Sept. 30, 2026: RIAs & Funds Must Verify Qualified Crypto Custodians

A qualified custodian is a regulated entity, defined under Rule 206(4)-2 of the Investment Advisers Act, that is legally permitted to hold client funds and securities on behalf of an adviser. As of September 2025, the SEC confirmed that state-chartered trust companies can meet this bar for crypto assets under specific supervisory conditions. If you work in compliance, treasury, or legal at an RIA or fund, the takeaway is blunt: verify the custodian’s actual regulatory status yourself. Never take a vendor’s marketing page as proof.
TL;DR:
- State-chartered trust companies can qualify as custodians for crypto assets if authorized by their regulators and meet specific operational safeguards.
- Custodians must provide regular SOC 2 Type II reports, audited financial statements, and clear custody agreements demonstrating segregation and protections.
- Using cold storage, MPC, and multisignature setups can mitigate risks, but understanding their technical differences is essential for evaluating custodians.
- Custodians’ insurance policies and operational resilience must be thoroughly reviewed, as regulatory qualification does not guarantee sound controls.
- Ongoing due diligence includes annual reassessments, detailed documentation, and considering governance frameworks like DARE certification to ensure compliance and risk management.
Table of Contents
- What “Qualified Custodian” Actually Means in Crypto
- The 2025 SEC No-Action Letter and the Push to Modernize the Custody Rule
- Why This Isn’t Optional for RIAs and Funds
- The Due-Diligence Checklist: What to Actually Request
- Cold Storage, MPC, Multisig, and Proof-of-Reserves, Explained
- What People Get Wrong About “Qualified” Custody
- Publisher Perspective: Where the Governance Gaps Actually Show Up
- Regulators Beyond the SEC: FINRA and State Trust Supervisors
- Tokens, Coins, and Why Custody Requirements Differ by Asset Type
- Operational, Regulatory, and Cyber Risks in Custody
- How Major Custodians Compare on Compliance Standing
- Investor Protections and Dispute Resolution Under Qualified Custody
- Editorial Take: The Checklist Matters More Than the Label
- Strengthen Custody Governance With DARE Certification
- Sources
What “Qualified Custodian” Actually Means in Crypto
The term did not originate with digital assets. It comes from the Custody Rule, which requires registered investment advisers with custody of client funds or securities to place those assets with an institution that meets a defined legal standard, not just any company that says it offers “custody services.” That distinction matters more in crypto than almost anywhere else, because so many platforms use the word loosely.
Under the traditional framework, a qualified custodian is one of the following:
- A bank or savings association
- A registered broker-dealer
- A registered futures commission merchant (FCM)
- Certain eligible foreign financial institutions
- State-chartered trust companies, when they meet specific operational and supervisory conditions the SEC laid out in 2025
That last category is new, and it is the one reshaping the market. For decades, “qualified custodian” meant a bank or broker-dealer holding stock certificates or account records. Crypto custody works differently at a technical level. There is no central registry confirming who owns what. Ownership is determined by control of a private key, and whoever controls that key can move the asset, no paperwork required.
Legal scholars at Penn Carey Law point out that the Custody Rule was never written around a specific cryptographic method. Its actual policy goal is protecting client assets from theft, loss, and custodial insolvency, regardless of the technology involved. That framing matters for compliance teams evaluating vendors: the question is not “does this custodian use blockchain,” but whether its key management, governance, and financial structure actually deliver on that underlying protection goal. A custodian can check every regulatory box and still have sloppy key management. The charter tells you it is eligible to be a qualified custodian. It does not tell you whether the underlying controls are sound.
The 2025 SEC No-Action Letter and the Push to Modernize the Custody Rule
The regulatory ground shifted meaningfully in the back half of 2025, and every compliance officer overseeing digital asset exposure needs to understand the shift, not just know it happened.
On September 30, 2025, SEC staff issued a no-action letter confirming that state-chartered trust companies can act as qualified custodians for crypto assets, provided they meet specific operational and supervisory conditions. This was not a blanket approval. It was conditional relief, and the conditions carry real weight:
- The trust company must be expressly authorized by its state regulator to custody crypto assets, not just generally chartered as a trust institution
- The adviser relying on the arrangement must annually reassess whether the trust company still meets the required safeguards
- Segregation, recordkeeping, and supervisory practices have to mirror what a bank custodian would be expected to maintain
Alongside the no-action letter, the SEC released a Custody Rule modernization framework proposing a broader rethink. One idea getting serious attention: a reasonableness-based safeguarding pathway that would let advisers use certain non-qualified-custodian arrangements when a traditional QC setup is genuinely impractical, as long as the alternative still meets the rule’s underlying protection goals. This is the “QSC versus QC” debate you’ll see referenced in comment letters. It is far from settled.
Industry response has been pointed. A joint comment letter from BPI, AGC, and FSF urged the SEC to hold any expanded definition of qualified custodian to the same investor-protection standard as traditional bank custody, warning against diluting the term just to accommodate crypto-native players. Their concern, in plain terms: if “qualified” starts meaning something looser for digital assets than it does for stocks and bonds, the label stops doing its job.
For a compliance team, the practical read is this: the SEC opened a door for trust companies, but it did not remove the burden of proof from the adviser. You still have to document why you believe a given custodian meets the bar, and that documentation needs annual refreshing, not a one-time sign-off.
Why This Isn’t Optional for RIAs and Funds
The Custody Rule applies whenever an adviser has custody, and in crypto, “custody” is defined by control, not by who technically holds the account. If your firm, or a related person, holds private keys, has the ability to move client crypto without a client’s separate authorization, or maintains any access path that could move assets unilaterally, you have custody under the rule. That threshold catches more arrangements than most compliance teams initially assume.
Once you’re in custody territory, three obligations follow:
- Periodic account statements must be sent to clients showing holdings and transactions, sourced from the qualified custodian’s own records, not the adviser’s internal ledger.
- Surprise examinations by an independent public accountant are required annually to verify that client assets actually exist where they’re supposed to be.
- Audit documentation from the custodian, covering controls and financial condition, needs to be reviewable on request, not just referenced in a sales deck.
Skip any of these and the exposure isn’t theoretical. SEC enforcement actions against advisers for custody violations have resulted in censures, fines, and, in repeat or egregious cases, registration revocation. Beyond the regulatory penalty, there’s a fiduciary problem: if client crypto turns out to be sitting with an entity that never actually met the qualified custodian standard, the adviser is on the hook for that failure, not the vendor.
The Due-Diligence Checklist: What to Actually Request
Regulatory status is the floor, not the finish line. Investopedia’s guidance on selecting a crypto custodian lays out a due-diligence sequence that holds up well against what institutional compliance teams actually need. Here’s how to run it.
-
Confirm the charter and state authorization. A trust company charter alone doesn’t prove much. Ask the state regulator, not just the vendor, whether that charter’s scope covers crypto custody specifically. Akin Gump’s analysis of the September 2025 letter makes this point directly: documented supervisory scope for crypto activities is what separates a real qualified custodian from a trust company that simply added “digital assets” to its website.
-
Request SOC 1 and SOC 2 Type II reports. A Type I report only confirms controls exist at a point in time. Type II confirms they operated effectively over a period, usually six to twelve months. If a custodian can only produce Type I, treat that as a yellow flag, not a technicality.
-
Pull audited GAAP financial statements. You want to know the custodian’s balance sheet, not just its uptime record. A custodian that’s thinly capitalized is a counterparty risk regardless of how good its cold storage setup looks.
-
Read the custody agreement line by line for segregation language. Confirm assets are held in bankruptcy-remote accounts, titled for the benefit of clients, and not commingled with the custodian’s own balance sheet. Check for rehypothecation clauses. If the agreement allows the custodian to lend out or reuse client assets, that’s a materially different risk profile than pure custody.
-
Get the actual insurance policy, not the marketing summary. Ask for coverage limits, named exclusions, and whether claims history exists. As Investopedia notes, insurance coverage varies widely: some policies cover hot-wallet theft directly but explicitly exclude staking losses or specific operational failures.
-
Examine the technical architecture. Ask what percentage of assets sit in cold storage, whether key generation uses hardware security modules (HSMs), and how multi-party computation (MPC) or multisignature schemes distribute signing authority.
-
Test operational resilience. Ask about third-party vendor dependencies, incident response drills, and disaster recovery testing cadence. A custodian that hasn’t run a tabletop exercise in two years is a different risk than one that runs quarterly failover tests.
Pro Tip: Ask for the custodian’s most recent SOC 2 Type II report’s exception list, not just the auditor’s summary opinion. Even a “clean” report usually has minor exceptions noted in the fine print, and how a custodian responded to them tells you more about its operational maturity than the headline opinion does.
Cold Storage, MPC, Multisig, and Proof-of-Reserves, Explained
Custodians use overlapping but distinct technical models, and knowing the difference matters when you’re evaluating what you’re actually being sold.

Cold storage means private keys are generated and stored on devices with no internet connection, often inside HSMs kept in physically secured, access-controlled facilities. It protects against remote hacking, but it trades away speed. Moving assets out of deep cold storage can take hours or days by design, which is a feature for large institutional holdings and a liability for anything requiring same-day liquidity.
Multi-party computation (MPC) splits a private key into multiple encrypted shares distributed across separate parties or systems, so no single device or person ever holds the complete key. Transactions get signed through a cryptographic protocol that combines partial signatures without reconstructing the full key anywhere.
Multisignature (multisig) wallets require a set number of independent signatures, say, three out of five, before a transaction executes. It’s conceptually simpler than MPC and has a longer operational track record, though it can be less flexible when adding or rotating signers.
Hot wallets stay connected to the internet for operational liquidity. Custodians typically hold only a small fraction of total client assets hot at any time, insuring that pool separately from cold reserves, because it carries meaningfully higher exposure.
Proof-of-reserves attestations let an auditor verify that a custodian holds assets matching client balances at a specific point in time. What these attestations generally cannot verify is liability completeness, meaning whether the custodian owes obligations elsewhere that aren’t reflected in the snapshot, or whether reserves were borrowed briefly just to pass the audit window. Treat proof-of-reserves as a useful data point, not a complete solvency guarantee.
What People Get Wrong About “Qualified” Custody
“Qualified” is a legal classification, not a safety certificate. That distinction gets lost constantly, and it causes real problems. As Cobo’s institutional guidance puts it, qualified status tells you a custodian meets a regulatory definition, not that your assets are immune from loss.
A few specific misunderstandings show up again and again:
- Insurance is not blanket coverage. Policies carry sub-limits, exclusions, and specific covered-event definitions. A $500 million headline policy figure might apply only to a narrow category of theft, not operational error or insider fraud.
- Rehypothecation is a real risk, not a hypothetical one. If a custody agreement permits the custodian to lend or reuse client assets, those assets are exposed to the custodian’s own counterparty risk, not just custody risk.
- Commingling defeats the purpose of segregation. Ask explicitly whether client assets are held in individually titled accounts or pooled omnibus accounts, and how the custodian’s records distinguish ownership internally.
- Past custody failures, from exchange collapses to custodian insolvencies, mostly trace back to governance gaps, not just weak cryptography. Poor internal controls and inadequate segregation caused more damage than any technical hack.
Publisher Perspective: Where the Governance Gaps Actually Show Up
Institutions moving into crypto custody consistently stumble in the same place: they treat vendor selection as a one-time procurement decision rather than an ongoing governance obligation. A custodian that passed diligence in 2024 might not meet the same bar in 2026, especially with the SEC’s framework still shifting underneath everyone.
Certification programs built specifically around digital asset governance, including the DARE framework, exist precisely to operationalize what otherwise stays informal: documented evidence collection, policy templates mapped to custody requirements, and annual renewal cycles that force teams to re-verify rather than assume last year’s diligence still holds. That structure matters more than most compliance teams expect until they’re asked to produce evidence during an exam.
Regulators Beyond the SEC: FINRA and State Trust Supervisors
The SEC sets the custody standard for registered investment advisers, but it isn’t the only regulator in the room. FINRA oversees broker-dealers, including those that hold crypto assets as part of a qualified custodian arrangement, and enforces its own net capital and customer protection rules on top of SEC requirements.
State banking and trust regulators carry outsized weight in this specific market, because the 2025 no-action letter routed custody eligibility through state trust charters rather than a new federal category. States like New York, through its Department of Financial Services BitLicense regime, and South Dakota and Wyoming, which built trust charters specifically accommodating digital assets, each apply different supervisory intensity. A trust company chartered in a state with a lighter crypto-specific examination regime isn’t automatically disqualified, but it warrants closer diligence on what that state actually supervises versus what the charter merely permits.
The Commodity Futures Trading Commission (CFTC) enters the picture when a crypto asset is classified as a commodity or when custody involves futures commission merchants. Whether a given token falls under SEC or CFTC jurisdiction remains an unsettled question for a meaningful share of the market, which complicates custody analysis for firms holding a mixed portfolio of assets.
Tokens, Coins, and Why Custody Requirements Differ by Asset Type
Not every crypto asset custody problem looks the same, and treating a base-layer coin like a wrapped token or a staked asset invites mistakes.
Native coins like Bitcoin and Ether custody relatively cleanly: the custody question is almost entirely about key control. Tokens built on smart contract platforms, including many ERC-20 tokens, add a layer of complexity because custody has to account for the underlying smart contract’s behavior, not just the private key. A flawed or upgradable contract can affect asset behavior in ways pure key custody doesn’t capture.
Staked assets introduce a different wrinkle entirely: custody has to address lockup periods, slashing risk if a validator misbehaves, and whether staking rewards flow through the same segregation protections as the principal asset. A custody agreement silent on staking treatment is a gap worth flagging before signing, not after.
Operational, Regulatory, and Cyber Risks in Custody
Three risk categories deserve separate line items in any due-diligence file, because mitigating one doesn’t mitigate the others.
Operational risk covers human error, key management failures, and process breakdowns, mitigated through documented procedures, dual controls, and regular internal audits. Regulatory risk covers the possibility that a custodian’s charter or authorization gets revoked, narrowed, or challenged, which is why the annual reassessment requirement in the 2025 no-action letter isn’t just paperwork. Cyber risk covers external attacks on infrastructure, mitigated through the technical controls covered earlier: cold storage ratios, MPC or multisig architecture, and incident response readiness.
The strongest custodians treat these as connected, not siloed, running combined tabletop exercises that simulate a cyber incident triggering a regulatory disclosure obligation simultaneously.
How Major Custodians Compare on Compliance Standing
The qualified custodian market splits roughly into three tiers: nationally chartered trust companies with long track records serving traditional finance, state-chartered trust companies purpose-built for digital assets, and broker-dealer or bank subsidiaries extending existing custody infrastructure into crypto.
Each tier carries different tradeoffs. Nationally chartered players generally bring deeper balance sheets and longer audit histories, which matters for institutions prioritizing counterparty stability. Purpose-built digital asset trust companies often offer more sophisticated technical architecture, since crypto custody is their core business rather than an add-on. Bank and broker-dealer subsidiaries can offer integration advantages for firms already using that institution’s other services, but their crypto-specific supervisory scope varies and needs the same charter verification as any standalone trust company. No tier is categorically superior. The right fit depends on your asset mix, liquidity needs, and existing custody relationships.
Investor Protections and Dispute Resolution Under Qualified Custody
Custody by a genuinely qualified custodian changes the practical dispute landscape in a client’s favor. Assets held in segregated, bankruptcy-remote accounts are shielded from a custodian’s general creditors if that custodian becomes insolvent, which is precisely the protection an unregulated exchange wallet doesn’t offer.
Dispute resolution mechanisms also differ by custodian type. Bank and trust company custodians are typically subject to state or federal banking supervision with formal complaint escalation paths, while broker-dealer custodians fall under FINRA’s arbitration framework. Contractual dispute clauses in the custody agreement itself, covering liability caps, indemnification triggers, and governing law, end up mattering as much as the regulatory label. Read them before a dispute happens, not during one.
Editorial Take: The Checklist Matters More Than the Label
The conventional advice on crypto custody spends too much energy debating whether a provider technically qualifies and not enough on what happens after that box gets checked. The SEC’s 2025 no-action letter is a meaningful development, but it answers a narrower question than most people treat it as answering. It tells you a state trust company can qualify. It does not tell you whether the specific one you’re evaluating actually meets the operational bar in practice.
The real judgment call sits in the due-diligence file: the SOC 2 exceptions, the insurance exclusions, the rehypothecation language buried in section fourteen of a custody agreement nobody reads twice. Regulatory status filters out the obvious bad actors. It does nothing to distinguish between two custodians that both technically qualify but differ enormously in operational discipline.
If you take one thing from the current regulatory moment, it’s this: treat the qualified custodian designation as a starting filter, not a conclusion, and build the annual reassessment obligation into your actual compliance calendar rather than your assumptions.
— Gregg
Strengthen Custody Governance With DARE Certification
Choosing a qualified custodian solves one piece of the puzzle. It doesn’t solve the internal governance problem: who at your firm owns the annual reassessment, who tracks SOC report renewals, and who can produce evidence during an exam without scrambling. DARE is not a custodian and doesn’t hold assets. It’s a certification framework built for the compliance, risk, and treasury professionals who have to prove their firm’s custody oversight actually works.

The DARE certification covers policy templates mapped to custody and safekeeping obligations, structured assessment checklists for vendor diligence, and audit-readiness modules that turn scattered documentation into something you can hand an examiner with confidence. Annual renewal cycles are built into the program itself, which matches exactly what the SEC’s 2025 guidance now expects of advisers relying on state trust custodians. If your team needs a defensible, repeatable way to demonstrate custody governance rather than reassembling evidence every exam cycle, explore the DARE certification program and see what a structured readiness path looks like for your organization.
This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.
Sources
- Custody Rule Modernization: A Model Framework for Crypto Asset Safeguarding
- How to Choose a Qualified Crypto Custodian
- Crypto Custody • Penn Carey Law
