The U.S. Securities and Exchange Commission has proposed modernized rules for registered transfer agents that explicitly address electronic and blockchain-based securities records. The proposal would update requirements for record retention, risk management, business continuity, safeguarding, and compliance, applying to traditional transfer agents as well as registered tokenization firms and issuers maintaining tokenized securities.
The SEC identifies distributed-ledger data integrity, tokenized-security protection, and blockchain operating models as material operational risks requiring controls. The proposal follows SEC staff guidance issued in May 2025 that permitted transfer agents to use distributed-ledger technology for official master securityholder files when federal securities requirements are met; the rules are not yet effective and will be open for public comment for 60 days after publication in the Federal Register.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
The SEC proposed amendments to modernize transfer-agent requirements for electronic and blockchain-based securities records, including record retention, safeguarding, operational-risk management, business continuity, and compliance policies. The proposal identifies blockchain data integrity, tokenized-security security, and distributed-ledger operating models as material risks for transfer agents to manage.
The SEC Division of Trading and Markets issued nonbinding guidance stating that registered transfer agents could use distributed-ledger technology for all or part of an official master securityholder file if they complied with federal securities requirements.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.