Skip to content
Back to articles

What the SEC's latest custody proposal means for global crypto custody

Category: Articles  /  Published:

On 1 October 2026 the US Securities and Exchange Commission proposed a new set of custody rules for crypto assets held by registered investment advisers and regulated funds. Release IA-7023 would allow advisers to hold client crypto themselves under strict conditions and would let trust companies chartered by US states act as crypto custodians. SEC Chair Paul Atkins presented the proposal as a compliant pathway for advisers and funds whose existing custody rules were written for securities held at banks and broker-dealers.

The proposal only applies in the US, but the conditions it sets for holding crypto are worth reading well beyond it. They show in some detail what the regulator of the world's largest capital market expects from a custody arrangement, and most of those expectations will already be familiar to anyone working under MiCA, the Dubai VARA rulebook or Türkiye's custody rules.

The proposal targets US advisers and funds

Release IA-7023 would amend the custody rules for SEC-registered investment advisers and regulated funds, and it covers only crypto assets that are funds or securities. The SEC treats payment stablecoins from issuers permitted under the GENIUS Act and tokenized deposits as funds, and tokenized securities as securities, so both fall within the rule. It does not set up a licence or registration category for custodians. The text is open for comment for 60 days after it appears in the Federal Register, and the final rules may look different.

Two new routes would open. The first is adviser self-custody, meaning the adviser holds any portion of the private keys needed to move a client's asset. It is available only after the adviser decides in writing, asset by asset and every quarter, that no qualified custodian will hold the asset. If a qualified custodian later becomes available, the asset has to move to it as soon as reasonably practicable, which makes self-custody a fallback for assets the custodial market does not yet cover. The rule text is technology-neutral, but the release describes in some detail the practices the SEC expects.

Key management

Only persons designated by the adviser may access key material, and the keys cannot be shared with clients or service providers. The release points to air-gapped storage, hardware security modules and physical measures such as keeping key copies in separate locations. Cold storage is expected in most cases.

Joint authorisation

Every transfer needs approval from at least 2 designated persons, 1 of them a management person. The release names MPC and multi-signature wallets as ways to do this and asks for protection against blind signing, where a signer approves a transaction without seeing what it does.

Segregation

Each client's assets must sit in addresses that hold only that client's assets, which rules out omnibus addresses. Clients can then follow their own holdings on the chain, and the assets are easier to protect if the adviser becomes insolvent.

Cybersecurity

A written risk assessment is required before the adviser takes custody of an asset and at least once a year after. It covers the vulnerabilities of each asset and network, wallet setup, insider threats and key holders who work remotely or travel.

Internal control report

An independent accountant has to report on whether the controls were well designed and worked throughout the period, the scope of a Type II report, and check that holdings reconcile to the network. The first report is due within 6 months, then once a year. Clients also receive quarterly statements for each address.

State trust companies

The second route lets advisers and funds use state-chartered trust companies as crypto custodians. Each year the adviser or fund has to confirm the trust company's authorisation from its state banking regulator and review its safeguarding policies, audited financial statements and internal control report. Client assets must be kept separate from the trust company's own.

The SEC also looked at whether crypto trading requires assets to leave custody and be prefunded on trading platforms, and decided against a separate rule. Its outreach found that advisers and funds can trade without prefunding, for example by keeping assets in cold storage at the custodian during trading and settling ownership afterwards.

The same controls recur across regimes

Put the SEC proposal next to Article 75 of MiCA, the VARA custody rulebook and Türkiye's custody rules and the drafting looks quite different, yet the controls being tested are largely the same. All four keep client assets apart from the custodian's own and protect access to private keys. All four also put limits on how assets move and require some form of reporting or independent check.

Crypto custody controls compared across the SEC proposal, EU MiCA, Dubai VARA and Türkiye: client asset segregation, key management, transfer controls, and records and assurance

Türkiye writes the thresholds into the rules

The SEC's approach is principle-based. It asks for a reasonable basis after due inquiry and for appropriate technology, and it is up to the adviser to show how those standards are met. Türkiye takes a more prescriptive route and writes the mechanisms into the rules.

Under the rules of the Capital Markets Board (SPK) and the infrastructure criteria set by TÜBİTAK, at least 95% of customer crypto assets at a custody institution have to be held in cold wallets. Keys and key shares are generated inside hardware security modules (HSMs), and signing happens inside them too. Custody institutions also connect to MKK, Türkiye's central securities depository, which keeps the records of customer balances.

Proof of reserves is audited periodically by an independent information systems auditor, and there are limits on how long the same auditor can serve. A custody institution needs at least 500m TRY in capital, with more equity required once assets in custody exceed 1bn TRY.

Paribu Custody's controls map to the shared standard

Paribu Custody was built to this level of control from its first day, and each control on that list is in place today. Most of them run on ColdShield®, Paribu's custody technology combining HSM, multi-party computation (MPC) and attested secure enclaves. The points below follow the same order as the SEC conditions.

  • Key management: Keys and key shares are generated inside HSMs, and cold wallet signing takes place in an air-gapped environment. Getting physical access to the signing environment takes more than one authorization, and the person who approves a transfer is never the one who carries out the physical operation. Each access is logged with biometric and multi-factor authentication, and if a device detects tampering it wipes its keys and raises an alarm.
  • Joint authorisation (Admin quorum): Critical administrative actions such as permission changes, new transfer rules and whitelist additions need approval from several members of an admin quorum. A new workspace starts with the strictest setting, where every member has to approve. Lowering that threshold needs as many approvals as the current threshold requires, so one person cannot quietly weaken the protection.
  • Blind signing: The HSM checks 3 things before it signs anything. The request has to carry signatures from 2 separate authority groups, it has to carry the policy engine's signature confirming the rules were applied, and all of these have to belong to the same client environment and authorised users. On top of that, the amount, destination address and network are fingerprinted and signed when the request is created and checked again just before signing, so a request that has been changed after approval never reaches the HSM.
  • Transfer rules: The policy system begins with a rule that blocks every transfer, and that rule cannot be edited or moved. A transfer only goes through if a more specific rule allows it. Every rule change is chained to the hash of the previous change, so if someone edits the rules directly in the database the chain breaks and the system catches it before signing.
  • Segregation: Client assets are held in segregated wallets and vaults, apart from the company's own assets.
  • Network risk: Each network runs on at least 3 nodes from different providers, 1 of them Paribu's own, and a deposit is only credited after 2 separate nodes have confirmed it.
  • Records and assurance: Logs are sealed as they are written, with each entry carrying the fingerprint of the one before it, so changing a whitelist record, a rule definition or a transaction log breaks the chain and gets detected. ColdShield® holds SOC 1 Type II and SOC 2 Type II reports, the company holds ISO 27001 certification, and customer balances are reconciled through Central Securities Depository (MKK) reporting.

A shared baseline for custodians everywhere

For custodians outside the US, the interesting part of the proposal is what it asks for. Segregated client assets, well-protected keys, approval by more than one person and independent checks against the chain now appear in US, EU, Dubai and Turkish rules, even though those rules were written separately.

Türkiye sets this out in fixed thresholds and the SEC sets it out as principles, but the controls themselves are the ones other regulators had already adopted. For an institution choosing a custodian in any of these markets, the practical question stays the same, which is whether each of these controls is in place and whether someone independent has checked it.

Frequently asked questions

What did the SEC propose on crypto custody?

On 1 October 2026 the SEC proposed rules on how registered investment advisers and regulated funds may hold crypto assets that are funds or securities. Advisers would be able to self-custody under conditions, and state trust companies would be allowed to act as custodians. The proposal also updates parts of the existing custody rules.

Can investment advisers self-custody crypto under the proposal?

Only if the adviser has decided in writing that no qualified custodian will hold that specific asset, and only for as long as that stays true. The decision is made asset by asset and reviewed every quarter. The adviser then has to meet conditions on key management, joint authorisation, segregation, cybersecurity, internal control reports and client statements.

What does the SEC proposal mean for custodians outside the US?

It does not apply to them directly. Its conditions do, however, closely match what MiCA, the Dubai VARA rulebook and Türkiye's framework already require, which suggests a common baseline for institutional crypto custody across jurisdictions.

Is the SEC crypto custody proposal in force?

No. Release IA-7023 is a proposal, open for comment for 60 days after publication in the Federal Register. The Commission reviews the comments before deciding whether to adopt final rules, and those rules may differ from the proposal.

How does the SEC proposal compare with MiCA?

Both require client assets to be kept apart from the custodian's own, both protect access to keys and both require regular client statements. MiCA applies to crypto-asset service providers across the EU and makes custodians liable for losses attributable to them. The SEC proposal applies to US advisers and funds and sets conditions on how they hold client crypto assets or where they place them.