On October 1, the US Securities and Exchange Commission issued a regulatory proposal to modernize crypto custody services. The framework aims to remove hurdles for registered investment advisers and regulated funds by permitting self-custody in limited cases and expanding eligible custodian entities. This includes state-chartered trust companies and broker-dealers, provided they meet strict operational safeguards like asset segregation and cybersecurity protocols.
The proposal operates under the Investment Advisers Act of 1940 and the Investment Company Act of 1940. It replaces the withdrawn 2023 “Safeguarding Rule” after significant criticism regarding its restrictive nature. Chairman Paul Atkins stated the new framework addresses uncertainty caused by outdated regulations. A 60-day public commentary period is now open, with voting on this and the related “Regulation Crypto Assets” proposal expected no earlier than the first half of 2027.
This development signals a strategic shift from restrictive oversight to structured integration of digital assets within traditional financial infrastructure. By explicitly authorizing state-chartered trust companies and broker-dealers as custodians, the SEC acknowledges that legacy banking institutions may lack the necessary technological agility or regulatory freedom to safeguard digital assets effectively. The allowance for limited self-custody by advisers further indicates a recognition that centralized third-party custody alone cannot meet all market needs, particularly when qualified providers are unavailable.
From an institutional adoption perspective, the move reduces compliance friction for firms seeking to offer crypto advisory services without forcing them into non-standard legal structures. However, the reliance on quarterly determinations for self-custody eligibility introduces operational complexity that requires robust internal controls. Market participants should monitor the 60-day comment period closely, as industry feedback will likely shape the final definitions of “qualified third-party custodian” and the specific cybersecurity standards required for asset segregation.