OIRA review of revised crypto custody rules signals the end of enforcement-driven regulation—and the beginning of a more complex compliance architecture.
On September 30, 2025, the SEC staff issued a no-action letter that quietly redrew the boundaries of crypto asset custody for registered investment advisers. Days later, the White House's Office of Information and Regulatory Affairs opened its review of a revised custody rule proposal. Two events, one trajectory: the regulatory framework governing who can hold digital assets for institutional clients is being rebuilt from the ground up.
Tracing the fault lines in this system's logic reveals something more consequential than a procedural update. The SEC is transitioning from an enforcement-first posture—where guidance emerged through penalties and settlement orders—to a dual-track model combining formal rulemaking with conditional exemptions. For an industry that has spent four years navigating regulatory ambiguity, this shift carries both opportunity and embedded risk.
The Regulatory Context: From Enforcement to Architecture
The current custody framework for investment advisers traces back to the Investment Advisers Act of 1940. Under Rule 206(4)-2, advisers must maintain client assets with qualified custodians, with limited exceptions. For crypto assets, this created a persistent problem: few traditional custodians qualified, and those that did often refused to hold digital assets due to regulatory uncertainty.
The SEC's initial response was enforcement-driven. From 2020 through 2023, the Commission brought a series of actions against platforms offering crypto custody services without proper registration. The message was clear—existing rules applied, even if they didn't fit. But enforcement creates precedent without clarity. Each action answered one question while leaving three unanswered.
In 2023, the SEC proposed a comprehensive custody rule update. It was withdrawn. The reasons remain opaque, but industry observers noted significant pushback from both traditional financial institutions and crypto-native firms. The proposal's fate suggested internal disagreements about scope, particularly around whether crypto assets should be treated as funds requiring the same safeguards as securities.
The September 30 no-action letter changed the calculus. By providing conditional relief for state-chartered trust companies, the SEC staff created a workable path forward without waiting for formal rulemaking. The letter's conditions—asset segregation, regular reporting, independent verification—mirror what a formal rule would likely require.
The structural insight here is that the no-action letter functions as a beta test for the final rule. The SEC can observe how state trust companies implement these conditions, where failures occur, and what additional safeguards prove necessary. By the time the formal rule emerges from OIRA review, the Commission will have operational data to calibrate requirements.
The OIRA Review: What It Actually Signals
OIRA review is a gatekeeping mechanism within the executive branch. Every significant federal regulation must pass through this office, which assesses costs, benefits, and consistency with presidential priorities. The opening of OIRA review for the SEC's custody proposal indicates the rulemaking has cleared internal Commission hurdles and entered the interagency review phase.
Observing the cold mechanics of this process, several implications emerge.
First, the timeline. OIRA review typically takes 60-90 days, though complex rules can extend longer. The SEC's regulatory agenda has targeted October 2026 for final adoption. That date is a planning goal, not a legal deadline. Delays are possible—particularly if OIRA raises substantive concerns or if the transition to a new SEC chair alters priorities.

Second, the scope. The 2023 proposal was withdrawn, meaning the current version reflects subsequent revisions. The specific language remains undisclosed during OIRA review. This opacity creates an information vacuum that market participants will fill with speculation. Expect narratives about "crypto custody relief" and "institutional adoption catalysts" to circulate before the actual text emerges.
Third, the political dimension. OIRA review is not purely technocratic. The White House signals policy priorities through this process—expediting rules it supports, slow-walking those it opposes. The current administration's crypto-friendly posture suggests a favorable disposition, but this cuts both ways. A favorable review could accelerate the timeline; a skeptical one could introduce modifications that dilute the rule's utility.
The Core Analysis: Dissecting the Dual-Track Model
The dual-track approach—rule-making plus no-action relief—creates a layered compliance environment that rewards sophisticated actors while punishing those who rely on outdated assumptions.
The no-action letter provides immediate, conditional authorization for state trust companies to custody crypto assets for RIAs. This is not a legal exemption from securities laws; it is a staff-level commitment not to recommend enforcement action under specified facts. The distinction matters. A no-action letter can be withdrawn or superseded. It binds no one beyond the staff who issued it. Yet for practical purposes, it creates a safe harbor baseline that advisers and custodians can operate within.
The conditions embedded in the letter reveal the SEC's substantive concerns: asset segregation to prevent commingling, independent verification to ensure reporting accuracy, and control frameworks to address the unique risks of blockchain-based assets. These conditions track the fault lines that have produced past enforcement actions—from the FTX collapse to smaller custody failures where client assets were misappropriated.

For state trust companies, the letter transforms their competitive position. Previously, their crypto custody offerings operated in a gray zone. Now they have explicit, conditional authorization. The commercial implications are significant. These institutions can market themselves as SEC-staff-sanctioned custodians, differentiating themselves from offshore platforms and unregulated wallet providers.
The proposed rule, if finalized, would extend similar conditions to a broader category of custodians. The likely requirements—maintaining assets in segregated accounts, obtaining reasonable assurance that sub-custodians follow similar standards, undergoing periodic independent verification—would create a compliance burden that smaller players may find prohibitive. This creates a structural advantage for established financial institutions with existing compliance infrastructure.
The Contrarian Angle: What the Bulls Miss
The prevailing narrative frames custody rule clarification as an unambiguous positive—a catalyst for institutional capital flows, a legitimization of crypto as an asset class, a green light for RIAs to allocate client funds. This narrative contains elements of truth but obscures critical countervailing forces.
First, rule clarity cuts both ways. Once the SEC codifies custody requirements, non-compliance becomes easier to identify and penalize. The current ambiguity allows some advisers to hold crypto assets without formal custody arrangements, relying on the "not our responsibility" defense. A clear rule eliminates this cover. Institutions that have been operating in the gray zone may face a compliance cliff, not a runway.
Second, the no-action letter's conditions are not trivial. Asset segregation for crypto assets requires technical infrastructure—separate wallets, distinct keys, verifiable ownership records. Many state trust companies lack this infrastructure today. The letter creates an opportunity, but seizing it requires capital investment and operational changes. The lag between authorization and implementation may be longer than market participants expect.
Third, the competitive dynamics shift in unexpected ways. The letter advantages state trust companies over national banks and broker-dealers, who must wait for the formal rule. This creates a window where a specific institutional type gains first-mover advantage. But that window is temporary. When the final rule emerges, the competitive field re-levels—potentially disadvantaging early movers who invested in state-specific compliance regimes that differ from federal requirements.
Fourth, the enforcement risk doesn't disappear; it migrates. The SEC's staff has committed not to recommend enforcement for compliant actors. But what constitutes compliance under a no-action letter is subject to interpretation. The staff's conditions may be read narrowly or broadly. Future SEC chairs may adopt different interpretive positions. The letter provides a safe harbor baseline, but that harbor's boundaries remain uncertain.
The Takeaway: Accountability Through Architecture
The SEC's custody rule revision is best understood not as a policy event but as an architectural one. It constructs the infrastructure through which institutional capital can flow into crypto assets—defining who can hold those assets, under what conditions, with what safeguards. The rule's final shape will determine which business models thrive, which become obsolete, and which remain perpetually marginal.
The September 30 no-action letter offers an immediate, actionable signal. State trust companies that satisfy the letter's conditions can begin offering crypto custody services today. RIAs can direct client assets to these custodians with greater confidence. The commercial effects should be measurable within quarters, not years.

The proposed rule extends this logic to the broader custody market. Its final language—particularly around eligibility requirements, safeguard conditions, and reporting obligations—will set the compliance baseline for the next regulatory cycle. Market participants should prepare for a regime where custody is no longer an ambiguity to exploit but a compliance burden to manage.
Isolating the variable that will determine this rule's impact: the gap between regulatory authorization and operational capability. The SEC can authorize state trust companies to custody crypto assets. It cannot make them competent to do so. The institutions that bridge this gap—investing in secure infrastructure, developing robust control frameworks, hiring personnel with blockchain expertise—will capture disproportionate value. Those that treat the no-action letter as a marketing opportunity without operational substance will become cautionary tales in the next enforcement cycle.
The rule's trajectory deserves continued attention. OIRA review status, the SEC's regulatory agenda updates, new commissioner appointments, and state trust companies' actual custody volumes will provide signals about the rule's direction and impact. The October 2026 target date may slip; the rule's content may evolve; the political context may shift. What remains constant is the structural logic: custody is the choke point through which institutional capital must pass. Whoever controls that choke point controls the terms of institutional access.
The silence between the blockchain transactions is where the compliance architecture takes shape. The SEC's custody rulemaking is that architecture, rendered in regulatory text. Its implications will extend far beyond the institutions directly affected—rippling through exchange volumes, ETF structures, and the broader market for digital assets. The question is not whether the rule arrives, but what it demands of those it governs.