SEC proposes a compliant path for crypto custody — what changes in the U.S.

The SEC has proposed a new custody framework for crypto assets, and it targets a problem institutional investors have faced for years: how to hold digital assets under a rule built for traditional securities. On October 1, the Commission voted to propose amendments to the adviser and regulated-fund custody rules. The document is not law and does not immediately change what funds can do. It does, however, set out a concrete path for public comments and potential adoption.

What the SEC just proposed

The proposal would widen the circle of permitted custodians for crypto assets held by registered investment advisers and regulated funds. Eligible state trust companies could serve as custodians, provided the adviser or fund can demonstrate a reasonable basis for believing that the entity is authorized to provide crypto custody and maintains policies designed to protect assets from theft, loss, misuse and misappropriation.

The more controversial element is limited self-custody. An adviser or fund would first have to determine that no permitted custodian is available for the asset. That determination would need to be reviewed quarterly. Self-custody would not mean that every investor could send funds to a personal wallet from a regulated fund; it means the registered entity would act as custodian under specified conditions.

The safeguards are the real story

This is a proposed compliance path, not a waiver of investor protections. The SEC describes conditions around segregation of client assets, books and records, internal controls and verification. An adviser using a state trust company would need to perform due diligence before entering the relationship and annually afterward.

The proposal also expects firms to assess the risks of loss, theft, misuse and misappropriation. That matters because crypto custody is not only about where an asset sits. It is about who can sign transactions, how access is divided, what is recoverable and what happens when a key is compromised. The proposal tries to connect the legal custody test to the technical realities of digital assets.

For institutional operators, the operational details will determine whether self-custody is practical. A robust setup may use multiple signers, multi-party computation or other controls so that no single employee can move client assets alone. Those controls can reduce one-person failure risk, but they also create questions about governance, incident response, vendor dependence and auditability.

Why this matters now

The timing is significant. The SEC and other U.S. regulators are pursuing separate pathways for crypto market structure, while asset managers continue to ask for direct exposure to digital assets. Custody has become a bottleneck: a fund may have a mandate to hold an asset, but traditional custodians may not support the relevant network, staking model or transaction process.

A clearer route could lower the cost of custody and make direct holdings more practical for funds that cannot use a traditional bank, broker or qualified custodian. It could also encourage technology-native arrangements in which a regulated firm controls a wallet through distributed authorization rather than a single private key.

But the same flexibility creates new concentration and governance risks. A firm that becomes both portfolio manager and custodian has more responsibility, not less. Its policies would need to explain signing authority, wallet whitelists, emergency procedures, reconciliation, insurance and client access. The technical design would become part of the compliance file.

What the proposal does not do

The proposal is not an automatic approval for every crypto asset or every wallet. It applies only within the scope of the custody rules, with different treatment depending on whether an asset is a fund, a security or a similar investment. It is not a blanket determination of the legal status of all crypto assets.

It also does not replace exchange-traded products with direct custody. For many U.S. retail and institutional investors, an ETF remains a separate vehicle with its own structure, fees and risks. The custody proposal is more directly about how advisers and regulated funds can hold assets on behalf of clients.

Finally, this is not a final rule. The Commission will accept public comments, and the final text may change. The key question is whether the agency can make flexibility measurable: firms need to know exactly how to prove that a custodian was unavailable, how often controls must be tested and what evidence regulators will accept after an incident.

The next 60 days

The comment period will be the first practical test. Likely questions include how firms should document the absence of a qualified custodian; whether state trust companies have sufficient technical expertise; what independent verification should look like; and who is accountable when a custody arrangement fails.

The answers will matter beyond Bitcoin. They will shape how funds approach tokenized securities, blockchain-based settlement and other digital assets that do not fit neatly into legacy custody infrastructure. They may also influence whether advisers build internal control systems or outsource the most sensitive functions to specialized providers.

The SECs move is concrete, but it does not resolve every custody question. If adopted, the framework could make room for institutional crypto exposure while demanding stronger operational discipline from firms that hold client assets themselves. The debate is therefore not simply self-custody versus qualified custody. It is whether the rules can recognize the differences between digital assets and traditional securities without losing the accountability investors need.

Sources: SEC proposed custody rules — Commissioner Peirces statement.

This article is for informational purposes only. It is not investment advice.