Executive Summary
On September 1, 2026 the SEC proposed the first substantive rewrite of its transfer agent rules since the early 1980s. Buried in the 421-page proposal is a sentence the tokenization industry has waited eight years to read: the official record of who owns a security – the master securityholder file – would be allowed to live on a blockchain.
This is the shift from tokens that represent ownership to tokens that are ownership. But the proposal comes with one condition that most of the commentary is skipping, and that condition decides which token architectures survive. This article explains the proposal in plain language and what to do about it.
Key Takeaways
- The SEC proposed modernized transfer agent rules on September 1, 2026 – the first substantive update since the late 1970s and early 1980s.
- A registered transfer agent could use a blockchain as its master securityholder file – the official ownership record – but would not be required to.
- The condition: the transfer agent must keep exclusive control over that record. A plain, uncontrolled token on a public chain does not qualify. Permissioned, compliance-enforcing token contracts do.
- Wallet addresses would be recognized as securityholder contact information, and transfer agents would disclose which blockchains they use.
- New obligations arrive too: cybersecurity and risk management policies, business continuity plans, and a duty to refuse transfers that would violate registration requirements.
- It is a proposal, not a rule. Comments are open for 60 days after Federal Register publication; a final rule would likely land in 2027.
First, What Is a Transfer Agent?
Every issuer of securities in the US needs someone to keep the official list of who owns what. That someone is the transfer agent: a registered entity that maintains the shareholder register, processes transfers, replaces lost certificates, and sends out dividends.
It is unglamorous plumbing, and it matters enormously. Whatever the transfer agent’s books say is, legally, who owns the company. Not the broker’s screen. Not the token in a wallet. The register.
The rules governing this plumbing were written in the late 1970s and early 1980s, for a world of paper certificates and mainframes. They have not been substantively updated since.
What the SEC Proposed, in Plain Language
The proposal (Release No. 34-106246, fact sheet) does five things that matter for tokenized securities:
1. The register can live on a blockchain. The amended rules would permit a transfer agent to use “a blockchain or other distributed ledger technology as its master securityholder file, or a component thereof.” Permit, not mandate. The guiding principle is technology-neutral: the record must be securely maintained and promptly updated, whatever platform it runs on.
2. Wallet addresses become part of the record. A blockchain wallet address is explicitly named as a valid form of securityholder contact information, alongside a mailing address, phone number, and email.
3. Transfer agents must disclose their blockchain use. The revised registration and annual report forms would ask about distributed ledger technology, tokenized securities serviced, and which blockchains hold master securityholder files.
4. The compliance floor rises for everyone. A reframed safeguarding rule would require written risk management policies covering cybersecurity, operational risk, and business continuity, plus segregated bank accounts for client funds. Old exemptions for small transfer agents would be rescinded.
5. Transfer agents become gatekeepers. A new rule on restrictive legends would require transfer agents to refuse to facilitate a transaction unless they have a reasonable basis to believe it does not violate the registration requirements of the Securities Act. In a tokenized world, that check moves into the transfer infrastructure itself.
SEC Chairman Paul S. Atkins framed the proposal as reflecting how transfer agents actually operate today, explicitly naming “blockchain technology” in connection with securities offerings and share transfers.
The Condition Everyone Is Skipping
The headline writes itself: the SEC blesses on-chain ownership. The actual text is more precise, and the precision is the story.
The proposal requires the transfer agent to maintain exclusive control over the master securityholder file. And the SEC openly asks, in its request for comment, how to handle records that exist “solely on a blockchain or distributed ledger that is not exclusively controlled by the transfer agent.”
Read that carefully. A vanilla token on a public chain – freely transferable, no compliance layer, nobody accountable – cannot be the official register under this framework. What can: a token contract where a regulated agent controls the registry, enforces transfer restrictions, and can freeze or correct records when the law requires it.
The SEC is not choosing between blockchain and no blockchain. It is choosing between accountable on-chain records and unaccountable ones. That choice decides which token standards and platforms fit the future US framework – and it lands squarely on the side of permissioned, compliance-enforcing architectures.
Why This Matters for the Industry
Until now, tokenized securities in the US mostly ran on a two-layer model: the token moves on-chain, and the “real” register gets updated off-chain afterwards. The token was a mirror, not the source of truth. That gap created legal uncertainty, reconciliation costs, and a ceiling on what institutions were willing to put on-chain.
If this proposal becomes a rule, the mirror can become the source. A transfer of the token can be the transfer of the security. Settlement, register update, and compliance check collapse into one event.
The practical consequences:
- The transfer agent becomes the strategic seat of tokenized markets. Whoever combines a transfer agent registration with token-registry technology controls the record that everything else references.
- Compliance-first token design wins. Standards built for enforceable transfer restrictions and agent control map directly onto the SEC’s requirements. Free-floating wrappers do not.
- Costs rise for legacy players. Cybersecurity, risk management, and business continuity requirements favor technology-native providers over firms retrofitting decades-old systems.
We Have Been Building for This Since 2018
Stobox was founded in 2018 on a thesis that sounded stubborn at the time: a tokenized security only works when compliance lives inside the token’s infrastructure, not in a PDF next to it.
That thesis is now the SEC’s guiding principle, so it is worth retracing the steps:
- 2018 – Stobox is founded to build infrastructure for tokenized securities, when most of the market is still chasing utility tokens.
- 2019 – Gene Deyev, Stobox’s Founder & CEO, co-authors one of the first books on security token offerings, laying out why regulated tokenization needs its own discipline.
- The Stobox Tokenization Framework follows: eight phases from strategy to STO, treating legal structuring and compliance as the core of the work rather than an afterthought.
- Stobox backs ERC-7943 (uRWA), the push for a universal standard for real-world assets – token contracts with enforceable restrictions and accountable control, exactly the properties an “exclusive control” requirement demands.
- Stobox Compass issues compliant tokenized securities with issuer-controlled registries, transfer restrictions, and recovery functions built in – primarily on Base, with Arbitrum and Canton also supported.
- May 2025 – Gene Deyev takes part in the SEC Crypto Task Force roundtable on tokenized securities, as the agency begins the work that surfaces in this proposal.
- Today – Stobox has structured and supported $305M+ in assets across 100+ clients, and Stobox Intelligence tracks the regulatory record this proposal now joins.
The point of the timeline is not self-congratulation. It is that the “boring” interpretation of tokenization – regulated agents, controlled registries, compliance in the transfer path – kept looking conservative right up until the regulator wrote it into a proposed rulebook.
What Happens Next
The comment period runs for 60 days after the proposal is published in the Federal Register. The SEC is asking pointed questions: how to link on-chain records (wallet, quantity) with off-chain identity (name, address), what to do about ledgers no single party controls, and how retention rules apply to immutable networks. Expect heavy participation from transfer agents, blockchain platforms, and issuers – and expect the final rule, likely in 2027, to reflect those answers.
For issuers, the preparation is concrete: if you are planning a US offering of tokenized securities, choose an architecture a transfer agent can control. Transfer restrictions, freeze and recovery functions, an authoritative registry. Retrofitting them later is expensive; issuing without them may soon mean your token cannot be the register at all.
If you want to assess where your asset stands, the Stobox readiness score is free, and the Tokenization Framework walks through the structuring work this kind of regime rewards. For a deeper conversation, talk to a Stobox specialist.
The register is moving on-chain. The winners will be the ones who treated that as an engineering and compliance problem before it became a headline.