Back to homepage

SEC proposes crypto custody framework for advisers and funds that would permit self-custody and state trust company custodians

October 9, 2026

On October 1, the SEC proposed a package of rules and amendments under the Investment Advisers Act of 1940 and the Investment Company Act of 1940 that would create a “tailored framework” for crypto asset custody by registered investment advisers and regulated funds, including registered management investment companies and business development companies. The SEC said its current custody rules were designed for traditional assets and that permitted custodians may not be available for some crypto assets, particularly nascent or novel ones.

Under the proposal, an adviser could self-custody a client’s crypto asset only if it determines in writing, before taking custody and at least quarterly after that, that no permitted custodian is available. That finding could not rest on cost, and the adviser would have to move the asset to a custodian as soon as reasonably practicable once one becomes available. Among other conditions, the adviser would have to document its safeguarding expertise, maintain key management controls requiring two-person transaction approval, maintain cybersecurity controls, obtain independent internal control reports, send quarterly account statements, and agree in writing to treat the asset as a “financial asset.” A regulated fund could self-custody through its adviser only if the fund’s board also reviews the adviser’s finding and determines that the asset would receive “reasonable care.”

The proposal also would establish state trust companies as a new category of permitted custodian for crypto assets, so advisers and funds would no longer have to determine whether such a company qualifies as a “bank” under the custody rules. SEC staff addressed that question in a September 30, 2025, no-action letter (covered by InfoBytes here), and the SEC’s views would supersede inconsistent staff positions if the rules are adopted. To use a state trust company, an adviser or fund would need a “reasonable basis, after due inquiry,” before engaging the company and annually after that, to believe the company is authorized by its state banking authority to provide crypto custody and maintains written safeguarding policies. On the same schedule, the adviser or fund would have to review the company’s audited financial statements and internal control report. Client crypto assets also would have to be segregated from the company’s own assets. The proposal also would amend Form ADV and Form N-CEN to collect information on crypto custody.

Separately, the proposal would update the custody rules more broadly by, among other things, dropping the requirement that custody-rule accountants be registered with and inspected by the Public Company Accounting Oversight Board and allowing regulated funds to use any registered broker-dealer as a custodian if its custody of fund assets is subject to the SEC’s customer protection rule. Comments are due December 7.