CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

SEC Crypto FAQ: Token Buybacks and Network Upgrades

CryptaCount Editorial · · 9 min read
ACCOUNTING STANDARDS SEC Crypto FAQ: Token Buybacksand Network Upgrades

The SEC's Division of Corporation Finance updated its crypto FAQ on 25 September 2026, and the message accounting professionals and CFOs need to absorb is this: a token buyback programme, a planned network upgrade, or marketing of a protocol's existing capabilities will not, on its own, turn a crypto asset into a security. The guidance is incremental rather than transformative, but it resolves several classification questions that have been generating legal risk in financial statements and disclosure documents for the better part of three years. Alongside the SEC update, the CFTC issued its own crypto FAQ confirming that regulated firms may use blockchain infrastructure for recordkeeping. Both updates carry direct consequences for how crypto assets are classified and presented in US GAAP and IFRS-based crypto financial statements.

SEC Crypto FAQ: Token Buybacks and Network Upgrades

What the Updated FAQ Actually Says

Token buybacks on a functioning network

The SEC staff stated that announcing a buyback programme for a token associated with an already-functional crypto network would not, by itself, constitute an investment contract under the Howey test. The operative word is "functional." Where a network is live, delivering its stated services, and the buyback is a treasury mechanism rather than a fundraising pitch, staff do not regard it as the kind of managerial effort that satisfies Howey's third prong.

The caveat matters: the same buyback announced during a pre-launch phase, framed to holders as a source of returns, would receive very different treatment. Issuers pitching a buyback as a yield mechanism before their network is operational remain squarely in securities territory. Finance teams reviewing token programmes should document the network's functional status at the time any buyback is announced; that timestamp and the accompanying board narrative will be material to any subsequent securities analysis.

Network upgrades and development activity

The FAQ states that services to "secure, maintain, improve, or enhance" a functional crypto system, or to facilitate network effects, do not constitute the kind of entrepreneurial or managerial effort the Howey test requires. This matters because one of the most common arguments regulators have historically used to claim a crypto asset is a security is that holders are dependent on a core development team's ongoing work.

By drawing this line for functional networks, the SEC staff have created breathing room for protocols that continue to ship upgrades post-launch. Development roadmap disclosures, which many issuers have avoided or minimised precisely because of Howey concerns, may now be less legally fraught for networks that can credibly demonstrate operational status. That said, the FAQ is explicit that the answer "will still heavily depend on the specifics of each case," so no issuer should treat this as a blanket clearance.

Marketing and profit expectations

Marketing a network's current uses generally does not create the expectation of profit that Howey requires. Statements about future features also escape classification as long as they stop short of promoting profit potential. The line the staff are drawing is between describing what a protocol does (or will do technically) and promising that token holders will profit as a result. The former is permissible; the latter remains a red flag regardless of network status.

This distinction has immediate implications for how token issuers draft press releases, blog posts, and investor presentations. Legal and finance teams should audit existing marketing materials against this standard, particularly any language that links feature releases to token price appreciation or holder returns.

How This Builds on the March 2025 Framework

The September FAQ is not a standalone document. It extends the SEC's March 2025 guidance, which laid out the agency's general framework for applying securities laws to crypto assets. That earlier document established the analytical structure; this update fills in specific scenarios that practitioners raised in the intervening months, including the Clarity Act debate and its Senate stall. Read our analysis of how the Clarity Act's Senate failure reshapes the regulatory landscape for the broader legislative context.

Because the Clarity Act did not advance, the SEC continues to operate under existing securities law with no new statutory definition of what constitutes a "digital commodity" versus a "digital security." The FAQ is the agency's way of providing some practical clarity while Congress catches up, but its guidance is staff-level, not rulemaking. It carries persuasive weight and represents the agency's enforcement posture, but it is not binding law and can be revised.

Accounting Implications: US GAAP

Classification drives the accounting model

Whether a crypto asset is a security or not is not merely a legal question. It determines which accounting standard applies, which in turn drives measurement, disclosure, and audit risk. Under US GAAP, crypto assets that are not securities and meet the definition of indefinite-lived intangible assets fall under ASC 350-60, which requires fair-value measurement through profit or loss. Crypto assets that are securities may instead fall under ASC 320 or ASC 321, with different measurement and impairment rules depending on whether they have readily determinable fair values and whether the entity has significant influence.

The SEC's clarification that token buybacks and network upgrades on functional networks do not automatically create securities means that more tokens may credibly remain in the non-security, indefinite-lived intangible bucket. That keeps them within ASC 350-60's fair-value regime, which FASB made mandatory for entities holding qualifying crypto assets following its 2023 standard update. For CFOs, the practical impact is that the income statement will continue to reflect unrealised gains and losses on these holdings, which affects reported earnings volatility and requires clear disclosure of the measurement approach.

For a deeper dive into how treasury strategies interact with these standards, see our piece on accounting implications for bitcoin treasury companies under ASC 350-60.

Disclosure considerations for token issuers

Issuers that run buyback programmes now have some staff-level support for the position that the programme does not make their token a security, assuming the network is functional. But the accounting disclosure obligations do not disappear. Public company issuers still need to disclose the existence of buyback programmes, the treasury assets used to fund them, and the accounting treatment applied to any tokens repurchased. Repurchased tokens held in treasury are generally derecognised from the asset side and offset against equity or expensed, depending on the entity's specific facts and accounting policy elections. Those policy elections should be documented and consistently applied.

Accounting Implications: IFRS

The SEC FAQ is US-specific, but the classification question it addresses has a direct read-across for IFRS preparers, particularly multinationals reporting under IAS 38 or IFRS 9. Under IFRS, the classification of a crypto asset as a financial instrument (IFRS 9), an intangible asset (IAS 38), or inventory (IAS 2) turns in part on whether it confers rights similar to those of a security. For IFRS-based crypto financial statements, the SEC's articulation of when a token does and doesn't behave like a security can inform the entity's own classification analysis, even though IFRS has no equivalent FAQ.

The IASB's work on a dedicated crypto asset standard remains in progress. Until that standard is finalised, IFRS preparers applying IAS 38 to crypto assets held as intangibles will continue to use the cost or revaluation model. Those who can access an active market may elect revaluation, but most will default to cost less impairment. The SEC's guidance does not change IFRS measurement, but it does reduce one source of classification uncertainty that has complicated IFRS disclosures for US-listed entities reporting dual frameworks.

The CFTC's Parallel Update: On-Chain Recordkeeping

What regulated firms can now do

Separate from the SEC's FAQ, the CFTC published its own crypto FAQ on 24 September 2026. The update covers two areas relevant to accounting and operations teams. First, futures commission merchants and clearinghouses are permitted to invest customer funds in tokenised versions of previously permitted assets, subject to existing investment and custody requirements. Second, and more operationally significant, the CFTC confirmed that regulated firms can use blockchains to satisfy their recordkeeping obligations under CFTC rules.

The condition is straightforward but important: the records must be producible on demand, even if the blockchain itself or its block explorer is unavailable. This means firms cannot rely solely on a live node or a third-party explorer to access their records. They need a contingency, whether that is a local archive, a replicated off-chain copy, or a contractual guarantee from an infrastructure provider, that ensures records remain accessible during network disruptions or explorer outages.

Accounting and audit implications of on-chain records

For accounting firms auditing CFTC-regulated entities, this guidance has direct implications for audit evidence. Records maintained on-chain are, in principle, immutable and timestamped, which can strengthen the reliability of transaction records as audit evidence. However, auditors will need to evaluate whether the firm's contingency arrangements for off-chain access are adequate and whether the firm has controls over the integrity of the on-chain data, including key management and access controls over any private keys used to write records to the chain.

The CFTC's position also signals a broader regulatory comfort with blockchain infrastructure as a compliance tool, which accounting teams at regulated firms should note when evaluating their own record management systems and vendor arrangements.

SEC Crypto FAQ: Token Buybacks and Network Upgrades

Practical Steps for Accounting Firms and CFOs

Immediate review priorities

The SEC FAQ does not require any filing or formal response, but it does warrant a structured internal review for any entity that holds, issues, or advises on crypto assets in the US market. The following steps are worth prioritising in the near term.

First, map each crypto asset on the balance sheet against the functional-network test. Document whether the associated network was operational at the date the asset was acquired or when any buyback or upgrade announcement was made. That documentation will support the accounting classification and, if ever challenged, the entity's securities law position.

Second, review marketing and communications materials for any language that links network features or buyback programmes to holder profit expectations. Legal and finance should align on a review process before the next round of materials goes out.

Third, for CFTC-regulated entities, assess whether existing recordkeeping systems can satisfy the new on-chain guidance, and specifically whether the contingency arrangements for off-chain access meet the "producible on demand" standard the CFTC described.

Fourth, update the accounting policy notes in financial statements where token classifications have been reassessed in light of the FAQ. Auditors will want to see that the entity has engaged with the updated guidance and that its classifications remain supportable.

Longer-term monitoring

The FAQ is staff-level guidance, not a final rule. The SEC could revise it, and future enforcement actions will continue to refine the boundaries. Accounting firms should build a monitoring process that flags SEC and CFTC FAQ updates, enforcement actions involving the specific fact patterns the guidance addresses, and any legislative developments that might alter the underlying legal framework. Given the pace of regulatory activity in this space through 2026, a quarterly review cycle is the minimum that prudent risk management requires.

Source: The Block

USGeneralAdoptedAccounting Standards

FAQ

Does the SEC's updated FAQ mean token buyback programmes are always securities-law compliant?

No. The FAQ states that a buyback on a functional network does not automatically create an investment contract, but the analysis remains fact-specific. A buyback on a pre-launch network, or one marketed as a source of returns for holders, could still satisfy the Howey test and result in the token being treated as a security.

How does the functional-network test affect ASC 350-60 accounting?

If a token is not a security and qualifies as an indefinite-lived intangible asset, it falls under ASC 350-60, which requires fair-value measurement through profit or loss. The SEC's guidance that functional-network tokens are less likely to be securities supports keeping more tokens within this accounting model, but each entity must document its own classification analysis.

What does the CFTC's on-chain recordkeeping guidance mean for audit evidence?

Records kept on a blockchain are generally immutable and timestamped, which can strengthen their reliability as audit evidence. However, auditors will need to verify that the regulated firm has adequate contingency arrangements for producing those records if the blockchain or its explorer is unavailable, and that appropriate controls exist over the integrity and access rights of on-chain data.

Does this SEC guidance apply to IFRS preparers?

Not directly. The FAQ is a US staff-level document with no formal authority over IFRS reporting. However, IFRS preparers classifying crypto assets under IAS 38, IFRS 9, or IAS 2 can use the SEC's articulation of security-like characteristics as one input into their own classification analysis, particularly for dual-listed entities or those with US operations.

What should accounting firms do right now in response to these updates?

Firms should map client crypto holdings against the functional-network test, review marketing materials for profit-expectation language, assess CFTC-regulated clients' recordkeeping contingency arrangements, and update accounting policy disclosures where classifications have changed. Staff-level guidance warrants internal review rather than immediate regulatory filings, but the documentation created during that review is valuable audit evidence.

Related articles

Accounting Standards
IFRS Crypto Assets vs. FASB Fair Value: What the GAAP Gap Means for Digital Asset Reporting
Accounting Standards
Bitcoin Treasury Companies: Operating Business or Passive Holder?
Accounting Standards
AICPA Issues New Stablecoin and Mining Audit Guidance
Accounting Standards
AICPA Adds Stablecoin and Mining Revenue Chapters to Digital Assets Practice Aid