The U.S. Securities and Exchange Commission has proposed a new framework for how registered investment advisers and regulated funds can hold crypto assets, including a conditional path for advisers to safeguard certain assets themselves and a proposed expansion of eligible custodians to state-chartered trust companies.
Announced on October 1, the proposal would amend rules under the Investment Advisers Act of 1940 and the Investment Company Act of 1940. The SEC says the changes are intended to modernize custody requirements that were designed around traditional financial assets and to remove regulatory barriers affecting advisers and funds seeking exposure to digital assets.
The proposal is significant because custody is one of the practical building blocks of institutional crypto markets. Fund managers may have investment strategies for digital assets, but they also need a legally compliant way to hold private keys, segregate assets, manage transactions and demonstrate that assets are protected from loss, theft or misuse.
The SEC’s initiative attempts to address that infrastructure gap without abandoning core custody protections.
What the SEC is proposing
At its core, the proposal would create a tailored custody framework for crypto assets held by registered investment advisers and regulated funds.
The SEC’s proposal covers registered investment companies and business development companies in addition to registered advisers. It would also update related reporting, recordkeeping and custody provisions that apply to traditional assets.
Two of the most consequential changes concern who can safeguard crypto assets.
First, qualifying advisers and funds could use a self-custody framework under specified conditions.
Second, state-chartered trust companies could become an additional category of permitted custodian for crypto assets, subject to conditions designed to protect client and fund assets.
Importantly, this is not a blanket authorization for any investment adviser to hold any crypto asset directly. The proposed rules contain detailed eligibility requirements, operational controls and disclosure obligations.
Conditional self-custody is not unrestricted self-custody
The terminology requires particular attention.
Commissioner Hester Peirce noted that the proposal’s use of the term “self-custody” does not describe an individual investor holding their own private keys. In the SEC proposal, it generally refers to an adviser acting as custodian for client or regulated-fund assets rather than relying on a separate permitted custodian. Peirce said she would have preferred the term “shelf-custody” to avoid confusion with ordinary investor self-custody.
The proposed pathway is also intentionally conditional.
A threshold requirement would be that the adviser determine, before taking custody and subsequently on a quarterly basis, that no permitted custodian is available to maintain the particular crypto asset. This recognizes a practical problem in digital markets: some assets may exist before established custodial infrastructure capable of supporting them becomes available.
That requirement is designed to prevent advisers from simply choosing direct custody whenever it is convenient. The model instead creates an exception for situations in which an appropriate outside custodian is unavailable.
Stronger controls would accompany adviser custody
The proposal does not treat direct custody as a lower-control alternative.
The SEC’s proposed framework would require advisers using this route to maintain safeguarding systems addressing issues including private-key management and joint authorization of crypto transactions by at least two people. Client crypto assets would also have to be maintained in addresses corresponding to that client’s assets on the relevant blockchain network.
Cybersecurity would form another layer of the framework.
Advisers would have to mitigate cybersecurity risks associated with safeguarding client assets and review their cybersecurity controls and implementation at least annually. They would also have to obtain internal-control reports concerning their safeguarding activities within six months of beginning custody and annually thereafter.
The proposed rules would also require quarterly account statements for clients whose crypto assets are held through the adviser custody framework. The statement would identify the relevant crypto-asset addresses and be delivered electronically in a reasonably usable format.
These measures show that the SEC is attempting to apply traditional custody principles to blockchain infrastructure rather than simply removing the custodian requirement.
State trust companies could gain a clearer role
The second major element is the proposed recognition of state-chartered trust companies as permitted crypto custodians.
The SEC says advisers and regulated funds would need a reasonable basis, following due inquiry, to conclude that a state trust company is authorized by the relevant state banking authority to provide crypto custody. They would also need to determine that the trust company maintains written policies and procedures designed to protect crypto assets and related cash from theft, loss, misuse and misappropriation. The proposed requirements specifically address areas such as private-key management and cybersecurity.
The adviser or fund would conduct that assessment before engaging the trust company and again annually.
The proposed approach builds on an issue the SEC staff had already addressed through a 2025 no-action letter involving state trust companies. That earlier staff position recognized that state-chartered trust companies could provide crypto custody under specified conditions, including safeguards, independent financial audits, control reports and asset segregation.
The new rulemaking would move that concept from a fact-specific staff assurance toward a formal regulatory framework.
Atkins: existing rules have not kept pace
SEC Chairman Paul Atkins presented the proposal as part of a broader modernization of U.S. digital-asset regulation.
In his October 1 statement, Atkins argued that crypto markets have developed substantially since Bitcoin’s creation while many custody provisions remain rooted in an earlier financial environment. He said the proposal would provide advisers and funds with a compliant route to hold crypto assets where one had previously been difficult to establish.
Atkins has also emphasized the infrastructure problem in earlier remarks. On September 14, he said the SEC should answer “yes” to the questions of whether investment advisers can custody crypto for clients and whether state trust companies can serve as custodians, subject to appropriate conditions. He said the first pathway matters because suitable third-party custodians may not yet exist for some assets, while the second reflects a custody model already functioning in practice.
His position connects the proposal to the SEC’s broader strategy of updating the regulatory architecture around issuance, trading, transfer and custody rather than treating these as isolated questions.
Uyeda emphasizes investor protection and practicality
Commissioner Mark Uyeda focused on the balance between safeguarding assets and creating rules that can actually be followed.
He said the basic principles of custody — including asset segregation and appropriate controls — remain unchanged, even though the mechanics must evolve as technology changes. His argument is that a distributed ledger cannot be supervised using exactly the same operational assumptions as paper certificates stored in bank vaults.
Uyeda also highlighted the problem created when regulators require advisers to use custodians that are technically or commercially unavailable for certain digital assets.
He characterized the proposal as a “workable path to compliance” while stressing that self-custody presents an inherent conflict-of-interest concern and does not remove an adviser’s fiduciary duties.
That point is central. Allowing an adviser to control private keys does not mean the adviser receives fewer legal responsibilities. Instead, the proposed framework shifts some of the operational burden from an outside custodian to the adviser while adding additional controls.
The proposal applies to a defined subset of crypto assets
Another important limitation is the scope of the rules.
Peirce’s statement notes that not every crypto asset would automatically fall under the proposed custody requirements. Under the Advisers Act changes, the framework would apply to crypto assets that are funds or securities; for regulated-fund accounts under the Investment Company Act, the proposed rules would focus on crypto assets that are securities or similar investments.
This means the proposal should not be described as a universal federal custody regime covering every token, coin or blockchain-based asset.
The legal classification of the underlying asset remains important.
Broader modernization of fund custody
The initiative is broader than digital assets alone.
The SEC says the proposal would modernize several existing custody requirements, including rules concerning financial-statement audits for advisers and broker-dealer custodial services for regulated funds. Uyeda also highlighted proposed changes involving when regulated funds can use broker-dealers as custodians and certain exceptions relating to authorized discretionary trading and standing letters of authorization.
Taken together, the proposal represents an attempt to update the custody framework at a time when financial assets increasingly exist as blockchain-based records rather than as paper certificates or conventional electronic book entries.
Why the proposal matters for tokenized securities
The timing also connects the initiative with the SEC’s recent work on tokenization.
On September 17, the Commission issued its temporary Innovation Exemption for certain onchain venues trading tokenized NMS stocks. That framework created a limited, conditional pathway for permissioned venues and automated market-making infrastructure while the SEC gathers experience and considers longer-term regulation.
CryptoQuorum has covered that development in detail in SEC Allows Limited Tokenized NMS Stock Trading.
The custody proposal addresses another part of the same ecosystem. A functioning tokenized market requires not only rules for issuing and trading digital representations of securities, but also reliable mechanisms for holding the underlying assets and controlling the associated private keys.
The institutional infrastructure is developing on several fronts. CryptoQuorum’s DTCC Tokenization Service coverage examines how traditional market infrastructure is being adapted for blockchain-based securities.
Similarly, the recent expansion of Ondo Intelligent Portfolios illustrates how tokenization is moving from individual financial instruments toward complete portfolio structures.
What happens next?
The SEC has not finalized the rules.
The public comment period will remain open for 60 days after the proposing release is published in the Federal Register. The SEC is seeking feedback across numerous technical and regulatory questions, meaning the final framework could differ materially from the proposal.
This stage is therefore better viewed as a proposed roadmap than as a new operating rule for investment advisers and funds.
The most important issues for commenters are likely to include the conditions surrounding adviser custody, the responsibilities assigned to boards and investment advisers, cybersecurity and internal-control requirements, the treatment of state trust companies, and the practical definition of when an acceptable third-party custodian is unavailable.
A potentially important step for institutional crypto
The SEC’s October 1 proposal addresses one of the less visible but most important infrastructure problems in institutional digital assets: who can legally and operationally hold the assets once an adviser or fund decides to gain exposure.
Its approach combines greater flexibility with detailed safeguards.
Conditional adviser custody could help address assets for which suitable third-party custodians are unavailable. State-chartered trust companies could expand the pool of specialized custodians. At the same time, private-key controls, cybersecurity reviews, internal reporting, account statements and fiduciary obligations would remain central to the framework.
The proposal therefore does not eliminate the traditional principles of custody. Instead, it attempts to translate those principles into a financial system where ownership and control can be represented through blockchain addresses and cryptographic keys.
For the U.S. digital-asset market, that may prove to be one of the more consequential regulatory questions of the next stage of institutional adoption.
Key points
| Area | SEC proposal |
|---|---|
| Covered entities | Registered investment advisers and regulated funds |
| Regulated funds | Investment companies and business development companies |
| Adviser custody | Conditional self-custody pathway |
| Alternative custodian | State-chartered trust companies |
| Private keys | Formal safeguarding controls |
| Transaction authorization | Proposed joint authorization by at least two people |
| Cybersecurity | Annual review of controls |
| Internal controls | Report within six months, then annually |
| Client statements | At least quarterly for adviser self-custody |
| Status | Proposed rule, not final |
| Comments | 60 days after Federal Register publication |
Disclaimer
This article is for informational purposes only and does not constitute legal, financial, investment, tax or regulatory advice. The SEC action discussed here is a proposed rule and is subject to public comment and potential changes before any final rule is adopted. Digital assets involve significant technological, market, custody, liquidity and regulatory risks.



Why Crypto Rallied After Clarity Act Failed
CFTC Clarifies Tokenized Collateral Rules and On-Chain Recordkeeping
Brazil Crypto Regulation Tightens as Self-Custody Reporting Expands
SEC Data Show U.S. IPO Activity Accelerates in First Half of 2026