SEC Proposes Crypto Custody Framework: What Self-Custody Could Mean for Advisers and Funds

Crypto investment strategies depend on more than identifying an opportunity. They also depend on whether the assets can be held within a workable legal and operational framework.

On October 1, 2026, the Securities and Exchange Commission proposed new rules and amendments under the Investment Advisers Act of 1940 and the Investment Company Act of 1940 addressing crypto custody for registered investment advisers and regulated funds, including registered investment companies and business development companies. The proposal would permit conditional self-custody and expand the use of state trust companies as crypto custodians. It is a proposal, not an effective rule.

For asset managers, the significance is practical: the SEC is proposing a framework for situations in which a crypto investment is available, but an appropriate custodian is not.

Why Crypto Custody Needs a Tailored Framework

Traditional custody rules were designed around assets and institutions that existed long before blockchain networks. Crypto introduces a different operational problem: an asset can become available before a permitted custodian develops the capability to support it.

SEC Chairman Paul Atkins identified this gap as a central reason for the proposal. Custodial capabilities can lag the deployment of new crypto assets by months, creating barriers for advisers and funds seeking exposure on behalf of investors.

From Launch Legal’s perspective, this gap connects investment decisions directly to legal infrastructure. A manager may understand a token’s investment thesis and technical design while still needing to resolve who can hold it, who controls transfers, and how investors’ interests are protected.

The proposed framework would make those custody questions a more explicit part of investment governance.

Self-Custody Would Be Conditional

The proposal uses the term “self-custody,” rather than “shelf-custody.”

An adviser would need to determine in writing, before taking self-custody and at least quarterly thereafter, that a permitted custodian is unavailable for the particular asset. For regulated funds, custody would occur through the fund’s adviser, with additional board oversight.

The practical implication is that self-custody would require an ongoing assessment. A manager considering this route should be prepared to explain its search for custodial support and maintain evidence supporting its conclusion.

A useful preparation process would identify:

  • Which custodians were evaluated.

  • Whether they support the relevant asset and network.

  • What limitations prevent the proposed custody arrangement.

  • Who owns the review process.

  • How changes in custodial availability will be escalated.

These are preparation considerations, rather than a substitute for the proposed rule’s specific conditions. They would help turn a legal determination into a repeatable operational process.

Technical Controls Would Become Compliance Controls

The SEC’s fact sheet identifies several proposed self-custody safeguards:

Area

Proposed safeguard

Expertise

Document expertise in safeguarding each asset.

Transaction authority

Address private-key management and require joint authorization by at least two people.

Segregation

Maintain each client’s assets in addresses containing only that client’s assets.

Cybersecurity

Mitigate relevant risks and review controls at least annually.

Independent review

Obtain an accountant’s internal control report within six months, then annually.

Client reporting

Provide quarterly account statements, subject to applicable exceptions.

Legal documentation

Agree in writing to treat the assets as financial assets under applicable state law.

For regulated funds, boards would review custodian availability initially and quarterly, and assess reasonable care initially and annually.

For managers evaluating readiness, these conditions raise questions that go beyond selecting a wallet provider.

Can one employee move assets alone? Can the organization recover access if a signer leaves? Are client holdings separated in the actual wallet architecture? Can an independent reviewer evaluate whether the controls work?

A custody policy becomes useful when it answers those questions and matches the systems people actually use. Written procedures, access permissions, transaction approvals, and incident response should describe the same operating model.

State Trust Companies Could Have a Clearer Role

The proposal would establish a distinct route for eligible state trust companies to custody crypto assets and related cash or cash equivalents. Under the proposed framework, an adviser or fund would assess state authorization and safeguarding policies, review audited financial statements and internal control reports, and ensure separation from the custodian’s proprietary assets. Existing routes remain available where a trust company already satisfies the applicable statutory definition of a bank.

The practical opportunity is a broader and more explicit set of custody arrangements. The corresponding responsibility is meaningful diligence.

Managers evaluating a provider should consider whether its capabilities fit the actual strategy: the assets involved, supported networks, transfer processes, recovery arrangements, and reporting needs. A provider’s general reputation may be relevant, but the custody decision should address the specific portfolio and operating model.

Contract review should also examine how the relationship handles service interruptions, disputed instructions, security incidents, and termination. These issues matter when an investment strategy depends on continuous access to assets.

Scope Matters: This Is Not a Universal Token-Management Exemption

The proposed Advisers Act amendments concern crypto assets that are funds or securities, with a distinct treatment for regulated-fund accounts. The Investment Company Act custody rules concern securities and similar investments.

Accordingly, the proposal should not be presented as automatic permission for every business, DAO, treasury operator, or individual managing tokens for others.

The threshold questions remain essential:

  • What is the legal status of the manager?

  • Whose assets are being held?

  • Which rules apply to the arrangement?

  • How is each asset classified?

  • What authority does the manager have over transfers and access?

For a private fund, corporate treasury, or community-owned structure, those answers may differ substantially. The commercial description of the activity—“treasury management,” for example—does not by itself resolve the legal analysis.

How to Understand the “First Compliant Path” Claim

Chairman Atkins described the proposal as creating a compliant pathway where none previously existed. That statement conveys the SEC’s policy objective: addressing gaps left by custody rules developed for traditional markets.

For legal planning, however, the more precise description is that the SEC is proposing a tailored crypto custody framework, including a conditional self-custody route.

Calling it the first compliant path for anyone managing tokens would obscure both its scope and its status. Managers should distinguish between a proposed future option and the legal basis for their current activities.

That distinction also matters in investor communications. Offering materials and client discussions should accurately describe what is available today, what remains proposed, and which operational changes would be needed before a future rule could be used.

What Managers Can Prepare Now

Launch Legal’s view is that the proposal creates a useful opportunity to assess readiness before implementation decisions are required.

Map the custody arrangement. Identify assets, networks, wallets, custodians, signers, and service providers. Record who can authorize transfers or obtain access.

Evaluate operational capacity. Consider whether staffing, cybersecurity, segregation, reporting, and independent review can support the contemplated arrangement.

Align documentation with practice. Review advisory agreements, custody contracts, disclosures, and internal policies against the actual allocation of authority.

Assign responsibility. Determine who will conduct recurring reviews, maintain evidence, report deficiencies, and oversee remediation.

Develop concrete comments. Firms facing custody gaps can explain where the proposed conditions fit existing practices and where implementation presents difficulties. Examples involving particular assets, networks, or control arrangements will be more useful than broad statements of support or opposition.

The Comment Period

Comments are due 60 days after publication of the proposing release in the Federal Register, rather than 60 days after the October 1 announcement. The SEC identifies the proceeding as File No. S7-2026-35, with Release Nos. IA-7023 and IC-36353.

The calendar deadline should be checked against the published notice before a submission is scheduled

Learn More

This blog post is for informational purposes only and is not legal advice. Please consult with a Launch Legal attorney regarding your specific situation.