CFTC Issues Developer No-Action Position: What It Means for Crypto Accounting Software
The Commodity Futures Trading Commission issued a sweeping no-action position on 17 September 2026, telling software developers it will not recommend enforcement action against them for failing to register as introducing brokers, so long as they satisfy a defined set of conditions. For accounting firms, auditors, and CFOs who rely on crypto accounting software that connects users to derivatives markets, this development redraws a compliance boundary that has been ambiguous for years.
What the CFTC Actually Said
The agency's no-action position is the regulatory mechanism by which staff signal they will not pursue a case, even where a technical argument for enforcement might exist. This latest position builds directly on an earlier, narrower letter the CFTC had issued to crypto wallet provider Phantom, which was seeking to add derivatives trading functionality to its product.
From Single-Firm Relief to an Industry Framework
The September 2026 position takes what Phantom received and converts it into a reusable framework. Any software developer who acts as a conduit between end users and a designated contract market can now seek shelter under the same logic, provided they meet the CFTC's stated criteria. Those criteria include specific disclosure obligations to users, the adoption of written policies and procedures, and adherence to other conditions the agency outlined in its position document.
Patrick Wilson, General Counsel at the Solana Policy Institute, framed the shift plainly: the earlier Phantom relief was company-specific; this new position gives the broader developer community a structural template. Builders can now design products that connect users to regulated derivatives infrastructure without automatically triggering broker registration requirements, as long as they operate within the framework's boundaries.
The Footnote That Could Matter Most
Buried in a footnote, the CFTC noted that the no-action position could extend beyond "crypto asset-related software." That single line is worth paying attention to. If the agency interprets the framework expansively in future guidance, it could eventually apply to software categories that nobody currently thinks of as falling within CFTC jurisdiction. For developers of digital asset accounting software that aggregates data from derivatives venues, that potential scope expansion is a live question, not a theoretical one.
The Regulatory Context: Why This Happened Now
The CFTC's timing is not accidental. The U.S. Senate failed in a procedural vote to advance the Clarity Act, the legislation that would have established a comprehensive federal framework for digital assets for the first time. With that legislative path closed, at least for now, both the SEC and the CFTC have signalled they will pursue their own regulatory agendas through existing authority. The no-action position is an early, visible example of that strategy in practice. For background on how the SEC and CFTC are pursuing rulemaking after the Clarity Act stalled, the trajectory has been building since the Senate vote.
The SEC moved first, releasing its own innovation exemption designed, in its own framing, to bring U.S. capital markets into the digital age. The CFTC's no-action position follows the same directional logic: use existing tools to reduce friction for compliant participants while preserving the agency's ability to act against bad actors.
The Permanence Problem and Its Accounting Implications
Industry sources were candid on the day of the announcement: no-action letters are not permanent. A future Commission can rescind them. One industry participant put the risk plainly, noting that while the expansion of the framework is welcome news, there remains real potential for a future administration to undo it. The same source suggested that wider adoption of the framework by more developers makes it politically and operationally harder to reverse, but that protection is contingent, not guaranteed.
Why Accounting Firms Should Document This Now
The impermanence of no-action relief creates a specific documentation task for accounting firms and CFOs. If a piece of crypto bookkeeping software your practice uses to pull in derivatives data or execute reporting functions relies on the CFTC's no-action position to operate without registering as an introducing broker, that reliance needs to be recorded in your risk register today. Here is why this matters in practical terms.
First, audit trail integrity. If the no-action position is later rescinded and the software vendor has to restructure its product or registration status, the data flows and reporting outputs your firm generated under the prior regime may need to be disclosed or re-examined. A clear internal record of which software was in use, under what regulatory conditions, and during which reporting periods insulates your practice from retrospective questions.
Second, vendor due diligence. The new framework requires software developers to maintain written policies and procedures and to provide specific user disclosures. When assessing any digital asset accounting software that touches derivatives markets, your due diligence checklist should now include confirmation that the vendor has adopted the CFTC's required criteria. A vendor that claims the shelter of the no-action position but has not actually implemented the required controls is not protected, and by extension neither is the firm relying on its outputs.
Third, financial statement implications. Where a reporting entity's derivatives positions are captured through software that interfaces with designated contract markets, auditors need to understand the regulatory status of that software at the balance sheet date. A software provider operating within the CFTC's framework presents a different risk profile than one that has not yet assessed its obligations. That distinction is relevant to the going concern and regulatory compliance disclosures in any crypto-exposed financial statement.
What the Framework Requires of Software Developers
The CFTC has not issued a blanket amnesty. Developers who want to rely on the no-action position must satisfy the agency's conditions. Based on the position document, those conditions include providing clear disclosures to users about the nature of the software's role, adopting internal policies and procedures that govern how the software connects users to contract markets, and staying within the functional boundaries the agency has described.
Practical Compliance Steps for Developers and Their Clients
For software developers, the immediate priority is a gap analysis: does the current product architecture and its associated documentation actually satisfy the CFTC's stated criteria? Simply deciding the framework applies is not sufficient. The conditions need to be operationalised and evidenced.
For accounting firms and CFOs who are clients of those developers, the ask is different but equally specific. Request written confirmation from your software vendor that they have assessed the no-action position and taken the steps required to operate within it. Retain that confirmation. If the vendor cannot provide it, escalate the question to your compliance or legal team before the next reporting period closes.
The CFTC's acknowledgement that the framework could expand beyond crypto asset-related software also invites a broader review. Any software in your stack that connects users to derivatives infrastructure, whether or not it is currently marketed as a crypto product, may become relevant as the agency clarifies the scope of the footnote.
Broader Market Structure Implications
The convergence of the SEC's innovation exemption and the CFTC's no-action position signals a coordinated, if informal, shift in how U.S. regulators are approaching developer liability in the digital asset space. Both agencies are choosing, for now, to reduce friction for developers who operate within disclosed and procedurally governed frameworks rather than extending registration requirements that were designed for a different market structure.
For accounting firms advising clients on digital asset strategy, that shift has a specific implication: the regulatory risk profile of software that previously sat in a grey area has improved materially, but it has not been eliminated. The grey area has become a conditional safe harbour, and the conditions are what matter. Understanding what the Clarity Act's Senate defeat means for digital asset accounting firms remains essential context for evaluating how durable these agency-level positions will prove to be.
The CFTC also signalled ambitions to convert the Phantom no-action letter into a formal rulemaking. That has not happened yet. Until it does, the current framework exists at the discretion of the sitting Commission, and any firm building business processes around it should plan for the possibility that those discretionary positions change.
Frequently Asked Questions
Does the CFTC's no-action position mean software developers are permanently exempt from broker registration?
No. A no-action position reflects staff's current intention not to recommend enforcement. It is not a rule or a statutory exemption and can be rescinded by a future Commission. Developers and the firms that use their products should treat it as conditional relief, not permanent authorisation.
Which types of software does the framework cover?
The primary focus is software that acts as a conduit between users and designated contract markets, what the CFTC describes as crypto asset-related software. A footnote in the position document suggests the framework could extend further, but that scope has not been formally confirmed. Firms should seek legal advice on whether their specific tools fall within the current boundaries.
What conditions must a software developer satisfy to rely on the no-action position?
The CFTC requires developers to provide defined disclosures to users, adopt written policies and procedures governing how their software connects users to contract markets, and operate within the functional parameters described in the position document. A developer who simply claims the relief without implementing the required controls does not have the protection the position offers.
How should accounting firms document their reliance on software covered by this framework?
Firms should record in their risk register which software products are being assessed against the no-action criteria, obtain written confirmation from vendors that they have implemented the required conditions, and note the reporting periods during which each piece of software was in use under this framework. This documentation supports both internal audit and any external review of regulatory compliance.
Does this development affect how crypto derivatives positions are reported in financial statements?
Indirectly, yes. The regulatory status of the software used to capture and report derivatives data is relevant to the auditor's assessment of the reliability of those data flows. If a software provider is operating within the CFTC's framework, that supports a more stable compliance environment for the reporting entity. If the provider has not assessed or implemented the framework's requirements, that represents an elevated operational and regulatory risk that may warrant disclosure.
Source: The Block
