# SEC Custody Rule Modernization — Digital Asset Securities

Framework id: `sec_custody_digital`. Securities Regulation. Publisher: U.S. Securities and Exchange Commission (SEC). Version: December 2025 (Discussion Draft). Region: USA. Mapping licence: CC BY-SA 4.0.
Source text: https://www.sec.gov/

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (20, average coverage 53%)
- SEC-CD-01 Qualified custodian eligibility and regulatory authorisation: CA-01, CA-02, PL-01, PM-01, PM-02, PS-01, RA-01, SA-01, SA-09 (18%)
- SEC-CD-02 Exclusive control and possession of private keys: AC-01, AC-02, AC-03, AC-05, AC-06, IA-03, IA-05, SC-12, SC-13, SC-17, PE-02, PE-03 (62%)
- SEC-CD-03 Multi-signature and threshold signature scheme (TSS) requirements: AC-05, AC-06, IA-02, IA-05, SC-12, SC-13, SC-23, CM-06, SA-08 (55%)
- SEC-CD-04 Client asset segregation — digital asset securities from firm assets: AC-04, AC-05, AC-06, CM-08, MP-04, SC-02, SC-03, SC-04, AU-02, AU-03 (52%)
- SEC-CD-05 Dual authorisation and transaction approval controls: AC-01, AC-02, AC-03, AC-05, AC-06, AC-17, AU-02, AU-09, AU-10, IA-02, IA-05, CM-05 (75%)
- SEC-CD-06 Cryptographic key management — generation, storage, and backup: SC-12, SC-13, SC-17, IA-05, CP-06, CP-09, MP-04, MP-05, PE-02, PE-03, CM-06, SA-08 (80%)
- SEC-CD-07 Key rotation, revocation, and cryptographic end-of-life: SC-12, SC-13, IA-05, CM-03, CM-06, SI-02, MA-02, AU-02 (60%)
- SEC-CD-08 HSM, cold storage, warm wallet, and hot wallet tier architecture: SC-12, SC-13, SC-28, PE-02, PE-03, PE-06, CM-02, CM-06, SA-08, RA-03, CP-06 (65%)
- SEC-CD-09 Distributed ledger and blockchain network risk assessment: RA-01, RA-02, RA-03, RA-05, SA-09, PM-09, CM-08, SI-07, SC-07, SR-02 (48%)
- SEC-CD-10 Third-party custodian oversight and sub-custodian due diligence: SA-09, SA-04, SR-01, SR-02, SR-03, SR-06, CA-02, CA-07, PM-09, AC-20 (68%)
- SEC-CD-11 Incident response and SEC breach notification for digital asset custody: IR-01, IR-02, IR-03, IR-04, IR-05, IR-06, IR-07, IR-08, IR-09, AU-06, SI-04 (72%)
- SEC-CD-12 Business continuity, disaster recovery, and cryptographic key recovery: CP-01, CP-02, CP-03, CP-04, CP-06, CP-07, CP-08, CP-09, CP-10, SC-12, RA-03 (70%)
- SEC-CD-13 Transfer capability verification and proof-of-control testing: CA-02, CA-07, SC-12, SI-06, SI-07, AU-02, CP-04 (45%)
- SEC-CD-14 Independent examination and annual audit requirements: CA-01, CA-02, CA-07, AU-01, AU-06, AU-11, PM-01, PM-07, SA-01 (50%)
- SEC-CD-15 Record-keeping, audit trail, and transaction logging: AU-01, AU-02, AU-03, AU-04, AU-05, AU-06, AU-07, AU-08, AU-09, AU-10, AU-11, AU-12 (82%)
- SEC-CD-16 Safeguarding against theft, loss, misuse, and insider threat: AC-02, AC-05, AC-06, AU-06, AU-09, AU-10, IA-02, IA-05, PE-02, PE-03, PE-06, PS-03, PS-04, PS-07, PS-08, SI-04, MP-04, SC-12 (76%)
- SEC-CD-17 State-chartered trust company qualified custodian provisions: CA-01, CA-02, PM-01, PM-02, RA-01, SA-01, SA-09, AC-01, AU-01 (20%)
- SEC-CD-18 Customer protection and net capital computations (broker-dealer): AU-02, AU-03, AU-06, AU-11, CM-08, PM-01, PM-09, RA-01, RA-03 (15%)
- SEC-CD-19 Conflicts of interest and governance for digital asset custodians: AC-05, PM-01, PM-02, PL-01, PS-01, PS-06, RA-01, CA-01, AT-03 (30%)
- SEC-CD-20 Client disclosure and reporting obligations: AC-01, AU-02, AU-03, AU-06, AU-11, PT-01, PT-05, PT-06, PM-01 (25%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=sec_custody_digital
- Control-to-clause mappings as JSON: /api/v1/frameworks/sec_custody_digital?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/sec-custody-digital.json
- Page for people: /frameworks/sec-custody-digital/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
