US Advisers and Broker Dealers: 5 DARE Steps for SEC Crypto Custody

Custody obligations for crypto assets now run through two anchor rules: the Custody Rule (Advisers Act Rule 206(4)-2) for registered investment advisers and Rule 15c3-3 for broker-dealers, both reshaped by the SEC’s March 2026 interpretive release. Firms handling digital assets need to document key-management controls, reassess every custodian and sub-custodian contract, and build exam-ready evidence files before the next sweep. The Securities and Exchange Commission, the Federal Reserve, and the Office of the Comptroller of the Currency are the three regulators setting the pace on this, and none of them are waiting for a final rule to start asking questions.
TL;DR:
- Proper classification of crypto assets as securities or non-securities is essential, affecting custody requirements and ongoing controls.
- Documentation of custody analysis, including control locations and asset-specific facts, becomes the foundation for downstream compliance decisions.
- Custody arrangements relying on non-traditional custodians require detailed policies, regular assessments, and evidence of technical control meet reasonableness standards.
- Broker-dealer custody of crypto securities must prove exclusive control through specific controls like multi-party signing and control location documentation.
- Regulation is moving toward evaluating custody based on actual controls and risks rather than check-the-box compliance, demanding thorough, proactive evidence collection.
Table of Contents
- What Does the SEC’s 2026 Interpretation Mean for Crypto Custody?
- How Is the Custody Rule Being Modernized for Crypto Assets?
- What Does Rule 15c3-3 Require for Broker-Dealer Crypto Custody?
- What Do Banking Agencies Require for Crypto Safekeeping?
- Which Operational Controls Should Firms Document for Custody Programs?
- How Should Firms Vet Sub-Custodians and Structure Contracts?
- Where Does Custody Rulemaking Stand and What Should You Watch?
- How Does the DARE Framework Map to Custody Exam Readiness?
- Where Can You Find the Primary Sources to Monitor?
- An Editorial Take on Where Custody Compliance Is Actually Heading
- Sources
What Does the SEC’s 2026 Interpretation Mean for Crypto Custody?
The SEC’s March 2026 interpretive release does something the industry had been asking for since 2022: it gives a working taxonomy for sorting crypto assets by legal character rather than by ticker symbol. The SEC’s interpretation walks through how the Howey investment-contract test applies to different categories of tokens and transactions, and it spells out when a crypto asset that is not itself a security can still get pulled into securities regulation through the way it is sold, staked, or bundled into a program.
That classification question is not academic. It is the hinge that decides which custody regime applies.
If a token is a security, an adviser’s custody obligations flow through Rule 206(4)-2 and a broker-dealer’s flow through Rule 15c3-3. If it is not a security, the firm still owes clients a safeguarding and fiduciary duty, just not under the securities custody framework specifically. Get the classification wrong and you either over-engineer controls for an asset that never needed them or, worse, leave a security-classified token sitting in an arrangement that would not survive an exam.
The interpretation organizes crypto assets into rough buckets:
- Network tokens with no ongoing enterprise obligations (often not securities on their own).
- Tokens sold or marketed as part of an investment scheme (frequently swept into the investment-contract analysis).
- Tokens tied to staking, yield programs, or centralized promises of profit (the SEC flags these as the highest-risk category for triggering security status).
- Tokenized traditional securities (treated as securities regardless of the wrapper).
The SEC has been explicit that the analysis is transaction-specific, not asset-specific. The same token can be a security in one distribution context and not in another, which is exactly the kind of nuance that makes blanket “our platform only handles non-security tokens” policies risky. Compliance teams should treat every new token listing or program as its own facts-and-circumstances review, not a one-time determination.
Two things from the release are worth flagging directly for a compliance file. First, the SEC frames the taxonomy as guidance for firms to apply themselves, not a pre-cleared list, meaning documentation of your own analysis matters as much as the conclusion you reach. Second, the release ties classification explicitly to custody consequence: once an asset is deemed a security, there is no separate “crypto exception” to Rule 206(4)-2 or Rule 15c3-3. The custody machinery that applies to a share of stock applies to a tokenized version of that same economic interest.
For advisers and broker-dealers, that means the classification memo you write today becomes the foundation for every downstream custody decision, including which safeguarding model you use and which sub-custodian due diligence standard applies.
How Is the Custody Rule Being Modernized for Crypto Assets?
Rule 206(4)-2 continues to require registered investment advisers with custody of client funds or securities to hold those assets with a qualified custodian, though originally written for cash and traditional securities rather than private keys.
The problem regulators are now confronting is that qualified custodians for crypto assets are scarce relative to demand, and many advisers work with clients who insist on self-custody arrangements or platforms that do not fit neatly into the traditional bank-or-broker qualified custodian mold.
Two developments are reshaping how RIAs should think about this gap.
The first is staff relief commonly referred to as the Crypto Custody No-Action Letter, under which SEC staff have indicated they will not recommend enforcement action against advisers relying on qualifying state-chartered trust companies for crypto custody, provided specific conditions around licensing, segregation, and audit are met. That relief matters because it widens the pool of qualified-custodian-equivalent options beyond national banks and registered broker-dealers.
The second is the model framework whitepaper submitted to the SEC in December 2025, which proposes a reasonableness standard for non-qualified-custodian safeguarding. Under this framework, arrangements using multi-signature or multi-party computation architecture (MS/MPC) could satisfy custody objectives even without a traditional qualified custodian, as long as the firm can demonstrate the technical controls meet an objective reasonableness bar. Regulators appear to be shifting toward evaluating what a custody arrangement actually does rather than which box it checks.
Pro Tip: Do not wait for the model framework to become binding rule text before building your evidence trail. Examiners are already asking advisers to show how they evaluated custodian reasonableness, even under the current rule.
For an RIA, that means the documentation stack examiners will expect now includes:
- A written safeguarding policy naming the specific controls (MPC, hardware security modules, multi-signature thresholds) used for each asset type.
- A custodian and sub-custodian assessment memo, updated at least annually, covering licensing status, insurance, and audit history.
- Client disclosures describing the custody arrangement in plain terms, including whether a qualified custodian or an alternative safeguarding model is used.
- Segregation evidence showing client assets are distinguishable from firm assets and from other clients’ holdings at the wallet or account level.
A comparison of custody solution categories can help firms map which safeguarding model fits which client base without defaulting to whatever a single vendor happens to sell.
What Does Rule 15c3-3 Require for Broker-Dealer Crypto Custody?
Rule 15c3-3, the customer protection rule, requires broker-dealers to maintain physical possession or control of customer securities. For crypto asset securities, “physical possession” obviously does not mean a paper certificate in a vault. Staff guidance from December 2025 lays out how the “possession or control” standard translates to digital assets, and the bar is stricter than many firms initially assumed.
The SEC’s statement on broker-dealer custody of crypto asset securities makes clear that a broker-dealer must be able to show that no other party can unilaterally transfer the asset out of the customer’s account. That is a technical requirement as much as a legal one: it means documenting exactly who holds signing authority, how multi-party approval workflows are configured, and where the control location physically and cryptographically sits.
Practical control models that satisfy this standard tend to combine a few elements:
- Defined control locations, meaning a specific custodian, cold-storage vault, or MPC network node identified in writing as the point of control.
- Multi-party signing requirements that prevent any single employee, vendor, or automated process from moving assets alone.
- Recordkeeping that ties each private key or key-share to a specific control location and a specific customer account, not a pooled or unlabeled wallet.
The SEC’s trading and markets FAQ reinforces that existing Rule 15c3-3 mechanics apply to crypto asset securities without a carve-out, and it flags recordkeeping gaps around control locations as a recurring source of friction in staff conversations with firms.
Special-purpose broker-dealer (SPBD) guidance adds another layer for firms specifically structured around digital asset securities. SPBDs operate under a narrower business model focused on custody and trading of crypto asset securities, and that structure changes which custody options are practical: an SPBD is generally expected to limit itself to non-margin, fully paid custody arrangements, which simplifies some of the possession-or-control analysis but requires its own set of segregation and capital documentation. Firms weighing whether to register as an SPBD or operate under a traditional broker-dealer license should treat that custody-control question as a threshold decision, not an afterthought.
What Do Banking Agencies Require for Crypto Safekeeping?
Banks and state trust companies offering crypto custody answer to a different but overlapping set of expectations. The OCC, the Federal Reserve, and the FDIC issued joint guidance in July 2025 that defines “safekeeping” in operational terms: a banking organization must demonstrate actual control of the cryptographic keys associated with the assets it holds, not merely a contractual promise to keep them safe.
That distinction between fiduciary and non-fiduciary safekeeping roles matters for legal exposure. A bank acting in a fiduciary capacity, such as a trustee, owes duties of loyalty and care that go beyond simple custodial safekeeping and typically require more granular recordkeeping on beneficial ownership and asset segregation. A non-fiduciary custodial role focuses more narrowly on secure possession and accurate recordkeeping, but the joint agency guidance makes clear that even non-fiduciary safekeeping demands documented cryptographic key controls and internal audit coverage tailored specifically to crypto, not repurposed from a bank’s existing physical-asset audit program.
The guidance lists several controls examiners will look for directly:
- Documented cryptographic key generation, storage, and rotation procedures, ideally independently attested.
- Internal audit programs scoped specifically to crypto custody operations, run on a defined cadence rather than folded into general IT audits.
- Third-party oversight protocols for any sub-custodian or technology vendor involved in key management.
- Clear insolvency-treatment language establishing how customer crypto assets are treated if the bank or a sub-custodian fails.
Pro Tip: Ask your legal team to produce a one-page insolvency memo for each account model you use. Examiners increasingly want to see that a bank has actually modeled what happens to customer assets in a receivership, not just asserted that assets are “held for the benefit of customers.”
Banking examiners evaluating a custody program will typically request the key-management audit report, the third-party oversight file for each sub-custodian, and a narrative explaining the account model, whether omnibus or individually segregated, and why that model was chosen for that customer base. A guide to institutional custody considerations covers how these account-model decisions play out for different client types, which is worth reviewing before an exam rather than during one.
Which Operational Controls Should Firms Document for Custody Programs?
Regulators across the SEC and the banking agencies keep circling back to the same handful of technical and procedural controls. Practitioner experience with SEC staff conversations points to documentation gaps around key management, fork and airdrop governance, and evidence of third-party oversight as recurring sources of examination friction, which means these are the areas to get airtight first.
Build your control documentation around these steps:
- Key generation and storage architecture. Specify whether keys are generated and stored via hardware security modules (HSMs), multi-party computation (MPC), or a hybrid model, and document the vendor or internal system responsible for each.
- Split custody and multi-signature thresholds. Record exactly how many signers or key-shares are required to authorize a transfer and who holds each share.
- Key rotation policy. Set a defined rotation schedule and document every rotation event, including who authorized it and why.
- Backup and recovery procedures. Detail how keys are backed up, where backups are stored geographically, and how recovery is tested, not just described.
- Incident response plan. Lay out the specific steps for a suspected key compromise, including client notification timelines and forensic procedures.
Account model choice deserves its own line in the policy. Omnibus accounts, where multiple customers’ assets sit in a single on-chain address, are operationally simpler and cheaper to run, but they raise insolvency questions about how individual customer claims get reconstructed if the custodian fails. Segregated accounts, with a dedicated address per customer, make ownership tracing straightforward but multiply the operational overhead of key management. Neither model is inherently compliant or noncompliant; what regulators want is a written rationale for the choice and an insolvency analysis that matches it.
Forks, airdrops, and staking rewards need their own governance language, since these events create new assets that were not part of the original custody agreement. A defensible policy states in advance how the firm will handle an unplanned fork (claim on behalf of customers, decline to support, or pass the decision to the customer) and how staking rewards get allocated and reported.
Pro Tip: Treat your fork and airdrop policy as a living document tested against real events, not a hypothetical clause. Regulators have flagged silence on this topic as a gap even when the underlying key-management controls were solid.
Audit and testing frequency should scale with asset value and complexity: quarterly internal control testing at minimum, with an independent third-party key-management audit at least annually. A private key risk management guide and a broader digital asset access control resource both walk through how to structure this testing cadence in more technical detail.
How Should Firms Vet Sub-Custodians and Structure Contracts?
Hiring a sub-custodian does not transfer regulatory responsibility. The joint banking-agency guidance is explicit that a firm choosing to work with a sub-custodian remains accountable for assessing that sub-custodian’s key-management practices, insolvency treatment, and audit controls, which means due diligence has to be substantive, not a checkbox exercise.
Collect the following before signing or renewing any custody or sub-custody contract:
- Recent audited financial statements from the sub-custodian, not just a summary balance sheet.
- SOC 2 Type II or comparable independent attestation reports covering the specific systems handling client keys.
- A dedicated key-management audit report, separate from general SOC coverage.
- Custody test reports demonstrating successful recovery and transfer procedures under simulated failure conditions.
On the contract side, several clauses are worth treating as non-negotiable rather than aspirational:
- Segregation language that legally, not just operationally, separates customer assets from the sub-custodian’s own balance sheet.
- No rehypothecation without explicit written consent, closing off any implied right for the sub-custodian to lend or reuse customer assets.
- Audit rights granting the contracting firm or its regulator access to inspect the sub-custodian’s controls on demand, not only during scheduled reviews.
- Insolvency allocation language specifying exactly how customer assets are treated and returned if the sub-custodian enters bankruptcy or receivership.
- Breach notification service-level agreements with a firm deadline, ideally 24 to 72 hours, for reporting any suspected security incident.
A legal perspective on safeguarding digital assets in custody and wallet arrangements walks through how these contract clauses hold up in practice, particularly around insolvency allocation, which is often the clause that gets the least attention until it is the one that matters most. Regulators consistently frame the contracting firm, not the vendor, as the party accountable if oversight documentation is thin, so keep a running file of every due-diligence review, not just the signed contract.
Where Does Custody Rulemaking Stand and What Should You Watch?
As of mid-2026, formal rule text for Custody Rule modernization has not yet been finalized. Regulatory-tracking reporting indicates the SEC submitted custody-rule modernization material for OIRA and White House review in August 2026. The specifics of the draft rule were still undisclosed publicly at that stage. That review step sits between an agency finishing internal drafting and issuing a formal Notice of Proposed Rulemaking (NPRM), so it signals movement without giving firms the actual rule text to plan against yet.
The standard path from here runs through a few predictable checkpoints: OIRA completes its review, the SEC issues an NPRM with a public comment period (typically 60 to 90 days), the SEC reviews comments and may revise the proposal, and only then does a final rule get adopted, usually with a compliance date set months out from adoption.
Signals worth tracking in the near term include:
- OIRA review completion, which typically precedes an NPRM by weeks to a few months.
- Any SEC open meeting agenda referencing custody rule amendments, a reliable sign that formal proposal text is close.
- Public comment period announcements, which give firms a defined window to weigh in through their trade associations or directly.
Tie your preparation to each stage rather than waiting for a final rule. Before an NPRM drops, finalize your current-state documentation so you have a clean baseline to compare against any proposed changes. During a comment period, have your compliance and legal teams draft internal comments even if you do not submit them publicly, since the exercise forces you to identify where a proposed rule would actually change your operations. Before a final rule takes effect, budget time for a full gap analysis against the adopted text, not just the proposal, since final rules frequently diverge from what was originally proposed.
How Does the DARE Framework Map to Custody Exam Readiness?
Every regulator expectation covered so far collapses into five practical categories: governance, operational controls, third-party risk, audits, and disclosures. This structure is reflected in some digital asset certification frameworks that exist specifically because compliance teams need a way to convert scattered regulatory releases into one evidence file they can hand an examiner.
Governance means a documented custody policy with named accountable owners, board or senior-management sign-off, and a version history showing the policy has actually been reviewed on a schedule. Operational controls means the key-management, account-model, and incident-response documentation covered earlier in this piece, indexed and ready to produce on request. Third-party risk means the sub-custodian due-diligence file, updated at least annually and tied to specific contract clauses. Audits means independent attestation reports and internal audit findings, with evidence that identified issues were actually remediated. Disclosures means the client-facing language describing custody arrangements in terms a non-technical client can understand.
| DARE category | What examiners expect to see |
|---|---|
| Governance | Board-approved custody policy with review history |
| Operational controls | Key-management architecture and incident response plan |
| Third-party risk | Sub-custodian due-diligence file and contract clauses |
| Audits | Independent attestation reports with remediation evidence |
| Disclosures | Client-facing custody arrangement descriptions |
What a structured certification adds on top of an internal policy binder is a verifiable, external credential. Some certification assessments produce blockchain-backed credentials that give an examiner or a client an auditable trail showing a specific person or team was evaluated against a defined standard, not just that a policy document exists somewhere in a shared drive. That distinction matters more than it sounds: a policy nobody outside the firm has reviewed carries less weight than a credential tied to an independent assessment process.
Firms building or refreshing a custody governance program can use the DARE certification framework as the organizing structure for exactly this kind of evidence file, mapping each regulatory expectation to a specific artifact before an exam ever starts rather than scrambling once a request letter arrives.
Where Can You Find the Primary Sources to Monitor?
Bookmark these directly rather than relying on secondhand summaries, since custody guidance changes fast enough that a six-month-old blog post can already be stale.
- The SEC’s 2026 interpretive release for the token taxonomy that determines which custody regime applies to a given asset.
- The model framework whitepaper for the clearest current articulation of what a non-qualified-custodian safeguarding program needs to demonstrate.
- The joint banking-agency safekeeping guidance for the specific control and audit language examiners at OCC, Fed, and FDIC-supervised institutions will cite.
- The SEC’s broker-dealer custody statement for the possession-or-control standard under Rule 15c3-3.
- The SEC’s trading and markets FAQ for plain-language answers staff have already given on recurring custody questions.
Pull the relevant paragraphs from each into your policy documents directly, with citations, rather than paraphrasing from memory during an exam response.
An Editorial Take on Where Custody Compliance Is Actually Heading
The industry keeps treating custody as a technology problem: pick the right MPC vendor, get the right HSM, and compliance follows. It doesn’t. Every regulator release covered here, from the banking agencies to SEC staff statements, ties technical controls back to a legal question: who actually has the right to that asset if something goes wrong. A flawless key-management setup with no insolvency analysis behind it is a stronger security posture and a weaker compliance posture than firms assume.
The conventional advice, wait for the final Custody Rule text before committing resources, gets the sequencing backward. Staff positions and the model framework are already shaping how examiners think today, final rule or not. Firms that build their evidence file now, mapped to governance, controls, third-party risk, audits, and disclosures, will not need to redo that work when the rule lands. They will just need to check it against the final text.
— Gregg
This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.
Sources
- Application of the Federal Securities Laws to Certain Types of Crypto Assets and Certain Transactions Involving Crypto Assets (SEC interpretation) — 2026
- Statement on the Custody of Crypto Asset Securities by Broker-Dealers — SEC (Dec 17, 2025)
- Custody Rule Modernization: A Model Framework for Crypto Asset Safeguarding — SEC (Dec 19, 2025)
- Crypto-Asset Safekeeping by Banking Organizations — Joint agencies (Jul 2025)
- Trading and Markets: Frequently Asked Questions Relating to Crypto Asset Activities and Distributed Ledger Technology — SEC (FAQ)
