SonarX
BlogGuides· 16 min read· By SonarX Team

How the SEC's Proposed Transfer Agent Rules Treat Distributed Ledger Records

The SEC's proposed transfer agent rules would permit a distributed ledger to serve as the master securityholder file. Comments close November 3, 2026.

SEC Transfer Agent Rules: What the Proposal Asks of a Record

The Securities and Exchange Commission has proposed rules that would let a blockchain be the master securityholder file, the record of who owns a security. The Transfer Agent Rules reached the Federal Register on September 4, 2026, at 91 FR 56946, and comments close November 3, 2026, under File No. S7-2026-30. The permission is conditional, and the release leaves the condition undefined.

The proposal answers three questions about that record.

  • What the file has to be. Electronic form becomes mandatory, and a distributed ledger could be that file, or a component of it.
  • What an agent must make, keep, retain and produce. Records would have to be sufficient to show the required information, retained for six years, and held in a system with four named controls.
  • What has to be reported. Form TA-2 would collect the number of issues where distributed ledger technology maintained the file, and the number by tokenization model.

The proposal permits the technology and puts the requirements on the record: electronic, exclusively controlled, reconciled between state and history, and producible on demand.

The proposal

Key takeaways

  • Electronic form becomes mandatory, and a distributed ledger could be the master securityholder file, or a component of it.
  • The permission is conditional. The technology is the agent’s choice provided the agent maintains “at all times exclusive control” over the file, a phrase the release never defines.
  • Position detail is current state, and the transfer journal is time-sequenced history. A new record-difference category applies when the two disagree.
  • Rule 17ad-10(f) would still require a recordkeeping agent to keep deleted position detail for six years from deletion. Onchain records could hold it.
  • One date is fixed: comments are due November 3, 2026. The proposal sets no compliance date, no phase-in and no transition period.
  • The Commission asks 175 numbered questions. One asks whether a file kept exclusively on an immutable blockchain network should be exempt from the deletion-retention requirement.

What is the master securityholder file? It is “the official list of individual securityholder accounts maintained by a registered transfer agent.” Under the proposal it “shall be maintained in electronic form,” and only one recordkeeping transfer agent may maintain it per issue.

Scope

What the transfer agent rules cover, and what they leave out

The release amends Forms TA-1 and TA-2, amends thirteen rules, rescinds Rule 17ad-4, and adds two: Rule 17ad-30 on compliance policies and procedures, Rule 17ad-31 on restrictive legends. Four things a reader might expect here are handled elsewhere or not at all.

  • Whether a token is a security. The release makes no such determination. A footnote cites a staff Statement on Tokenized Securities and states that “Staff statements have no legal force or effect.”
  • Any approval or safe harbour for tokenizing a security. The proposal offers none. The definition “would not mandate or otherwise endorse a specific electronic format,” and the flexibility holds only if “the standards as set forth in proposed Rule 17ad-7(f) … are met.”
  • Broker-dealer and adviser custody. The proposal amends no custody rule outside the transfer agent set. The agent’s own duty changes: Rule 17ad-12 becomes written policies and procedures protecting securities and funds against “theft, loss, misappropriation, misuse … and improper or unauthorized access.” Question 113 asks whether “stablecoins and tokenized deposits can be funds.”
  • Who counts as a registered holder. The file is “intended to be synonymous with … the ‘stockholder ledger’ or ‘stockholder register,’” and the proposal does not amend state law. Question 40 asks whether a holder without a name and mailing address would “still be considered a registered securityholder pursuant to applicable law.”

Deadlines

Deadlines, and the consequences the proposal states

One date below is fixed: the comment deadline. The release sets no compliance date, no phase-in and no transition period, so a duration marked if adopted would apply only on adoption. The Economic Analysis assumes an effective date for modelling only.

DateWhat appliesWho it affects
November 3, 2026Comments due, File No. S7-2026-30Anyone commenting
December 31, then March 31 (existing)Form TA-2’s period ends, then the form is filedForm TA-2 filers
45 days (if adopted)Registration effective 45 days after filing, not 30Applicants
One business day (if adopted)Turnaround, prompt posting, and a co-transfer agent’s records and inquiry repliesAll agents; co-transfer agents
Six years (if adopted)Uniform retention, “the first two years in an easily accessible place”All registered agents
Six years from deletion (retained)Position detail deleted from the file, dated from deletionRecordkeeping agents
15 calendar days (if adopted)On ceasing to act for an issue, records go to the issuerOutgoing agents
Annually, or on material change (if adopted)The board approves the compliance policies and proceduresAll registered agents
No dateNo compliance date or phase-in; transition goes to comment at Questions 52 and 103Everyone

What the proposal says about consequences

The release states no penalty amount, no penalty schedule, no fine figure and no criminal provision. It carries a reminder instead: the proposed Form TA-1 signature block would recite that where an agent does not comply with Section 17(b), “the Commission may seek all available relief … in district court and/or an administrative proceeding,” and a footnote records that an agent “may be subject to censure, suspension, limitation, or revocation of its registration.”

Two provisions could be mistaken for penalties. The Rule 17ad-10(g) buy-in is remedial, runs 60 days from discovery, and “is designed to deter transfer agents from permitting record differences to accrue.” A missed clock is not automatically a violation either: the design avoids “a de facto strict liability standard that would result in a rule violation for a single missed turnaround.”

Who reads what

Which section answers your question

If you areWhat you are probably askingRead
A transfer agent piloting a ledgerWhat exclusive control coversIf you keep the master file on a distributed ledger
An issuer with a tokenized issueWhat position detail collectsIf you issue tokenized securities
An examiner, auditor or accountantWhat is produced, and how fastIf you examine or audit transfer agents
An engineering team building the systemWhich controls sit on the systemIf you build the recordkeeping system
Counsel tracking the comment fileWhich questions stay open175 questions, and what they leave unresolved
Anyone reconciling ownership against a chainWhich records the obligations needWhat this asks of the record

Recordkeeping agents

If you keep the master file on a distributed ledger

The rule text mandates electronic form and leaves the technology open. The release then states: “the amended definition would permit a transfer agent to utilize a blockchain or other distributed ledger technology as its master securityholder file, or a component thereof, but it would not mandate it.” Three qualifiers apply: the file must meet the standards in proposed Rule 17ad-7(f), the proposal endorses no electronic format, and the discretion holds only while the agent maintains “exclusive control over, and responsibility for, such a crucial record.”

One agent owns it: “There can be only one recordkeeping transfer agent for a given issue of securities.” That does not bar delegation: the amendment would not prevent use of “a service company or co-transfer agent, or multiple linked files or systems, or a particular technology.” Three records must now be made, not merely kept if they exist: the transfer journal, the control book and the master securityholder file, “including all records, documents, and information that compose” them. Form TA-2 Question 4(e) then counts the issues where the registrant “maintained the master securityholder file using distributed ledger technology, in whole or in part.”

Issuers

If you issue tokenized securities

“Certificate detail” becomes “position detail,” a neutral term “that can apply to any form of security.” Three items are about identity. Item one would require, “for all securities, an applicable unique identifier for the security,” with CUSIP and FIGI as examples the rule “would not mandate.” Item three would require the holder’s full name and “any other relevant identifying, titling, or formatting information necessary to … identify the specific securityholder,” illustrated as “a digital wallet address in the case of any tokenized security.” Item four would require contact information “including at a minimum a physical mailing address,” and names a wallet address only as something that information “could include” in addition.

Reporting attaches to the issue rather than the agent. Form TA-2 Question 6(b) would require “the number of issues, by tokenization model and security type, serviced by the registrant as of December 31,” under two models, issuer-sponsored and third-party sponsored. Question 13 would require an attachment giving “both the name of the issue and its identification number from the master securityholder file.” The reason: “Under the existing rules, the Commission does not know which transfer agent services a particular security.” A tokenized equity settles on a specific chain, such as Robinhood Chain, and that chain becomes part of the same picture.

Examiners

If you examine or audit transfer agents

Two provisions set different production standards. The system must “provide indexing and retrieval capabilities sufficient to allow immediate production … in both a human-readable format and in a reasonably usable electronic format.” Production on demand is separate: a “legible, true, complete, and current copy … in a reasonably usable electronic format,” provided “promptly upon demand.” Only “in unusual circumstances” would a delay beyond one business day still meet it.

Where a third party holds the records, there are two routes. Either the agent has independent access, which it does “if it can regularly access the records without the need of any intervention by the third party,” or it files with the Commission and its appropriate regulatory agency “a legally binding written agreement signed by a duly authorized person of the third party.” Either way the duty stays with the agent. Retention becomes uniform at six years. As agents expand their use of “distributed ledger technology, AI, and other nascent technologies,” broader retention becomes “essential to the Commission’s oversight and examination capabilities.”

System builders

If you build the recordkeeping system

The rule text speaks to the system, not the ledger. The proposal newly defines an “electronic recordkeeping system” as “a system designed to maintain, retain, or preserve records in a digital format.” It needs “reasonable controls to ensure the integrity, accessibility, reproducibility, redundancy, and continuity of records,” and it names four: protection “from unauthorized changes or destruction”; retrieval sufficient for immediate production in two formats; an audit trail “that tracks access, modification, and deletion of records, including the identity of the user and the date and time of the action”; and “means to recover altered, damaged, or lost records.”

This proposal contains no non-rewriteable, non-erasable requirement. It says the opposite: “The controls should not include write-prohibitions that may be incompatible with ordinary transfer agent functions. Instead, an audit trail system that tracks access, modification, and deletion of records … would be more appropriate.”

Rule 17ad-6 also loosens: “records sufficient to show” the required information replaces “a log, tally, journal, schedule, or other record.”

You may also be named. Form TA-2 Question 5(b) would collect service providers in eight checkbox categories, including “recordkeeping system providers,” “tokenization agents” and “distributed ledger technology platforms,” each with a space for the provider’s name, though that information “would not be made publicly available on EDGAR.” The proposal would remove Form TA-1’s service-company question.

Definitions

What is position detail, and what is a transfer journal?

State, history, and the requirement that they agree

Position detail is current state. The transfer journal, defined for the first time, is “a record of all issuances, cancellations, transfers, distributions of cash or securities, additions and cancellations of position detail.” It is also “a time-sequenced record of all changes in position detail” that any registered transfer agent may keep, while the file “establishes the list of an issue’s current registered owners.”

Then the two must agree. The proposal would add a third category of record difference: “Position detail in the master securityholder file is inconsistent with the history of transactions in the transfer journal.” The requirement that state must match history is a reconciliation obligation.

The other terms that carry weight

  • Control book. It would show an issuer’s “authorized, issued, and outstanding securities,” with “outstanding” the addition, and a footnote confirms that “record” here covers “records existing on a distributed ledger or blockchain.”
  • Presentor. The third new definition is presentor: “the registered securityholder, the entitlement holder, and their authorized agents,” aligned to the Uniform Commercial Code’s “appropriate person.” The release proposes no definition of “payment agent.”

Open questions

175 questions, and what they leave unresolved

The release asks 175 numbered questions across 18 request-for-comment blocks. The questions below bear on whether a ledger can hold the file.

  • Question 105. “Should transfer agents that maintain the master securityholder file exclusively on an immutable blockchain network be exempt from the record deletion and retention requirement … in Rule 17ad-10(f) …”
  • Question 84. “How should the Commission address situations where records exist solely on a blockchain … not exclusively controlled by the transfer agent?”
  • Question 83. “… recordkeeping systems that associate onchain database records … with offchain … records … so that the transfer of a tokenized security … results in a corresponding transfer … on the master securityholder file?”
  • Question 99. “… would be able to regularly access and view the records maintained on the blockchain … without … intervention by a third party”
  • Question 88. “For transfer agents that maintain records on distributed ledgers … how should the requirements for … a master securityholder file, control book, and transfer journal be applied?”
  • Question 50. “Are there specific requirements or conditions that should apply to the use of blockchain … as a master securityholder file …?”
  • Question 94. “Are there circumstances in which maintaining such an audit trail would be technically infeasible or operationally impractical …?”

Questions 45 and 84 put the conditions around “exclusive control” to comment.

The record

What this asks of the record

Read as a data specification, the obligations reduce to a short list of record properties.

The obligationThe record it needs
Securities transferred before a record date but posted after it “shall be posted as of the record date”The register as it stood on a past date
The transfer journal: all issuances, cancellations, transfers “and cancellations of position detail”Every movement, time-sequenced, from the first entry
Rule 17ad-10(f): deleted position detail retained six years from deletion, which “could be maintained … by onchain records”Detail that outlives the current state
Rule 17ad-9(g)(3): position detail “inconsistent with the history of transactions in the transfer journal”State reconciled against history, continuously
Rule 17ad-9(a)(1): “an applicable unique identifier for the security”A stable identifier per instrument, joinable across systems

Put those five rows against a ledger that only appends, and the shape of the problem is visible. An append-only register cannot answer an examiner on its own. It needs three things kept alongside it: a corrections record that tells a correction apart from a new entry, so that detail deleted from the register is retained rather than overwritten; a read that reproduces the register as it stood on any past date, which is what a record date requires; and an audit trail over the system that reads and writes the ledger, because the ledger itself records what moved, not who at the transfer agent touched a row. None of that is supplied by the chain. All of it is what the proposal’s recordkeeping rules describe.

Five limits belong with the table.

  • A registered holder’s identity is not in chain data. The rule wants a full name and, at minimum, a physical mailing address. Mapping a wallet to a named holder is the agent’s own work.
  • The audit trail covers the agent’s system, not the chain. It wants “the identity of the user and the date and time of the action.” Chain data does not record who edited a row.
  • “Exclusive control” is not a data property. The instrument leaves the term undefined and puts it to comment. No record, onchain or off, settles it.
  • Tokenization model is not a property of chain data. Issuer-sponsored against third-party sponsored describes an arrangement, not a token.
  • The control book is issuer-authorised data. Authorized counts come from a charter or indenture, which the agent obtains from the issuer.

For disclosure: SonarX indexes public chains and sells the resulting data. It is not a registered transfer agent, maintains no master securityholder file, and files no Form TA-1 or TA-2. The determination is yours, or your counsel’s.

Elsewhere

Four other regimes answer the same question differently

The question in each case is whether the ledger can be the register of ownership, or must mirror one kept elsewhere. This proposal answers at the transfer agent layer, and conditions permission on control, not on recognition of onchain title.

  • Singapore. MAS announced Project Guardian on 31 May 2022, defining tokenisation as “the process of digitally representing assets or items of value through a smart contract on a blockchain.”
  • European Union. The DLT Pilot Regime “began applying in the EU on 23 March 2023” and creates three infrastructure types: a DLT multilateral trading facility, a DLT settlement system, and a DLT trading and settlement system. It runs “for a period of at least 3 years.”
  • Hong Kong. The SFC’s circular on tokenised securities, 2 November 2023, ref. 23EC52, treats them as traditional instruments that “utilise DLT … in their security lifecycle,” and requires disclosure of “whether off-chain or on-chain settlement is final.”
  • United Kingdom. The Digital Securities Sandbox is “a regulated live environment” for “the activities of notary, maintenance and settlement for financial securities,” and is “due to run until 8 January 2029.”

Ownership can sit in three places: the transfer agent’s file, a depository’s records for street-name holdings, or the ledger. This proposal would let the ledger be the transfer agent’s file, and it conditions the choice on “exclusive control,” a phrase it never defines.

Summary of a proposed rule, not legal advice. Citations are to the NPRM as published in the Federal Register on September 4, 2026, 91 FR 56946, Release No. 34-106246, File No. S7-2026-30. Last reviewed September 9, 2026.

Frequently asked questions

Can a blockchain be the master securityholder file?

The proposal would permit it, not require it. The release states that the amended definition would permit a transfer agent to utilize a blockchain or other distributed ledger technology as its master securityholder file, or a component thereof, but that it would not mandate it. The permission is conditioned on the agent maintaining at all times exclusive control over the file, and on meeting the recordkeeping standards in proposed Rule 17ad-7(f).

What is the master securityholder file?

The master securityholder file is the official list of individual securityholder accounts maintained by a registered transfer agent. The SEC release calls it the authoritative record of who owns an issuer's securities, and equates it to the record state corporate law calls the stockholder ledger or stockholder register. Under the proposal the file would have to be maintained in electronic form and may consist of multiple linked files or systems.

What does "exclusive control" mean in Rule 17ad-9(b)?

The release does not define the phrase. Proposed Rule 17ad-9(b) says the specific technology, systems, or files that compose the master securityholder file are within the transfer agent's discretion, provided the transfer agent maintains at all times exclusive control over the master securityholder file. No definition of exclusive control is proposed anywhere in the release, and Questions 45 and 84 put the conditions around the phrase out for comment.

When do comments on the SEC transfer agent rules close?

Comments are due on or before November 3, 2026, under File No. S7-2026-30. The release was published in the Federal Register on September 4, 2026 at 91 FR 56946. That is the only fixed date in the release. The proposal sets no compliance date, no phase-in and no transition period for any provision, and it asks commenters what transition period would be appropriate.

What does Rule 17ad-10(f) require?

Proposed Rule 17ad-10(f) would require every recordkeeping transfer agent to retain a record of all position detail deleted from the master securityholder file for a period of six years from the date of deletion. The obligation carries over from the existing rule; what the proposal rescinds is the hard-copy alternative. The release adds that the information could be maintained, for example, by onchain records.

Does the SEC proposal approve tokenized securities?

The release makes no determination about whether a token or a tokenized security is a security, and it proposes no approval, licence, registration or safe harbour for tokenizing one. It reaches tokenized securities through recordkeeping and reporting obligations on registered transfer agents. A staff Statement on Tokenized Securities is cited in a footnote which states that staff statements have no legal force or effect.