On 16 July 2026, the US Securities and Exchange Commission proposed Regulation E-Delivery, a new framework that could permit electronic delivery to become the default method for certain information required under the federal securities laws.
The proposal would allow issuers, investment advisers, broker-dealers and other covered entities to deliver covered information electronically without first obtaining affirmative consent from every recipient, provided that the conditions of the proposed regulation are satisfied.
Regulation E-Delivery is currently a proposal, not a final rule. It was published in the Federal Register on 21 July 2026, and the public comment period is scheduled to close on 21 September 2026.[1][3]
At first glance, the proposal may look like a modernization initiative focused on replacing paper communications with emails, mobile notifications or online portals.
Operationally, however, electronic delivery involves more than selecting a digital channel.
A firm may need to control:
what information was approved;
which version was used;
whether the content included personal financial information;
which delivery method was permitted;
when delivery was attempted;
whether the delivery failed;
and what happened after a failure.
Electronic delivery is therefore not merely a channel decision.
It creates a chain connecting communication content, the approved version, delivery method and supporting evidence.
What would Regulation E-Delivery change?
Under the proposal, a covered entity could use electronic delivery for a recipient who has not opted out where the recipient has provided, or accepted the use of, an electronic address for receiving covered information and the firm has provided the required clear and conspicuous disclosure about electronic delivery.[2][3]
That electronic address would not necessarily be limited to an email address.
Depending on the circumstances, it could include:
an email address;
a mobile telephone number;
an inbox within a mobile application;
or an inbox within an online account or web portal.
However, an address provided solely for an unrelated purpose, such as a technical-support request, would not automatically qualify as an address provided for receiving covered information.
The disclosure would need to describe the types of covered information that would be delivered electronically and the delivery methods that might be used.
Recipients would retain the ability to opt out and receive all or some covered information in paper form, free of charge.
The proposal would cover a broad range of people and organizations with delivery obligations under the federal securities laws, including issuers, broker-dealers, investment advisers and investment companies.[1][2]
Two proposed methods of electronic delivery
Regulation E-Delivery would establish two principal delivery methods.
1. Direct delivery
Where covered information does not contain personal financial information, the covered entity could deliver it directly to the recipient’s electronic address.
For example, the information could be included:
within the body of an email;
as an email attachment;
or through another permitted electronic communication.
The communication would need to include all the covered information being delivered.
The information would also need to be presented in a widely available format suitable for electronic reading, printing and permanent electronic retention.[2][3]
2. A statement of availability
A covered entity could instead send a statement informing the recipient that covered information is available through a website, application or another permitted electronic location.
The statement-of-availability method would be required where the covered information contains personal financial information. It could also be used voluntarily for information that does not contain personal financial information.[2][3]
This distinction matters because the permitted delivery route would depend partly on the content being communicated.
Electronic delivery is therefore not simply:
“The customer prefers email, so send an email.”
The communication process may first need to determine:
what type of document is being generated;
whether it contains personal financial information;
which delivery method is permitted;
and what notification content must accompany it.
That creates a practical connection between content classification and delivery control.
Personal financial information would require protected access
The proposal defines personal financial information as information specific to a recipient’s personal financial matters, such as an account number or details relating to a particular securities transaction.
Under the proposed regulation, covered information containing personal financial information could not be sent using the direct-delivery method.
Instead, the recipient would receive a statement of availability containing a website address through which the information could be accessed.
Access to the information would need to involve a process reasonably designed to safeguard the personal financial information. This could include passwords, two-factor authentication, biometrics, cryptography or another appropriate security process.
After the recipient completes the safeguarding process, the website address would need to lead directly to the relevant covered information.[2][3]
This means that two communications that appear similar from a customer-experience perspective could require different technical journeys.
A general regulatory communication without personal financial information might potentially be included directly in an email.
An account-specific document containing personal financial information might instead require:
a controlled notification;
a secure authentication process;
access to the correct document;
and evidence connecting the notification to the information made available.
The proposal does not prescribe how firms must design their internal template or document-management systems.
It does, however, make the relationship between content type and delivery method operationally important.
The notification becomes controlled communication content
A statement of availability would not be an empty message telling the recipient that a document is waiting somewhere online.
The proposed regulation sets out content requirements for the statement itself.
It would need to include:
a prominent statement alerting the recipient that covered information is available;
identification of the covered entity and the covered information;
a brief description of the information;
an explanation, where applicable, of whether the information may require action within a fixed time frame to exercise certain rights;
and the website address where the information can be accessed.[2][3]
The statement would also need to explain that covered information made available on a website may be superseded by subsequent versions.
In addition, it would need to contain prominent information about:
requesting a paper copy free of charge;
opting out of electronic delivery;
receiving all or some covered information in paper form;
and updating the electronic address used for delivery.
The notification is therefore part of the regulatory communication, not merely an envelope wrapped around it.
Its wording, links and presentation may matter.
Operationally, this creates questions such as:
Which version of the statement of availability was approved?
Did it contain all the required information?
Was the correct website address inserted?
Did the wording accurately identify the available information?
Was the recipient told about any relevant action deadline?
When did that version become effective?
Was the correct version used for that particular delivery?
Those are communication-control questions.
Delivery timing would still apply
Electronic delivery would not remove the underlying legal deadline attached to the information.
Under the proposal, the covered information would need to be available on the relevant website no later than the date on which it must be delivered under the federal securities laws.
It would also need to be available no later than the date on which the statement of availability is delivered.[2][3]
A faster channel does not make timing controls automatic.
A firm may still need to determine:
whether the correct communication was generated before the deadline;
whether the approved version was used;
whether delivery was attempted at the correct time;
whether the correct information was linked;
and whether the information was actually available when the notification was sent.
Website availability would need to be controlled
Where the statement-of-availability method is used, the proposal would impose requirements on the website or electronic location where the covered information is made available.
If another availability period is already specified under the federal securities laws, that period would continue to apply.
Where no other period is specified:
information containing personal financial information would need to remain available for at least three years after posting;
other covered information would need to remain available for at least one year.[2][3]
The information would also need to be presented in a format suitable for:
reading online;
printing on paper;
and permanent electronic retention without charge.
The proposed one-year and three-year periods relate to how long the information must remain available through the website under Regulation E-Delivery.
They should not be confused with any separate books-and-records requirements that may apply to the firm or the underlying document.
Operationally, firms may therefore need to know:
when a document was posted;
which version was posted;
how long it was required to remain available;
whether a later version superseded it;
and whether the earlier communication could still be reconstructed after it was no longer displayed.
A successful send is not the end of the process
One of the most operationally significant parts of the proposal concerns failed electronic delivery.
Covered entities relying on Regulation E-Delivery would need to adopt and implement written policies and procedures reasonably designed to identify and remediate failed electronic delivery.[2][3]
A failure could include an invalid or inoperable electronic address identified through an email bounce-back or another detection method.
Where a firm identifies a failure, it would need to take prompt and reasonable remediation steps.
These steps could include:
obtaining a new electronic address;
delivering the affected information in paper form;
or continuing paper delivery until the recipient provides a new electronic address.
The proposing release explains that an individual failed delivery would not necessarily require the recipient to be moved permanently to paper for every future communication.
The firm could deliver the affected information in paper form while attempting to establish a valid electronic address for later deliveries.
Persistent electronic-delivery failures, however, could require the recipient to be returned more broadly to paper delivery unless an alternative electronic address is provided.[2][3]
This creates a communication journey rather than a single send event:
The communication is generated.
Delivery is attempted.
A failure is detected.
The failure is classified.
A remediation route is selected.
The communication is delivered again or moved to paper.
The result is recorded.
The SEC proposal does not say that firms must use a particular audit-log product or communication-evidence platform.
However, a delivery record containing only the words “email sent” may provide a narrow view of what actually happened.
Operationally, firms may need to connect the delivery event to:
the communication;
the approved version;
the recipient;
the electronic address;
the timestamp;
the delivery outcome;
and any subsequent remediation.
Existing paper recipients would require a controlled transition
The proposal includes a special transition process for certain recipients receiving covered information in paper form when Regulation E-Delivery becomes effective.
The transition provisions would apply where:
the recipient is currently receiving at least some covered information in paper form;
the covered entity has an electronic address for that recipient;
and the covered entity wishes to move the recipient to default electronic delivery.
Generally, the covered entity would need to send:
an initial paper notice at least 180 days before the planned transition;
and a follow-up paper notice 30 days before the transition date.[2][3]
The notices would need to explain:
the upcoming transition;
the types of information that would be delivered electronically;
the electronic address that would be used;
the planned transition date;
the recipient’s ability to opt out;
the ability to continue receiving all or some information on paper;
and the process for updating or confirming the electronic address.
An early address confirmation could change the transition timetable
The proposal contains an important exception to the normal transition timetable.
Where a recipient updates or confirms an electronic address after receiving the initial paper notice and has not opted out, the covered entity could begin electronic delivery before the normal 180-day transition date.
If the recipient updates or confirms the address after receiving the initial notice, the covered entity would not be required to send the 30-day follow-up paper notice.
The follow-up notice would also not be required where the recipient opts out after receiving the initial notice.[2][3]
This is separate from the treatment of recipients who are already receiving all covered information electronically when the regulation becomes effective.
Those recipients generally would not require the special paper transition notices because they would not be experiencing a change from paper to electronic delivery.
The transition process could therefore create several communication populations operating at the same time:
recipients already receiving electronic delivery;
new recipients beginning with default electronic delivery;
existing paper recipients awaiting transition;
recipients who confirm or update their electronic address;
recipients who opt out;
recipients for whom the firm has no qualifying electronic address;
recipients experiencing an individual delivery failure;
and recipients returned more broadly to paper after persistent failures.
Each population may require a different communication, delivery channel, effective date or process.
Without controlled templates and clearly managed effective versions, parallel journeys can quickly become difficult to reconstruct.
What the SEC proposal does not require
The proposal does not expressly require firms to use:
a specific version-control platform;
a template approval workflow;
an immutable audit log;
a particular communication-rendering system;
or a product such as CommsPliant.
It is important not to turn an operational interpretation into a regulatory claim.
The proposed regulation focuses on the conditions under which electronic delivery would satisfy applicable delivery requirements under the federal securities laws.
The connection to communication governance comes from the practical questions firms may face when implementing and evidencing those conditions.
For example:
What content was delivered?
Which version was in effect?
Did the notification include the required information?
Was the document classified correctly?
Was the permitted delivery method used?
Was delivery attempted on time?
Was the linked information available?
Did the electronic address fail?
What remediation followed?
Can the communication and its delivery context be reconstructed later?
The proposal does not prescribe one system for answering those questions.
It does make the questions difficult to ignore.
From approved content to audit evidence
Electronic delivery can create several separate technical records:
an approved template;
a generated email or PDF;
a statement of availability;
a document stored on a website;
an electronic delivery attempt;
a bounce-back;
a paper-delivery instruction;
a recipient preference change;
or a remediation decision.
Keeping these records separately is not necessarily the same as maintaining a connected communication history.
A more complete evidence chain may need to connect:
approved content → controlled version → generated communication → delivery context → delivery outcome → remediation evidence
That chain goes beyond proving that an email server processed a message.
It helps demonstrate what was communicated, which version was authorized and how the delivery process operated around it.
Where CommsPliant fits
CommsPliant provides a control layer for regulated customer communications.
Templates can be managed in a structured, version-controlled environment rather than remaining buried in application code or scattered across folders and disconnected systems.
Business and operational teams can prepare communication changes. Compliance or authorized reviewers can review and approve them. Existing systems can then generate the appropriate approved version through an integration.
CommsPliant is not the email provider, postal service or customer portal.
Those systems may remain responsible for sending the message, issuing the notification or presenting the document.
CommsPliant helps control the communication before and during generation:
which template was approved;
which version was effective;
who approved it;
what output was generated;
and what evidence connects that output to the controlled communication process.
For firms considering the implications of default electronic delivery, that distinction matters.
Delivery infrastructure can show that a delivery event occurred.
Communication governance helps show what the event contained, which version was used and why that content was authorized.
Electronic delivery does not reduce the need for control
The SEC proposal reflects a financial-services market in which investors and customers already use electronic channels as part of everyday activity.
Making electronic delivery easier could reduce paper, printing and postage costs while giving recipients faster access to important information.
But replacing paper does not remove the need for governance.
It changes the evidence firms may need to preserve.
Instead of proving only that a document entered the postal process, firms may increasingly need to demonstrate:
which digital communication was approved;
which version was generated;
which delivery method was used;
whether the information was available on time;
whether delivery succeeded;
and what happened when it did not.
Electronic delivery may be faster.
The communication control underneath it still needs to be deliberate.
Control the communication behind electronic delivery