Here’s the comprehensive report on legal gaps and enforcement challenges in the SEC-CFTC MOU for crypto compliance. It covers nine critical areas:
- Non-binding nature and political fragility — terminable with 30 days’ notice, tied to current administration
- Token classification lifecycle gap — no mechanism for when tokens transition between security and commodity status
- DeFi and DAO enforcement void — the MOU’s “Covered Firms” framework doesn’t reach decentralized protocols
- “Super app” and alternative compliance ambiguity — endorsed conceptually but with zero defined criteria or process
- Enforcement vacuum — 60% decline in SEC crypto actions in 2025, with state enforcement expected to fill the gap
- Discretionary data sharing — robust on paper but non-mandatory, with historical cybersecurity concerns
- “Piling on” risk in parallel enforcement — coordination could broaden rather than constrain total exposure
- State enforcement and private litigation gap — the MOU doesn’t preempt state authority at all
- Congressional dependency — the deepest questions can only be durably resolved by legislation that remains stalled
Executive Summary
The March 11, 2026, Memorandum of Understanding between the SEC and CFTC represents a landmark interagency cooperation framework, but legal experts have identified significant structural gaps, enforcement vulnerabilities, and durability risks that compliance professionals must account for. While the MOU signals a meaningful shift away from jurisdictional “turf wars” toward coordinated oversight, it is a principles-based coordination agreement—not a rulebook, not legislation, and not enforceable against either agency or any third party. This report examines nine categories of gaps and challenges that legal and compliance teams should understand and plan around.
The Non-Binding Nature and Political Fragility Problem
The most fundamental gap in the MOU is structural: it creates no legally binding obligations and can be terminated by either party with just 30 days’ written notice. This is not a theoretical concern—the 2026 MOU itself supersedes the 2018 MOU, demonstrating that these frameworks are routinely replaced when leadership changes.
Both chairmen were candid about this limitation. Husch Blackwell’s legal analysis noted that “rules adopted today can be reversed tomorrow” and that “only congressional legislation can provide the durable statutory framework the industry needs”. The MOU’s life is effectively tied to the current administration: if new SEC or CFTC chairs take a different view of harmonization, the entire cooperative framework collapses. For firms making multi-year technology and compliance investments, the absence of statutory permanence is a core business risk.
The MOU’s own text reinforces this fragility. Article III(4) provides that the agreement does not “supersede any applicable laws or regulations,” does not “create any legally binding obligations,” and does not “confer upon any person the right or ability, directly or indirectly, to obtain, suppress, or exclude any information or to challenge the execution of a request for assistance”. No market participant can rely on the MOU as a legal defense or mandate either agency to follow its terms.
The Token Classification and Lifecycle Gap
Perhaps the most consequential gap for crypto compliance is the absence of a defined mechanism for classifying tokens and managing their lifecycle transitions between SEC and CFTC jurisdiction.
The core problem
A token may launch as an investment contract (a security under SEC jurisdiction) but evolve into a utility instrument or payment mechanism (potentially a commodity under CFTC oversight). Legal experts at Husch Blackwell observe that “the absence of clear transition points has created uncertainty around registration, disclosure, and ongoing compliance obligations”. One analysis from CryptoverseLawyers noted that in 2025, “a single governance token can be four things at once: a commodity (CFTC’s view), a security (SEC’s view), a derivative (both agencies agree when leverage is involved), and an enforcement target for two separate federal regulators”.
What the MOU promises vs. delivers
The MOU commits to “clarifying product definitions through joint interpretations and rulemakings”, and both chairmen have endorsed the development of a crypto-asset taxonomy that would distinguish digital commodities, digital collectibles, and digital “tools” from securities. CFTC Chairman Selig has stated that these categories should not be treated as securities “even when they are sold as part of an investment contract”.
However, the MOU provides no timeline, no specific criteria, no interim safe harbors, and no administrative process for resolving classification disputes. The taxonomy remains aspirational, and even if jointly adopted, it would still be sub-legislative guidance subject to reversal. The CLARITY Act, which would resolve this legislatively by assigning CFTC jurisdiction over digital commodities and SEC jurisdiction over investment contracts, remains delayed in Senate markup as of early 2026. A White House meeting in February 2026 failed to resolve industry deadlocks over the bill.
Compliance implication
Firms cannot yet rely on any codified classification framework. Until either the agencies issue binding joint interpretations or Congress acts, the lifecycle transition problem—when a token “morphs” from a security to a commodity or vice versa—remains unresolved and a significant source of enforcement risk.
The DeFi and DAO Enforcement Void
The MOU does not specifically address decentralized finance (DeFi) protocols, decentralized autonomous organizations (DAOs), or autonomous on-chain systems—despite these being among the fastest-growing and most legally ambiguous areas of crypto.
Jurisdictional ambiguity persists
Both agencies have acknowledged that DeFi protocols “enable trading without traditional intermediaries” and “present similar issues” to the jurisdictional overlap problem. The CFTC’s Ooki DAO case established that DAOs can be sued as unincorporated associations and that “decentralization does not preclude enforcement”—token-holder voting can create personal liability. Yet neither agency has articulated a clear regulatory framework for purely decentralized protocols.
Chairman Selig previewed the concept of “clear and unambiguous safe harbors for software developers,” including “possible innovation exemptions” for non-custodial wallets, DeFi protocols, and on-chain software. However, these safe harbors are not part of the MOU text and remain conceptual. The MOU’s language about “Covered Firms” focuses on traditional dual-registrant entities (IA/CPO, BD/FCM, etc.)—categories that do not map naturally onto permissionless, non-custodial protocol architectures.
Gap for compliance
DeFi builders face a compliance paradox: the MOU’s harmonization benefits are concentrated on registered, intermediated entities, while the platforms that most need jurisdictional clarity—decentralized exchanges, lending protocols, and autonomous market makers—receive no direct guidance from this framework.
The “Super App” and Alternative Compliance Ambiguity
The MOU’s endorsement of “alternative compliance” and “appropriately tailored and regulated super apps” is one of its most forward-looking provisions, but also one of its least defined.
What is promised
Article III(3) commits the agencies to “facilitate alternative compliance and enable a path for appropriately tailored and regulated super apps, where such approaches can achieve regulatory objectives more efficiently while preserving investor protection and market integrity”. SEC Chair Atkins has separately described a vision where “securities intermediaries should be able to offer a broad range of products and services under one roof with a single license”.
What is missing
The MOU provides no criteria for what qualifies as a “super app,” no application process, no minimum compliance conditions, and no investor protection guardrails. The concept of an “Innovation Exemption” described by Chairman Atkins—a fast-track pathway for new crypto projects to launch by complying with “principles-based conditions”—exists only in speeches, not in rule text.
Legal experts have raised concerns about potential investor protection erosion. If dually regulated firms can satisfy “similar requirements from one agency’s rulebook rather than maintaining separate compliance programs for each”, there is an inherent risk that the less protective regime becomes the effective standard. This is especially significant for retail investors who may not appreciate that a platform operating under “alternative compliance” may not provide the same protections as a fully registered broker-dealer or futures commission merchant.
Compliance implication
Firms interested in “super app” models or alternative compliance pathways should monitor for formal rulemaking or guidance, but should not build compliance programs around an unarticulated framework. Any early mover faces regulatory risk if the criteria eventually adopted differ from their assumptions.
The Enforcement Vacuum and Regulatory Whiplash
The MOU’s enforcement coordination provisions exist against a backdrop of dramatic enforcement pullback that some legal experts view as creating a dangerous interim gap.
The enforcement retreat
SEC cryptocurrency enforcement declined 60% in 2025, with only 13 actions initiated—the lowest level since 2017—and monetary penalties totaling just $142 million, less than 3% of 2024 levels. The SEC dismissed or closed high-profile enforcement actions against Coinbase, Binance, Gemini, Uniswap, OpenSea, Robinhood, Crypto.com, and Ondo Finance. The SEC has also completely removed cryptocurrency from its 2026 Examination Priorities for the first time since 2018.
Legal criticism
SEC Commissioner Crenshaw dissented from the Coinbase dismissal, warning that it “ignores 80 years of well-established law” and that “whatever the law may be tomorrow, market participants should not be able to avoid the law as it stands today”. She argued the dismissals result in “less clarity,” not more. Democratic lawmakers have alleged the enforcement retreats coincided with industry donations to the Trump campaign, raising concerns about regulatory integrity.
The Harvard Law School Forum on Corporate Governance’s 2025 enforcement review noted that case closures were “policy-oriented” decisions, and all signs indicate “this rollback will continue for the foreseeable future” with a “corresponding surge in crypto-related enforcement actions by both state enforcers and private parties”.
The gap between retreating enforcement and future rulemaking
The MOU promises that the “regrettable era of duplicative enforcement actions and conflicting remedial obligations” is over, and commits the agencies to coordinate enforcement “as practicable and as appropriate”. But the MOU does not address what happens in the interim period between the current enforcement pullback and the adoption of a clear regulatory framework. Firms that operate in this “gray zone” may face retroactive risk if political dynamics change, as statutes of limitations can extend beyond a single administration.
State-level enforcement gap
Bloomberg Law has warned that “state regulators are expected to ramp up enforcement to fill perceived gaps in US enforcement, especially on consumer protection grounds” and that “private litigants can ensnare crypto companies in lengthy and expensive litigation, especially after downturns in the crypto markets”. The MOU is a federal inter-agency agreement that does not preempt or address state regulatory authority—a significant compliance gap for firms operating nationally.
Data Sharing: Discretionary, Not Mandatory
The MOU’s data-sharing framework is robust on paper but structurally discretionary. Article IV(2) states that “all sharing of information pursuant to this MOU will be at the sole discretion of each Party”. This means neither agency can compel the other to share data, even on matters of common regulatory interest.
Historical precedent for concern
When the SEC and CFTC entered into an earlier MOU on Form PF data sharing, Commissioners Mark Uyeda and Caroline Pham issued a joint dissent raising three objections: (1) it was unnecessary for the CFTC to receive data on non-CFTC registrants; (2) broader distribution of sensitive data “increases its vulnerability to cybersecurity threats”; and (3) the MOU’s confidentiality provisions were “inadequate given the sensitivity” of the information.
The 2026 MOU’s confidentiality framework is more detailed, requiring NIST-compliant security standards, encryption, administrative and technical safeguards, and advance notice before enforcement use. However, the same structural tension exists: the more broadly data flows between agencies, the greater the cybersecurity surface area and the risk of inadvertent disclosure—particularly as both agencies build interoperable analytical tools and expand direct access to swap data repositories and security-based swap data repositories.
Compliance implication
For registrants, the practical reality is that information provided to one agency is now more likely to reach the other, but the timing, scope, and consistency of sharing remain unpredictable. Firms should assume maximal cross-agency visibility and prepare information-production strategies accordingly.
The “Piling On” Risk in Parallel Enforcement
While the MOU aims to eliminate “duplicative relief and conflicting remedial obligations”, legal history suggests that coordinated enforcement can create its own risks for market participants.
Historical pattern
A Willkie Farr analysis of joint SEC-CFTC enforcement actions found that parallel actions “pose unique risks that penalties and undertakings will extend beyond what is necessary to rectify the harm or deter future violations, particularly when it comes to monetary penalties”—a practice colloquially known as “piling on”. While the CFTC has pledged to give “dollar-for-dollar credit for disgorgement or restitution payments” in parallel actions, “the SEC has not issued a statement regarding parallel investigations,” and more recent enforcement actions (2018–2019) imposed separate penalties to each agency rather than crediting overlapping obligations.
The MOU’s enforcement provisions (Article V, Section 2) provide for consultation on “potential charges and relief, sequencing of filings, litigation strategy, and public communications”, but these are aspirational (“the agencies will endeavor”) and do not create enforceable rights for respondents. Due process protections against duplicative penalties remain a matter of each agency’s discretion, not a structural guarantee.
Compliance implication
Firms under investigation should prepare for the possibility that coordinated enforcement means broader theories of liability crossing product and market lines, even if the agencies seek to present a unified front. Defense strategies must account for the risk that coordination enhances rather than constrains the total scope of sanctions.
The State Enforcement and Private Litigation Gap
The MOU is exclusively a federal inter-agency agreement and does not address—much less preempt—state regulatory authority over digital assets.
The emerging patchwork
As federal enforcement recedes, state regulators have been staking claims in crypto markets. The North American Securities Administrators Association (NASAA) has criticized the CLARITY Act’s preemption clause, and state attorneys general and securities regulators retain independent authority to pursue fraud, consumer protection, and money transmitter enforcement. Bloomberg Law observers have warned that the current federal posture “shifts risk assessment to states” and that “state regulators are expected to ramp up enforcement to fill perceived gaps”.
For firms operating nationally, this creates a compliance landscape where federal harmonization may reduce duplicative SEC-CFTC friction while simultaneously increasing state-level fragmentation. Money transmitter laws alone can require “54 awkward conversations” with individual state regulators, and these state regimes are not touched by the MOU.
Congressional Dependency and Legislative Uncertainty
The MOU explicitly positions itself as a bridge to legislation, not a substitute for it. Both chairmen have stated that “only congressional legislation can provide the durable statutory framework the industry needs”.
The legislative landscape
Multiple bills are under consideration, but none have been enacted:
A February 2026 White House meeting failed to resolve industry deadlocks between banks and crypto firms over stablecoin provisions. The former SEC Chief Accountant has warned that the CLARITY Act as drafted is “severely deficient” and risks enabling “another FTX-type fraud”.
The gap
Until legislation passes, the MOU’s harmonization workstreams operate within existing statutory authority—authority that was designed for a pre-crypto financial system. The agencies cannot, through an MOU, redefine what constitutes a security or a commodity; they can only coordinate how they exercise existing discretion. This structural limitation means that the deepest classification and jurisdictional questions—the ones that matter most for crypto compliance—remain unresolved by the MOU and can only be durably resolved by Congress.
Dispute Resolution and Institutional Design Weaknesses
The MOU’s governance provisions, while more developed than its predecessor, contain important structural limitations that could undermine harmonization in practice.
Chairman-level resolution only
Article VII states that “issues raised by the Parties relating to administration of this MOU shall be resolved by the Chairmen of the respective Parties, or by the Chairmen’s designees”. There is no independent arbitrator, no escalation mechanism beyond the chairmen, and no process for resolving substantive policy disagreements. If the two chairmen disagree on a classification, enforcement, or examination question, the MOU offers no resolution pathway—the agencies simply revert to independent action.
Aspirational language throughout
The MOU’s operative provisions are consistently hedged with “will endeavor,” “will strive,” “as practicable and as appropriate,” and “subject to applicable law”. These formulations are standard for inter-agency MOUs but mean that virtually every cooperation commitment is qualified and non-obligatory. In a regime where the agencies have fundamentally different statutory mandates, institutional cultures, and political constituencies, aspirational language may prove insufficient when genuine policy conflicts arise over novel products or enforcement theories.
Practical Compliance Recommendations
Given these identified gaps, legal and compliance teams should consider the following actions:
- Do not treat the MOU as regulatory certainty. Build compliance programs that can withstand both the current harmonized posture and a potential reversion to independent, adversarial oversight under future leadership.
- Prepare for multi-front exposure. Federal coordination, state enforcement, and private litigation all present distinct risks. A compliance strategy focused solely on federal regulators is incomplete.
- Map token lifecycles proactively. Until binding classification guidance exists, document the basis for every product classification decision, including analysis under both securities and commodities frameworks.
- Assume cross-agency data visibility. Prepare information-production and privilege strategies on the assumption that anything shared with one federal regulator will be available to the other.
- Monitor legislative developments closely. The CLARITY Act, Senate companion bills, and GENIUS Act will materially affect every open question identified in this report. Engage in comment processes and congressional outreach where possible.
- Develop “super app” or alternative compliance proposals cautiously. The MOU signals openness, but no formal pathway exists. Any early-mover strategy should include robust fallback compliance for traditional registration categories.
- Account for retroactive risk. Statutes of limitations extend beyond any single administration. The current enforcement lull does not extinguish historical exposure, and both state regulators and private plaintiffs may fill the gap.
Bill | Status | Key Feature |
CLARITY Act (House) | Passed House July 2025; pending Senate | Defines “digital commodities” under CFTC; securities under SEC |
Digital Asset Market Clarity Act (Senate Banking) | Discussion draft, January 2026 | Comprehensive 100+ page framework; covers SEC authority over “ancillary assets” |
Digital Commodity Intermediaries Act (Senate Agriculture) | Discussion draft, January 2026 | Narrower; CFTC authority over digital commodity intermediaries |
GENIUS Act (Stablecoins) | Under review | Stablecoin reserve, yield, and issuer requirements |
Contact LawVisory to find out more.



Post Tags :
Jeffrey Smith
Jeffrey Smith, JD. is the Managing Attorney at LawVisory, specializing in SEC compliance, privacy regulation, and regulatory risk management for RIAs, broker-dealers, and fintech innovators. With over a decade of experience advising regulated entities, Jeff helps firms operationalize compliance through actionable frameworks and evidence-based readiness programs.
March 27, 2026
About Us
High-quality legal and compliance services from a global perspective without the big law firm price tag.
Newsletter Sign Up
Contact Us
+1 202-854-0515
info@lawvisory.com
1250 Connecticut Ave NW #700, Washington, DC 20036