SEC Crypto Custody Rule 2026: What Advisers Must Do

Article author
Angelina Manko
Head of Legal & Regulatory Affairs

The US Securities and Exchange Commission released a 760-page SEC crypto custody proposal on October 1, 2026 that would reshape how registered investment advisers, registered investment companies, and business development companies hold crypto assets that are funds or securities. The proposal is not a final rule, but its new rule 223-1 framework places adviser self-custody, state-chartered trust company custody, and DeFi activity under detailed operational conditions.

The proposal, formally titled Adviser and Regulated Fund Custody Rules; Crypto Custody Rules, carries Release Nos. IA-7023 and IC-36353 and File No. S7-2026-35. It would redesignate the existing Advisers Act custody rule 206(4)-2 as rule 223-1, while adding Investment Company Act rules 17f-8 and 17f-9.

Key takeaway: The SEC crypto custody proposal 2026 would allow adviser-held private keys only as a documented fallback where no qualified custodian is available, with quarterly availability testing, segregated client addresses, multi-person transfer approvals, independent-control reporting, and recurring cybersecurity reviews.

What does the SEC crypto custody proposal 2026 actually cover?

The SEC crypto custody proposal applies only to crypto assets that are funds or securities for the relevant regulated entity, rather than creating a universal custody regime for every digital asset. Rule 223-1 would preserve qualified-custodian custody as the baseline, while creating a conditional adviser self-custody pathway and a limited state trust company custody option for crypto assets and related cash.

Today, an adviser with custody must generally maintain client funds and securities with a qualified custodian. The existing categories are banks or savings associations, registered broker-dealers, registered futures commission merchants, and certain foreign financial institutions. The underlying Advisers Act custody rule was first adopted in 1962 and later amended in 2003 and 2009.

The SEC acknowledges a practical market constraint: few traditional custodians have offered robust services for a substantial range of crypto assets. That constraint drives the proposal’s central compromise. Rather than treating every adviser-held key as prohibited, the SEC would permit narrowly defined self-custody when a qualified custodian will not maintain a given crypto asset.

The framework matters for firms that manage crypto exposure through separately managed accounts, private funds, registered funds, tokenized structures, or bespoke mandate arrangements. It does not mean every crypto wallet operated by an adviser becomes compliant by default. Each pathway contains its own documented eligibility and governance conditions.

SEC proposal pathway Proposed legal mechanism Core eligibility condition Required operational evidence
Qualified custodian custody Rule 223-1 baseline Client assets held by a bank, savings association, registered broker-dealer, registered futures commission merchant, or qualifying foreign financial institution Custody arrangement consistent with the qualified-custodian framework
Adviser self-custody Proposed rule 223-1(b)(7) Adviser determines in writing that no qualified custodian will maintain each crypto asset Quarterly written reassessment, client-specific addresses, joint authorization, cybersecurity assessments, accountant control report
State trust company custody Proposed rule 223-1(d)(13)(v) Trust company is authorized by its state banking authority to custody crypto assets Annual authorization, private-key, cybersecurity, financial-statement, and internal-control review
Registered fund self-custody Proposed rule 17f-9 Fund board finds that no qualified custodian is available and that the asset would receive reasonable care Initial and quarterly board review of adviser reports, plus annual reasonable-care determination
DeFi smart-contract activity Rule 223-1 approach to DeFi Crypto asset remains under self-custody, another permitted custodian, or an exception Smart-contract diligence and custody analysis for the deposited asset

The proposal also rejects a more permissive route for trading platforms. The SEC states that it considered and rejected a stand-alone rule that would have let advisers and funds leave assets on platforms that are not permitted custodians. For market participants, this makes custody classification a threshold design question rather than an issue that can be deferred until after a trading relationship is established.

When can an investment adviser use crypto self-custody?

An investment adviser could use crypto self-custody under proposed rule 223-1 only after determining in writing that no qualified custodian will maintain the specific crypto asset, and the adviser must repeat that determination at least quarterly. The adviser must move the asset to a qualified custodian as soon as reasonably practicable when one becomes available.

The proposal uses “self-custody” in a deliberately limited sense. It means the adviser holds a client’s crypto asset through possession of any part of the private keys required to transact, without using a permitted custodian. This is not a rule allowing end investors to hold their own coins outside an intermediary relationship. Commissioner Hester Peirce described the distinction as “shelf-custody,” separating adviser custody from investor self-custody.

The self-custody requirements form a control stack, not a single wallet-policy requirement:

  1. Written unavailability determination: Before custody of each crypto asset, the adviser must document that no qualified custodian will maintain it. The assessment must recur at least quarterly.

  2. Client asset segregation: Each client’s crypto assets must reside in one or more on-chain addresses that store only that client’s assets. The proposal therefore does not permit omnibus wallet structures for adviser self-custody.

  3. Joint transfer authorization: A transfer requires authorization by two or more people, with at least one management person. For a registered fund, one authorizer must be an officer of the fund.

  4. Restricted key-material access: Private keys and any part of a private key needed to transact are “key materials” under the proposal. The definition captures key shards as well as complete keys, and access must remain limited to designated supervised persons.

  5. Independent accountant reporting: An independent public accountant must issue an internal control report within six months after self-custody begins, then at least once per calendar year. The accountant must verify that crypto assets reconcile to the relevant crypto network.

  6. Cybersecurity and safeguarding reviews: The adviser must conduct at least annual written cybersecurity risk assessments and annual documented reviews of safeguarding controls.

  7. Quarterly client statements: The adviser must provide each client with quarterly statements showing the relevant on-chain address, balances, and transactions.

  8. UCC Article 8 agreement: Adviser and client must agree in writing to treat each self-custodied crypto asset as a financial asset, with the adviser acting as securities intermediary under UCC Article 8.

In our experience auditing smart contract and key-management architectures at Soken, multi-party authorization is effective only when it is supported by independent approval boundaries, clear emergency procedures, monitored signer changes, and reliable reconciliation between internal records and on-chain state.

The SEC has not proposed a dollar threshold, capital requirement, or insurance requirement within rule 223-1(b)(7). That absence should not be mistaken for a light-touch regime. The proposed control requirements place substantial weight on documented governance, technical access controls, reconciliation, and continuing evidence that a qualified custodian remains unavailable.

The SEC estimates self-custody setup costs of $173,499 per adviser and annual costs of $433,833 per adviser. The estimate includes $376,000 for the annual internal-control report and assumes 823 advisers would use the pathway. Those figures show that the proposal frames adviser self-custody as an exception requiring mature compliance operations, not as a low-cost alternative to institutional custody.

Firms considering this route should combine technical custody design with smart contract security and infrastructure review, because custody compliance will depend on the actual security properties of wallet controls, signing workflows, recovery processes, privileged access, and any smart contracts that receive client assets.

How would state trust company crypto custody work?

State-chartered trust companies would become permitted custodians for clients’ crypto assets and related cash if advisers and funds complete defined written diligence before engagement and annually thereafter. Proposed rule 223-1 would require confirmation that the trust company has state authority to custody crypto assets, written private-key management policies, written cybersecurity policies, audited financial statements, and an internal-control report.

This provision would codify, subject to conditions, a September 30, 2025 SEC staff no-action letter that allowed advisers and funds to treat a state trust company as a bank. The proposal does not grant blanket acceptance to every state-chartered trust company. The adviser or fund must make and preserve its own written determination concerning the entity’s authorization and controls.

The adviser or fund must also confirm that client assets are segregated from the trust company’s proprietary assets. This is a basic custody safeguard with direct consequences in a stress event, insolvency, or dispute over asset ownership. Technical segregation, legal segregation, wallet architecture, account documentation, and reconciliation should all point to the same result.

The SEC identified about 484 state-chartered trust companies, with about 19 specializing in crypto custody. It estimates that about 1,645 advisers and 1,430 funds would use state trust company custodians. These estimates make the proposed trust-company pathway commercially material, even though the provision is narrower than a broad authorization for all crypto service providers.

A custody due-diligence file should test more than a trust company’s charter. It should examine how the institution creates, stores, shards, rotates, and recovers key materials; how it governs transaction approval; whether client assets are segregated at the legal and address levels; and how it detects unauthorized transfers or changes to privileged access. A compliance conclusion unsupported by the underlying technical architecture is fragile.

For comparison, other custody regimes use more explicit prudential thresholds:

Jurisdiction or regime Custody requirement Concrete standard
US SEC proposed rule 223-1 State trust company may custody crypto assets and related cash if eligibility and control conditions are met Written verification of state authorization, key-management policy, cybersecurity policy, audited financial statements, and internal-control report
European Union MiCA Crypto custody is a licensed service EUR 125,000 minimum capital for Class 2 providers, including custody, or one quarter of prior-year fixed overheads if higher
Hong Kong SFC VATP framework Licensed virtual asset trading platforms must protect client virtual assets through storage and compensation arrangements 98% of client virtual assets in cold storage, with coverage for 50% of cold-storage assets and 100% of hot-storage assets
Wyoming special purpose depository institutions Fiat deposits require liquid-asset backing 100% or more backed by unencumbered liquid assets
UK FCA cryptoasset regime Cryptoasset activities, including custody, enter the UK authorization regime Regime applies from October 25, 2027, with the authorisation gateway opened on September 30, 2026

The SEC proposal does not import MiCA capital requirements or Hong Kong cold-storage ratios. Instead, it emphasizes written eligibility determinations, control documentation, asset segregation, and ongoing review. Firms serving multiple jurisdictions should avoid treating one jurisdiction’s custody approval as a complete answer for another.

What does rule 223-1 mean for DeFi, staking, and smart contracts?

Rule 223-1 would not create a DeFi safe harbor: an adviser could deposit client crypto assets into a smart contract only when the assets remain maintained under the adviser self-custody rule, another permitted custodian arrangement, or an applicable exception. The SEC leaves staking, liquid staking receipt tokens, smart-contract risk, and contract due diligence open for comment rather than resolving them through a blanket exemption.

This is one of the proposal’s most consequential boundaries for Web3-native investment operations. A wallet can meet a signing-policy requirement while the protocol receiving the wallet’s transaction creates a different custody, control, or asset-recovery problem. The relevant question is not merely who signs the deposit transaction. The question is whether the client asset remains maintained in a manner permitted by the custody rule after interacting with the smart contract.

The SEC specifically flags admin keys that can upgrade or pause a smart contract, observing that those keys can be abused. That focus is technically sound. Upgrade authority, pause authority, mint authority, oracle dependencies, withdrawal queues, validator delegation rights, and governance controls can all affect whether a deposited position remains available, transferable, and accurately valued.

For crypto self-custody investment advisers, a defensible DeFi review should create evidence in several layers:

  • Contract authority mapping: Identify every admin, upgrade, pause, guardian, multisignature, or governance role that can alter contract behavior.
  • Asset-flow analysis: Trace what the client deposits, what receipt token or claim is received, and what conditions govern redemption or withdrawal.
  • Key-management review: Determine whether the adviser’s key controls meet rule 223-1 requirements before and after a smart-contract interaction.
  • Protocol-change monitoring: Watch for contract upgrades, parameter changes, governance actions, or admin-key changes that alter the custody risk profile.
  • Incident and exit procedures: Document who may suspend further deposits, initiate exits, notify clients, and reassess the continued availability of the asset.
  • Records and reporting: Reconcile the on-chain position to internal books and client statements, including the relevant on-chain address and transaction history.

These tasks are both technical and legal. Soken’s Web3 compliance and legal services can help align contractual disclosures, custody terms, UCC Article 8 arrangements, and governance obligations with the technical controls that support them. Readers can also follow related research through the Soken Hub.

What should advisers and funds do before the comment deadline?

Registered advisers and funds should treat the current proposal as a design and evidence exercise because comments are due 60 days after Federal Register publication, while the exact deadline was not set as of October 2, 2026. The most useful immediate action is to build an asset-by-asset custody inventory that identifies each crypto asset, current custodian, key holder, wallet structure, smart-contract exposure, and qualified-custodian availability.

The SEC has posed 342 numbered questions across the 760-page release. It also requests feedback on whether modernization amendments should have a transition period of six months, one year, or another period. No separate transition period is proposed for the crypto custody rules themselves.

A practical readiness review should distinguish between arrangements that can likely remain within qualified custody and those that rely on an exception. Advisers should avoid a binary “custodied” or “self-custodied” label. The proposed rule demands more granular evidence: who possesses any portion of the private keys, which client owns each address, whether two-person authorization exists, whether a management person participates, whether an independent accountant can test controls, and whether a qualified custodian now supports the relevant asset.

For registered funds, the board process requires special attention. A registered fund could self-custody through its adviser only where the board reviews the adviser’s written report initially and quarterly, and determines before custody and annually that the crypto asset would receive reasonable care if self-custodied. Board materials should therefore contain a clear technical and operational basis for that determination, not merely a market-availability assertion.

The SEC estimates total initial costs of $301,856,490 and total annual costs of $433,706,625 for the proposal, while stating that it could not quantify the main benefits. Those estimates reinforce a central operational point: a written policy alone will not satisfy the proposed model. Advisers need evidence that the policy is implemented in wallet architecture, access controls, accounting, client reporting, and third-party oversight.

Build the custody inventory before choosing a compliance narrative. For each asset, record whether a qualified custodian is available, whether the adviser holds any key material, whether the asset enters a smart contract, and whether the client’s on-chain address is dedicated solely to that client. That single mapping exercise will expose the gap between a general crypto policy and the operational evidence rule 223-1 would require.

The SEC’s proposal places adviser self-custody at the intersection of legal classification and technical control design. Firms that respond during the comment period should test whether quarterly custodian availability reviews, client-specific addresses, multi-person authorizations, accountant reporting, and DeFi diligence are workable in their actual operating model, then document where the proposed requirements need clarification.

Article author
Angelina Manko
Head of Legal & Regulatory Affairs

Frequently Asked Questions

What is the SEC's 760-page crypto custody proposal?

On October 1, 2026, the US Securities and Exchange Commission released a 760-page crypto custody proposal formally titled Adviser and Regulated Fund Custody Rules; Crypto Custody Rules. The SEC proposal would reshape how regulated advisers and funds hold crypto assets that are funds or securities.

What would SEC rule 223-1 replace?

The SEC proposal would redesignate the existing Advisers Act custody rule 206(4)-2 as rule 223-1. The 760-page US Securities and Exchange Commission proposal would also add Investment Company Act rules 17f-8 and 17f-9 when crypto assets are funds or securities.

Can investment advisers self-custody crypto under SEC rule 223-1?

The SEC's 760-page proposal would permit adviser-held private keys only as a documented fallback when no qualified custodian is available. The proposed rule 223-1 framework also calls for quarterly availability testing before advisers rely on that self-custody route.

How does the SEC proposal treat state-chartered trust companies?

The SEC's 760-page crypto custody proposal places state-chartered trust company custody under detailed operational conditions. The US Securities and Exchange Commission proposal would reshape custody by registered investment advisers, registered investment companies, and business development companies when crypto assets are funds or securities.

Does the SEC crypto custody proposal cover DeFi activity?

The US Securities and Exchange Commission's 760-page proposal places DeFi activity under detailed operational conditions in its crypto custody framework. The proposal, released October 1, 2026, is not a final rule and concerns crypto assets held by regulated advisers and funds when those assets are funds or securities.

Chat