Can Accredited Investor Checks Run On-Chain?
Yes, within limits the interpretation is careful to preserve. SEC Compliance and Disclosure Interpretation 260.40, issued 21 July 2026, confirms that in a Rule 506(c) offering of a tokenized security the required written representations may be provided programmatically through the token by means of a digital attestation. Both representations are in scope: that the purchaser is accredited, and that the minimum investment was not financed by a third party for the purpose of making the investment. What the interpretation does not do is lower any standard. It sits inside the high minimum investment safe harbour, which still requires $200,000 from a natural person and $1 million from an entity, and the issuer still owes an objective determination that its verification steps were reasonable. This guide sets out what changed, what did not, and where the automation creates new exposure.
TL;DR — Key Takeaways
- ✓What Changed: CDI 260.40, issued 21 July 2026, lets 506(c) representations be made programmatically through a tokenized security by digital attestation.
- ✓Two Representations: That the purchaser is accredited, and that the minimum investment was not third-party financed for the purpose of the investment.
- ✓What Did Not Change: The high minimum investment safe harbour stands — $200,000 for a natural person, $1 million for an entity, plus no actual knowledge to the contrary.
- ✓The Issuer Still Owes a Determination: Reasonable steps remain “an objective determination by the issuer based on the particular facts and circumstances.” The protocol does not inherit that duty.
- ✓The New Exposure: An attestation design that accepts a flawed input accepts it identically every time. Automation raises consistency in both directions.

A Small Interpretation With a Large Operational Consequence
CDI 260.40 confirms that the written representations behind a Rule 506(c) offering can be collected through the token itself rather than alongside it. Issued on 21 July 2026 by the Division of Corporation Finance, it covers two specific representations and leaves every substantive condition of the exemption untouched.
The significance is not doctrinal. Nothing about who may buy a private placement has changed, and nothing about what an issuer must conclude has changed. What has changed is that the subscription and verification process can run in one place instead of two — the offering on-chain and the paperwork beside it — which removes a reconciliation problem rather than a legal one.
Whether an issuer has taken reasonable steps to verify accredited investor status “remains an objective determination by the issuer based on the particular facts and circumstances.”
— SEC Division of Corporation Finance, CDI 260.40, 21 July 2026
That sentence is the whole guardrail. A digital attestation is a way of receiving a representation, and receiving a representation has never been the same thing as verifying a fact.
The Safe Harbour the Interpretation Sits Inside
CDI 260.40 operates within the high minimum investment framework, which permits representation-based verification only where the commitment is large enough to be evidence in itself: $200,000 for a natural person and $1 million for a legal entity. The interpretation does not lower those minimums.
| Condition | Requirement | Changed by CDI 260.40? |
|---|---|---|
| Written representations | Accredited status, and minimum not third-party financed | Form only — may now be a digital attestation |
| Minimum investment, natural person | $200,000 | No |
| Minimum investment, legal entity | $1,000,000 | No |
| Actual knowledge standard | No actual knowledge that a purchaser is not accredited or that the minimum was financed | No |
| Entities accredited through equity owners | Per-owner conditions requiring equivalent minimum obligations | No |
| Records of the verification process | Sufficient records retained through the token standard protocol | Restated for an on-chain process |
Key Insight
Only one row in that table moved, and it moved in form rather than substance. This is worth stating plainly because the interpretation has been read in places as opening 506(c) verification to automation generally, which it does not do. A tokenized offering with a $25,000 minimum gets nothing from CDI 260.40 — it is outside the safe harbour the interpretation operates within, and its issuer still needs reasonable verification steps of the ordinary kind. The interpretation is genuinely useful and genuinely narrow, and programmes that read it as broad will build the wrong thing.
The Reconciliation Problem It Removes
Before this interpretation, a tokenized 506(c) offering ran two records: the token, which knew who held what, and a subscription file, which knew who had represented what. Those records had to be kept in agreement by process, and process is where drift happens.
The failure was rarely dramatic. It looked like a holder whose representation was collected under a prior offering and assumed to carry forward, or a transfer approved against a stale eligibility list, or an audit that could not tie a specific on-chain holder to a specific signed document. None of these is a technology problem, and all of them are cheaper to prevent than to reconstruct.
Genuinely Improved
- One record instead of two, so drift has nowhere to form
- The representation is tied to the acquiring holder, not to a name in a file
- Auditability — the process leaves evidence by construction
- Subscription can complete without an out-of-band step
Unchanged
- Who qualifies as an accredited investor
- The $200,000 and $1 million minimums
- The issuer's objective determination
- Transfer restrictions after the initial sale
The right-hand column is longer than the left, which is the honest summary of this development. It removes an operational tax on tokenized private placements without moving the substantive law an inch — and the operational tax was real, which is why the interpretation matters despite its modesty. Where it fits into the wider onboarding stack is covered in RWA investor onboarding, KYC and AML.
The Exposure Automation Creates
A manual reviewer makes scattered errors; an attestation mechanism makes the same error every time. That is an improvement in consistency and a concentration of design risk, and the second half is the part that needs governing.
A flawed attestation design propagates perfectly
If the mechanism accepts a representation that does not actually cover the financing condition, it accepts it identically across every subscription in the offering. The exemption exposure is then programme-wide rather than per-investor, which changes the remediation from correcting a file to reassessing an offering.
Records must be produced, not merely be on a chain
The staff called for sufficient records of the process used through the token standard protocol. An examiner asking how a specific holder was verified needs an answer, and “it is on-chain” is a location rather than a record. The retrievable artefact is the deliverable.
Attestations do not age gracefully
Accredited status is a fact about a person at a time. An attestation made at subscription says nothing about that person two years later, and a system that displays it indefinitely invites the inference that it is current. Where eligibility must be current, the attestation needs an explicit validity treatment.
Subscription eligibility is not transfer eligibility
CDI 260.40 addresses representations at purchase. Whether a holder may receive tokens on a secondary transfer is governed by the offering's restrictions, and conflating the two is the misreading most likely to put an exemption at risk.
The third and fourth points share a root cause: an attestation is a statement about a moment, and a token persists. Any design that renders a past statement as a present status will eventually be relied on for something it does not support.
Who Should Act on This, and Who Should Not
The interpretation is worth building against only for offerings that already sit inside the high minimum framework. For everyone else it is context, not a change in requirements.
Act on it
- 506(c) offerings at $200k / $1m minimums
- Programmes issuing repeatedly to the same holders
- Issuers whose audit pain is tying holders to documents
- Platforms running subscription out of band today
Not for you
- Offerings below the safe harbour minimums
- Reg A+ and Reg CF structures
- Registered fund distribution
- Non-US offerings under local regimes
Design questions
- Does the attestation cover the financing condition?
- What record does an examiner receive?
- How is staleness represented?
- Is transfer eligibility separately enforced?
One point deserves emphasis for the middle column. An offering outside the safe harbour is not prohibited from using digital attestations — it simply does not get the safe harbour's conclusion that representations plus minimums constitute reasonable steps. Such an issuer can still collect representations on-chain and must still perform verification of the ordinary kind, which is a workflow choice rather than a compliance shortcut.
How Blockmaze Implements Attestation-Backed Eligibility
An attestation is only useful if it can be produced later, scoped to what it actually covers, and separated from the transfer rules that govern the holder afterwards. Those three properties are design decisions, not consequences of putting a representation on a chain.
Attestation Bound to Holder and Offering
A representation is recorded against the holder and the specific offering it was made for, so it cannot be read as covering a later issuance it was never given for.
Retrievable Verification Record
The steps taken are retained as a produceable record rather than as chain state an examiner is invited to reconstruct — the recordkeeping the interpretation expects.
Validity Made Explicit
Each attestation carries the date and scope of what was represented, so an expired or narrow representation reads as expired rather than as current eligibility.
Transfer Rules Enforced Separately
Eligibility at transfer is evaluated against the instrument's restrictions, not against the subscription attestation — keeping the two questions the interpretation keeps apart.
The first item is what makes an attestation reusable without becoming overbroad. A verified status that attaches to a holder and can be presented to a new offering is the efficiency issuers actually want; a status that silently satisfies conditions nobody checked against it is how an exemption is lost. The identity layer underneath this is covered in decentralized identity for compliant RWA issuance.
Moving Subscription Verification On-Chain?
Blockmaze binds each attestation to its holder and offering, keeps a produceable verification record, makes validity explicit, and enforces transfer eligibility separately.
Frequently Asked Questions
What does CDI 260.40 actually permit?
That in a Rule 506(c) offering of a tokenized security, the written representations an issuer must obtain may be provided programmatically through the token itself by means of a digital attestation. Two representations are in scope: that the purchaser is an accredited investor, and that the purchaser's minimum investment amount was not financed in whole or in part by a third party for the specific purpose of making the investment. The staff interpretation was issued on 21 July 2026 by the Division of Corporation Finance.
Does this lower the accredited investor standard?
No. CDI 260.40 changes the form the representation takes, not the substance of what must be represented or the conditions under which representations alone suffice. The interpretation sits inside the high minimum investment safe harbour, which still requires a minimum investment of $200,000 for a natural person and $1 million for a legal entity, plus the issuer having no actual knowledge of facts indicating a purchaser is not accredited or that the minimum was financed. Every one of those conditions survives.
Why do the minimum investment amounts matter so much?
Because they are what makes representation-based verification reasonable in the first place. The safe harbour's logic is that someone committing $200,000 as a natural person or $1 million as an entity is very likely accredited, so the size of the commitment does evidentiary work that a questionnaire otherwise has to do. Take the minimum away and the representation is just an assertion. This is why CDI 260.40 is narrower than it first reads: it applies to a high-minimum offering structure, not to 506(c) generally.
What does the issuer still have to do?
Make an objective determination. The staff was explicit that whether an issuer has taken reasonable steps to verify accredited investor status “remains an objective determination by the issuer based on the particular facts and circumstances.” A digital attestation is a method of collecting a representation, not a transfer of responsibility to the protocol. The issuer must also retain sufficient records of the process used through the token standard protocol — an on-chain process still has to be evidenced, and pointing at a chain is not the same as producing records.
What breaks if the attestation is wrong?
The same thing that breaks when a paper representation is wrong, with one difference in degree. If a purchaser was not accredited, the exemption is at risk for that sale, and the issuer's defence rests on whether its verification steps were reasonable. The difference on-chain is scale: an attestation mechanism that accepts a flawed input accepts it identically across every subsequent subscription, so a single design error propagates in a way a human reviewer's error does not. Automation raises consistency and raises the cost of being consistently wrong.
Does an attestation follow the investor to the secondary market?
Not by itself. CDI 260.40 addresses representations at the point of purchase in a 506(c) offering. Whether a holder remains eligible on a later transfer is a transfer-restriction question governed by the offering's terms and the securities the holder acquired, not by the attestation that supported the original sale. Treating a subscription-time attestation as continuing eligibility evidence is the most likely misreading of this interpretation, and it is the reading that would put an exemption at risk.
Related Articles
RWA Investor Onboarding: KYC and AML Process
The verification machinery a digital attestation plugs into.
Why Can't US Retail Investors Buy Tokenized Assets?
Why 506(c) is the default exemption, and what it costs in investor breadth.
Decentralized Identity for Compliant RWA Issuance
The identity layer that makes a portable attestation possible.
What Are the Four SEC Tokenization Models?
How the SEC classifies tokenized structures, and what follows from each.