Feature Regulatory Compliance
Treasury's GENIUS Act Section 3 NPRM: What Stablecoin Issuers Need to Do Before January 18, 2027
Treasury published its NPRM implementing Section 3 of the GENIUS Act on August 18, 2026. The rule defines who can legally issue payment stablecoins, what authorization track applies at each asset threshold, and sets two hard deadlines: January 18, 2027 for issuers and July 18, 2028 for digital asset service providers. Comment deadline is October 19, 2026.
Table of Contents
TL;DR
- Treasury published its NPRM implementing Section 3 of the GENIUS Act on August 18, 2026 (Federal Register 2026-16796) — the rule that defines who can legally issue payment stablecoins in the US.
- January 18, 2027: unlawful to issue a payment stablecoin without authorization. July 18, 2028: unlawful for digital asset service providers to offer or facilitate unauthorized stablecoins.
- Authorization tiers split at $10 billion in outstanding issuance: below that, state supervision (if Treasury certifies); at or above, OCC or Federal Reserve.
- Comment deadline: October 19, 2026. If you’re issuing, planning to issue, or building products on top of stablecoins, this NPRM is not optional reading.
When the GENIUS Act passed in July 2025, the stablecoin industry knew the licensing framework was coming. On August 18, 2026, Treasury published the NPRM that turns that expectation into a regulatory deadline: January 18, 2027.
After that date, issuing a payment stablecoin in the United States without authorization from a designated federal or state regulator is unlawful. Not subject to enhanced oversight. Not triggering a warning letter. Unlawful — with criminal teeth attached.
The rule has a comment deadline of October 19, 2026. There are open questions in the NPRM that will affect how it applies in practice. But the core framework is clear enough that the clock is already running on authorization track decisions.
What the NPRM Does
Federal Register document 2026-16796 implements Section 3 of the GENIUS Act — the section that establishes the authorization framework for payment stablecoin issuers. It’s not a licensing rule for exchanges or custodians (that comes later, with separate rulemaking). This NPRM is focused specifically on who may create and first-transfer payment stablecoins into circulation.
The core prohibition is straightforward: beginning January 18, 2027, it is unlawful to issue a payment stablecoin unless the issuer is:
- A federally chartered national bank or trust company authorized by the OCC
- An insured depository institution authorized by the Federal Reserve
- A state-chartered institution operating under a state framework that Treasury has certified as “substantially similar” to the federal requirements
The July 18, 2028 deadline applies to the next layer down: digital asset service providers — exchanges, brokers, custodians, and other intermediaries — who after that date may not offer, sell, or facilitate transactions in payment stablecoins issued by entities that aren’t authorized under the framework.
How “Issue” Is Defined — and Why It Matters
The NPRM’s definition of “issue” is the most consequential technical provision for companies trying to determine whether they’re regulated as issuers.
Under the NPRM, “issue” means the first transfer of a payment stablecoin from the issuer to another party — the initial act that creates someone else’s right to use, transfer, convert, redeem, or repurchase the token. The person who performs that first transfer is the issuer.
This definition has practical implications:
Secondary market participants are not issuers. An exchange that buys already-issued USDC on the open market and resells it is not issuing stablecoins. The first-transfer line is the bright line between the issuer and everyone else in the chain.
Minting and wrapping are not automatically excluded. A company that takes an existing stablecoin and wraps or re-issues it — creating a new token with a new first-transfer relationship — may qualify as an issuer under the NPRM. The agency has flagged this as an open question in the rulemaking. If your product architecture involves wrapped stablecoins or bridged versions across chains, the first-transfer analysis needs to happen before January 2027.
Redemption doesn’t make you an issuer. Accepting stablecoin in exchange for fiat and retiring the token isn’t an “issue” event. This matters for treasury and payment operations that redeem stablecoin without creating new supply.
The Authorization Tiers: Threshold-Based
The NPRM creates a tiered authorization structure based on outstanding stablecoin issuance:
Under $10 Billion: State Supervision Option
Issuers with less than $10 billion in outstanding payment stablecoins may elect to operate under state supervision — provided Treasury certifies that the applicable state’s regulatory framework is “substantially similar” to the federal requirements established by the GENIUS Act and the NPRM.
This is the path that most state-licensed stablecoin operations will pursue, particularly in states like New York (which already operates BitLicense and trust company frameworks) and Wyoming (which has the Special Purpose Depository Institution charter). Whether those existing state frameworks receive Treasury certification — and on what timeline — is one of the critical open questions in the rulemaking.
For issuers currently operating under state frameworks, the practical risk is this: if Treasury doesn’t complete substantial-similarity certifications before January 18, 2027, there may be a window where even state-licensed issuers lack a clear authorization path. That’s not a theoretical concern — it’s a timeline question that deserves attention in comments and in issuer planning.
At or Above $10 Billion: Federal Oversight
Issuers at or above the $10 billion threshold in outstanding payment stablecoins are subject to direct federal oversight. The applicable regulator depends on the issuer’s charter:
- OCC: For national banks or federally chartered trust companies issuing stablecoins under a national bank or OCC special purpose charter
- Federal Reserve: For insured depository institutions (state member banks, savings associations) issuing stablecoins
The $10 billion threshold is measured on outstanding issuance — the total value of payment stablecoins the issuer has in circulation. The NPRM doesn’t fully specify the measurement mechanics (trailing period, snapshot date, frequency of recalculation), which is another area where comments can add practical value.
For the current stablecoin market, this threshold puts Tether (USDT) and Circle (USDC) — both well above $10 billion in outstanding issuance — directly in the federal oversight tier. For smaller issuers growing toward that threshold, the NPRM creates a natural compliance inflection point.
The Two Deadlines and What They Mean in Practice
January 18, 2027 — The Issuer Deadline
This is the hard cutoff for issuers. After January 18, 2027, issuing a payment stablecoin without authorization is unlawful — not just subject to enhanced scrutiny, not just something examiners might flag. The GENIUS Act includes criminal consequences for unauthorized issuance, which the NPRM’s implementing framework preserves.
That’s approximately four months from today. For a company that doesn’t yet have an authorization track — no OCC application, no Federal Reserve application, no state charter under a framework that Treasury has certified — the January deadline is not achievable. The more realistic option is to either cease new issuance before January 18, 2027, or ensure all new issuance happens through an authorized entity while the longer authorization process completes.
For issuers already operating under state frameworks in states expected to receive Treasury certification, the question is when that certification arrives — before or after January 18.
July 18, 2028 — The DASP Deadline
The digital asset service provider deadline is 18 months later than the issuer deadline. That stagger is deliberate: it gives the issuer authorization framework time to develop and gives DASPs time to assess which issuers have obtained authorization.
After July 18, 2028, a DASP that offers, facilitates, or maintains custody of payment stablecoins from unauthorized issuers faces its own liability. This creates a downstream compliance structure: even if an unauthorized issuer continues operating, DASPs who touch those stablecoins take on exposure. In practice, exchanges and custodians will need to maintain an authorized-issuer whitelist — and stablecoins that aren’t on it will face delisting pressure as 2028 approaches.
The Cross-Border Question the NPRM Leaves Open
The NPRM explicitly flags foreign issuer treatment as an open question. The practical scenario: a stablecoin issued by a non-US entity that is widely used by US persons. How does the authorization requirement apply?
The GENIUS Act’s language reaches “issuers” of payment stablecoins without limiting scope to US-chartered entities. Whether Treasury will assert jurisdiction over foreign issuers — and on what basis — is one of the more consequential questions in the rulemaking. A foreign issuer that processes a first-transfer to a US person may fall within the definition. A foreign issuer that sells through offshore intermediaries with no direct US nexus presents a harder case.
For US-based DASPs, the DASP deadline creates indirect pressure: if you’re listing a stablecoin from a foreign issuer that hasn’t obtained authorization under the US framework, you’ll face the same post-July 2028 exposure as you would for any other unauthorized issuer. The cross-border question is the issuer’s problem, but DASPs can’t ignore it.
What Your Compliance Program Needs Before October 19
The comment deadline is October 19, 2026 — six weeks away. For stablecoin issuers, that’s not just an advocacy opportunity; it’s a planning deadline. Here’s what needs to happen before then:
Determine your authorization track. If you’re currently issuing or plan to issue payment stablecoins, identify which authorization track applies: state (if you’re below $10 billion and operating in a state that’s likely to receive certification), OCC, or Federal Reserve. If you don’t know, the NPRM’s comment period is the moment to get clarity, because the January 2027 deadline won’t wait for it.
Assess your “issue” exposure. If your product architecture involves wrapping, bridging, or re-issuing existing stablecoins, conduct a first-transfer analysis under the NPRM’s definition. If the analysis is ambiguous, flag it in comments — the agency needs industry input on how these product architectures interact with the definition.
Map your DASP exposure. If you’re an exchange, custodian, or broker, identify every payment stablecoin in your product catalog. For each, determine whether the issuer is on track for authorization before January 2027. Start the conversation now about how you’ll handle stablecoins from issuers who aren’t going to make it.
Submit comments on the open questions. The NPRM is genuinely open on the state certification timeline, the $10 billion measurement mechanics, and foreign issuer treatment. Industry comments on these questions shape the final rule. The comment deadline is October 19 — participation costs time but it’s the most direct way to address the operational ambiguities before they become hard compliance problems.
For companies running new product development alongside stablecoin compliance work, the New Product Risk Assessment can structure the authorization-track analysis as part of your pre-launch review — particularly useful for products that combine stablecoin rails with payment features that trigger the first-transfer definition.
How This Connects to What Came Before
The GENIUS Act’s NPRM is the third major stablecoin compliance document in 2026. The CIP NPRM from August 2026 addresses identity verification requirements for stablecoin transactions. The AML compliance guidance from July 2026 covers FinCEN and OFAC obligations that apply once you have issuer status. And the July 2025 compliance deadline analysis covered the initial GENIUS Act implementation timeline.
The Section 3 NPRM is the foundational document — it defines who the regulated entities are. The CIP and AML requirements build on top of that definition. If you’re not an authorized issuer, you’re either stopping issuance or racing to get authorized. If you are authorized, the CIP and AML frameworks are your next compliance layer.
The Practical Bottom Line
Four months is not enough time to obtain a new bank or trust company charter. It may not be enough time to complete state licensing in states where Treasury certification hasn’t been granted. What it is enough time to do:
- Determine which authorization track you’re pursuing
- File a comment that gets your operational questions into the agency’s record
- Map your product exposure to the first-transfer definition
- Brief your board on the January 2027 deadline and what authorization gap, if any, exists
The GENIUS Act gave stablecoin issuers a clear regulatory framework after years of ambiguity. The Section 3 NPRM is the implementation of that framework. Companies that treat the January 2027 deadline as a planning horizon rather than a hard cutoff will find themselves in the same position as any regulated entity that didn’t prepare: scrambling for compliance after the window has closed.
Sources:
- Treasury Announces NPRM on Payment Stablecoin Issuer Requirements — Treasury Press Release
- Federal Register 2026-16796: Requirements Applicable to Payment Stablecoin Issuers — Federal Register
- GENIUS Act Section 3 NPRM: Key Provisions and Comment Deadline — Jones Day
- Treasury Publishes Stablecoin Issuer Licensing Rule Under GENIUS Act — Duane Morris
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
New Product Risk Assessment
Structured risk review process for new products, services, and business initiatives.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What does the Treasury's GENIUS Act Section 3 NPRM require?
What is the difference between the January 2027 and July 2028 deadlines?
Which authorization track applies to my stablecoin — state or federal?
What does 'issue' mean under the NPRM's definition?
What are the consequences of issuing a payment stablecoin without authorization after January 18, 2027?
When is the comment deadline and what open questions should stablecoin issuers raise?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
New Product Risk Assessment
Structured risk review process for new products, services, and business initiatives.
◆ Keep reading
Related posts.
Regulatory Compliance
SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test
The SEC's Doximity insider trading judgment exposes two MNPI control tests: earnings access and post-termination trading.
Sep 11, 2026
Regulatory Compliance
FinCEN Health Care Fraud Analysis: $17.5 Billion in Suspicious Activity
FinCEN's health care fraud analysis reveals $17.5B in suspicious activity. Here is how BSA teams should update monitoring and SAR controls.
Sep 10, 2026
Regulatory Compliance
The CFPB Eliminated Federal Disparate Impact. Illinois Made It State Law. What Lenders with Illinois Customers Must Do Before January 2027.
Illinois enacted SB 3777 on July 31, 2026, creating an independent state-law disparate impact standard for credit decisions under the Illinois Human Rights Act — effective January 1, 2027. The federal government moved in exactly the opposite direction three months earlier. Lenders using AI or algorithmic underwriting need to understand what changed and what it requires.
Sep 9, 2026