The SEC's Proposed Crypto Custody Rules: A Control Checklist for Web3 Builders

The SEC's Proposed Crypto Custody Rules: A Control Checklist for Web3 Builders
The SEC's October 1, 2026 crypto custody proposal would give registered investment advisers and regulated funds additional ways to safeguard certain crypto assets, including conditional adviser self-custody and eligible state trust companies. It is a proposal, not a final rule, and its custody requirements do not cover every crypto asset or every crypto user.
For Web3 builders, the immediate lesson is operational rather than political: map who can access keys, who can authorize transfers, where each client's assets sit, and what evidence proves the controls work. The proposal makes those boundaries more concrete, even before the Commission decides whether to adopt it.
What the SEC actually proposed
On October 1, the Securities and Exchange Commission proposed amendments to custody rules under the Investment Advisers Act of 1940 and the Investment Company Act of 1940. The stated audience is registered investment advisers and regulated funds, meaning registered investment companies and business development companies. The SEC described the package as a tailored framework for crypto custody alongside other updates to existing custody requirements. The Commission has not adopted the proposal as a final rule. The SEC's announcement is at https://www.sec.gov/newsroom/press-releases/2026-100-sec-proposal-would-address-how-investment-advisers-funds-can-custody-crypto-assets-under-federal.
Two proposed routes are drawing attention. First, an adviser could hold some client crypto assets itself when no permitted custodian is available, but only under a detailed set of conditions. Second, an eligible state-chartered trust company could serve as a permitted custodian if it meets specific diligence, reporting, and safeguarding requirements. Neither route is a blanket permission to skip controls or to treat every wallet arrangement as compliant.
The proposal would allow a comment period of 60 days after the proposing release appears in the Federal Register. The SEC's October 2 rule page still shows a placeholder for the publication date, so a calendar deadline should not be guessed from the October 1 vote date. Teams should monitor the actual filing and submit comments through the SEC process if they have operational evidence or implementation concerns.
Start with scope, not the word crypto
The word crypto can make this sound broader than it is. Under the proposed Advisers Act changes, the custody rule would apply to crypto assets that are funds or securities. For a regulated fund's account, the relevant category is securities and similar investments. The proposed Investment Company Act rules likewise focus on a regulated fund's securities or similar investments. The release therefore does not say that all crypto assets held by all people become subject to this custody framework. See the proposal text at https://www.sec.gov/files/rules/proposed/2026/ia-7023.pdf.
That scope distinction matters for the asset inventory. The SEC proposal says native digital commodities such as Bitcoin, Ether, and Solana generally would not fall under the Advisers Act custody rule for advisory clients that are not regulated funds, because they are not funds or securities. The same assets may be treated as securities or similar investments for a regulated fund's account. Tokenized securities and certain payment stablecoins can raise different questions because the asset's legal character and the account holding it matter.
A useful first step is to record the legal and operational basis for each asset classification rather than using one blanket label for the whole product. Record who provides advice, whether the account belongs to a regulated fund, what rights the asset represents, and whether the asset is held as a security, fund, or similar investment. Legal counsel should determine how those facts map to the text. A product team should not treat a protocol-level label, ticker, or wallet type as a substitute for that analysis.
This is also where compliance design connects to product design. In our guide to tokenized-equities compliance-gated markets, the emphasis is on the controls that sit around an asset, not just the smart contract that records it.
Adviser self-custody is a conditional control system
In the proposal, adviser self-custody is not the same thing as an individual user holding a personal wallet without an intermediary. Commissioner Hester M. Peirce made that distinction explicitly, saying she would have preferred the term shelf-custody to separate adviser custody from direct personal custody. Her statement also says that crypto assets are not all subject to custody requirements. That nuance helps keep the discussion focused on regulated intermediaries and client assets. Her October 1 statement is at https://www.sec.gov/newsroom/speeches-statements/peirce-statement-proposed-amendments-custody-rules-100126.
Before an adviser used this route for a particular asset, it would have to make a written determination, after due inquiry, that it has a reasonable basis for believing no qualified custodian will maintain that asset. It would need to revisit and document the determination at least quarterly. The proposal requires an asset-by-asset inquiry, not a generic assertion that crypto custody is difficult. If a qualified custodian becomes available, the adviser would have to move the asset as soon as reasonably practicable.
The safeguarding section goes beyond a policy statement. An adviser would need documented expertise for each asset and systems capable of protecting it from loss, theft, misuse, and misappropriation. Key access would be limited to designated supervised persons. Transfers would require joint authorization by two or more designated people, including at least one management person. The release does not prescribe a single technical implementation such as multisignature wallets or multiparty computation.
Segregation is another core condition. Each client's crypto assets would be held at one or more addresses that store only that client's assets, without commingling with other clients, the adviser, or related persons. At least quarterly, the client would receive an account statement with address and network information. The proposal also calls for disclosure, written records, cybersecurity measures, annual reviews, and independent accountant reporting.
These requirements resemble the operational discipline in a smart contract security checklist: define authority, limit privileges, preserve evidence, and test what happens when a control fails.
State trust companies bring a different diligence burden
The second proposed path is not simply to choose any institution organized under state law. The proposed definition requires a state trust company to be organized under state law, supervised and examined by a state authority that supervises banks, and permitted to exercise fiduciary powers. Before relying on one, and annually after engagement, an adviser or fund would have to make written, due-inquiry determinations about its authority and safeguards.
The proposed review reaches into evidence. The adviser or fund would review the company's latest annual audited financial statements, prepared under U.S. generally accepted accounting principles by an independent public accountant. It would also review a current or prior calendar year's internal control report. The firm would need written safeguarding policies that address private key management and cybersecurity, and client assets would have to remain segregated from the trust company's proprietary assets.
This changes vendor evaluation from a brand-name check into a continuing evidence process. Procurement teams should ask how the provider handles key access, incident escalation, reconciliations, independent assurance, and changes in legal authorization. An annual review is not a one-time onboarding form. If key people, systems, or subcontractors change, a control owner should know whether the change affects the evidence supporting the firm's conclusion.
For a broader incident-control perspective, see our overview of trust boundaries in crypto infrastructure, which explains why handoffs between operators can matter as much as the individual systems.
Translate the rule text into engineering questions
The proposal is written for regulated advisers and funds, but its control logic gives product and infrastructure teams a practical design test. Start by drawing the custody path from user authorization through wallet software, key storage, transaction approval, network broadcast, confirmation, and reconciliation. Mark every point where a person or service can read a key, approve an action, change an address, or halt a transfer.
Then distinguish possession from influence. A service may not possess a private key but could still have administrative power over a signing policy, recovery process, allowlist, or upgrade path. Conversely, a key share may exist without any one operator being able to move assets alone. The proposed rule uses its own legal definitions, so teams should not assume that a technical diagram settles the legal question. It does, however, help counsel see where practical control exists.
A useful security review follows each failure mode. What happens if a device is stolen, an employee leaves, a cloud account is compromised, a signing service is unavailable, or an address is replaced by mistake? Who can freeze or rotate access, and how is that action recorded? A layered approach to admin-key risk, multisigs, and timelocks can help teams turn those scenarios into explicit operational procedures.
Evidence should be created as part of normal operations. Keep current access lists, approval logs, change tickets, asset-to-address mappings, reconciliation records, incident reports, and review sign-offs. Where a proposal specifies timing, build the calendar into the control workflow: quarterly determinations and statements, annual cybersecurity assessments and reviews, and an initial independent control report within six months of self-custody. If the rule changes, those workflows can be updated without rebuilding the product from scratch.
A named expert's framing is a useful test for those plans. SEC Commissioner Mark T. Uyeda said, “Rules that are unworkable in practice will not protect investors but merely provide the illusion of protection.” The sentence is a reminder that a control has to be both demonstrable and operable under pressure. His October 1 statement is at https://www.sec.gov/newsroom/speeches-statements/uyeda-statement-proposed-amendments-custody-rules-100126.
Separate network security from client asset custody
For Autheo, the distinction is especially useful because the platform should not be described as a custody service simply because applications use a blockchain. Autheo's plain-English positioning is a distributed cloud platform, not just a blockchain. The Layer 1 provides a trust and economic foundation, while the mesh and infrastructure layers are intended to connect distributed resources and applications. Those roles are related, but they are not interchangeable with a qualified custodian's legal responsibilities.
That means builders should draw separate boxes for validator operations, app-level wallet control, any custodian, and the services that execute or route a workload. Validators secure the network's trust layer. They do not automatically hold every application's customer assets. Staking keys, contract administrator keys, user signing keys, and a custodian's keys answer different questions and should have separate ownership, recovery, and access rules.
Autheo mainnet went live on May 14, 2026, and staking and transaction fees are live today. Decentralized compute and storage through the coming Autheo Marketplace, AI inference, and TheoID are rolling out over the coming months. None of that changes who controls an app's keys or whether a regulated firm meets a custody rule. Teams can learn more about the platform in Autheo's complete guide, while treating custody analysis as a separate legal and operational workstream.
This is a boundary, not a product claim. The point is not that Autheo or any particular chain qualifies as a custodian, and nothing in a network's consensus or staking model creates that status by itself. The point is that infrastructure, application controls, and custody arrangements need clear interfaces. The clearer those interfaces are, the easier it is to assess outages, preserve a reliable audit trail, and explain responsibilities to clients and reviewers.
A practical checklist while the proposal is pending
The SEC rule page identifies this as a proposed rule, with a 60-day comment window after Federal Register publication. Until a final text exists, teams should avoid claiming that a particular service or architecture is compliant because of the proposal. They can still do useful preparation now, especially if it improves resilience under existing obligations.
Inventory assets and accounts. Document which assets are held for advisory clients or regulated funds, the legal basis for classification, and the person responsible for confirming whether the custody rule applies.
Map control, not only custody labels. Identify key holders, policy administrators, transaction approvers, recovery paths, and the systems that can alter addresses or signing thresholds. Keep the map current as people and vendors change.
Test the evidence trail. Confirm that address segregation, approvals, reconciliation, access reviews, incident handling, and client statements can be demonstrated from records. Treat quarterly and annual review dates as workflow events, not calendar reminders that have no owner.
Evaluate custodians on continuity as well as assurances. Ask how the provider reports incidents, supports recovery, maintains key controls, and supplies independent financial and control evidence. Record a fallback plan if the provider becomes unavailable.
Keep legal interpretation with qualified counsel. The proposal's asset scope and conditional routes depend on the facts, and the rule may change after public comment. Product and engineering teams should provide precise system facts rather than making a final legal conclusion.
Key Takeaways
The SEC's October 1, 2026 announcement is a proposal for registered investment advisers and regulated funds, not a final rule for every crypto user.
Proposed adviser self-custody depends on an asset-specific finding that no qualified custodian is available, repeated at least quarterly, plus detailed controls for keys, approvals, segregation, cybersecurity, statements, and outside review.
The proposed state trust company path requires continuing due diligence and evidence, including annual review of authorization, written safeguards, audited financial statements, and internal control reports.
The comment window lasts 60 days from Federal Register publication. The deadline should be confirmed from the actual publication, not inferred from the Commission's vote date.
A network's validator or staking model is distinct from application-level key custody. Map the roles, make handoffs explicit, and avoid claims that infrastructure alone establishes custody compliance.
For developers and infrastructure teams, the best response is to make authority visible before a rule is final: document the keys, approval paths, recovery processes, and evidence that supports each claim. Explore Autheo's builder resources at https://www.autheo.com/build, and use the developer guide to see how a first smart contract build fits into the platform.
Gear Up with Autheo
Rep the network. Official merch from the Autheo Store.
Theo Nova
The editorial voice of Autheo
Research-driven coverage of Layer-0 infrastructure, decentralized AI, and the integration era of Web3.
About this author →Get the Autheo Daily
Blockchain insights, AI trends, and Web3 infrastructure updates delivered to your inbox every morning.



