Dual registrant regulatory roundup - September 2026
Dual registrant regulatory roundup - September 2026
September 10, 2026
United States
United States
United States
Welcome to the Regulatory Roundup. Each month, Eversheds Sutherland Investment Services attorneys review significant regulatory developments (including notable rulemakings and guidance from securities regulators) from the previous month that are of interest to retail broker-dealer and investment adviser firms.
On August 18, 2026, the SEC proposed new rules titled “Regulation Crypto Assets,” that, among other things, would establish a tailored offering regime for certain investment contracts involving crypto assets (covered investment contracts). The proposal builds on the joint SEC/CFTC interpretive release issued in March 2026, which established a classification framework for crypto assets, and the comment period will remain open for 60 days after publication of the proposed release in the Federal Register. While the proposal primarily addresses the offering side—creating two new exemptions from Securities Act registration for startup offerings (up to $5 million) and larger fundraising offerings (up to $75 million, modeled on Regulation A)—it also contains provisions with broader implications for broker-dealers and market intermediaries.
The proposal would also create a safe harbor from the term “investment contract” in the definitions of “security” under the federal securities laws, intended to provide market participants with greater clarity as to when a covered investment contract has ceased to exist because of a lack of essential managerial efforts—and, accordingly, when a crypto asset is no longer a “subject crypto asset” that would trigger securities law obligations for intermediaries. Additionally, the proposal would add a new definition of “qualified purchaser” under the Securities Act to preempt state securities law registration and qualification requirements for offers and sales of covered investment contracts issued under Regulation Crypto Assets, extending also to certain secondary market transactions. The antifraud and antimanipulation provisions of the federal securities laws would continue to apply to all transactions involving covered investment contracts, regardless of whether an exemption is relied upon.
In August 2026, FINRA published “Cybersecurity Effective Practices,” a framework of 12 cybersecurity principles and effective practices designed to help member firms strengthen their cybersecurity programs. The publication is informed by member firms’ regulatory obligations, industry risk principles and practices FINRA has observed through member firm oversight. FINRA states that the framework does not create new legal or regulatory requirements, or new interpretations of existing requirements, and does not relieve members of any existing obligations. Each practice is described as scalable to firms of all sizes and adaptable based on a firm’s risk profile, business model and technology complexity.
The publication identifies the regulatory obligations that may be implicated by a firm’s cybersecurity program, including SEC Regulation S-P (requiring written policies and procedures addressing administrative, technical and physical safeguards for customer information, including a program reasonably designed to detect, respond to and recover from unauthorized access with procedures for notifying affected individuals and for oversight of service providers); SEC Regulation S-ID (requiring firms that offer or maintain covered accounts to develop and implement a written program to detect, prevent and mitigate identity theft); FINRA Rules 3110 (Supervision) and 4370 (Business Continuity Plans and Emergency Contact Information); and the Exchange Act recordkeeping obligations under Rules 17a-3 and 17a-4. The publication specifically notes that firms relying on security logs to comply with the requirements of Rule 30 of SEC Regulation S-P should be aware that Exchange Act Rule 17a-4(e)(14)(ii) requires a minimum three-year retention period for such logs.
The 12 effective practices cover: (1) Governance – including designating a cybersecurity lead and embedding cybersecurity into firm culture; (2) Risk Management – identifying critical assets and evaluating internal and external threats on a recurring basis; (3) Third-Party Risk Management – including maintaining vendor inventories, imposing cybersecurity contractual requirements, monitoring fourth-party relationships and establishing documented termination processes; (4) Asset Management – maintaining and classifying inventories of hardware, software, cloud services and data flows; (5) Access Control and Identity Management – including multifactor authentication, role-based access controls, least privilege, segregation of duties and zero trust principles; (6) Data Protection – including encryption at rest and in transit, secure and immutable backups, data loss prevention and data retention aligned with regulatory requirements; (7) Security Awareness and Training – including ongoing training for all associated persons, phishing simulations and enhanced training for staff with access to sensitive systems; (8) Vulnerability and Patch Management – including periodic scanning, risk-based remediation prioritization and addressing end-of-life systems; (9) Security Monitoring – including logging and alerting, monitoring associated persons and third-party access and enhanced supervision of privileged access; (10) Threat Intelligence and Information Sharing – including subscribing to feeds such as FINRA’s Financial Intelligence Fusion Center and sharing anonymized threat indicators with regulators, the FBI and CISA; (11) Incident Response and Reporting – emphasizing a tested incident response plan to reduce response time, preserve evidence and meet applicable notification requirements; and (12) Resilience and Recovery – including tested backups, tabletop exercises, documented recovery playbooks and defined Recovery Point and Recovery Time Objectives.
FINRA files proposed rule change to modernize senior investor protections and introduce fraud prevention tool for all customers (SR-FINRA-2026-018)
On August 13, 2026, FINRA filed with the SEC a proposed rule change to amend Rules 0150 (Application of Rules to Exempted Securities Except Municipal Securities), 2165 (Financial Exploitation of Specified Adults) and 4512 (Customer Account Information) and to adopt new Rule 2166 (Temporary Delays for Suspected Fraud). The filing follows FINRA’s January 2026 request for comment in Regulatory Notice 26-02 and reflects modifications made in response to commenter feedback. The proposal is designed to modernize protections for senior and vulnerable investors and to make additional fraud prevention tools available for all customers.
The proposed amendments to Rule 4512 are designed to increase adoption and effectiveness of the trusted contact framework. The amendments would permit member firms to use the term “emergency contact” as an alternative to “trusted contact person,” addressing concerns that customers unfamiliar with the latter term may hesitate to designate a contact. The amendments would also permit firms to seek a customer’s authorization to apply a trusted contact person to all of the customer’s existing and future accounts with the firm, provided the customer is also offered the option to assign the contact on an account-by-account basis.
The proposed amendments to Rule 2165 would extend the maximum temporary hold period from 55 business days to 145 business days through a structured framework of three additional 30-business-day extensions, subject to conditions. Each extension would require that the member firm has made reasonable follow-up efforts with the relevant authority regarding the status of the reported matter, has not received a substantive response and continues to have a reasonable belief of financial exploitation. The first extension beyond 55 business days would require notification to all parties authorized to transact business on the account and to the trusted contact person. The amendments would also expand existing references in Rule 2165 to expressly include federal regulators and agencies (in addition to state), expand the types of associated persons authorized to place or extend a temporary hold to include those serving in specialized senior investor protection or fraud prevention roles and change the existing terminology of “funds or securities” to “funds, securities, or other assets” throughout the rule to ensure it covers crypto assets, such as payment stablecoins regulated under the GENIUS Act.
Proposed new Rule 2166 would offer member firms a separate safe harbor framework, modeled on Rule 2165 but more streamlined, to protect all customers—regardless of age or capacity—from suspected fraud. The rule would permit a member firm to place a temporary delay of up to 10 business days on a transaction or disbursement if there is a reasonable belief that fraud has occurred, is occurring, has been attempted or will be attempted. The 10-business-day period reflects an increase from the five business days initially proposed in Regulatory Notice 26-02, made in response to commenter feedback that a shorter period would be insufficient for investigation and customer outreach. Within two business days of placing a delay, the member firm must notify the customer of the delay, the reason and how the firm can be contacted. The rule defines “fraud” broadly as “a deceptive scheme perpetrated by a third party that targets a customer and results in a request for a disbursement of funds, securities, or other assets or a transaction in securities based on false or misleading information,” covering identity theft, account takeovers and other schemes. Like Rule 2165, proposed Rule 2166 would provide a safe harbor from FINRA Rules 2010, 2150 and 11870 when a member firm acts in accordance with the rule’s requirements, along with supervision, training and recordkeeping requirements.
__________
If you have any questions about this Legal Briefing, please feel free to contact any of the attorneys listed or the Eversheds Sutherland attorney with whom you regularly work.
The materials on the Eversheds Sutherland website are for general information purposes only and do not constitute legal advice. While reasonable care is taken to ensure accuracy, the materials may not reflect the most current legal developments. Eversheds Sutherland disclaims liability for actions taken based on the materials. Always consult a qualified lawyer for specific legal matters. To view the full disclaimer, see our Terms and Conditions or Disclaimer section in the footer. Eversheds Sutherland is a provider of legal and other services operating through various separate and distinct legal entities. For further information about these entities and Eversheds Sutherlands' structure please see the Legal Notice page of this website.