
The October 2026 proposal opens two routes for regulated institutions, but each converts “who holds the keys?” into a testable governance obligation.
On October 1, 2026, the U.S. Securities and Exchange Commission proposed a dedicated custody framework for registered investment advisers and regulated funds holding crypto assets. Published in the Federal Register on October 6, the package is neither final law nor a general blessing for every token. It is a targeted attempt to reconcile two realities: custody rules are central to investor protection, yet the set of traditional institutions able and willing to safeguard every relevant crypto asset remains incomplete.
The proposal’s importance is not simply that it is “pro-crypto.” Its deeper move is to replace a practical dead end with two conditional routes. First, advisers and funds could use qualifying state trust companies as permitted custodians, subject to due diligence, audited financial information, control reports and asset segregation. Second, an adviser could self-custody client crypto—but only as a fallback after determining in writing, initially and every quarter, that no permitted custodian is available for the asset. That route would bring detailed requirements around expertise, key management, dual authorization, cybersecurity, independent control testing, account statements and, for funds, board oversight.
Our thesis is that the proposal changes the institutional crypto question from whether custody can fit within regulated asset management to which party owns each failure mode, and what evidence proves its controls work. It could broaden access and increase competition. It could also concentrate unfamiliar operational risk inside advisers, impose fixed costs that advantage large firms, and create false confidence if legal segregation and technological control do not survive a custodian failure or a key compromise. The market impact will therefore depend less on the headline permission than on the quality of implementation, the final scope, and the comments submitted before the SEC’s December 7, 2026 deadline.
The SEC rulemaking page identifies the package as File S7-2026-35, Release IA-7023 and IC-36353. It covers registered advisers under the Investment Advisers Act and regulated investment companies and business development companies under the Investment Company Act. The agency’s press release says the proposal would also modernize non-crypto elements of the custody regime, including financial-statement audits and broker-dealer custodial services.
Scope is crucial. As Commissioner Hester Peirce emphasized in her supporting statement, the crypto provisions do not automatically cover every crypto asset. The proposed Advisers Act amendments would apply to crypto assets that are funds or securities; for regulated-fund accounts, the relevant category is a security or similar investment. The Investment Company Act rules likewise concern crypto assets that are securities or similar investments. Classification remains a separate legal question.
Nor does “self-custody” mean an individual holding assets in a personal wallet. Here it means an adviser possessing some portion of the private-key material necessary to access and transact in a client’s asset, rather than maintaining that asset with a permitted custodian. Peirce called attention to that linguistic gap: this is intermediary custody by an adviser, not disintermediated ownership by the end investor.
flowchart TD
A[Adviser or regulated fund considers a crypto asset] --> B{Asset within the applicable custody-rule scope?}
B -- No --> Z[Proposal's crypto-custody route does not decide treatment]
B -- Yes --> C{Permitted custodian available for this asset?}
C -- Yes --> D[Use permitted custodian]
D --> E{State trust company?}
E -- Yes --> F[Verify authority, controls, audited financials and segregation]
E -- No --> G[Apply existing and modernized permitted-custodian rules]
C -- No --> H[Document finding initially and quarterly]
H --> I[Conditional adviser self-custody]
I --> J[Expertise, dual authorization, cybersecurity and independent controls]
J --> K[Quarterly client evidence and fund-board oversight where applicable]The decision tree matters because self-custody is not designed as an elective parallel track. The proposal requires a documented determination that a permitted custodian is unavailable, repeated quarterly. If a qualified option emerges, an adviser may need to migrate the assets or stop self-custodying them. The architecture is therefore dynamic: custody status must follow market capability, rather than being fixed when the investment is first made.
The following table separates the proposal’s two crypto-specific pathways. It is a synthesis of the Federal Register proposal, not a substitute for the rule text.
Dimension | Conditional adviser self-custody | Qualifying state trust company |
|---|---|---|
Entry condition | Written finding, initially and quarterly, that no permitted custodian is available | Reasonable basis, after due inquiry, that the company is authorized by its state regulator and capable of safeguarding crypto assets |
Core operator | Adviser holds necessary key material | Separate state-chartered trust company |
Principal controls | Asset-specific expertise; private-key controls; at least two-person authorization; client-specific addresses; cybersecurity mitigation | Written safeguarding policies; audited financial statements; internal-control reporting; service agreement and segregation |
Independent evidence | Internal-control report within six months and annually thereafter; onchain reconciliation; surprise examination or applicable audit route | Adviser or fund receives and reviews financial and control evidence initially and periodically |
Client visibility | At least quarterly statements or usable electronic information identifying addresses, balances and transactions | Custodial reporting under the service and custody framework |
Governance burden | Adviser and, for a regulated fund, its board directly oversee a conflict-laden arrangement | Adviser or fund must select and monitor an external provider; outsourcing does not erase fiduciary responsibility |
Chair Paul Atkins frames the change as closing a gap created by rules that predate the internet. His October 1 statement argues that custodial support can lag a new asset’s deployment by months. Commissioner Mark Uyeda’s statement puts the policy tension more precisely: asset segregation remains a durable principle, but it cannot look identical for paper certificates in a vault and entries on a distributed ledger.
That distinction is the proposal’s intellectual center. Traditional custody separates portfolio management from safekeeping and gives an independent institution control of assets. Adviser self-custody recombines those roles. The SEC tries to compensate with process: two-person approval limits unilateral action; separate client addresses improve attribution; independent control testing challenges management’s own assertions; and direct comparison with onchain records can expose reconciliation failures. Yet process controls do not recreate institutional independence. They make the conflict observable and auditable.

The proposal reallocates availability, operational and legal risk across advisers, control operators and custodians; it does not make those risks disappear.
Today, an adviser may identify a potentially suitable crypto asset but find no custodian that both qualifies under the rules and supports that network or token. The proposal would reduce that “custody veto.” State trust companies could widen the provider pool, while fallback self-custody could cover assets before third-party support matures.
The likely effect is not indiscriminate access. Compliance costs rise with network novelty. An adviser would need demonstrable expertise for each asset, workable segregation, transaction controls and external assurance. Assets with weak operational tooling, ambiguous ownership rights or difficult reconciliation may remain uneconomic. In other words, the framework could expand the frontier while making the evidence threshold more explicit.
The quarterly availability determination changes the operating model. A firm could not simply document “no custodian” at launch and forget it. It would have to monitor whether a permitted service becomes available, reassess the rationale, and manage a migration without disrupting investment strategy or exposing assets in transit. Boards of regulated funds would need enough information to oversee a technical arrangement whose risks can change after software upgrades, forks, personnel changes or emerging attack methods.
sequenceDiagram
participant PM as Portfolio team
participant C as Compliance and risk
participant O as Custody operations
participant A as Independent accountant
participant B as Fund board / client
PM->>C: Propose exposure to an in-scope crypto asset
C->>C: Test permitted-custodian availability
alt Permitted custodian exists
C->>O: Approve external custody with due diligence
else No permitted custodian
C->>O: Authorize fallback self-custody
O->>O: Apply segregated addresses and dual approval
A->>O: Test controls and reconcile to the network
O->>B: Deliver quarterly balances and transactions
C->>C: Repeat availability test each quarter
end
B->>C: Challenge exceptions, incidents and migration planThe proposal’s independent-control framework recognizes a distinctive advantage of public networks: an accountant can compare internal records with balances and transactions visible on the relevant blockchain. That can make certain existence and movement tests more direct than in opaque sub-ledgers.
But blockchain visibility does not prove every fact investors care about. It cannot, by itself, establish that a client has a legally enforceable claim, that keys have not been copied, that governance can recover from compromise, or that a bankruptcy court will respect the intended segregation. Onchain evidence is a powerful component of assurance, not a substitute for contracts, internal controls and legal analysis.
The strongest argument for the proposal is practical: a rule that demands a custodian where none exists can block regulated advice without producing real protection. The strongest counterargument is equally practical: allowing the investment manager to control client assets collapses a separation designed to prevent misuse. The proposal answers with guardrails, but their effectiveness will vary by firm.
First, the framework may favor scale. Independent control reports, specialized cybersecurity staff, round-the-clock key operations and fund-board education impose fixed costs. Large advisers can amortize them; smaller firms may remain dependent on external custodians or avoid the asset class. More formal custody routes do not necessarily mean more diverse competition at the adviser level.
Second, “unavailable” will need disciplined interpretation. Does it mean that no permitted custodian supports the asset at any price, or that available service is commercially unreasonable, technologically incomplete, or incompatible with a strategy? Loose standards could turn an exception into routine practice. Overly rigid standards could preserve the very custody bottleneck the SEC wants to solve.
Third, state trust companies are heterogeneous. A charter is an entry credential, not proof that every provider has equal capital strength, cyber resilience, insurance, recovery design or insolvency treatment. The proposal’s due-diligence and financial-review obligations are therefore substantive, not a box-checking exercise. Legal segregation must also match operational reality: omnibus structures, staking arrangements, bridges or smart-contract interactions can complicate the claim that assets are cleanly isolated.
Fourth, key compromise is asymmetric. A mistaken bank transfer may be reversible; a validly signed blockchain transaction often is not. Two-person authorization reduces insider and error risk, but it does not guarantee independence if both approvers share systems, incentives or a compromised environment. Good governance must examine common-mode failure, not merely count signatures.
Finally, this remains a proposal. The Commission may alter definitions, conditions, transition periods and reporting requirements after comments. The official rulemaking page sets December 7, 2026 as the comment deadline. Institutions should read the package as a direction of travel and a request for evidence, not as current permission to restructure custody today.
Three signals will indicate whether the final framework achieves its stated balance. One is the final definition of custodian “availability,” because it determines how narrow the self-custody exception really is. A second is whether independent reports test operating effectiveness across the full key lifecycle—including generation, backup, authorization, recovery and incident response—rather than documenting policies on paper. A third is whether contracts and state-law arrangements create durable client property rights when a provider fails.
The proposal also places a premium on migration readiness. If quarterly review finds that a permitted custodian has become available, the firm needs a safe path from internal control to external control. Conversely, if a custodian exits an asset, an adviser may need a controlled fallback. The winning operating model is therefore not a single vault. It is a governed ability to move between custody states without losing the chain of evidence.
The SEC’s October proposal is consequential because it acknowledges that institutional crypto custody is neither identical to traditional safekeeping nor exempt from its core principles. It offers regulated advisers and funds a way around an infrastructure gap, while making the alternative costly, conditional and reviewable.
That balance is sensible in concept. Wider provider choice may reduce concentration and allow regulated investors to reach assets that custody rules previously made impractical. Yet adviser self-custody internalizes a conflict that traditional custody deliberately exports. Its legitimacy will rest on whether independent evidence, board challenge, legal segregation and technical controls are strong enough to survive the exact moments custody rules are built for: fraud, insolvency, cyberattack and operational stress.
The headline is therefore not that Washington has approved institutional self-custody. It is that the SEC has proposed a new accountability map. In that map, possession of keys is only the beginning; the decisive question is whether every transfer of control comes with a defensible transfer of risk, oversight and proof.
Research current through October 7, 2026. This report is analysis, not legal or investment advice.