SEC-CFTC Taxonomy Draws a Line in the Sand: Crypto Now Has Five Flavors of Risk
A March 2026 SEC interpretation, joined by the CFTC, creates a formal token taxonomy and clarifies when crypto assets enter or exit investment contract status—while FINRA demands documented controls and the SEC reframes enforcement priorities away from registration-only cases.
In the year of our algorithm, 2026, the SEC and CFTC finally did what no one expected: they agreed on something. On March 17, they jointly issued an interpretation that carves the crypto universe into five categories—digital commodities, digital collectibles, digital tools, stablecoins, and digital securities—and specifies the precise conditions under which a non-security token might slip into or out of an investment contract [^claim_1727]. The CFTC, in a move that feels like a diplomatic treaty between warring city-states, committed to administering the Commodity Exchange Act in lockstep with the SEC’s interpretation, effectively ending the jurisdictional tug-of-war that has defined crypto regulation for a decade [^claim_1728].
For crypto-native firms, this taxonomy is the regulatory Rosetta Stone. Exchange listing standards, token issuance counsel, and custody workflows now have a formal classification system to reference. The interpretation addresses airdrops, protocol mining, protocol staking, and wrapping of non-security crypto assets—activities that previously lived in legal gray zones [^claim_1727]. The question is no longer ‘is this a security?’ but ‘under which category does this token fall, and what controls are required?’
The SEC’s enforcement posture is shifting in parallel. In its FY2025 results, the Commission reported 456 enforcement actions and $17.9 billion in monetary relief [^claim_1729]. But it explicitly flagged seven crypto firm registration-related cases and six definition-of-a-dealer cases as having identified no direct investor harm and producing no investor benefit—a tacit admission that pure-status cases were resource misallocations [^claim_1730]. That signals a pivot away from registration-only actions toward fraud, manipulation, and investor harm cases. The February 2025 launch of the Cyber and Emerging Technologies Unit, which targets misconduct involving blockchain, AI, and cybersecurity, reinforces this shift [^claim_1731].
FINRA is tightening the operational screws. On June 23, 2026, it published a Crypto Asset Activity Information Request requiring member firms to report current and planned crypto activities by July 24, 2026 [^claim_1732]. FINRA has already identified potential violations of Rule 2210 (communications), Rule 3110 (supervision), and Rule 3310 (AML compliance) in member-firm crypto activities [^claim_1733]. For broker-dealers touching spot crypto, private placements, or tokenized products, the message is clear: documented controls, surveillance, and verifiable AML processes are now the compliance baseline.
Crypto-native firms should audit their token taxonomies against the SEC-CFTC framework, ensure FINRA-required inventories are complete, and prepare for a regime where enforcement focuses on harm rather than registration status. Watch for the July 24 FINRA response deadline and subsequent examinations.
Provenance ledger
7 claims web-citedEvery claim below cites a source URL, and each URL was checked for validity before publish. The excerpt shown is the researcher's own summary of the page — it is not re-derived from the source, so it is not a verified verbatim quote. Follow the link to confirm any claim against the original. Citation markers in the text jump here.
[1] The SEC and CFTC jointly issued a March 17, 2026 interpretation that says most crypto assets are not themselves securities, provides a token taxonomy for digital commodities, digital collectibles, digital tools, stablecoins, and digital securities, and clarifies how a non-security crypto asset can enter or exit an investment contract status. web-cited
“The Commission interpretation: - Provides a coherent token taxonomy for digital commodities, digital collectibles, digital tools, stablecoins, and digital securities. - Addresses how a ‘non-security crypto asset’... may become subject to, and how it may cease to be subject to, an investment contract. - Clarifies the application of federal securities laws to airdrops, protocol mining, protocol staking, and the wrapping of a non-security crypto asset.”
This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.
[2] The March 17, 2026 SEC interpretation explicitly says the CFTC will administer the Commodity Exchange Act consistently with the SEC’s interpretation, creating a coordinated federal jurisdictional framework for crypto assets. web-cited
“The Commodity Futures Trading Commission (CFTC) joined the interpretation to provide guidance that the CFTC and its staff will administer the Commodity Exchange Act consistent with the Commission’s interpretation.”
This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.
[3] The SEC’s April 7, 2026 enforcement-results release says the Commission filed 456 enforcement actions in fiscal year 2025, including 303 standalone actions and 69 follow-on administrative proceedings, and obtained monetary-relief orders totaling $17.9 billion. web-cited
“During fiscal year 2025, the Commission filed 456 enforcement actions, including 303 standalone actions and 69 ‘follow-on’ administrative proceedings... obtaining orders for monetary relief totaling $17.9 billion.”
This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.
[4] The SEC says fiscal year 2025 included seven crypto firm registration-related cases and six definition-of-a-dealer cases, and the Commission now views those cases as having identified no direct investor harm and demonstrating a misallocation of resources. web-cited
“Together with seven crypto firm registration-related and six ‘definition of a dealer’ cases, these cases identified no direct investor harm from those violations, produced no investor benefit or protection...”
This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.
[5] The SEC says it launched the Cyber and Emerging Technologies Unit in February 2025 to complement the Crypto Task Force and to combat misconduct involving blockchain technology, AI, account takeovers, cybersecurity, and related securities transactions. web-cited
“In February 2025, the Commission announced the launch of the Cyber and Emerging Technologies Unit to complement the work of the Crypto Task Force and to protect investors by combatting misconduct as it relates to securities transactions involving blockchain technology, AI, account takeovers, cybersecurity, and other areas.”
This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.
[6] FINRA published a 2026 Crypto Asset Activity Information Request on June 23, 2026 and requires member firms to respond by July 24, 2026. web-cited
“On June 23, 2026, FINRA published the 2026 Crypto Asset Activity Information Request in FINRA Gateway, asking member firms about their current and planned crypto asset activities. FINRA requests that firms respond by July 24, 2026.”
This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.
[7] FINRA’s 2026 crypto asset oversight materials say it has identified potential Rule 2210 communications violations, Rule 3110 supervision failures, and Rule 3310 AML-program deficiencies in member-firm crypto activities. web-cited
“FINRA has identified potential violations of FINRA Rule 2210... Rule 3110... and Rule 3310 (Anti-Money Laundering Compliance Program) related to the failure by member firms to establish AML programs reasonably designed to detect and cause the reporting of suspicious transactions in crypto assets...”
This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.
Sources
- https://www.sec.gov/newsroom/press-releases/2026-30-sec-clarifies-application-federal-securities-laws-crypto-assets
- https://www.sec.gov/newsroom/press-releases/2026-34
- https://www.finra.org/crypto-asset-activity-information-request-2026
- https://www.finra.org/rules-guidance/guidance/crypto-assets-update