The SEC Custody Rules proposal issued on October 1, 2026, would set technical and control requirements for investment advisers and regulated funds that custody certain crypto assets. As of October 8, 2026, the proposal was not in effect, and the public comment deadline was December 7, 2026, according to the SEC release page.
The proposal matters because custody is not only a legal status question. For crypto assets, custody depends on operational controls around private keys, transaction approval, client segregation, reporting, and cybersecurity review. The rule text does not treat every token the same way. It focuses on crypto assets that qualify as securities or similar investments, while assets outside that definition are not covered by the proposed custody rules.
SEC Custody Rules: Covered Crypto Assets
Scope Is Tied To Securities Status
The proposal would apply under the Advisers Act and the Investment Company Act only to crypto assets that are securities or similar investments. The published Federal Register proposal states that assets not meeting that definition would not be covered by these custody requirements Federal Register proposal. That scope limit is technically significant because a custody system may hold different asset types, but the proposed rule duties would not automatically attach to every asset in a wallet, account, or operational workflow.
For advisers and regulated funds, this means classification work would sit upstream of custody design. A firm could not evaluate custody controls in isolation if the rule applies only to a defined subset of assets. The technical inventory would need to identify which assets are in scope, which networks they use, which addresses hold them, and which internal systems create, approve, sign, or record transactions.
Self-Custody Is Conditional, Not Open-Ended
The proposal would allow advisers to self-custody client crypto securities and assets if conditions are met. Regulated funds could self-custody through their adviser, with board oversight required for that arrangement. This is not the same as an unrestricted permission to hold private keys internally. The proposal attaches conditions to the decision, including custodian availability review, documented expertise, safeguarding systems, and reporting obligations.
That structure creates a control-based model. The adviser must be able to show why self-custody was used and how the assets are protected. The proposed requirements are not limited to written policies; they reach into system design, approval workflow, asset segregation, and recurring review.
Technical Controls For Self-Custody
Private Key Management And Joint Authorization
An adviser choosing self-custody would need documented expertise in safeguarding each crypto asset. The proposal also requires systems designed to prevent loss, theft, misuse, or misappropriation. Those systems must include private key management and joint authorization by at least two individuals for crypto-asset transactions.
This requirement places transaction approval at the center of the control model. A private key process would need to limit unilateral action. The proposal does not specify a particular wallet product, hardware device, or signing architecture in the research provided. The supported point is narrower: the system must manage private keys and require at least two individuals to authorize transactions.
Operationally, that raises practical questions that advisers would need to answer through policies and system records. Which individuals can approve transfers? How are approval events recorded? How does the system prevent one person from initiating and completing a transaction alone? How are changes to approver access handled? The proposal’s technical force comes from requiring controls that can be maintained and reviewed, not from endorsing one custody technology.
Client Address Segregation
Under the SEC Custody Rules proposal, client crypto assets must be kept in one or more addresses corresponding only to that client’s crypto assets on the relevant crypto-network. This requirement is aimed at preventing commingling. It also affects reconciliation: if a client’s assets are held at addresses assigned only to that client, statements and public ledger checks can be matched more directly.
Segregation by address may also increase operational overhead. Address management, transaction labeling, balance checks, and exception handling all become part of custody control. The research does not state how advisers must handle every network-specific feature, such as staking, smart contract custody patterns, or account abstraction. Those details remain uncertain based on the provided record, so a cautious reading is that firms would need asset-by-asset procedures aligned with the proposal’s segregation requirement.
Determinations, Reviews, And Reports
SEC Custody Rules Determination Process
Before self-custody and at least quarterly afterward, an adviser would need to make a written determination that no qualified custodian is available to maintain custody of the specific crypto asset. This is a recurring requirement, not a one-time file note. If a permitted custodian becomes available, the adviser’s ability to continue relying on self-custody would need to be evaluated against the proposal’s conditions.
The proposal would also allow regulated funds or advisers to use state trust companies as qualified custodians, subject to conditions. That detail matters because the custody decision is not limited to national banks or a single institutional model in the research provided. The adviser’s written determination would need to focus on the specific asset and custodian availability, rather than broad statements about the crypto market.
Cybersecurity And Internal Control Reports
The proposal requires mitigation of cybersecurity risks, with annual reviews of cybersecurity controls and the effectiveness of implementation. It also requires an internal control report on safeguarding crypto assets within six months of first maintaining custody and annually after that. For a related control discussion, Techncoins has covered digital asset security under 2026 U.S. rules.
These requirements connect custody to evidence. A written policy that is not tested, reviewed, or supported by control reporting would not be enough under the proposal as described in the research. Advisers would need records showing that controls exist, that they are reviewed, and that safeguarding processes are subject to internal control reporting on the stated timeline.
Client Statements And Ledger Reconciliation

Quarterly Account Statement Details
For self-custodied accounts, advisers would need to issue account statements at least quarterly. Those statements must include the crypto asset address on the relevant network, end-of-period balances, and all transactions from that address. Clients must also be urged to compare the statement with what the public ledger shows.
This is a direct technical link between custody records and public blockchain data. The statement requirement depends on address-level reporting, transaction history, and balance presentation. The public ledger comparison language also signals that clients should receive enough detail to verify what is visible on-chain, though the research does not describe a required user interface, explorer, or reconciliation tool.
Record Quality And Training Materials
Account statements, address records, transaction logs, and approval records would need to align. If a transaction is approved internally, signed on a network, and later reported to a client, the supporting records should connect those events without ambiguity. Teams preparing internal training decks on these proposed custody workflows may find general presentation resources at a related site, Freeslideshows.
The proposal also includes amendments to Form ADV and related schedules to add questions about self-custody, reliance on exceptions, use of state trust companies, and other information intended to support transparency. Based on the research, those reporting changes would sit beside the operational controls rather than replace them.
SEC Custody Rules And Operational Readiness
Who Would Be Most Affected
The SEC Custody Rules proposal is best read as a custody control framework for advisers and regulated funds handling in-scope crypto assets. The most affected parties would be advisers considering self-custody, regulated funds using adviser custody arrangements, boards overseeing fund custody, and state trust companies or other permitted custodians that may serve as qualified custodians under the proposal’s conditions.
For technical teams, the core work would be mapping assets, addresses, approval rights, private key controls, cybersecurity reviews, internal control reporting, and client statement data. For governance teams, the work would include written qualified custodian determinations, recurring quarterly review, board oversight for regulated funds using self-custody through an adviser, and disclosure updates.
The proposal was still open for comment as of October 8, 2026, with comments due on December 7, 2026. Because it was not yet effective, firms should avoid treating the proposal as final law. The supported technical takeaway is narrower and clearer: if adopted in the form described in the research, the proposal would move crypto custody compliance toward documented asset-specific controls, address-level segregation, dual-person transaction authorization, recurring custodian analysis, cybersecurity review, and verifiable client reporting.



