.
In short, the SEC crypto custody rule 2026 pushes digital assets into a clearer, safer framework for advisers and funds. Start by validating your custodian, tightening records, and preparing for audits. Document a narrow, temporary self-custody path only when truly needed. Acting now will make compliance smoother when the SEC finalizes the rule.
(Source: https://www.coindesk.com/policy/2026/10/01/u-s-sec-maps-out-crypto-custody-in-new-proposal-that-furthers-its-digital-assets-agenda)
For more news: Click Here
FAQ
Q: What does the SEC crypto custody rule 2026 propose?
A: The SEC crypto custody rule 2026 sets a clear regulatory framework for how investment advisers and funds can custody digital assets, naming qualified custodians, tightening books and records, and allowing limited adviser self-custody when no custodian is available. The proposal is open for a 60-day public comment period and firms are advised to prepare controls, disclosures, and audits now.
Q: Who must comply with the proposed custody requirements?
A: The proposal targets SEC-registered investment advisers that invest in crypto for clients, registered funds that hold digital assets directly or indirectly, and service partners including custodians, administrators, and auditors that support those firms. Service providers involved in custody arrangements will need to align with the rule’s expectations for segregation, reporting, and controls.
Q: What entities can serve as qualified custodians under the proposal?
A: The rule leans on the concept of “qualified custodians” and explicitly permits state-chartered trust companies that meet the proposal’s high standards to act as custodians. Firms should expect strengthened requirements for asset segregation, safekeeping, and access controls to address digital-asset risks.
Q: When can advisers use the self-custody exception and what conditions apply?
A: Advisers may self-custody client crypto only if no qualified custodian is reasonably available for that specific asset, the adviser demonstrates required expertise and security controls, and the firm reevaluates availability at least quarterly. The pathway is intended to be rare and temporary, for example when a newly launched token lacks custodian support.
Q: What books, records, and disclosures will firms need to maintain?
A: Advisers and funds must keep accurate, timely records of wallet balances, movements, approvals, and reconcile on-chain data with internal ledgers, retaining cryptographic evidence of ownership where appropriate. They must also disclose custody arrangements, risks, service providers, valuation methods, and update filings and client materials such as Form ADV.
Q: How will audits and oversight change under the proposed rule?
A: The proposal tightens independent verification with enhanced auditor procedures, increased surprise exams for advisers, and greater reliance on third-party assurance reports such as SOC reports from custodians. Audits will focus on evidence that assets exist, are controlled, and are segregated rather than depending solely on proof-of-reserves.
Q: What practical steps should firms take now to comply with the SEC crypto custody rule 2026?
A: Under the SEC crypto custody rule 2026, start by inventorying every token, network, and wallet and mapping asset flows, then validate that your custodian meets the proposal’s criteria and update service agreements and SLAs. Strengthen safekeeping controls, build a crypto subledger with routine on-chain reconciliations, upgrade disclosures and audit readiness, and document a narrow self-custody pathway for assets lacking custodian support.
Q: What common pitfalls should firms avoid when preparing for the proposal?
A: Avoid keeping client assets on exchange accounts and assuming they qualify as custody, letting traders or portfolio managers control private keys or hot wallets, and applying one-size-fits-all controls across different chains. Also do not forget the quarterly review required for any self-custody exception and ensure robust incident escalation, timely regulator and client notifications, and rehearsed disaster recovery plans for key loss or custodian outages.