Reg CA is not a switch for a bull market in issuing tokens, but a "graduation exam" for existing tokens
Authors: Molly & Jeff & Ethan, IOSG
On August 18, 2026, the U.S. Securities and Exchange Commission (SEC) released the proposal for the "Regulation Crypto Assets" (Reg CA). On August 21, the proposal was officially published in the Federal Register, with the public comment period ending on October 20. This rule has not yet been implemented and is still in the opinion collection phase. Core Judgments
Reg CA will not trigger ICO 2.0. Issuing new tokens has become easier, but only for amounts below $5 million. There is a four-year cumulative cap, and the same token can only be used once in a lifetime, even airdrops count against the limit. This scale cannot support a market cycle. In the SEC's own calculations, no assumptions were made for increased issuance.
The real benefit of Reg CA lies in clearing existing tokens. The safe harbor provision has no limit on amount or nationality, and old projects can also use it: as long as all commitments made in the white paper are fulfilled, a report can be submitted, and the token can shed its securities status. Among over 9,000 tokens globally, the vast majority have never had their legal status formally addressed—this rule governs not who can issue tokens, but who can "graduate."
Reg CA is likely to be implemented, but it will be later and narrower. All three sitting SEC commissioners support it, and the White House has publicly endorsed it, with the chair considering it a signature project of their term. However, the final version will not be released until at least 2027, and the provision excluding state law applicability, which affects the jurisdiction of various states, is the most likely to be cut. Reg CA, as an administrative rule, cannot change laws and does not cover the CFTC. This framework is more like a bridge, not a destination.
I. What is Reg CA? What is driving the introduction of Reg CA? Before focusing on the rule itself, we can first look at the timing of its emergence. The day after the proposal was released, on August 19, Trump met with a group of executives from crypto companies at the White House—Coinbase, Gemini, Ripple, Chainlink Labs, Kraken, Anchorage, Grayscale, OKX were all present—publicly urging Congress to pass a "fair version" of the CLARITY Act as soon as possible. In the same week, the CFTC held its first Innovation Advisory Committee meeting. SEC Chair Atkins released Reg CA while calling on Congress to send the CLARITY Act to the president's desk. The market's reaction to cryptocurrencies that week was also very direct. On the day the proposal was released, August 18, Bitcoin was still above $64,000; after the White House meeting on the 19th, it broke $70,000 for the first time since late May; combined with factors like Treasury buybacks, declining long-term yields, and ETF inflows, the week's highest price reached $77,600, with a weekly increase of about 22%, the largest single-week rise in over two years.
Putting these events together points to the same judgment: The way the U.S. is advancing crypto regulation has shifted from "waiting for Congress to legislate" to "administrative action first"—the White House sets the tone, the SEC issues rules, and the CFTC lays the groundwork, with legislation following behind. Reg CA is the most concrete step in this combination.
The rapid progress of this proposal is directly related to the current personnel structure of the SEC. The committee has five statutory seats, but currently only three are filled, all by Republicans—the last Democratic commissioner, Caroline Crenshaw, left office at the end of her term in January 2026. Atkins, Peirce, and Uyeda have all issued supportive statements, which is rare in recent major rulemaking, indicating that the checks on this rule will mainly come from outside the agency.
Will it ultimately become a formal rule? Our judgment is: the probability is not low, but the timing will be later than the market expects, and the content will likely be narrower than the current version. The supportive side is clear—there are no opposing votes within the committee, the White House has publicly endorsed it, and the chair considers it a signature project of their term. Risks are concentrated in three areas: first, it needs to accept comments during the review period and undergo congressional scrutiny, especially Rule 500, which directly undermines state jurisdiction, making state securities regulators likely to voice objections; second, if the CLARITY Act passes first, Reg CA will need to realign with it. According to the SEC's usual timeline, the final rule is unlikely to be finalized until at least 2027 after the comment period ends on October 20.
▲ Figure 1: Legislative Phase of the Regulation Crypto Assets
A rule born in legislative gridlock
Reg CA did not appear out of nowhere. It is an administrative alternative path after legislative blockage.
The CLARITY Act (the "Digital Asset Market Clarity Act"), which the industry has high hopes for, passed the House vote in July 2025 and cleared the Senate Banking Committee in May 2026, but has yet to complete a full Senate vote. On August 8, the Senate proposed a cloture motion, which was immediately followed by a recess until September 13, missing the window before the recess. The next milestone is the procedural vote on September 15 (motion to proceed), which needs to cross the 60-vote threshold—if passed, there is still a chance for legislation within 2026; if not, it will be election season, and the difficulty of passing legislation will significantly increase. As of the time of writing, Polymarket's pricing for the CLARITY Act passing this year is below 20%.
The SEC did not wait for this outcome but actively promoted regulatory change. In a statement on August 18, SEC Chair Atkins made the motivation very clear: forcing crypto assets into existing securities rules is a "square peg in a round hole," resulting in "driving investment overseas and limiting the protections we can provide to domestic investors." He set the rule's goals as "minimum effective dose, maximum construction freedom, and sustainable certainty," aiming to "pave a way to bring innovators back to the U.S."
Reg CA and the CLARITY Act aim to solve the same problem, but they are not the same thing. The overlapping parts are directional: neither assumes "once a security, always a security," both provide a path for crypto assets to graduate from securities status, both set the graduation timeline at around four years, and both prioritize ongoing disclosure over pre-approval as the main regulatory means. It can be said that the SEC has created an administrative version based on the framework Congress is discussing, intentionally aligning in direction to avoid future conflicts between the two standards.
However, the differences lie in hierarchy and coverage, and these two points determine that they cannot replace each other. In terms of hierarchy, the CLARITY Act is law, while Reg CA is merely an administrative rule. Laws can amend both the Securities Act and the Commodity Exchange Act, redefining the jurisdictional boundaries between the SEC and CFTC; administrative rules cannot change laws and do not cover the CFTC, and can be overturned by the next commission or struck down by the courts. In terms of coverage, CLARITY is a complete set of market structure legislation—covering issuance, trading platforms, brokers, custodians, etc.; Reg CA only addresses "how to compliantly issue"—after the tokens are issued, where they are traded, who provides market making, and who provides custody are explicitly stated as not being addressed by the proposal. CLARITY legislates for the entire market, while Reg CA opens a door for issuers. Once the door is open, who manages the road behind it still awaits congressional legislation. The rule itself: two exemptions, one safe harbor, one state law pathway First, let's clarify what scenarios this rule addresses. It targets the act of project parties raising funds from the public through the issuance of crypto assets (tokens)—previously referred to as ICOs. Under current law, such issuances are mostly deemed securities offerings: either register with the SEC (which is impractical in terms of cost and time), or apply exemptions designed for equity such as Reg D, Reg A, or Reg CF (none of which fit well). What Reg CA aims to do is create a separate set of rules for the issuance of crypto assets and additionally solve a problem that does not exist in the equity world—whether tokens can one day no longer be securities.
It is proposed to be incorporated into Title 17 of the Code of Federal Regulations, Part 228, with core content including: two issuance exemptions (how to compliantly issue), one safe harbor (when tokens are no longer securities), and one state law pathway (how to circulate nationwide after issuance).
▲ Figure 2: Four Parts of Reg CA
Rule 200 Startup Exemption: Filing to start, but only one chance
This provision stipulates that small issuances follow a filing system. If a project raises no more than $5 million cumulatively within four years, it only needs to submit a Form NOR (Notice of Issuance) to EDGAR to start selling, the SEC does not conduct any pre-review and does not require financial statements at all, only a principled narrative disclosure covering investment contract structure, token specifications, management team, token economics, governance, and risk factors. This is the lowest threshold in the entire set of rules and the most discussed in the market.
The real highlights and pitfalls are not in the $5 million figure itself. There are three details in the provisions that have a far greater impact than the limit itself.
First, it does not require the issuer to be a U.S. entity. The text states that the issuer "can be an entity, an individual, or a group of individuals or entities" (Rule 200(b)(2), 91 FR 54609), and the preamble of the proposal clearly states that the startup exemption does not require a U.S. entity. This is the only provision in the entire set of rules that is completely open to non-U.S. entities: Cayman foundations, BVI entities, or even a developer team without any entity can invoke it.
Second, the scope of "covered transactions" goes far beyond fundraising. The definition in Rule 100 explicitly includes airdrops, as well as "rewards or incentives for activities conducted to operate, govern, or secure the associated network"—that is, staking rewards and governance rewards. For example: a five-person team sets up a foundation in the Cayman Islands to create a DePIN network, submits a Form NOR, publicly roadshows, and raises $3 million from global retail investors; after the mainnet goes live, they airdrop a batch of tokens to early node operators, valued at $1.5 million at the time of issuance. This $1.5 million also counts against the $5 million cap, totaling $4.5 million, leaving only $500,000 of room. For projects with large airdrop scales, this limit is tighter than the market expects; and the proposal does not specify a valuation method for non-cash consideration—whether based on fair value, spot price, or weighted average price is currently left blank.
Third, it is a one-time use and limited to related parties. The same issuer and its related parties can only invoke this exemption once for the same or "substantially similar" crypto asset. Once used, there is no going back, and the term "substantially similar" is not defined in Rule 100, with the SEC also soliciting opinions on whether to set a de minimis threshold.
Additionally, there is a timing trap: the exemption only covers transactions that occur after the submission of Form NOR. Any public communication before submission may constitute an "offer" that is not protected by the exemption. Rule 300 Fundraising Exemption: Higher amounts correspond to higher requirements This provision stipulates that large issuances require qualification review. When the fundraising scale goes up, it must apply the Rule 300 fundraising exemption. It is divided into two tiers—Tier 1 allows raising $20 million every 12 months, and Tier 2 allows raising $75 million every 12 months—both tiers must submit Form 1-CRYPTO, and sales can only occur after SEC qualification review is passed, followed by ongoing information disclosure reports. In exchange, it allows issuers to publicly test the waters before formal filing. In terms of financial requirements, Tier 1 must provide financial statements compliant with U.S. GAAP but is exempt from audit, while Tier 2 must be audited.
But the real threshold for this tier is not the amount, but the entity qualifications and jurisdiction. The provisions require that the issuer be an entity established under U.S. law, with three cumulative requirements: more than half of the executives or directors must be U.S. citizens or residents, over 50% of assets must be located in the U.S., and the business must be primarily managed in the U.S. Returning to the previous example—if the Cayman team wants to raise $30 million under this tier, "setting up a subsidiary in Delaware" will not meet these three requirements, effectively meaning a complete relocation to the U.S.
In addition, restrictions on investors are also stricter, with both tiers requiring non-accredited investors to limit purchases to 10% of their annual income or net worth (whichever is higher), and there is no exception like the usual Reg A exemption that allows "listed securities to be exempt." Therefore, a retail investor with an annual income of $200,000 and a net worth of $500,000 can invest a maximum of $50,000 in a single transaction. However, this 10% limit may be difficult to enforce in the crypto world. Issuers can rely directly on the purchaser's own statements to determine compliance, as long as they are unaware that the statement is false at the time of sale. On-chain, this means three things: issuers cannot verify the income and net worth declared by purchasers, cannot aggregate the purchase amounts of the same person across multiple wallet addresses, and cannot know how much they have bought from other issuers.
▲ Figure 3: The real dividing line is not the amount, but nationality
Additionally, there is a provision regarding the handling of insider sell-offs, which may illustrate the orientation of this rule more than the text itself. a16z and Coinbase both proactively requested limits in their written opinions to the SEC's crypto working group—Coinbase's original statement suggested that "the development team and related parties should be restricted from selling tokens for their own accounts until the network or protocol has been sufficiently decentralized," arguing that this is to "ensure that issuers, development teams, and related parties maintain ongoing economic incentives to complete the project." The SEC received this and acknowledged in the text that this risk does indeed exist, but the chosen response is to require disclosure, rather than setting a holding period. The SEC acknowledges the economic utility of lock-up periods but has not set that requirement. When the regulated party is more conservative than the regulator, the issue is no longer about lobbying winning, but about no one stepping on the brakes.
Rule 400 Investment Contract Safe Harbor: The most significant provision under Reg CA
This provision stipulates: when tokens are no longer "securities." There are only two conditions— the issuer has completed or permanently ceased all core management work promised under that investment contract, and no new commitments are made; and a transformation report Form TR is submitted to the SEC. Once satisfied, that investment contract "will be deemed to no longer exist," and the attached crypto assets, in terms of the definitions of the Securities Act and the Exchange Act, will no longer be considered securities.
What does "no longer being a security" specifically mean? It means that the issuance and transfer of this token no longer need to seek any exemptions, no registration is required; the platforms trading it do not have to register as securities exchanges or brokers because of it; institutions holding it are not bound by securities custody rules; and issuers no longer bear ongoing disclosure obligations under the Securities Act and the Exchange Act. However, it should be clarified that it removes the registration and disclosure shackles brought by the "securities" identity, not all regulation—federal securities law's anti-fraud provisions still apply, as do commodity regulation, state law anti-fraud, and consumer protection. The safe harbor is not a license. The proposal clarifies in the same section: like any safe harbor, it "only applies within the scope of the issuer meeting its conditions, and the commission is not thereby excluded from challenging whether the issuer indeed meets these conditions."
For a specific example: a project issued tokens in 2021 through Reg D 506(c) private placement, promising three things in the white paper: launching the mainnet, open-sourcing the client, and transferring governance to a DAO. Once all three are completed, it submits Form TR, stating that these three commitments have been fulfilled and no new core management commitments will be made, then this token will be deemed not to be a security. After that, the team continues to fix bugs, release new versions, and fund ecosystem development—the proposal clearly states that once the associated network reaches "functionality," activities for maintaining, updating, and enhancing that network, including sponsoring or funding development projects, do not constitute core management work. This effectively cancels the core of the enforcement theory from 2018 to 2024 that "continued development by the foundation equals continued management efforts."
Applying Rule 400's conditions as a rough filter, mainstream tokens roughly fall into three categories. One category is those that do not need this rule at all—BTC, ETH, etc., which have long been treated as non-securities in regulatory practice. Another category is the most typical graduation candidates: those that completed financing through a clear round of token sales in their early years, delivered the mainnet and core functions promised in the white paper, and still have a signable foundation or entity. Tokens like DOT, FIL, SOL, NEAR, AVAX fit this profile (not representing that they have been qualified). The third category is those that cannot proceed: Ripple is still actively operating and continuously making commitments, so "permanently ceasing core management efforts" is meaningless for it; tokenized securities and RWA are excluded due to contracts being tied to assets other than tokens. As for governance tokens (like UNI, AAVE), the distribution side is clean, but the bottleneck is at the last hurdle: the protocol is governed by a DAO, and who is qualified to represent the "issuer" to sign this is itself a governance issue that needs to be resolved first. Rule 500 Exclusion of State Law Applicability: The only thing that cannot be replaced by existing exemptions, and also the most likely to be cut This provision stipulates: to let each state's "blue sky laws" (the securities laws of each U.S. state) no longer apply on a state-by-state basis. U.S. securities regulation operates on a dual track of federal and state: passing the SEC does not mean it can be sold; theoretically, registration or exemption applications must still be handled separately in each state where there are investors. The federal government has created the concept of "covered security"—as long as it falls into this category, all state registration and qualification requirements are excluded. Rule 500's technical path is quite clever: it redefines "qualified purchaser"—anyone who is sold under Reg CA, and any transactions of covered investment contracts conducted by anyone other than the issuer, underwriter, or dealer are considered qualified purchasers. What qualified purchasers buy are covered securities, and thus state registration and qualification requirements are excluded.
In practical terms: a token issued under Reg CA, sold on Coinbase from A to B, does not require A, who is neither the issuer nor the underwriter or dealer, to separately handle registration or exemption applications in each state. No existing exemption can provide this. But the exemption is contingent on the issuer continuously maintaining periodic reporting (temporary reports do not count towards this determination); if reporting is interrupted, the exemption stops, and corrections must be made to restore it. For holders of this token, this represents a new, time-varying compliance status risk—the token you hold enjoys state law exemptions today, but may not tomorrow, and you may not know.
It is worth noting that this provision itself is not stable. It directly cuts the jurisdiction of state regulatory agencies, and state securities regulators are likely to push back during the comment period. The SEC is also asking in its solicitation of opinions whether to impose income, net worth, or investment asset thresholds on "qualified purchasers," and whether secondary market transactions should be included. How is it new compared to existing exemptions? For the past ninety years, U.S. companies have had only two doors to raise funds from the public.
One door is registration: submitting an S-1 registration statement, undergoing review, bearing ongoing disclosure obligations and real legal responsibilities—this is the path for U.S. IPOs. What is gained is two things: the ability to sell to anyone and free circulation after listing. The other door is to go through exemption procedures: the process is simplified, but costs must be paid elsewhere. Reg D can only sell to accredited investors, Reg CF has a one-year resale lock, and Reg A requires qualification review and auditing. If you want to reach the public and want free circulation, you have to exchange registration and disclosure for it; taking the lighter path always comes with a tether.
Reg CA is the first time this tether has been cut—only for this class of assets, and it only cuts the issuance side.
▲ Figure 4: Comparison of Reg CA with Existing Exemptions
What does this comparison table illustrate? In summary, it can be boiled down to three sentences.
First, it provides a small fundraising channel that did not exist before. Below $5 million, filing to start, no pre-review, no financial statements required, can publicly advertise, open to everyone, and tokens can be transferred once received. None of the existing exemptions can simultaneously achieve these things: Reg D 506(c) can publicly solicit but only sells to accredited investors, Reg CF is open to everyone but has a one-year lock, and Reg A can do everything but requires review and auditing. Reg CA removes these restrictions all at once.
Second, it is the first time that the exclusion of state law applicability extends to the secondary market. Previous exemptions only covered the initial sale by the issuer, but every subsequent transfer still faced state regulation. Tokens under Reg CA are different; when A sells to B on an exchange, they also enjoy the exemption. This determines whether a token can truly circulate in the U.S., rather than having to go through the process again in each state.
Third, and most fundamentally: the identity of securities now has an endpoint. Stocks, shares under Reg A, shares under Reg CF, restricted securities under Reg D—when bought, they are securities, and five years later, ten years later, or after the company sells, they are still securities, with no exit. Tokens under Reg CA are not: if they meet the conditions of Rule 400 and submit Form TR, they can no longer be securities. This is not just a "slight loosening"; this is a change of track.
II. Benefits and Drawbacks: Who Truly Benefits
The market's default answer is the project parties issuing new tokens, but we do not see it that way. First, for the two tiers of issuance exemptions that the market is discussing, the SEC estimates in its assessment of document burdens that there will be a total of 130 issuances under the two tiers each year, with 99 under the startup exemption and 31 under the fundraising exemption. This number is not a cap; it simply transfers the actual number of crypto-related issuances under existing Reg D, Reg A, and Reg CF into the new rules, the SEC estimates that the new rules will not generate any additional issuances. Second, Rule 400's safe harbor is open to issuers who have not used this rule, which is an unusual design in the exemption system, essentially declaring that its service targets already existed before the rule took effect. The SEC expects that 475 issuers will only use Rule 400's safe harbor each year, without going through any issuance exemptions, which is 3.6 times the two tiers of issuance exemptions. The SEC is more answering a qualitative question about existing tokens, not a capital formation question. This assumption may be conservative, but it indicates where the SEC's focus lies: the market is talking about ICO 2.0, while the SEC's arithmetic is about clearing existing tokens. The true beneficiaries are written in this ratio, not on the fundraising channel side. Who can truly benefit from Reg CA? The first category of beneficiaries is existing tokens and the old projects behind them. From 2013 to 2024, approximately 9,746 crypto assets were launched and traded globally (according to CoinMarketCap, excluding those that have been delisted; the SEC has indicated that this number may be low), while only 636 issuers completed crypto issuances in the U.S. using existing exemptions from 2016 to 2024 (regardless of whether they are U.S. or overseas teams). There is a huge gap in between, this gap indicates one thing: the legal status of the vast majority of tokens has never been formally addressed by any process. They have neither been confirmed nor denied, stuck in a long-term legal status with no exit, and once a token is deemed to belong to an investment contract, it is continuously bound by securities law, with no process allowing it to exit. Rule 400 provides this batch of tokens with an administrative procedural endpoint for the first time, provided that the essential managerial efforts promised by the project party at issuance have been completed or permanently ceased, and no new commitments are made. In other words, this rule addresses not how to issue tokens, but how to conclude after they are issued. The beneficiaries are not those who have not yet issued tokens, but those who have already issued and now want to shed their securities status.
The second category of beneficiaries is U.S. institutions holding existing tokens. Whether a token is a security may be just a legal label for retail investors, but for institutions, it is a question of whether they can buy it. As long as it may still be a security, a series of restrictions follow: funds must consider whether they will be deemed investment companies under the Investment Company Act, investment advisors must find qualified custodians according to securities custody rules, and auditors must ask every year how to classify this asset. Many institutions are not pessimistic; they simply cannot hold it on their books. Rule 400 turns this issue into a verifiable fact: whether the issuer has submitted Form TR can be easily checked on EDGAR. Moreover, the Investment Company Act and custody rules are enforced by the SEC itself, and the SEC's rules are just right for institutions. Pushing further, there are larger implications. Spot ETPs have expanded from Bitcoin and Ethereum to SOL and XRP, with each one having the prerequisite that the underlying asset is not treated as a security; otherwise, this vehicle is likely to be deemed an investment company. Rule 400 effectively fills this gap for other tokens. Of course, it is only a necessary condition, not a sufficient one; there also needs to be a regulated futures market, sufficient spot liquidity, and cooperation from exchanges. But before this rule, the vast majority of tokens did not even meet the threshold. Therefore, in the matter of clearing existing tokens, the sellers are the old projects, and the buyers are the institutions that have been watching from the sidelines.
The third category of beneficiaries, the quietest, is third-party professional service providers such as law firms, compliance agencies, and accounting firms. Onshore entity restructuring, auditing commitment texts, and analyzing and writing Form TR are real needs, but they are low-frequency, one-time, and highly overlapping with existing law firm businesses. They will be absorbed by professional service institutions and will not grow into an independent entrepreneurial market. This is a point that those who read Reg CA as a compliance SaaS opportunity may easily overlook. Who missed the opportunity: three categories of beneficiaries overestimated by the market However, there are three categories that the market mistakenly believes will benefit but actually do not. The first category is project parties that want to restart the U.S. primary market by issuing new tokens. Under the Reg CA rules, issuing tokens has indeed become easier; the startup exemption tier allows raising below $5 million with just a document to publicly solicit retail investors. But this $5 million is a one-time cap accumulated over four years, and there are only 99 crypto issuances at this scale in 2024. To raise more, one must enter the fundraising exemption tier, with a maximum of $75 million per year, but the cost is that it must be issued by a U.S. entity, along with ongoing reporting obligations. Moreover, the commitments written in the issuance filing will serve as the acceptance criteria for Rule 400 later; issuance may become easier, but graduation becomes more concrete. The current rules cannot support the narrative of a large-scale restart of ICO 2.0: the most groundbreaking and immediately actionable parts of Reg CA serve the tokens already in circulation, while the two exemptions for new issuances are constrained by the limits written into the text, insufficient in scale to support a market cycle.
The second category is DAOs and protocols that have already delegated decision-making to the community. The market assumes governance tokens can finally be issued compliantly, but reading through the text reveals an unspoken prerequisite: there must be an identifiable, signable, and accountable issuer. The Rule 200 startup exemption does allow a group of individuals or entities to act as the issuer, seemingly leaving a loophole for teams without corporate entities, but it immediately requires that every member of this group sign and certify on Form NOR (Notice of Issuance) and the transformation report, and each member individually and the group as a whole must meet all compliance conditions, including passing the bad actor screening under Rule 104. There is another hurdle: if they want to use the Rule 400 safe harbor to declare that the tokens are no longer securities, every member must also sign Form TR. For those protocols that did not make commitments to investors initially and whose networks are already functional, they are not even in the investment contract and do not need this rule. The real bottleneck is the intermediate group, where the team made commitments, and decision-making power has been dispersed among thousands of token holders, needing to "graduate" through Rule 400 while struggling to find signatories. The closer the project is to having an accountable entity, the easier the rules are to use; the further away, the less applicable they become.
The third category is institutions that want to do RWA and move stocks, bonds, and fund shares onto the blockchain. This category is the most thoroughly misunderstood: Reg CA, by definition, excludes tokenized securities. Rule 100 sets three requirements for covered investment contracts, one of which is that the crypto asset itself must not be a security. Tokenized U.S. stocks, tokenized government bonds, tokenized fund shares—all of these tokens are securities themselves and fall outside the scope of this rule. The proposal itself states that digital securities are more suitable for registered issuance, and this time does not change the registration rules. Therefore, Reg CA and RWA are two parallel tracks, not one. Reg CA governs projects where "the token itself is not a security, but the issuance of the token constitutes an investment contract," while tokenized securities are "the token itself is a security," which still follows the old path of registration or traditional exemptions. The other side of the rule: who will bear the uncertainty Looking back at the other side of the rule, there are three categories of true disadvantages. The first category is secondary market participants. The proposal does not touch on trading venues, brokers, custodians, and clearing, while the issuance side opens the door, the compliant secondary market lacks supporting measures. Moreover, Rule 500's exclusion of state law applicability is contingent on the issuer timely submitting periodic reports; if there is a gap, it stops, and market makers and trading venues are left with a compliance status that they cannot verify themselves. The second category is those betting on legal certainty. Reg CA only governs the SEC, not the courts. Issuers meeting the conditions of Rule 400's safe harbor may still be sued under §12(a)(1): selling unregistered securities without an effective exemption, buyers can demand refunds plus interest without proving fraud or fault, as long as they prove it is a security and not registered. It acts like a return receipt that does not ask for reasons; if the court determines that the token is still a security, the receipt becomes effective. The safe harbor provides administrative certainty, not judicial certainty. The third category is existing projects with vague commitments. Being vague was useful in the early stages; not writing specific milestones in the white paper, not providing timelines or personnel arrangements, made it easier to claim they were not securities, and previous legal interpretations have corroborated this direction. The problem is that once this path is overturned, there is no second path: the acceptance criteria for Rule 400 are based on what you promised before and whether you have completed it now, and if the project did not make any specific commitments initially, it cannot produce a verifiable list to prove it is no longer a security, instead getting stuck before the graduation line.
▲ Figure 5: Reg CA Benefit Map
So the answer changes with the standards. Issuing tokens has become easier, but only for the tier below $5 million. The old standard asked who could issue tokens, while the new standard asks who can graduate: not looking at the degree of decentralization, but at what was promised initially, whether it was verifiably completed, and whether the network is functional. This is not a benefit on the issuance side, but a settlement on the performance side.
Of course, since the current Reg CA is still a draft for public comment, there is still room for changes. There are three conditions that can falsify the judgment of "clearing existing tokens is better than ICO 2.0," and we will continue to monitor and track the formal release: first, the final version significantly relaxes the issuance side—raising the $5 million limit for the startup exemption, changing the one-time use restriction to repeatable, or deleting the four U.S. territorial requirements for the fundraising exemption; any one of these would fundamentally change the economics of new issuances, and the incremental narrative would overshadow the existing narrative; second, if the CLARITY Act passes this year, the statutory safe harbor would replace Rule 400, and Reg CA would become a supporting arrangement rather than a final rule, requiring a complete re-analysis based on the text of the CLARITY Act; third, if Rule 500 is cut in the final version—state securities regulators have historically strongly opposed the federal exclusion of state law applicability, and without it, even if tokens shed their federal securities status, secondary circulation would still have to go through blue sky laws state by state, making the legal significance of clearing existing tokens greater than the economic significance.
III. Compliance Reconstruction and Performance Constraints under Reg CA
Project Party Perspective: The focus of compliance shifts from the issuance point to the performance process For most project parties, the essence of Reg CA is not to limit fundraising amounts, but to move the compliance review gate to the early structural design and establish a long-term traceability mechanism for public statements and performance after token issuance. If they plan to use Reg CA for fundraising issuance in the future, project parties can complete the following four core dimensions of compliance reconstruction throughout the entire lifecycle of token issuance. It should be noted that Reg CA is still a proposed rule, and the following items 1 and 3 involve irreversible structural decisions; it is recommended to wait for the final version to be clarified before execution; items 2 and 4 are reversible actions that can be initiated immediately.
Separation of Financing Agreements: No longer bundling "equity + tokens" for issuance
According to Rule 100, compliant token investment contracts cannot be linked to any other assets (including equity and other derivative rights). The past industry practice of bundling equity + token warrants or SAFT in a single investment document financing model will directly lead to the project losing its qualification for compliant issuance under the Reg CA framework. If they plan to use Reg CA for fundraising issuance in the future, project parties must complete the legal structure separation during the seed round and Series A financing stages. The rules constrain the investment contract level, not the issuing entity level; the same entity can simultaneously conduct equity financing and token distribution, as long as it ensures that the two are not included in the same investment contract.
Standardizing White Paper Commitments: Clarifying the roadmap as the acceptance standard for the safe harbor
The core management effort disclosure required by Rule 103 will serve as the evidentiary basis for proving "commitments have been completed or permanently ceased" when submitting Form TR under Rule 400. The strategy in the white paper is an irreversible structural choice. While overly vague statements may avoid securities classification in the early stages, the lack of verification standards will make it extremely difficult to "graduate" later; clear statements may directly trigger securities classification initially but provide clear evidence for subsequent safe harbor proof. Therefore, before issuing tokens, it is necessary to strictly review the granularity of the statements in the white paper and roadmap, ensuring that all public commitments have verifiable engineering landing indicators; for existing commitments that are no longer intended to be fulfilled, compile and internally archive a list of commitments that will not be fulfilled, and decide whether to publicly declare them after the final version is clarified.
Decision on Entity Registration Location: Structuring to match target users and issuance channels
The Rule 300 fundraising exemption for public issuance (Tier 1/2) requires U.S. domestic entities, executives, and assets, while Rule 200 startup exemption and Reg D 506(c) private placement do not have domestic entity restrictions. If the project's commercial growth heavily relies on U.S. retail investors, it must complete onshoring (establishing a domestic entity) early (before Series A); the cost of restructuring later will be extremely high; if they go through Reg D 506(c) (with no cap and can later invoke Rule 400), traditional offshore foundations (Cayman/BVI) can still continue to apply. Therefore, during the early stage of structural design, it is necessary to clarify the target user profile and decide the structural direction based on whether it is aimed at U.S. retail investors, avoiding the blind establishment of offshore entities that lead to subsequent disqualification.
Project Operations After Token Issuance: Focus on completing functional delivery rather than decentralization
Reg CA clearly states that maintenance, updates, and funding activities after the network/application achieves functionality do not constitute core management efforts, and no new commitments should be made. This breaks the past misconception that "the team must disband or hand over code to achieve decentralization." The risk window is before functionality is achieved (commitment accumulation period); after functionality is achieved, the risk shifts to "new commitments" (new roadmaps will lead to compliance being reset). Therefore, before functionality is achieved, all external commitments should be centrally managed to avoid improvisational expansions of the roadmap in social media and AMAs; after functionality is achieved, establish a review mechanism for the release of new commitments, clearly distinguishing product announcements from issuer commitments in statements, and publicly archive performance evidence to reserve a basis for submitting Form TR under the Rule 400 safe harbor.
Investor Perspective: Track Preference, Valuation Variables, and Clause Reconstruction From the investor's perspective, the first change brought by Reg CA is the investors' preferences and choices regarding future investment projects. The most direct layer is the track: Rule 400 requires that "the core management efforts promised have been completed or permanently ceased," which naturally favors those projects where commitments can end—once a chain is launched, it is launched; once a protocol is deployed, it no longer relies on the issuer; while consumer applications and platforms that require continuous iteration inherently demand ongoing new commitments, placing them outside the graduation line for the long term; infrastructure may find it easier to navigate this path than applications. The second layer is pricing: whether a token can be depersonalized is now a variable that can be folded into valuation; with the same FDV, tokens that can be depersonalized and those that cannot should have a price difference, and "graduation clauses" will start appearing in Term Sheets—requiring project parties to cooperate in archiving performance evidence after functionality is launched and setting internal approvals for new roadmap commitments. Finally, the due diligence focus shifts—previously looking at code, team, and degree of decentralization, now it will be about "commitment archives": versions of the white paper, tweets, AMAs, Discord announcements, because under Rule 400, every word the project party has said is a liability on the balance sheet.
Secondly, the impact of Reg CA also focuses on compliance management and final exit paths for invested projects. The premise for invested projects to use Rule 400's safe harbor is that "the core management efforts promised have been completed or permanently ceased," and there are no new commitments. The performance progress of invested projects and their public statements directly determine whether the held assets can be depersonalized, which in turn directly affects asset valuation. Investors under the new rules need to evaluate existing projects according to the conditions of Rule 400's safe harbor, focusing on verifying the completion of public commitments made by the project party and the status of product functionality going live, rather than the degree of decentralization or the status of team departures; they must also control the public statements of invested projects to prevent new roadmap commitments after functionality goes live from resetting compliance; currently, they can promote already launched projects to complete performance public archiving, preserving evidence for future submission of Form TR.
Reg CA establishes a compliance framework of "issuing tokens looks at structural separation, performance looks at white paper fulfillment, exit looks at depersonalization graduation," requiring project parties to thoroughly isolate "equity and token" trading contracts in the early stages, choose the entity location based on user positioning, and strictly control public relations statements after product launch to prevent re-triggering reviews; at the same time, it requires VCs to update investment documents to constrain agreement separation and assess the feasibility of depersonalization for existing portfolios based on "roadmap fulfillment completion," reconstructing post-investment management and valuation logic by transforming regulatory uncertainty into assessable variables. Overall, this rule is less about a new round of token issuance dividends in the crypto market, and more about a system arrangement jointly promoted by regulators and leading institutions for the compliance of existing assets and risk clearing.













