SEC Custody Rule Modernization — Digital Asset Securities
SEC framework for custody of digital asset securities by broker-dealers and investment advisers. Covers qualified custodian requirements, exclusive control of private keys, multi-signature and threshold signature mandates, segregation of client assets, key management lifecycle, distributed ledger risk assessment, third-party custodian oversight, incident response, business continuity, transfer capability verification, independent examination, and safeguarding against theft, loss, and misuse.
Controls: 95
Total Mappings: 207
Publisher: U.S. Securities and Exchange Commission (SEC) Version: December 2025 (Discussion Draft) AC (8) AT (1) AU (12) CA (3) CM (5) CP (9) IA (3) IR (9) MA (1) MP (2) PE (3) PL (1) PM (4) PS (6) PT (3) RA (4) SA (4) SC (9) SI (4) SR (4)
AC Access Control
| Control | Name | SEC Custody (Digital Assets) References |
|---|---|---|
| AC-01 | Policy and Procedures | SEC-CD-02SEC-CD-05SEC-CD-17SEC-CD-20 |
| AC-02 | Account Management | SEC-CD-02SEC-CD-05SEC-CD-16 |
| AC-03 | Access Enforcement | SEC-CD-02SEC-CD-05 |
| AC-04 | Information Flow Enforcement | SEC-CD-04 |
| AC-05 | Separation of Duties | SEC-CD-02SEC-CD-03SEC-CD-04SEC-CD-05SEC-CD-16SEC-CD-19 |
| AC-06 | Least Privilege | SEC-CD-02SEC-CD-03SEC-CD-04SEC-CD-05SEC-CD-16 |
| AC-17 | Remote Access | SEC-CD-05 |
| AC-20 | Use of External Systems | SEC-CD-10 |
AT Awareness and Training
| Control | Name | SEC Custody (Digital Assets) References |
|---|---|---|
| AT-03 | Role-based Training | SEC-CD-19 |
AU Audit and Accountability
| Control | Name | SEC Custody (Digital Assets) References |
|---|---|---|
| AU-01 | Policy and Procedures | SEC-CD-14SEC-CD-15SEC-CD-17 |
| AU-02 | Event Logging | SEC-CD-04SEC-CD-05SEC-CD-07SEC-CD-13SEC-CD-15SEC-CD-18SEC-CD-20 |
| AU-03 | Content of Audit Records | SEC-CD-04SEC-CD-15SEC-CD-18SEC-CD-20 |
| AU-04 | Audit Log Storage Capacity | SEC-CD-15 |
| AU-05 | Response to Audit Logging Process Failures | SEC-CD-15 |
| AU-06 | Audit Record Review, Analysis, and Reporting | SEC-CD-11SEC-CD-14SEC-CD-15SEC-CD-16SEC-CD-18SEC-CD-20 |
| AU-07 | Audit Record Reduction and Report Generation | SEC-CD-15 |
| AU-08 | Time Stamps | SEC-CD-15 |
| AU-09 | Protection of Audit Information | SEC-CD-05SEC-CD-15SEC-CD-16 |
| AU-10 | Non-repudiation | SEC-CD-05SEC-CD-15SEC-CD-16 |
| AU-11 | Audit Record Retention | SEC-CD-14SEC-CD-15SEC-CD-18SEC-CD-20 |
| AU-12 | Audit Record Generation | SEC-CD-15 |
CA Security Assessment and Authorization
CM Configuration Management
| Control | Name | SEC Custody (Digital Assets) References |
|---|---|---|
| CM-02 | Baseline Configuration | SEC-CD-08 |
| CM-03 | Configuration Change Control | SEC-CD-07 |
| CM-05 | Access Restrictions for Change | SEC-CD-05 |
| CM-06 | Configuration Settings | SEC-CD-03SEC-CD-06SEC-CD-07SEC-CD-08 |
| CM-08 | System Component Inventory | SEC-CD-04SEC-CD-09SEC-CD-18 |
CP Contingency Planning
| Control | Name | SEC Custody (Digital Assets) References |
|---|---|---|
| CP-01 | Policy and Procedures | SEC-CD-12 |
| CP-02 | Contingency Plan | SEC-CD-12 |
| CP-03 | Contingency Training | SEC-CD-12 |
| CP-04 | Contingency Plan Testing | SEC-CD-12SEC-CD-13 |
| CP-06 | Alternate Storage Site | SEC-CD-06SEC-CD-08SEC-CD-12 |
| CP-07 | Alternate Processing Site | SEC-CD-12 |
| CP-08 | Telecommunications Services | SEC-CD-12 |
| CP-09 | System Backup | SEC-CD-06SEC-CD-12 |
| CP-10 | System Recovery and Reconstitution | SEC-CD-12 |
IA Identification and Authentication
IR Incident Response
| Control | Name | SEC Custody (Digital Assets) References |
|---|---|---|
| IR-01 | Policy and Procedures | SEC-CD-11 |
| IR-02 | Incident Response Training | SEC-CD-11 |
| IR-03 | Incident Response Testing | SEC-CD-11 |
| IR-04 | Incident Handling | SEC-CD-11 |
| IR-05 | Incident Monitoring | SEC-CD-11 |
| IR-06 | Incident Reporting | SEC-CD-11 |
| IR-07 | Incident Response Assistance | SEC-CD-11 |
| IR-08 | Incident Response Plan | SEC-CD-11 |
| IR-09 | Information Spillage Response | SEC-CD-11 |
MA Maintenance
| Control | Name | SEC Custody (Digital Assets) References |
|---|---|---|
| MA-02 | Controlled Maintenance | SEC-CD-07 |
MP Media Protection
PE Physical and Environmental Protection
PL Planning
| Control | Name | SEC Custody (Digital Assets) References |
|---|---|---|
| PL-01 | Policy and Procedures | SEC-CD-01SEC-CD-19 |
PM Program Management
| Control | Name | SEC Custody (Digital Assets) References |
|---|---|---|
| PM-01 | Information Security Program Plan | SEC-CD-01SEC-CD-14SEC-CD-17SEC-CD-18SEC-CD-19SEC-CD-20 |
| PM-02 | Information Security Program Leadership Role | SEC-CD-01SEC-CD-17SEC-CD-19 |
| PM-07 | Enterprise Architecture | SEC-CD-14 |
| PM-09 | Risk Management Strategy | SEC-CD-09SEC-CD-10SEC-CD-18 |
PS Personnel Security
PT Personally Identifiable Information Processing and Transparency
RA Risk Assessment
SA System and Services Acquisition
SC System and Communications Protection
| Control | Name | SEC Custody (Digital Assets) References |
|---|---|---|
| SC-02 | Separation of System and User Functionality | SEC-CD-04 |
| SC-03 | Security Function Isolation | SEC-CD-04 |
| SC-04 | Information in Shared System Resources | SEC-CD-04 |
| SC-07 | Boundary Protection | SEC-CD-09 |
| SC-12 | Cryptographic Key Establishment and Management | SEC-CD-02SEC-CD-03SEC-CD-06SEC-CD-07SEC-CD-08SEC-CD-12SEC-CD-13SEC-CD-16 |
| SC-13 | Cryptographic Protection | SEC-CD-02SEC-CD-03SEC-CD-06SEC-CD-07SEC-CD-08 |
| SC-17 | Public Key Infrastructure Certificates | SEC-CD-02SEC-CD-06 |
| SC-23 | Session Authenticity | SEC-CD-03 |
| SC-28 | Protection of Information at Rest | SEC-CD-08 |