# Regulation Systems Compliance and Integrity

> Briefs, arguments, decisions, and more.

URL: https://www.frixlaw.com/law-library/documents/fr%3A2014-27767

## Record

- **Collection:** Federal Register
- **Document type:** Rule
- **Published:** December 5, 2014
- **Citation:** 79 FR 72252

## Text

SECURITIES AND EXCHANGE COMMISSION
17 CFR Parts 240, 242, and 249
[Release No. 34-73639; File No. S7-01-13]
RIN 3235-AL43
Regulation Systems Compliance and Integrity

AGENCY:

Securities and Exchange Commission.

ACTION:

Final rule and form; final rule amendment; technical amendment.

SUMMARY:

The Securities and Exchange Commission (“Commission”) is adopting new Regulation Systems Compliance and Integrity (“Regulation SCI”) under the Securities Exchange Act of 1934 (“Exchange Act”) and conforming amendments to Regulation ATS under the Exchange Act. Regulation SCI will apply to certain self-regulatory organizations (including registered clearing agencies), alternative trading systems (“ATSs”), plan processors, and exempt clearing agencies (collectively, “SCI entities”), and will require these SCI entities to comply with requirements with respect to the automated systems central to the performance of their regulated activities.

DATES:

Effective date:
February 3, 2015.

Compliance date:
The applicable compliance dates are discussed in Section IV.F of this release.

FOR FURTHER INFORMATION CONTACT:

David Liu, Senior Special Counsel, Office of Market Supervision, at (312) 353-6265, Heidi Pilpel, Senior Special Counsel, Office of Market Supervision, at (202) 551-5666, Sara Hawkins, Special Counsel, Office of Market Supervision, at (202) 551-5523, Yue Ding, Special Counsel, Office of Market Supervision, at (202) 551-5842, David Garcia, Special Counsel, Office of Market Supervision, at (202) 551-5681, and Elizabeth C. Badawy, Senior Accountant, Office of Market Supervision, at (202) 551-5612, Division of Trading and Markets, Securities and Exchange Commission, 100 F Street NE., Washington, DC 20549-7010.

SUPPLEMENTARY INFORMATION:

Regulation SCI will, with regard to SCI entities, supersede and replace the Commission's current Automation Review Policy (“ARP”), established by the Commission's two policy statements, each titled “Automated Systems of Self-Regulatory Organizations,” issued in 1989 and 1991.
1

Regulation SCI also will supersede and replace aspects of those policy statements codified in Rule 301(b)(6) under the Exchange Act, applicable to significant-volume ATSs that trade NMS stocks and non-NMS stocks.
2

Regulation SCI will require SCI entities to establish written policies and procedures reasonably designed to ensure that their systems have levels of capacity, integrity, resiliency, availability, and security adequate to maintain their operational capability and promote the maintenance of fair and orderly markets, and that they operate in a manner that complies with the Exchange Act. It will also require SCI entities to mandate participation by designated members or participants in scheduled testing of the operation of their business continuity and disaster recovery plans, including backup systems, and to coordinate such testing on an industry- or sector-wide basis with other SCI entities. In addition, Regulation SCI will require SCI entities to take corrective action with respect to SCI events (defined to include systems disruptions, systems compliance issues, and systems intrusions), and notify the Commission of such events. Regulation SCI will further require SCI entities to disseminate information about certain SCI events to affected members or participants and, for certain major SCI events, to all members or participants of the SCI entity. In addition, Regulation SCI will require SCI entities to conduct a review of their systems by objective, qualified personnel at least annually, submit quarterly reports regarding completed, ongoing, and planned material changes to their SCI systems to the Commission, and maintain certain books and records. Finally, the Commission also is adopting modifications to the volume thresholds in Regulation ATS
3

for significant-volume ATSs that trade NMS stocks and non-NMS stocks, applying them to SCI ATSs (as defined below), and moving this standard from Regulation ATS to adopted Regulation SCI for these asset classes.

1

See
Securities Exchange Act Release Nos. 27445 (November 16, 1989), 54 FR 48703 (November 24, 1989) (“ARP I Release” or “ARP I”) and 29185 (May 9, 1991), 56 FR 22490 (May 15, 1991) (“ARP II Release” or “ARP II” and, together with ARP I, the “ARP Policy Statements”).

2

See
17 CFR 242.301(b)(6).
See also
Securities Exchange Act Release No. 40760 (December 8, 1998), 63 FR 70844 (December 22, 1998) (“ATS Release”).

3
17 CFR 242.300-303 (“Regulation ATS”).

Table of Contents

I. Introduction

II. Background

A. Automation Review Policy Inspection Program

B. Recent Events

III. Overview

IV. Description of Adopted Regulation SCI and Form SCI

A. Definitions Establishing the Scope of Regulation SCI—Rule 1000

1. SCI Entities

a. SCI Self-Regulatory Organization or SCI SRO

b. SCI Alternative Trading System

c. Plan Processor

d. Exempt Clearing Agency Subject to ARP

2. SCI Systems, Critical SCI Systems, and Indirect SCI Systems

a. Overview

b. SCI Systems

c. Critical SCI Systems

d. Indirect SCI Systems (Proposed as “SCI Security Systems”)

3. SCI Events

a. Systems Disruption

b. Systems Compliance Issue

c. Systems Intrusion

B. Obligations of SCI Entities—Rules 1001-1004

1. Policies and Procedures to Achieve Capacity, Integrity, Resiliency, Availability and Security—Rule 1001(a)

2. Policies and Procedures to Achieve Systems Compliance—Rule 1001(b)

3. SCI Events: Corrective Action; Commission Notification; Dissemination of Information—Rule 1002

a. Triggering Standard

b. Corrective Action—Rule 1002(a)

c. Commission Notification—Rule 1002(b)

d. Dissemination of Information—Rule 1002(c)

4. Notification of Systems Changes—Rule 1003(a)

5. SCI Review—Rule 1003(b)

6. SCI Entity Business Continuity and Disaster Recovery Plans Testing Requirements for Members or Participants—Rule 1004

C. Recordkeeping, Electronic Filing on Form SCI, and Access—Rules 1005-1007

1. Recordkeeping—Rules 1005-1007

2. Electronic Filing and Submission of Reports, Notifications, and Other Communications—Rule 1006

3. Access to the Systems of an SCI Entity

D. Form SCI

E. Other Comments Received

F. Effective Date and Compliance Dates

V. Paperwork Reduction Act

VI. Economic Analysis

VII. Regulatory Flexibility Act Certification

VIII. Statutory Authority and Text of Amendments

I. Introduction

The U.S. securities markets attract a wide variety of issuers and broad investor participation, and are essential for capital formation, job creation, and economic growth, both domestically and across the globe. The U.S. securities markets have been transformed by regulatory and related technological developments in recent years. They have, among other things, substantially enhanced the speed, capacity, efficiency, and sophistication of the trading functions that are available to

market participants.
4

At the same time, these technological advances have generated an increasing risk of operational problems with automated systems, including failures, disruptions, delays, and intrusions. Given the speed and interconnected nature of the U.S. securities markets, a seemingly minor systems problem at a single entity can quickly create losses and liability for market participants, and spread rapidly across the national market system, potentially creating widespread damage and harm to market participants, including investors.

4

See
Securities Exchange Act Release No. 61358 (January 14, 2010), 75 FR 3594, 3598 (January 21, 2010) (Concept Release on Equity Market Structure).

This transformation of the U.S. securities markets has occurred in the absence of a formal regulatory structure governing the automated systems of key market participants. Instead, for over two decades, Commission oversight of the technology of the U.S. securities markets has been conducted primarily pursuant to a voluntary set of principles articulated in the Commission's ARP Policy Statements,
5

applied through the Commission's Automation Review Policy inspection program (“ARP Inspection Program”).
6

5
While participation in the ARP Inspection Program is voluntary, the underpinnings of ARP I and ARP II are rooted in Exchange Act requirements.
See infra
notes 7-12 and accompanying text.

6

See infra
Section II.A (discussing the ARP Inspection Program).
See also supra
note 1. The ARP Inspection Program has historically been administered by the Commission's Division of Trading and Markets. In February 2014, to consolidate the inspection function of the group with the Commission's Office of Compliance Inspections and Examinations (“OCIE”), the ARP Inspection Program was transitioned to OCIE and has been renamed the Technology Controls Program (“TCP”). However, for ease of reference to the historical ARP Inspection Program, relevant portions of the SCI Proposal, and references in comment letters, this Release will continue to use the terms ARP, ARP Inspection Program, and ARP staff, unless the context otherwise requires.

Section 11A(a)(2) of the Exchange Act,
7

enacted as part of the Securities Acts Amendments of 1975 (“1975 Amendments”),
8

directs the Commission, having due regard for the public interest, the protection of investors, and the maintenance of fair and orderly markets, to use its authority under the Exchange Act to facilitate the establishment of a national market system for securities in accordance with the Congressional findings and objectives set forth in Section 11A(a)(1) of the Exchange Act.
9

Among the findings and objectives in Section 11A(a)(1) is that “[n]ew data processing and communications techniques create the opportunity for more efficient and effective market operations”
10

and “[i]t is in the public interest and appropriate for the protection of investors and the maintenance of fair and orderly markets to assure . . . the economically efficient execution of securities transactions.”
11

In addition, Sections 6(b), 15A, and 17A(b)(3) of the Exchange Act impose obligations on national securities exchanges, national securities associations, and clearing agencies, respectively, to be “so organized” and “[have] the capacity to . . . carry out the purposes of [the Exchange Act].”
12

7
15 U.S.C. 78k-1(a)(2).

8
Pub. L. 94-29, 89 Stat. 97 (1975).

9
15 U.S.C. 78k-1(a)(1).

10
Section 11A(a)(1)(B) of the Exchange Act, 15 U.S.C. 78k-1(a)(1)(B).

11
Section 11A(a)(1)(C)(i) of the Exchange Act, 15 U.S.C. 78k-1(a)(1)(C)(i).

12

See
Sections 6(b)(1), 15A(b)(2), and 17A(b)(3) of the Exchange Act, 15 U.S.C. 78f(b)(1), 78
o
-3(b)(2), 78q-1(b)(3), respectively.
See also
Section 2 of the Exchange Act, 15 U.S.C. 78b, and Section 19 of the Exchange Act, 15 U.S.C. 78s.

In March 2013, the Commission proposed Regulation Systems Compliance and Integrity (“Regulation SCI”)
13

to require certain key market participants to, among other things: (1) Have comprehensive policies and procedures in place to help ensure the robustness and resiliency of their technological systems, and also that their technological systems operate in compliance with the federal securities laws and with their own rules; and (2) provide certain notices and reports to the Commission to improve Commission oversight of securities market infrastructure. As discussed in further detail below and in the SCI Proposal, Regulation SCI was proposed to update, formalize, and expand the Commission's ARP Inspection Program, and, with respect to SCI entities, to supersede and replace the Commission's ARP Policy Statements and rules regarding systems capacity, integrity and security in Rule 301(b)(6) of Regulation ATS.
14

13
Securities Exchange Act Release No. 69077 (March 8, 2013), 78 FR 18083 (March 25, 2013) (“Proposing Release” or “SCI Proposal”).

14

See
17 CFR 242.301(b)(6) and ATS Release,
supra
note 2.

A confluence of factors contributed to the Commission's proposal of Regulation SCI and to the Commission's current determination that it is necessary and appropriate at this time to address the technological vulnerabilities, and improve Commission oversight, of the core technology of key U.S. securities markets entities, including national securities exchanges and associations, significant alternative trading systems, clearing agencies, and plan processors. These considerations include: the evolution of the markets to become significantly more dependent upon sophisticated, complex and interconnected technology; the current successes and limitations of the ARP Inspection Program; a significant number of, and lessons learned from, recent systems issues at exchanges and other trading venues,
15

increased concerns over “single points of failure” in the securities markets;
16

and the views of a wide variety of commenters received in response to the SCI Proposal.

15

See
Proposing Release,
supra
note 13, at 18085-91 for a further discussion of these developments and
infra
Section II.B (discussing recent events related to technology issues). In addition, prior to issuing the Proposing Release, in October 2012 the Commission convened a roundtable entitled “Technology and Trading: Promoting Stability in Today's Markets” (“Technology Roundtable”). The Technology Roundtable examined the relationship between the operational stability and integrity of the securities market and the ways in which market participants design, implement, and manage complex and interconnected trading technologies.
See
Securities Exchange Act Release No. 67802 (September 7, 2012), 77 FR 56697 (September 13, 2012) (File No. 4-652) and Technology Roundtable Transcript, available at:
http://www.sec.gov/news/otherwebcasts/2012/ttr100212-transcript.pdf.
A webcast of the Roundtable is available at:
www.sec.gov/news/otherwebcasts/2012/ttr100212.shtml.
As noted in the Proposing Release, the Commission believes that the information presented at the Technology Roundtable further highlighted that quality standards, testing, and improved response mechanisms are among the issues needing very thoughtful and focused attention in today's securities markets.
See
Proposing Release,
supra
note 13, at 18090-91 for further discussion of the Technology Roundtable.

16

See infra
Section IV.A.2.c (discussing single points of failure in the securities markets in conjunction with the adopted term “critical SCI system”).

The Commission received 60 comment letters on the proposal from national securities exchanges, registered securities associations, registered clearing agencies, ATSs, broker-dealers, institutional and individual investors, industry trade groups, software and technology vendors, and academics.
17

Commenters generally supported the goals of the proposal, but as further discussed below, some expressed concern about various specific elements of the proposal, and recommended certain modifications or clarifications.

17
Comments received on the proposal are available on the Commission's Web site, available at:
http://www.sec.gov/comments/s7-01-13/s70113.shtml. See
Exhibit A for a citation key to the comment letters cited in this release.

Upon request from some commenters, the Commission extended the comment period for an additional 45 days in order to give the public additional time to comment on the matters addressed by the SCI Proposal.
See
Securities Exchange Act Release No. 69606 (May 20, 2013), 78 FR 30803 (May 23, 2013).

After careful review and consideration of the comment letters,

the Commission is adopting Regulation SCI (“Rule”) and Form SCI (“Form”) with certain modifications from the SCI Proposal, as discussed below, to respond to concerns expressed by commenters and upon further consideration by the Commission of the more appropriate approach to further the goals of the national market system by strengthening the technology infrastructure of the U.S. securities markets.

II. Background

A. Automation Review Policy Inspection Program

For over two decades, the Commission's ARP Inspection Program has helped the Commission oversee the technology infrastructure of the U.S. securities markets. This voluntary information technology review program was developed by staff of the Commission to implement the Commission's ARP Policy Statements issued in 1989 and 1991.
18

Through these Policy Statements, the Commission articulated its views on the steps that SROs should take with regard to their automated systems, set forth recommendations for how SROs should conduct independent reviews, and provided that SROs should notify the Commission of material systems changes and significant systems problems.
19

In 1998, the Commission adopted Regulation ATS which, among other things, imposed by rule certain aspects of the ARP Policy Statements on significant-volume ATSs.
20

Further, Commission staff subsequently provided additional guidance regarding various aspects of the ARP Inspection Program through letters to ARP entities, including recommendations regarding reporting planned systems changes and systems issues to the Commission.
21

18

See
ARP Policy Statements,
supra
note 1. For a detailed discussion of the ARP Policy Statements,
see
Proposing Release,
supra
note 13, at 18085-86.

19

See
ARP Policy Statements,
supra
note 1.

20

See
17 CFR 242.301(b)(6) and ATS Release,
supra
note 2.

21
In June 2001, staff from the Division of Market Regulation sent a letter to the SROs and other participants in the ARP Inspection Program regarding Guidance for Systems Outage and System Change Notifications (“2001 Staff ARP Interpretive Letter”).
See
Proposing Release,
supra
note 13, at 18087, n. 35. The 2001 Staff ARP Interpretive Letter is available at:
http://www.sec.gov/divisions/marketreg/sroautomation.shtml.

Under the ARP Inspection Program, Commission staff (“ARP staff”) conducts inspections of the trading and related systems of national securities exchanges and associations, certain ATSs, clearing agencies, and plan processors (collectively “ARP entities”), attends periodic technology briefings by ARP entities, monitors planned significant system changes, and responds to reports of system failures, disruptions, and other systems problems of ARP entities. The goal of the ARP inspections is to evaluate whether an ARP entity's controls over its information technology resources in nine general areas, or information technology “domains,”
22

is consistent with ARP and industry guidelines. Such guidelines are identified by ARP staff from a variety of information technology publications that ARP staff believes reflects industry standards for securities market participants.
23

At the conclusion of an ARP inspection, ARP staff typically issues a report to the ARP entity with an assessment of the ARP entity's information technology program for its key systems, including any recommendations for improvement.
24

22
These information technology “domains” include: application controls; capacity planning; computer operations and production environment controls; contingency planning; information security and networking; audit; outsourcing; physical security; and systems development methodology. Each domain itself contains subcategories. For example, “contingency planning” includes business continuity, disaster recovery, and pandemic planning, among other things.
See id.
at 18086.

23

See id.
at 18086-87.

24
In addition, Commission staff conducts inspections of SROs, as part of the Commission's oversight of them. Unlike ARP inspections, however, which focus on information technology controls, such Commission staff primarily conducts risk-based examinations of securities exchanges, FINRA, and other SROs to evaluate whether they and their member firms are complying with the Exchange Act, the rules thereunder, and SRO rules, as applicable. As part of the Commission's oversight of the SROs, Commission staff also reviews systems compliance issues reported to Commission staff. The information gained from the Commission staff review of reported systems compliance issues helps to inform its examination risk-assessments for SROs.
See id.
at 18087.

Because the ARP Inspection Program was established pursuant to Commission policy statements rather than Commission rules, participation in and compliance with the ARP Inspection Program by ARP entities is voluntary. As such, despite its general success in working with SROs to improve their automated systems, there are certain limitations with the ARP Inspection Program. In particular, because of the voluntary nature of the ARP Inspection Program, the Commission is constrained in its ability to assure compliance with ARP standards. The Government Accountability Office (“GAO”) has identified the voluntary nature of the ARP Inspection Program as a limitation and recommended that the Commission make compliance with ARP guidelines mandatory.
25

In addition, as more fully discussed in the SCI Proposal, the evolution of the U.S. securities markets in recent years to become almost entirely electronic and highly dependent on sophisticated trading and other technology, including complex and interconnected routing, market data, regulatory, surveillance and other systems, has posed challenges for the ARP Inspection Program.
26

25

See
GAO, Financial Market Preparedness: Improvements Made, but More Action Needed to Prepare for Wide-Scale Disasters, Report No. GAO-04-984 (September 27, 2004). GAO cited instances in which the GAO believed that entities participating in the ARP Inspection Program failed to adequately address or implement ARP staff recommendations as the reasoning behind its recommendation to make compliance with ARP guidelines mandatory.

26

See
Proposing Release,
supra
note 13, at 18087-89.

B. Recent Events

A series of high-profile recent events involving systems-related issues further highlights the need for market participants to bolster the operational integrity of their automated systems in this area. In the SCI Proposal, the Commission identified several systems problems experienced by SROs and ATSs that garnered significant public attention and illustrated the types and risks of systems issues affecting today's markets.
27

Since Regulation SCI's proposal in March 2013, additional systems problems among market participants have occurred, further underscoring the importance of bolstering the robustness of U.S. market infrastructure to help ensure its stability, integrity, and resiliency.

27

See id.
at 18089-90. The Proposing Release also discussed the effects of Superstorm Sandy on the U.S. securities exchanges, noting certain weaknesses in business continuity and disaster recovery planning that were highlighted by the event.
See id.
at 18091.

In particular, since Regulation SCI's proposal, disruptions have continued to occur across a variety of market participants. For example, with respect to the options markets, some exchanges have delayed the opening of trading,
28

halted trading,
29

or experienced other errors as a result of systems issues,
30

and trading in options was halted due to a systems issue with the securities information processor for options market information.
31

Systems issues have also impacted consolidated market data in the equities markets, including one incident that led to a trading halt in all securities listed on a particular exchange.
32

Systems issues have also affected trading off of national securities exchanges, including an incident where FINRA halted trading in all OTC equity securities due to a lack of availability of quotation information resulting from a connectivity issue experienced by an ATS.
33

Systems issues during this time have not been limited to systems disruptions, but have also included allegations of systems compliance issues.
34

28
On April 25, 2013, the Chicago Board Options Exchange, Inc. (“CBOE”) delayed the opening of trading on its exchange for over three hours due to what CBOE described as an internal “software bug.”
See
CBOE Information Circular IC13-036, April 29, 2013, available at:
http://www.cboe.com/publish/InfoCir/IC13-036.pdf.
During this time, while trading in many products was able to continue on the other options exchanges, trading was completely halted for those products that are singly-listed on CBOE, including options on the S&P 500 Index and the CBOE Volatility Index (“VIX”). Trading was able to resume by approximately 1:00 p.m. ET, though some residual systems problems continued. Specifically, certain auction mechanisms were unavailable for the remainder of the day and some of the trade data from April 25 was erroneously re-transmitted to OCC on April 26.
See id.
and CBOE System Status notifications for

April 25, 2013, available at:
http://www.cboe.com/aboutcboe/systemstatus/search.aspx.
CBOE subsequently reported that preliminary staging work related to a planned reconfiguration of CBOE's systems in preparation for extended trading hours on the CBOE Futures Exchange and CBOE options exchange “exposed and triggered a design flaw in the existing messaging infrastructure configuration.”
See
CBOE Information Circular IC13-036, April 29, 2013, available at:
http://www.cboe.com/publish/InfoCir/IC13-036.pdf.

29
On November 1, 2013, Nasdaq halted trading on the Nasdaq Options Market (“NOM”) for more than five hours through the close of the trading day. Nasdaq stated that the halt was a result of “a significant increase in order entries which inhibited the system's ability to accept orders and disseminate quotes on a subset of symbols.” As Nasdaq stated, Nasdaq determined that it was in the best interest of market participants and investors to cancel all orders on the NOM book and continue the market halt through the close.
See
Nasdaq Market System Status Updates for November 1, 2013, available at:
https://www.nasdaqtrader.com/Trader.aspx?id=MarketSystemStatusSearch.

30
On April 29, 2014, NYSE Arca and NYSE Amex Options experienced a systems issue that resulted in numerous complex orders booking at incorrect prices. In some cases, this resulted in erroneous fill reports, all of which were subsequently nullified.
See
Trader Update to All NYSE Amex Options and NYSE Arca Options Participants, “Erroneous Complex Order Executions,” dated April 29, 2014, available at:
http://www1.nyse.com/pdfs/2014_04_29_NYSE_Amex_and_Arca_Options_Erroneous_Complex_Order_Executions.pdf.

31
On September 16, 2013, options market trading was halted for approximately 20 minutes due to a systems issue with the Options Price Reporting Authority (“OPRA”), the securities information processor for options market information that disseminates option quotation and last sale information to market data vendors. OPRA reported that it experienced problems processing quotes as a result of a software issue originating from a limited rollout of certain software upgrades.
See
Notice to All OPRA Market Data Recipients from OPRA, LLC, dated September 18, 2013, available at:
http://www.opradata.com/specs/16-sept-2013-opra-outage.pdf.

32
On August 22, 2013, the NASDAQ Stock Market LLC (“Nasdaq”) halted trading in all Nasdaq-listed securities for more than three hours after the Nasdaq UTP Securities Information Processor (“SIP”), the single source of consolidated market data for Nasdaq-listed securities, was unable to process quotes from exchanges for dissemination to the public. According to Nasdaq, a sequence of events created a spike in message traffic volume into the SIP exceeding the SIP's capacity and causing the system to fail. Nasdaq cited “more than 20 connect and disconnect sequences from NYSE Arca” and a “stream of quotes for inaccurate symbols from NYSE Arca” as events contributing to the systems problem. Nasdaq noted that the stream of messages, which was 26 times greater than usual activity, degraded the system and exceeded its capacity, ultimately resulting in the failure. Nasdaq stated that these events exposed a flaw in the SIP's software code which prevented a successful failover to the backup system.
See
“NASDAQ OMX Provides Updates on Events of August 22, 2013,” by NASDAQ OMX (August 29, 2013), available at:
http://www.nasdaqomx.com/newsroom/pressreleases/pressrelease?messageId=1204807&displayLanguage=en;
and Nasdaq Market System Status notifications for August 22, 2013, available at:
https://www.nasdaqtrader.com/Trader.aspx?id=MarketSystemStatusSearch.

Nasdaq experienced another outage related to the SIP on September 4, 2013. This incident lasted only several minutes and affected only a subset of Nasdaq-listed securities.
See
“NASDAQ OMX Issues Statement on the Securities Information Processor,” by NASDAQ OMX (September 4, 2013), available at:
http://ir.nasdaqomx.com/releasedetail.cfm?ReleaseID=788700.

The SIP consolidates quotation information and transaction reports from market centers and disseminates such consolidated information to market participants pursuant to the Commission-approved Joint Self-Regulatory Organization Plan Governing the Collection, Consolidation and Dissemination of Quotation and Transaction Information for Nasdaq-Listed Securities Traded on Exchanges on an Unlisted Trading Privilege Basis, available at:
http://www.utpplan.com/. See generally
Rule 608 of Regulation NMS, 17 CFR 242.608 (“Filing and amendment of national market system plans”).

More recently, on October 30, 2014, according to the NYSE, a network hardware failure impacted the Consolidated Tape System, Consolidated Quote System, and Options Price Reporting Authority data feeds at the primary data center. Exchanges experienced issues publishing and receiving trades and quotes as a result. After investigation of the issue, the Securities Industry Automation Corporation (“SIAC”) (the processor for the affected data feeds) switched over to the secondary data center for these data feeds and normal processing subsequently resumed. The exchanges then connected to the secondary data center as provided for in SIAC's business continuity plan.
See
“Service Advisory—CTA Update,” by NYSE (October 30, 2014), available at:
https://markets.nyx.com/nyse/market-status/view/13467
and “NMS SIP market wide issue,” by NYSE (October 30, 2014), available at:
https://markets.nyx.com/nyse/market-status/view/13465.

33
On November 7, 2013, FINRA halted trading for over 3
1/2
hours in all OTC equity securities due to a lack of availability of quotation information resulting from a connectivity issue experienced by OTC Markets Group Inc.'s OTC Link ATS.
See
“Market-Wide Quotation and Trading Halt for all OTC Equity Securities,” FINRA Uniform Practice Advisory, UPC #47-13, November 7, 2013, available at:
http://www.finra.org/web/groups/industry/@ip/@comp/@mt/documents/upcnotices/p381590.pdf;
“Quotation and Trading Halt for OTC Equity Securities,” FINRA Uniform Practice Advisory, UPC #48-13, November 7, 2013, available at:
http://www.finra.org/web/groups/industry/@ip/@comp/@mt/documents/upcnotices/p381593.pdf;
“OTC Markets Group Issues Statement on OTC Link® ATS Trading on November 7, 2013,” OTC Disclosure & News Service, November 7, 2013, available at:
http://www.otcmarkets.com/stock/OTCM/news/OTC-Markets-Group-Issues-Statement-on-OTC-Linkreg-ATS-Trading-on-November-7-2013?id=71144.
OTC Markets Group subsequently reported that a network outage at one of its core network providers caused the lack of connectivity to its primary data center in New Jersey.
See
“OTC Markets Group Issues Statement on OTC Link® ATS Trading on November 7, 2013,” OTC Disclosure & News Service, November 7, 2013, available at:
http://www.otcmarkets.com/stock/OTCM/news/OTC-Markets-Group-Issues-Statement-on-OTC-Linkreg-ATS-Trading-on-November-7-2013?id=71144.

34
For example, in June 2013, the Commission charged CBOE and its affiliate (C2 Options Exchange, Incorporated (“C2”)) for various systemic breakdowns in their regulatory and compliance responsibilities as self-regulatory organizations, including failure to enforce the federal securities laws and Commission rules.
See
Securities Exchange Act Release No. 69726, In the Matter of Chicago Board Options Exchange, Incorporated and C2 Options Exchange, Incorporated (settled action: June 11, 2013), available at:
http://www.sec.gov/litigation/admin/2013/34-69726.pdf
(“CBOE Order”). CBOE and C2 consented to an Order Instituting Administrative and Cease-and-Desist Proceedings Pursuant to Sections 19(h) and 21C of the Securities Exchange Act of 1934, Making Findings, and Imposing Sanctions and a Cease-and-Desist Order. In the CBOE Order, among other charges, the Commission stated that “CBOE's automated surveillance programs for manually handled trades were ineffective” and that “CBOE failed to maintain a reliable or accurate audit trail of orders” on its trading facility.
See id.
at 11, 13.

In addition, in May 2014, the Commission sanctioned the New York Stock Exchange LLC (“NYSE”) and two of its affiliated exchanges (NYSE Arca, Inc. (“NYSE Arca”), NYSE MKT LLC (“NYSE MKT”)) for alleged failure to comply with their responsibilities as self-regulatory organizations to conduct their business operations in accordance with Commission-approved exchange rules and the federal securities laws.
See
Securities Exchange Act Release No. 72065, In the Matter of New York Stock Exchange LLC, NYSE Arca, Inc., NYSE MKT LLC, and Archipelago Securities, L.L.C. (settled action: May 1, 2014), available at:
http://www.sec.gov/litigation/admin/2014/34-72065.pdf
(“NYSE Order”). NYSE, NYSE Arca, NYSE MKT, and Archipelago Securities consented to an Order Instituting Administrative and Cease-and-Desist Proceedings Pursuant to Sections 19(h) and 21C of the Securities Exchange Act of 1934, Making Findings, and Imposing Sanctions and a Cease-and-Desist Order. In the NYSE Order, the Commission cited various instances of NYSE systems not operating in compliance with their effective rules, such as NYSE's block trading facility not functioning in accordance with applicable rules; NYSE distributing an automated feed of closing order imbalance information to its floor brokers at an earlier time than specified in NYSE rules; and NYSE failing to execute certain orders in locked markets contrary to exchange rules.
See id.
In the NYSE Order, the Commission stated that the exchanges “lacked comprehensive and consistently-applied policies and procedures for . . . evaluating whether business operations were being conducted fully in accordance with existing exchange rules and the federal securities laws.”
Id.
at 3.

Systems issues are not unique to the U.S. securities markets, with similar incidents occurring in the U.S. commodities markets as well as foreign markets.
35

However, the Commission

believes that it is critical that key U.S. securities market participants bolster their operational integrity to prevent, to the extent reasonably possible, these types of events, which can not only lead to tangible monetary losses,
36

but which commenters believe to have the potential to reduce investor confidence in the U.S. markets.
37

35

See, e.g.,
Jacob Bunge, Bradley Hope, and Leslie Josephs, “Technical Glitch Hits CME Trading,” Wall St. J., April 8, 2014; Jeremy Grant, “Glitch Delays Singapore Derivative Trade,” Fin. Times, April 9, 2013; Tamsyn Parker, “NZX Trading

Resumes After Technical Glitch,” The New Zealand Herald, July 1, 2013; Matt Clinch, “Flash Crash: Israel Stocks Hit by Typo,” CNBC.com, available at:
http://www.cnbc.com/id/100986999;
and Ksenia Galouchko, “Moscow Exchange Halts Derivatives Trading for Almost an Hour,” Bloomberg, November 13, 2013.

36

See, e.g.,
Proposing Release,
supra
note 13 (discussing systems issues affecting the initial public offerings (“IPO”) of BATS Global Markets, Inc. and Facebook, Inc.). In a rule change approved by the Commission in March 2013, Nasdaq implemented a $62 million accommodation program to compensate certain members for their losses in connection with the Facebook IPO. Securities Exchange Act Release No. 69216 (March 22, 2013), 78 FR 19040 (March 28, 2013). In its quarterly earnings announcement for the second quarter of 2013, UBS reported a $356 million loss tied to Facebook's IPO, while The Knight Capital Group and Citadel Investment Group claimed losses of $30 million to $35 million and Citigroup cited losses close to $20 million.
See
Michael J. De La Merced, “Behind the Huge Facebook Loss at UBS,” N.Y. Times, July 21, 2012.
See also
Angel Letter at 15 (stating that catastrophic failures in exchange systems are extremely costly in terms of direct losses to participants and result in reduced investor confidence in markets); and Better Markets Letter at 2 (citing to the systems related problems at Knight Capital, Direct Edge, BATS, and during the Facebook IPO that resulted in investor or company losses).

37

See, e.g.,
Angel2 Letter at 2; Sungard Letter at 2; Better Markets Letter at 2; Leuchtkafer Letter at 3; FSI Letter at 3; and Angel Letter at 10, 15.

The SCI Proposal also noted that the risks associated with cybersecurity, and how to protect against systems intrusions, are increasingly of concern to all types of entities.
38

On March 27, 2014, the Commission conducted a Cybersecurity Roundtable (“Cybersecurity Roundtable”).
39

The Cybersecurity Roundtable addressed the cybersecurity landscape and cybersecurity issues faced by participants in the financial markets today, including exchanges, broker-dealers, investment advisers, transfer agents and public companies.
40

Panelists discussed, among other topics, the scope and nature of cybersecurity threats to the financial industry; how market participants can effectively manage cybersecurity threats, including public and private sector coordination efforts and information sharing; the role that government should play to promote cybersecurity in the financial markets and market infrastructure; cybersecurity disclosure issues faced by public companies; and the identification of appropriate best practices and standards with regard to cybersecurity. Although the views of panelists varied, many emphasized the significant risk that cybersecurity attacks pose to the financial markets and market infrastructure today and the need to effectively manage that risk through measures such as testing, risk assessments, adoption of consistent best practices and standards, and information sharing.

38

See
Proposing Release,
supra
note 13, at 18089-90.

39

See
Securities Exchange Act Release No. 71742 (March 19, 2014), 79 FR 16071 (March 24, 2014) (File No. 4-673). A webcast of the Cybersecurity Roundtable is available at:
http://www.sec.gov/news/otherwebcasts/2014/cybersecurity-roundtable-032614.shtml.

40
The first panel discussed the cybersecurity landscape, and panelists included: Cyrus Amir-Mokri, Assistant Secretary for Financial Institutions, Department of the Treasury; Mary E. Galligan, Director, Cyber Risk Services, Deloitte and Touche LLP; Craig Mundie, Member, President's Council of Advisors on Science and Technology; Senior Advisor to the Chief Executive Officer, Microsoft Corporation; Javier Ortiz, Vice President, Strategy and Global Head of Government Affairs, TaaSera, Inc.; Andy Roth, Partner and Co-Chair, Global Privacy and Security Group, Dentons US LLP; Ari Schwartz, Acting Senior Director for Cybersecurity Programs, National Security Council, The White House; Adam Sedgewick, Senior Information Technology Policy Advisor, national Institute of Standards and Technology; and Larry Zelvin, Director, National Cybersecurity and Communications Integration Center, U.S. Department of Homeland Security.

The second panel discussed public company disclosure of cybersecurity risks and incidents, and panelists included: Peter Beshar, Executive Vice President and General Counsel, Marsh & McLennan Companies, Inc.; David Burg, Global and U.S. Advisor Cyber Security Leader, PricewaterhouseCoopers LLP; Roberta Karmel, Centennial Professor of Law, Brooklyn Law School; Jonas Kron, Senior Vice President, Director of Shareholder Advocacy, Trillum Asset Management LLC; Douglas Meal, Partner, Ropes & Gray LLP; and Leslie T. Thornton, Vice President and General Counsel, WGL Holdings, Inc. and Washington Gas Light Company.

The third panel addressed cybersecurity issues faced by the securities markets, and panelists included: Mark G. Clancy, Managing Director and Corporate Information Security Officer, The Depository Trust and Clearing Corporation; Mark Graff, Chief Information Security Officer, Nasdaq OMX; Todd Furney, Vice President, Systems Security, Chicago Board Options Exchange; Katheryn Rosen, Deputy Assistant Secretary, Office of Financial Institutions Policy, Department of the Treasury; Thomas Sinnott, Managing Director, Global Information Security, CME Group; and Aaron Weissenfluh, Chief Information Security Officer, BATS Global Markets, Inc.

The final panel discussed how broker-dealers, investment advisers, and transfer agents address cybersecurity issues, and panelists included: John Denning, Senior Vice President, Operational Policy Integration, Development and Strategy, Bank of America/Merrill Lynch; Jimmie H. Lenz, Senior Vice President, Chief Risk and Credit Officer, Wells Fargo Advisors LLC; Mark R. Manley, Senior Vice President, Deputy General Counsel and Chief Compliance Officer, AllianceBernstein L.P.; Marcus Prendergast, Director and Corporate Information Security Officer, ITG; Karl Schimmeck, Managing Director, Financial Services Operations, Securities Industry and Financial Markets Association; Daniel M. Sibears, Executive Vice President, Regulatory Operations/Shared Services, FINRA; John Reed Stark, Managing Director, Stroz Friedberg; Craig Thomas, Chief Information Security Officer, Computershare; and David G. Tittsworth, Executive Director and Executive Vice President, Investment Adviser Association.

III. Overview

The Commission acknowledges that the nature of technology and the level of sophistication and automation of current market systems prevent any measure, regulatory or otherwise, from completely eliminating all systems disruptions, intrusions, or other systems issues.
41

However, given the issues outlined above, the Commission believes that the adoption of, and compliance by SCI entities with Regulation SCI, with the modifications from the SCI Proposal as discussed below, will advance the goals of the national market system by enhancing the capacity, integrity, resiliency, availability, and security of the automated systems of entities important to the functioning of the U.S. securities markets, as well as reinforce the requirement that such systems operate in compliance with the Exchange Act and rules and regulations thereunder, thus strengthening the infrastructure of the U.S. securities markets and improving its resilience when technological issues arise. In this respect, Regulation SCI establishes an updated and formalized regulatory framework, thereby helping to ensure more effective Commission oversight of such systems.

41

See, e.g.,
October 2, 2012 remarks by Dr. Nancy Leveson, Professor of Aeronautics and Astronautics and Professor of Engineering Systems, MIT, Technology Roundtable (stating, for example, that “it is impossible to build totally secure software systems” and “we've learned that we cannot build an unsinkable ship and cannot build unfailable software”), available at:
http://www.sec.gov/news/otherwebcasts/2012/ttr100212-transcript.pdf.

As proposed, Regulation SCI would have applied to “SCI entities” (estimated in the SCI Proposal to be 44 entities), a term which would have included all self-regulatory organizations (excluding security futures exchanges), ATSs that exceed specified volume thresholds, plan processors for market data NMS plans, and certain exempt clearing agencies. The most significant elements of the SCI Proposal
42

would have required each SCI entity to:

42
Each provision of the SCI Proposal is described in further detail below in Section IV.
See also
Proposing Release,
supra
note 13, at Section III.

• Implement policies and procedures reasonably designed to ensure that its “SCI systems” and “SCI security systems” have levels of capacity, integrity, resiliency, availability, and security, adequate to maintain the SCI entity's operational capability and

promote the maintenance of fair and orderly markets, with deemed compliance for policies and procedures that are consistent with current SCI industry standards, including identified information technology publications listed on proposed Table A;

• Implement policies and procedures reasonably designed to ensure that its systems operate in the manner intended, including in compliance with the federal securities laws and rules, and the entity's rules and governing documents, with safe harbors from liability for SCI entities and individuals;

• Upon any “responsible SCI personnel” becoming aware of the occurrence of an “SCI event” (defined to include systems disruptions, systems compliance issues, and systems intrusions), begin to take appropriate corrective action, including mitigating potential harm to investors and market integrity and devoting adequate resources to remedy the SCI event as soon as practicable;

• Report to the Commission the occurrence of any SCI event; and notify its members or participants of certain types of SCI events;

• Notify the Commission 30 days in advance of “material systems changes” (subject to an exception for exigent circumstances) and provide semi-annual summary progress reports on such material systems changes;

• Conduct an annual review, to be performed by objective, qualified personnel, of its compliance with Regulation SCI and submit a report of such annual review to its senior management and to the Commission;

• Designate those of its members or participants that would be required to participate in the testing (to occur at least annually) of its business continuity and disaster recovery plans, and coordinate such testing with other SCI entities on an industry- or sector-wide basis; and

• Meet certain other requirements, including maintaining records related to compliance with Regulation SCI and providing Commission representatives reasonable access to its systems to assess compliance with the rule.

The Commission received substantial comment on the SCI Proposal from a wide range of entities. Commenters generally expressed support for the goals of the rule, but many suggested that the SCI Proposal's scope was unnecessarily broad and could be more tailored to lower compliance costs and still achieve the goal of reducing significant technology risk in the markets. Broadly speaking, the areas of concern garnering the greatest comment included the: (i) Breadth of certain key proposed definitions; (ii) costs associated with the scope of the proposed rule, including its reporting obligations; (iii) publications designated on Table A as proposed examples of “current SCI industry standards;” (iv) proposed entity safe harbor for systems compliance policies and procedures; (v) breadth of the proposed mandatory testing requirements; and (vi) proposed access provision.
43

43
A more detailed discussion of commenters' views can be found below in Section IV.

The Commission has carefully considered the views of commenters in crafting Regulation SCI to meet its goals to strengthen the technology infrastructure of the securities markets and improve its resilience when technology falls short. Many of these modifications are intended to further focus the scope of the requirements from the proposal and to lessen the costs and burdens on SCI entities, while still allowing the Commission to achieve its goals. While Section IV below provides a detailed discussion of the changes the Commission has made to the SCI Proposal in adopting Regulation SCI today,
44

broadly speaking, the key changes include:

44
The Economic Analysis,
infra
Section VI, discusses the economic effects, including the costs and benefits, of the provisions of Regulation SCI, as adopted.

• Refining the scope of the proposal by, among other things, revising certain key definitions (including the definition of SCI systems and the definition of SCI ATS to exclude ATSs that trade only municipal securities or corporate debt securities (together, “fixed-income ATSs”)), refining the reporting framework for SCI events, and replacing the proposed 30-day advanced reporting requirement for material systems changes with a quarterly reporting requirement;

• Modifying the proposal to differentiate certain obligations and requirements, including tailoring certain obligations based on the criticality of a system (by, for example, adopting a new defined term “critical SCI system” for which heightened requirements will apply), and based on the significance of an event (such as adopting a new defined term “major SCI event” for purposes of the dissemination requirements, and establishing differing reporting obligations for SCI events that have had no or a de minimis impact on the SCI entity's operations or on market participants);

• Modifying the proposed policies and procedures requirements relating to both operational capability and the maintenance of fair and orderly markets, as well as systems compliance;

• Refining the scope of SCI entity members and participants that would be required to participate in mandatory business continuity/disaster recovery plan testing; and

• Eliminating the proposed requirement that SCI entities provide Commission representatives reasonable access to their systems because the Commission can adequately assess an SCI entity's compliance with Regulation SCI through existing recordkeeping requirements and examination authority, as well as through the new recordkeeping requirement in Rule 1005 of Regulation SCI.

In addition, the Commission notes that proposed Regulation SCI consisted of a single rule (Rule 1000) that included subparagraphs ((a) through (f)) addressing the various obligations of the rule. However, for clarity and simplification, adopted Regulation SCI is renumbered as Rules 1000 through 1007, as follows:

• Adopted Rule 1000 (which corresponds to proposed Rule 1000(a)) contains definitions for terms used in Regulation SCI;

• Adopted Rule 1001 (proposed Rules 1000(b)(1)-(2)) contains the policies and procedures requirements for SCI entities relating to both operational capability and the maintenance of fair and orderly markets, as well as systems compliance;

• Adopted Rule 1002 (proposed Rules 1000(b)(3)-(5)) contains the obligations of SCI entities with respect to SCI events, which include corrective action, Commission notification, and information dissemination;

• Adopted Rule 1003 (proposed Rules 1000(b)(6)-(8)) contains requirements relating to material systems changes and SCI reviews;

• Adopted Rule 1004 (proposed Rule 1000(b)(9)) contains requirements relating to business continuity and disaster recovery testing;

• Adopted Rule 1005 (proposed Rule 1000(c)) contains requirements relating to recordkeeping;

• Adopted Rule 1006 (proposed Rule 1000(d)) contains requirements relating to electronic filing and submission;

• Adopted Rule 1007 (proposed Rule 1000(e)) contains requirements for service bureaus.

IV. Description of Adopted Regulation SCI and Form SCI

A. Definitions Establishing the Scope of Regulation SCI—Rule 1000

A series of definitions set forth in Rule 1000 relate to the scope of Regulation SCI. These include the definitions for “SCI entity” (as well as the types of entities that are SCI entities,

namely “SCI SRO,” SCI ATS,” “plan processor,” and “exempt clearing agency subject to ARP”), “SCI systems” (and related definitions for “indirect SCI systems” and “critical SCI systems”), and “SCI event” (as well as the types of events that constitute SCI events, namely “systems disruption,” “systems compliance issue,” and “systems intrusion”).
45

45
Rule 1000 contains additional defined terms that are discussed in subsequent sections below.
See infra
Section IV.B.3 (discussing the definition of “responsible SCI personnel”), Section IV.B.3.d (discussing “major SCI event” and deletion of the proposed definition of “dissemination SCI event”), Section IV.B.4 (discussing deletion of the proposed definition for “material systems change”), Section IV.B.5 (discussing “SCI review” and “senior management”), and Section IV.C.2 (discussing “electronic signature”).

1. SCI Entities

Regulation SCI imposes requirements on entities meeting the definition of “SCI entity” under the rule. Proposed Rule 1000(a) defined “SCI entity” as an “SCI self-regulatory organization, SCI alternative trading system, plan processor, or exempt clearing agency subject to ARP.”
46

The Commission is adopting the definition of “SCI entity” in Rule 1000 as proposed.
47

46

See
proposed Rule 1000(a) and Proposing Release
supra
note 13, at Section III.B.1.

47
Proposed Rule 1000(a) also defined each of the terms within the definition of SCI entity for the purpose of designating specifically the entities that would be subject to Regulation SCI. As described in the Sections IV.A.1.a-d below, the Commission is also adopting these terms as proposed and without modification, with the exception of the definition of “SCI ATS,” which is being revised to exclude ATSs that trade only municipal securities or corporate debt securities.

Some commenters discussed the definition of SCI entity generally and advocated for an expansion of the proposed definition, asserting that additional categories of market participants may have the potential to impact the market in the event of a systems issue.
48

For example, one commenter suggested that the definition of “SCI entity” be extended to include the ATS and broker-dealer entities covered by the Regulation NMS definition of a “trading center.”
49

Another commenter stated that the Commission should potentially expand the definition of SCI entity to also include dark pools if they met the volume thresholds of ATSs.
50

48

See, e.g.,
NYSE Letter at 8-9 and Liquidnet Letter at 2-3.
See also
BlackRock Letter at 4 (stating, among other things, that Regulation SCI should extend to any trading platforms that transact significant volume because these venues have a meaningful role and impact on the equity market).
See also infra
Section IV.E (discussing comments regarding the potential inclusion of other types of entities, such as broker-dealers generally, within the scope of Regulation SCI).

49
Specifically, Section 600(b)(78) of Regulation NMS includes within the definition of a “trading center” “an ATS, an exchange market maker, an OTC market maker, or any other broker or dealer that executes orders internally by trading as principal or crossing orders as agent.” 17 CFR 242.600(b)(68).
See
NYSE Letter at 8-9.

50

See
CoreOne Letter at 7-9. CoreOne recommended that the Commission require dark pools to publicly disclose their aggregate volume in a manner similar to disclosures made by exchanges and ATSs. CoreOne stated that, once dark pools publicly disclose their volumes, it would be easier to evaluate whether dark pools should be included as SCI entities.
Id.

Other commenters believed that the scope of the definition should be more limited.
51

For example, one commenter suggested that the definition should only include those entities that are systemically important to the functioning of the U.S. securities markets and should utilize volume thresholds for exchanges and ATSs to make this determination.
52

51

See, e.g.,
KCG Letter at 6-8; ITG Letter at 2-4; and CME Letter at 2-5.

52

See
ITG Letter at 2-4, 7. This commenter argued that, alternatively, the Commission could impose a lower set of obligations on “lesser” SCI entities.
See id.,
at 9-11.
See also infra
notes 81-82 (discussing this commenter's suggested thresholds for exchanges) and note 131 (discussing this commenter's recommended thresholds for ATSs).
See
discussion in Sections IV.A.1.a and IV.A.1.b (relating to SCI SROs and SCI ATSs, respectively).

Several commenters advocated the adoption of a “risk-based” approach, which would entail categorizing market participants based on the criticality of the functions performed rather than applying Regulation SCI to all “SCI entities” equally.
53

Some commenters suggested replacing the term “SCI entity” with categories of participants based on potential market impact or including in the definition only those participants that are essential to continuous market-wide operation or that are the sole providers of a service in the securities markets.
54

Other commenters agreed with the proposed scope of the term “SCI entity,” but believed that the various requirements under the rule should be tiered based on risk profiles.
55

Several commenters identified various factors that should be considered in conducting a risk-assessment such as whether an entity is a primary listing market, is the sole market where the security is traded, or performs a monopoly or utility type role where there is no redundancy built into the marketplace, among others.
56

Some commenters identified specific functions that they believed to be highly critical to the functioning of the securities markets and thus pose the greatest risk to the markets in the event of a systems issue, including securities information processing, clearance and settlement systems, and trading of exclusively listed securities, among others.
57

53

See, e.g.,
BIDS Letter at 5-6; SIFMA Letter at 4-5; KCG Letter at 2-3, 6-8; Fidelity Letter at 2-4; UBS Letter at 2-4; and LiquidPoint Letter at 2-3.

54

See, e.g.,
BIDS Letter at 3-6; Direct Edge Letter at 1-2; and KCG Letter at 2-3, 6-8. Specifically, Direct Edge stated that SCI entities should include Commission-registered exchanges, securities information processors under approved NMS plans for market data, and clearance and settlement systems.

55

See, e.g.,
SIFMA Letter at 4 and Fidelity Letter at 3-4.

56

See, e.g.,
SIFMA Letter at 4 and Fidelity Letter at 3-4.

57

See, e.g.,
SIFMA Letter at 4; Direct Edge Letter at 1-2; and KCG Letter at 2-3.

After careful consideration of the comments, the Commission has determined to adopt the overall scope of entities covered by Regulation SCI as proposed.
58

As discussed below, the Commission continues to believe that it is appropriate and would further the goals of the national market system to subject all SROs (excluding securities futures exchanges), ATSs meeting certain volume thresholds with respect to NMS stocks and non-NMS stocks (discussed further below), plan processors, and certain exempt clearing agencies to the requirements of Regulation SCI. The Commission believes that this definition appropriately includes those entities that play a significant role in the U.S. securities markets and/or have the potential to impact investors, the overall market, or the trading of individual securities.
59

58

But see infra
Section IV.A.1.b (discussing revisions to the definition of “SCI ATS”).

59

See infra
Sections IV.A.1.a-d (discussing more specifically each category of entity included within the definition of “SCI entity”).

While some commenters supported expanding the definition of SCI entity to encompass various other types of entities, the Commission has determined not to expand the scope of entities subject to Regulation SCI at this time. As noted in the SCI Proposal, Regulation SCI is based, in part, on the ARP Inspection Program, which has included the voluntary participation of all active registered clearing agencies, all registered national securities exchanges, the only registered national securities association—Financial Industry Regulatory Authority (“FINRA”), one exempt clearing agency, and one ATS.
60

The ARP Inspection Program has also included the systems of entities that process and disseminate quotation and transaction data on behalf of the Consolidated Tape Association System (“CTA Plan”), Consolidated Quotation System (“CQS Plan”), Joint Self-Regulatory Organization Plan

Governing the Collection, Consolidation, and Dissemination of Quotation and Transaction Information for Nasdaq-Listed Securities Traded on Exchanges on an Unlisted Trading Privileges Basis (“Nasdaq UTP Plan”), and Options Price Reporting Authority (“OPRA Plan”).
61

Significant-volume ATSs have also been subject to certain aspects of the ARP Policy Statements pursuant to Regulation ATS.
62

In addition, one entity that has been granted an exemption from registration as a clearing agency has been subject to the ARP Inspection Program pursuant to the conditions of the exemption order issued by the Commission.
63

The scope of the definition of SCI entity is intended to largely reflect the historical reach of the ARP Inspection Program and existing Rule 301 of Regulation ATS, while also expanding the coverage to certain additional entities that the Commission believes play a significant role in the U.S. securities markets and/or have the potential to impact investors, the overall market, or the trading of individual securities. The Commission acknowledged in the SCI Proposal that there may be other categories of entities not included within the definition of SCI entity that, given their increasing size and importance, could pose risks to the market should an SCI event occur.
64

However, as discussed in further detail below,
65

the Commission believes that, at this time, the entities included within the definition of SCI entity, because of their current role in the U.S. securities markets and/or their level of trading activity, have the potential to pose the most significant risk in the event of a systems issue. Although some commenters suggested that Regulation SCI should cover a greater range of market participants,
66

the Commission believes that it is important to move forward now on rules that will meaningfully enhance the technology standards and oversight of key markets and market infrastructure. Further, the Commission believes that a measured approach that takes an incremental expansion from the entities covered under the ARP Inspection Program is an appropriate method for imposing the mandatory requirements of Regulation SCI at this time given the potential costs of compliance. This approach will enable the Commission to monitor and evaluate the implementation of Regulation SCI, the risks posed by the systems of other market participants, and the continued evolution of the securities markets, such that it may consider, in the future, extending the types of requirements in Regulation SCI to additional categories of market participants, such as non-ATS broker-dealers, security-based swap dealers, investment advisers, investment companies, transfer agents, and other key market participants. As noted in the SCI Proposal, should the Commission decide to propose to apply some or all of the requirements of Regulation SCI to additional types of entities, the Commission will issue a separate release discussing such a proposal and seeking public comment.
67

60

See
Proposing Release,
supra
note 13, at 18086.

61

See infra
note 196 and accompanying text.

62

See
Rule 301(b)(6) of Regulation ATS, 17 CFR 242.301(b)(6).

63

See
Proposing Release,
supra
note 13, at 18096-97.
See also infra
Section IV.A.1.d (discussing the inclusion in Regulation SCI of exempt clearing agencies subject to ARP).

64

See
Proposing Release,
supra
note 13, at 18138-39.

65

See infra
Sections IV.A.1.a-d (discussing more specifically each category of entity included within the definition of “SCI entity”).

66

See supra
notes 48-50 and accompanying text.

67

See
Proposing Release,
supra
note 13, at 18138.

With respect to another commenter's recommendation regarding dark pools, to the extent that this commenter intended its comment to refer to ATSs, ATSs would be included within the scope of Regulation SCI if they met the applicable volume thresholds discussed below.
68

To the extent that this commenter intended its comment to refer to other types of non-ATS dark venues where broker-dealers internalize order flow, the Commission notes that it has determined not to extend the scope of Regulation SCI to other types of broker-dealers at this time for the reasons discussed below.
69

68

See infra
Section IV.A.1.b (discussing definition of “SCI ATS”). This commenter also recommended that the Commission require dark pools to publicly disclose their aggregate volume to make it easier to evaluate whether dark pools should be included as SCI entities, and supported FINRA's plans to require such trading volume disclosures. The Commission notes that FINRA recently adopted new Rule 4552, which requires each ATS to report to FINRA weekly volume information regarding transactions in NMS stocks and OTC equity securities, and FINRA makes such information publicly available on its Web site.
See
Securities Exchange Act Release No. 71341 (January 17, 2014), 79 FR 4213 (January 24, 2014) (approving FINRA Rule 4552 requiring each ATS to report to FINRA weekly volume information and number of securities transactions). The Commission also notes that all ATSs (including dark pool ATSs) are required under Regulation ATS to provide the Commission with quarterly trading volume information.
See
Rule 301(b)(9) of Regulation ATS, 17 CFR 242.301(b)(9).

69

See infra
text accompanying notes 121-125.

The Commission has also determined not to further limit the scope of entities subject to Regulation SCI as suggested by some commenters. As discussed in more detail below, the Commission continues to believe that each of the identified categories of entities plays a significant role in the U.S. securities markets and/or has the potential to impact investors, the overall market, or the trading of individual securities, and thus should be subject to the requirements of Regulation SCI. Accordingly, the Commission does not agree that it should adopt a “risk-based” approach to
further limit
the categories of market participants subject to Regulation SCI. The Commission believes that limiting the applicability of Regulation SCI to only the most systemically important entities posing the highest risk to the markets is too limited of a category of market participants, as it would exclude certain entities that, in the Commission's view, have the potential to pose significant risks to the securities markets should an SCI event occur. However, the Commission believes it is appropriate to incorporate risk-based considerations in various other aspects of Regulation SCI. Consistent with the views of some commenters advocating that the requirements of Regulation SCI should be tailored to the specific risk-profile of a particular entity or particular system,
70

the Commission notes that Regulation SCI, as proposed, was intended to incorporate a consideration of risk within its requirements and believes it is appropriate to more explicitly incorporate risk considerations in various provisions of adopted Regulation SCI. For example, as discussed in further detail below, the requirement to have reasonably designed policies and procedures relating to operational capability was designed to permit SCI entities to take a risk-based approach in developing their policies and procedures based on the criticality of a particular system.
71

In addition, the Commission believes that it is appropriate to further incorporate a risk-based approach into other aspects of the regulation, and thus, as discussed below, is adopting a new term—“critical SCI systems”—to identify systems that the Commission believes should be subject to heightened requirements in certain areas.
72

Further, the Commission has determined that certain other definitions (such as the definition of “SCI systems”), and certain requirements of the rule (such as Commission notification for SCI events and material systems changes), should be scaled back and refined consistent with a risk-based approach, as discussed

below. The Commission believes that these modifications, further incorporating risk-based considerations in the requirements and scaling back certain requirements, provide the proper balance between requiring that the appropriate entities are subject to baseline standards for systems capacity, integrity, resiliency, availability, security, and compliance, while reducing the overall burden of the rule for all SCI entities, which is consistent with, and responsive to, the views of those commenters that the Commission take a more risk-based approach to SCI entities.

70

See supra
note 55 and accompanying text.

71

See infra
Section IV.B.1 (discussing the policies and procedures requirement under adopted Rule 1001(a)).

72

See infra
Section IV.A.2.c (discussing the definition of “critical SCI systems”).

a. SCI Self-Regulatory Organization or SCI SRO

Proposed Rule 1000(a) defined “SCI self-regulatory organization,” or “SCI SRO,” to be consistent with the definition of “self-regulatory organization” set forth in Section 3(a)(26) of the Exchange Act.
73

This definition covered all national securities exchanges registered under Section 6(b) of the Exchange Act,
74

registered securities associations,
75

registered clearing agencies,
76

and the Municipal Securities Rulemaking Board (“MSRB”).
77

The definition, however, excluded an exchange that lists or trades security futures products that is notice-registered with the Commission as a national securities exchange pursuant to Section 6(g) of the Exchange Act, as well as any limited purpose national securities association registered with the Commission pursuant to Exchange Act Section 15A(k).
78

Accordingly, the proposed definition of SCI SRO in Rule 1000(a) included all national securities exchanges registered under Section 6(b) of the Exchange Act, all registered securities associations, all registered clearing agencies, and the MSRB.
79

The definition of “SCI self-regulatory organization” or “SCI SRO” is being adopted in Rule 1000 as proposed.
80

73

See
15 U.S.C. 78c(a)(26): “The term `self-regulatory organization' means any national securities exchange, registered securities association, or registered clearing agency, or (solely for purposes of sections 19(b), 19(c), and 23(b) of this title) the Municipal Securities Rulemaking Board established by section 15B of this title.”

74
Currently, these registered national securities exchanges are: (1) BATS Exchange, Inc. (“BATS”); (2) BATS Y-Exchange, Inc. (“BATS-Y”); (3) Boston Options Exchange LLC (“BOX”); (4) CBOE; (5) C2; (6) Chicago Stock Exchange, Inc. (“CHX”); (7) EDGA Exchange, Inc. (“EDGA”); (8) EDGX Exchange, Inc. (“EDGX”); (9) International Securities Exchange, LLC (“ISE”); (10) Miami International Securities Exchange, LLC (“MIAX”); (11) NASDAQ OMX BX, Inc. (“Nasdaq OMX BX”); (12) NASDAQ OMX PHLX LLC (“Nasdaq OMX Phlx”); (13) Nasdaq; (14) National Stock Exchange, Inc. (“NSX”); (15) NYSE; (16) NYSE MKT; (17) NYSE Arca; and (18) ISE Gemini, LLC (“ISE Gemini”).

75
FINRA is the only registered national securities association.

76
Currently, there are seven clearing agencies (Depository Trust Company (“DTC”); Fixed Income Clearing Corporation (“FICC”); National Securities Clearing Corporation (“NSCC”); Options Clearing Corporation (“OCC”); ICE Clear Credit; ICE Clear Europe; and CME) with active operations that are registered with the Commission. The Commission notes that in 2012 it adopted Rule 17Ad-22, which requires registered clearing agencies to have effective risk management policies and procedures in place.
See
Securities Exchange Act Release No. 68080 (October 22, 2012), 77 FR 66220 (November 2, 2012) (“Clearing Agency Standards Release”). The Commission believes that Regulation SCI, to the extent it addresses areas of risk management similar to those addressed by Rule 17Ad-22(d)(4), complements Rule 17Ad-22(d)(4).

Additionally, on March 12, 2014, the Commission proposed rules that would apply to SEC-registered clearing agencies that have been designated as systemically important by the Financial Stability Oversight Council or that are involved in activities with a more complex risk profile, such as clearing security-based swaps.
See
Securities Exchange Act Release No. 71699 (Mar. 12, 2014), 79 FR 16865 (March 26, 2014) (“Covered Clearing Agencies Proposal”). Regulation SCI and proposed Rule 17Ad-22(e)(17) are intended to be consistent and complementary.
See also
Covered Clearing Agencies Proposal, 79 FR at 16866, n.1 and accompanying text (discussing the Commission's consideration of the relevant international standards).

77
15 U.S.C. 78c(a)(26). As noted in the Proposing Release, historically, the ARP Inspection Program did not include the MSRB, but instead focused on entities having trading, quotation and transaction reporting, and clearance and settlement systems more closely connected to the equities and options markets. The Commission believes that it is appropriate to apply Regulation SCI to the MSRB, particularly given the fact that the MSRB is the only SRO relating to municipal securities and is a key provider of consolidated market data for the municipal securities market. Accordingly, as proposed, the term “SCI SRO” included the MSRB. In 2008, the Commission amended Rule 15c2-12 to designate the MSRB as the single centralized disclosure repository for continuing municipal securities disclosure. In 2009, the MSRB established the Electronic Municipal Market Access system (“EMMA”). EMMA now serves as the official repository of municipal securities disclosure, providing the public with free access to relevant municipal securities data, and is the central database for information about municipal securities offerings, issuers, and obligors. Additionally, the MSRB's Real-Time Transaction Reporting System (“RTRS”), with limited exceptions, requires municipal bond dealers to submit transaction data to the MSRB within 15 minutes of trade execution, and such near real-time post-trade transaction data can be accessed through the MSRB's EMMA Web site. While pre-trade price information is not as readily available in the municipal securities market, the Commission's Report on the Municipal Securities Market also recommended that the Commission and MSRB explore the feasibility of enhancing EMMA to collect best bids and offers from material ATSs and make them publicly available on fair and reasonable terms.
See
Report on the Municipal Securities Market (July 31, 2012), available at:
http://www.sec.gov/news/studies/2012/munireport073112.pdf.
The Commission believes that the MSRB's SCI systems currently are limited to those operated by or on behalf of the MSRB that directly support market data (
i.e.,
currently limited to the EMMA, RTRS, and SHORT systems). As discussed more fully below, the EMMA, RTRS, and SHORT systems referenced by the MSRB in its comment letter would be market data systems within the definition of SCI systems because they provide or directly support price transparency.
See infra
note 253 and accompanying text.

78

See
15 U.S.C. 78f(g); 15 U.S.C. 78
o
-3(k). These entities are security futures exchanges and the National Futures Association, for which the CFTC serves as their primary regulator.
See generally
CFTC Concept Release on Risk Controls and System Safeguards for Automated Trading Environments, 78 FR 56542 (September 12, 2013) (“CFTC Concept Release”) (describing the CFTC's regulatory scheme for addressing risk controls relating to automated systems).

79
For any SCI SRO that is a national securities exchange, any facility of such national securities exchange, as defined in Section 3(a)(2) of the Exchange Act, 15 U.S.C. 78c(a)(2), also is covered because such facilities are included within the definition of “exchange” in Section 3(a)(1) of the Exchange Act, 15 U.S.C. 78c(a)(1).

80
The Commission notes that NSX ceased trading as of the close of business on May 30, 2014.
See
Securities Exchange Act Release No. 72107 (May 2, 2014), 79 FR 27017 (May 12, 2014) (Notice of Filing and Immediate Effectiveness of Proposed Rule Change To Cease Trading on Its Trading System) (“NSX Trading Cessation Notice”). In the NSX Trading Cessation Notice, NSX stated: “[T]he Exchange will continue to be registered as a national securities exchange and will continue to retain its status as a self-regulatory organization[;]” and further, that it “shall file a proposed rule change pursuant to Rule 19b-4 of the Exchange Act prior to any resumption of trading on the Exchange pursuant to Chapter XI (Trading Rules).” Because NSX remains a national securities exchange registered under Section 6(b) of the Exchange Act, it continues to meet the definition of SCI entity, and is counted as an SCI entity for purposes of this release.

One commenter suggested that the rule should include volume thresholds for exchanges.
81

Specifically, this commenter recommended that, with regard to exchanges, the definition should include only those exchanges that have five percent or more of average daily dollar volume in at least five NMS stocks for four of the previous six months.
82

Another commenter asked the Commission to adopt certain specific exceptions to the definition of SCI SRO and SCI entity for entities that are dually registered with the CFTC and Commission where the CFTC is the entity's “primary regulator” and for any entity that does not play a “significant role” in the markets subject to the Commission's jurisdiction and that cannot have a “significant impact” on the markets subject to the Commission's jurisdiction.
83

81

See
ITG Letter at 10. This commenter also suggested similar revised thresholds for SCI ATSs.
See also

infra
note 131 and accompanying text. Although only one commenter specifically commented on the proposed inclusion of SCI SROs within the scope of Regulation SCI, as discussed above, some commenters believed that Regulation SCI should generally take a more risk-based or tiered approach generally which, in some cases, would affect which entities (including SCI SROs) would be subject to Regulation SCI.
See supra
notes 53-56 and accompanying text.

82

See
ITG Letter at 10.

83

See
CME Letter at 2.

The Commission does not believe that a trading volume threshold is

appropriate for SCI SROs that are exchanges, but instead believes that Regulation SCI should apply to all SCI SROs. The threshold suggested by the commenter would exclude from Regulation SCI those exchanges with volumes below the suggested threshold; however, the Commission believes that all exchanges play a significant role in our securities markets. For example, all stock exchanges are subject to a variety of specific public obligations under the Exchange Act, including the requirements of Regulation NMS which, among other things, designates the best bid or offer of such exchanges to be protected quotations.
84

Accordingly, every exchange may have a protected quotation that can obligate market participants to send orders to that exchange. Among other reasons, given that market participants may be required to send orders to any one of the exchanges at any given time if such exchange is displaying the best bid or offer, the Commission believes that it is important that the safeguards of Regulation SCI apply equally to all exchanges irrespective of trading volume.

84

See generally
17 CFR 242.600-612. In addition, as the commenter's suggested thresholds would apply only with respect to exchanges that trade NMS stocks, national securities exchanges that do not trade NMS stocks (
i.e.,
options exchanges) would also be excluded from Regulation SCI under the commenter's suggestion. The Commission believes that it would be inappropriate to exclude options exchanges from the requirements of Regulation SCI, because technology risks are equally applicable to such exchanges, as evidenced by recent significant technology incidents affecting the options markets.
See supra
notes 28-31 and accompanying text. As such, systems issues at options exchanges can pose significant risks to the markets, and the Commission believes that the inclusion of options exchanges within the scope of Regulation SCI is necessary to achieve the goals of Regulation SCI.

With regard to one commenter's suggestion to except from the definition of SCI SRO those entities dually registered with the CFTC and Commission where the CFTC is the entity's “primary regulator,”
85

the Commission disagrees that such entities should be relieved from the requirements of Regulation SCI solely because they are dually registered.
86

While the CFTC is responsible for overseeing such an entity with regard to its futures activities, it does not have oversight responsibility for the entity's securities-related activities and systems. While the commenter stated that it (as a dual registrant) is already subject to similar requirements to adopt controls and procedures with regard to operational risk and reliability, security, and capacity of its systems pursuant to CFTC regulations, the Commission again notes that such requirements do not apply to such an entity's securities-related systems as such systems are outside of the CFTC's jurisdiction and, as such, such systems would not be subject to inspection and examination by the CFTC for compliance with such requirements.
87

Further, Regulation SCI imposes a notification framework to inform the Commission of SCI events and material systems changes, as well as other requirements unique to Regulation SCI. Accordingly, the Commission believes that such entities should be subject to the requirements of Regulation SCI. In addition, as noted above, this commenter also asked the Commission to create an exception for any entity that does not play a “significant role” in the markets subject to the Commission's jurisdiction and that cannot have a “significant impact” on the markets subject to the Commission's jurisdiction.
88

While the Commission disagrees with excluding SROs from coverage as discussed above, the Commission notes that it is revising the proposed definition of SCI systems to clarify that the term SCI systems encompasses only those systems that,
with respect to securities,
directly support trading, clearance and settlement, order routing, market data, market regulation, or market surveillance, as discussed below.
89

Accordingly, the Commission believes this change should address the commenter's concerns about the requirements applying to entities whose systems cannot affect the markets subject to the Commission's jurisdiction,
i.e.,
the U.S. securities markets.

85

See supra
note 83 and accompanying text.

86
The commenter notes that the Commission has proposed to exclude from the definition of SCI SRO those exchanges that list or trade security futures products that are notice-registered with the Commission pursuant to Section 6(g), as well as limited purpose national securities associations registered with the Commission pursuant to Exchange Act Section 15A(k).
See
Proposing Release,
supra
note 13, at 18093, n. 97 and accompanying text. The Commission notes that such entities are subject to the joint jurisdiction of the Commission and the CFTC. To avoid duplicative regulation, however, the CFMA established a system of notice registration under which trading facilities and intermediaries that are already registered with either the Commission or the CFTC may register with the other agency on an expedited basis for the limited purpose of trading security futures products. A “notice registrant” is then subject to primary oversight by one agency, and is exempted under the CFMA from all but certain specified provisions of the laws administered by the other agency.
See
Section 6(g)(4) and Section 15A(k)(3)-(4) (enumerating the provisions of the Exchange Act from which a notice-registered exchange and limited purpose national securities association, respectively, are exempted). Given this, the Commission believes that it is appropriate to defer to the CFTC regarding the systems integrity of these entities).
See also generally
CFTC Concept Release,
supra
note 78. This regulatory scheme does not apply outside of the specific contexts of security futures exchanges and associations. In contrast, entities that are registered with both the Commission and the CFTC in other capacities, such as clearing agencies, are subject to a full set of regulations by each regulator. The Exchange Act and Commodity Exchange Act do not exempt these entities, due to any dual regulatory scheme, from any provisions of the laws administered by the Commission and, as discussed further below, the Commission believes they should not be afforded an exclusion from Regulation SCI.

87
The Commission notes that, to the extent that such an entity's systems for its functions that fall in the purview of the Commission (relating to securities and securities-based swaps) and that fall in the purview of the CFTC (relating to futures and swaps) are integrated, it believes that the focus of the CFTC's exams and inspections of such systems would be on such systems' functionality related to non-securities-related activities, such as swaps or futures, and not those related to securities activities. Thus, the Commission believes that the potential examination and inspection of such integrated systems by both the CFTC and SEC does not support the exclusion of the SCI entities operating such systems, or the systems themselves, from the scope of Regulation SCI.

88

See supra
note 83 and accompanying text.

89

See
adopted Rule 1000 (emphasis added).
See also infra
Section IV.A.2.b (discussing the definition of “SCI systems”).

b. SCI Alternative Trading System

Proposed Rule 1000(a) defined the term “SCI alternative trading system,” or “SCI ATS,” as an alternative trading system, as defined in § 242.300(a), which during at least four of the preceding six calendar months, had: (1) With respect to NMS stocks—(i) five percent or more in any single NMS stock, and 0.25 percent or more in all NMS stocks, of the average daily dollar volume reported by an effective transaction reporting plan, or (ii) one percent or more, in all NMS stocks, of the average daily dollar volume reported by an effective transaction reporting plan; (2) with respect to equity securities that are not NMS stocks and for which transactions are reported to a self-regulatory organization, five percent or more of the average daily dollar volume as calculated by the self-regulatory organization to which such transactions are reported; or (3) with respect to municipal securities or corporate debt securities, five percent or more of either—(i) the average daily dollar volume traded in the United States, or (ii) the average daily transaction volume traded in the United States.
90

90

See
proposed Rule 1000(a) and Proposing Release,
supra
note 13, at Section III.B.1.

The proposed definition would have modified the thresholds currently appearing in Rule 301(b)(6) of Regulation ATS that apply to significant-volume ATSs.
91

Specifically,

the proposed definition would have: Used average daily dollar volume thresholds, instead of an average daily share volume threshold, for ATSs that trade NMS stocks or equity securities that are not NMS stocks (“non-NMS stocks”); used alternative average daily dollar and transaction volume-based tests for ATSs that trade municipal securities or corporate debt securities; lowered the volume thresholds applicable to ATSs for each category of asset class; and moved the proposed thresholds to Regulation SCI. In particular, with respect to NMS stocks, the Commission proposed to change the volume threshold from 20 percent of average daily volume in any NMS stock such that an ATS that traded NMS stocks that met either of the following two alternative threshold tests would be subject to the requirements of proposed Regulation SCI: (i) Five percent or more in any NMS stock, and 0.25 percent or more in all NMS stocks, of the average daily dollar volume reported by an effective transaction reporting plan; or (ii) one percent or more, in all NMS stocks, of the average daily dollar volume reported by an effective transaction reporting plan. With respect to non-NMS stocks, municipal securities, and corporate debt securities, the Commission proposed to reduce the standard from 20 percent to five percent for these types of securities,
92

the same percentage threshold for such types of securities that triggers the fair access provisions of Rule 301(b)(5) of Regulation ATS.
93

91
17 CFR 242.301(b)(6).

92

See
proposed Rule 1000(a).

93

See
Rule 301(b)(5) of Regulation ATS under the Exchange Act. 17 CFR 242.301(b)(5). In addition, as noted above, the proposed rule used alternative average daily dollar and transaction volume-based tests for ATSs that trade municipal securities or corporate debt securities.

The proposed definition of “SCI ATS” is being adopted substantially as proposed with regard to ATSs trading NMS stocks and ATSs trading non-NMS stocks, with the addition of a six-month compliance period for entities satisfying the thresholds in the definition for the first time, as discussed in more detail below. However, for the reasons discussed below, the Commission has determined to exclude from the definition of “SCI ATS” ATSs that trade only municipal securities or corporate debt securities and accordingly, such ATSs will not be subject to the requirements of Regulation SCI.

Inclusion of ATSs Generally

Many commenters provided comment on the inclusion of ATSs within the scope of Regulation SCI. Some commenters believed that more ATSs should be covered by Regulation SCI.
94

For example, some commenters suggested that the term “SCI ATS” should include all ATSs, because these commenters believed that they have the potential to negatively impact the market in the event of a systems issue.
95

Moreover, one commenter stated that the Commission should not distinguish between ATSs based on calculated thresholds because an ATS might limit trading on its system so as to avoid being subject to the requirements of Regulation SCI.
96

94

See, e.g.,
NYSE Letter at 9-10; Lauer Letter at 4; and CoreOne Letter at 7-8.

95

See, e.g.,
NYSE Letter at 9-10; and Lauer Letter at 4.

96

See, e.g.,
NYSE Letter at 9-10.

Conversely, other commenters stated that fewer, or even no, ATSs should be covered.
97

Such commenters generally argued that there are key differences between ATSs and exchanges, and thus, ATSs should be regulated differently from exchanges and not be included in Regulation SCI with exchanges.
98

The differences identified by commenters included: ATSs' relative market shares and sizes; the fact that ATSs are already subject to various regulations as broker-dealers (including Rule 15c3-5 under the Exchange Act, various FINRA rules, and Regulation ATS); and certain fundamental economic differences between the two types of entities (including that exchanges can gain revenue from listing and market data, have self-clearing, and have a protected quote).
99

One commenter argued that, if the Commission were to include ATSs in Regulation SCI, it should treat ATSs and SROs equally by allowing ATSs to have the same benefits of SROs, including allowing ATSs to derive an income stream from contributions to the SIP, have access to clearing, and have immunity from lawsuits.
100

Other commenters also noted that, although ATSs have an increasingly large, collective market share, ATSs have not contributed to any of the recent major systems issues that have impacted the market.
101

97

See, e.g.,
BIDS Letter at 3; ITG Letter at 3; KCG Letter at 8; and OTC Markets Letter at 9.

98

See, e.g.,
BIDS Letter at 3; ITG Letter at 3; KCG Letter at 9, 14-17; TMC Letter at 2; and OTC Markets Letter at 9.

99

Id.

100

See
OTC Markets Letter at 9.

101

See
ITG Letter at 4; and BIDS Letter at 3.

Another commenter stated that the SCI Proposal unfairly discriminated against ATSs by including them within the definition of SCI entity.
102

Specifically, although this commenter did not believe that Regulation SCI should be expanded to include more entities, it stated that the SCI Proposal's failure to capture certain entities (such as clearing firms, market makers, block positioners, and order routing firms) that it believed could have a greater impact on market stability in the event of a systems issue, while including ATSs, demonstrates that the proposal is arbitrary, capricious, and unfairly discriminatory in nature.
103

102

See
ITG Letter at 9.

103

See id.

After careful consideration of the comment letters, the Commission continues to believe that the inclusion of ATSs that trade NMS stocks and non-NMS stocks in Regulation SCI is appropriate.
104

The Commission believes that certain of those ATSs play an important role in today's securities markets, and thus should be subject to the safeguards and obligations of Regulation SCI. As noted in the SCI Proposal, the equity markets have evolved significantly over recent years, resulting in an increase in the number of trading centers and a reduction in the concentration of trading activity.
105

As such, even smaller trading centers, such as certain higher-volume ATSs, now collectively represent a significant source of liquidity for NMS stocks and some ATSs have similar and, in some cases, greater trading volume than some national securities exchanges, with no single national securities exchange executing more than approximately 19 percent of volume in NMS stocks in today's securities markets.
106

Accordingly, the Commission believes that ATSs meeting certain volume thresholds can play a significant role in the securities markets and, given their heavy reliance on automated systems, have the potential to significantly impact investors, the overall market,

and the trading of individual securities should an SCI event occur.

104
Given the inclusion of ATSs that trade NMS stocks and non-NMS stocks within the scope of Regulation SCI, Regulation ATS is also being amended to remove paragraphs (b)(6)(i)(A) and (b)(6)(i)(B) of Rule 301 so that Rule 301(b)(6) will no longer apply to ATSs trading NMS stocks and non-NMS stocks. However, as described below, the Commission has determined to exclude ATSs that trade only municipal securities or corporate debt securities from the scope of Regulation SCI, and such ATSs will remain subject to the requirements of Rule 301(b)(6) if they meet the volume thresholds therein. 17 CFR 242.301(b)(6).
See supra
notes 14 and 20 and accompanying text.

105

See
Proposing Release,
supra
note 13, at 18094.

106

See
market volume statistics reported by BATS, available at:
http://www.batstrading.com/market_summary/
(no single stock exchange executed more than approximately 19 percent during the second quarter of 2014, with Nasdaq having the highest market share of 18.6 percent). In comparison, according to data from Form ATS-R for the second quarter of 2014, approximately 18 percent of consolidated NMS stocks dollar volume took place on ATSs.

Commenters identified certain differences between exchanges and ATSs, which commenters argued justified different treatment under Regulation SCI for ATSs or exclusion of ATSs from the regulation completely.
107

While the Commission recognizes that there are some fundamental differences between ATSs and exchanges, including certain of those identified by commenters, the Commission does not agree that all ATSs should be excluded from Regulation SCI because, as discussed above, it believes that there are certain significant-volume ATSs that have the potential to significantly impact investors, the overall market, or the trading of individual securities should an SCI event occur. At the same time, the risk-based considerations permitted in adopted Regulation SCI may result in the systems of those ATSs that are subject to Regulation SCI (
i.e.,
SCI ATSs) being subject to less stringent requirements than the systems of SROs or other SCI entities in certain areas. For example, as discussed in further detail below, the Commission is adopting a definition of “critical SCI systems,” which are a subset of SCI systems that are subject to certain heightened requirements under Regulation SCI. This definition is intended to capture those systems that are core to the functioning of the securities markets or that represent “single points of failure” and thus, pose the greatest risk to the markets. The Commission believes that, as currently constituted, relative to the systems of SCI SROs, the systems of SCI ATSs generally would not fall within this category of critical SCI systems, and thus such SCI ATSs would not be subject to the more stringent requirements that would be applicable to the critical SCI systems of other SCI entities. The Commission also notes that other requirements under Regulation SCI are designed to be consistent with a risk-based approach. The Commission believes that this approach recognizes the different roles played by different SCI systems at various SCI entities and, where permitted, allows each SCI entity, including SCI ATSs, to tailor the applicable requirements accordingly.

107

See supra
notes 98-99 and accompanying text.

While some commenters noted that ATSs have not contributed to any of the recent high-profile systems issues,
108

the Commission does not believe that the relative lack of high-profile systems issues at ATSs to date is an indication that ATSs do not have the potential to have a significant impact on the market in the event of a future systems issue.
109

108

See supra
note 101 and accompanying text.

109
The Commission also notes that, as discussed above, in November 2013, a systems issue at OTC Link ATS led FINRA to halt trading in all OTC securities for over three hours.
See supra
note 33 and accompanying text.

Other commenters noted the competitive environment of ATSs and argued that, if one ATS experiences a systems issue and becomes temporarily unavailable, trading can be easily rerouted to other venues.
110

The Commission acknowledges that a temporary outage at an ATS (or at a SCI SRO, for that matter) may not lead to a widespread systemic disruption. However, the Commission notes that Regulation SCI is not designed to solely address system issues that cause widespread systemic disruption, but also to address more limited systems malfunctions and other issues that can harm market participants or create compliance issues.
111

110

See
ITG Letter at 3; and KCG Letter at 9.

111
The Commission notes that each ATS provides different services in terms of, among other things, pricing, latency, and order fills to meet investors' specific needs. Thus, for example, an ATS outage could interfere with the supply of certain services that investors demand and, thus, could impose costs on investors.

Some commenters also stated that inclusion of ATSs is not necessary because ATSs are already subject to sufficient regulations as broker-dealers, citing Rule 15c3-5 under the Exchange Act, various FINRA rules, and Regulation ATS.
112

While the Commission acknowledges that these rules similarly impose requirements related to the capacity, integrity and/or security of a broker-dealer's systems and are designed to address some of the same concerns that Regulation SCI is intended to address, the Commission notes that these rules generally take a different approach than Regulation SCI. For example, the obligations of an ATS under Rule 15c3-5 address vulnerability in the national market system that relate specifically to market access,
113

whereas Regulation SCI is designed to further the goals of the national market system more broadly by helping to ensure the capacity, integrity, resiliency, availability, and security of the automated systems of entities important to the functioning of the U.S. securities markets.
114

Thus, the Commission has determined to include ATSs within the scope of Regulation SCI because of their role as markets and a potential significant source of liquidity. With regard to the FINRA rules identified by commenters, the Commission does not believe that these rules, even when considered in combination with Rule 15c3-5, are an appropriate substitute for the comprehensive approach in Regulation SCI for ATSs in their role as markets.
115

Finally, as noted above,

Rule 301(b)(6) of Regulation ATS imposed by rule certain aspects of the ARP Policy Statements on significant-volume ATSs. As described in detail herein, Regulation SCI seeks to expand upon, update, and modernize the requirements of the ARP Policy Statements and Rule 301(b)(6), by, for example, expanding the requirements to a broader set of systems, imposing new requirements for information dissemination regarding SCI events, and requiring Commission notification for additional types of events, among others. Accordingly, the Commission believes that, for SCI ATSs, the existing broker-dealer rules and regulations identified by commenters are complemented by the requirements of Regulation SCI (other than Rule 301(b)(6), which will no longer apply to ATSs that trade NMS stocks and non-NMS stocks), and do not serve as substitutes for the regulatory framework being adopted today.

112

See supra
notes 98-99 and accompanying text.

113

See
Securities Exchange Act Release No. 63241 (November 3, 2010), 75 FR 69792 (November 15, 2010) (“Market Access Release”).

114
The Commission notes that Rule 15c3-5 focuses on addressing the particular risks that arise when broker-dealers provide electronic access to exchanges or ATSs and therefore does not address the same range of technology-related issues as Regulation SCI is designed to address. Both Rule 15c3-5 and Regulation SCI are policies and procedures-based rules that are designed to address the risks presented by the pervasive use of technology in today's markets.The policies and procedures required by Regulation SCI apply broadly to technology that supports trading, clearance and settlement, order routing, market data, market regulation, and market surveillance and, among other things, address their overall capacity, integrity, resilience, availability, and security. Rule 15c3-5, by contrast, is more narrowly focused on those technology and other errors that can create some of the more significant risks to broker-dealers and the markets, namely those that arise when a broker-dealer enters orders into an exchange or ATS, including when it provides sponsored or direct market access to customers or other persons, where the consequences of such an error can rapidly magnify and spread throughout the markets.
See also

infra
note 115 (discussing FINRA rules applicable to broker-dealers). The Commission will continue to monitor and evaluate the risks posed by broker-dealer systems to the market and the implementation of the Market Access Rule, and may consider extending the types of requirements in Regulation SCI to additional market participants in the future.

115
For example, NASD Rule 3010(b)(1) requires a member to establish, maintain, and enforce written procedures to supervise the types of business in which it engages and to supervise the activities of registered representatives, registered principals, and other associated persons that are reasonably designed to achieve compliance with applicable securities laws and regulations. This rule relates to policies and procedures to achieve compliance with applicable securities laws and regulations, and thus the Commission believes that this requirement is broadly related to adopted Rule 1001(b) regarding policies and procedures to ensure systems compliance. However, the Commission notes that, unlike adopted Rule 1001(b), which focuses on ensuring that an entity's systems operate in compliance with the Exchange Act, the rules and regulations thereunder and the entity's rules and governing documents, this NASD rule does not specifically address compliance of the systems of FINRA members. Further, the Commission does not believe this provision covers more broadly policies and procedures akin to those in adopted Rule 1001(a) that are designed to ensure that SCI systems have levels of capacity, integrity, resiliency, availability, and security adequate to maintain the SCI entity's operation capability and promote fair and orderly markets. Similarly, while FINRA Rule 3130 relates to adopted Rule 1001(b) regarding policies and procedures to ensure systems compliance in that it requires a member's chief compliance officer to certify that the member has in place written policies and procedures reasonably designed to achieve compliance with applicable FINRA rules, MSRB rules, and federal securities laws and regulations, it does not specifically address compliance of the
systems
of FINRA members, and does not require similar policies and procedures to those in adopted Rule 1001(a) regarding operational capability of SCI entities. Further, while FINRA Rule 4530 imposes a reporting regime for, among other things,

compliance issues and other events where a member has concluded or should have reasonably concluded that a violation of securities or other enumerated law, rule, or regulation of any domestic or foreign regulatory body or SRO has occurred, the Commission notes that these reporting requirements are different in several respects from the Commission notification requirements relating to systems compliance issues (
e.g.,
scope, timing, content, the recipient of the reports) and, importantly, would not cover reporting of systems disruptions or systems intrusions that did not also involve a violation of a securities law, rule, or regulation. In addition, FINRA Rule 4370 generally requires that a member maintain a written continuity plan identifying procedures relating to an emergency or significant business disruption, which is akin to adopted Rule 1001(a)(2)(v) requiring policies and procedures for business continuity and disaster recovery plans. Unlike Regulation SCI, however, the FINRA rule does not include the requirement that the business continuity and disaster recovery plans be reasonably designed to achieve next business day resumption of trading and two-hour resumption of critical SCI systems following a wide-scale disruption, nor does it require the functional and performance testing and coordination of industry or sector-testing of such plans, which the Commission believes to be instrumental in achieving the goals of Regulation SCI with respect to SCI entities.

The Commission also believes that, unlike with respect to exchanges, it is appropriate that Regulation SCI not apply to all ATSs. Exchanges, as self-regulatory organizations, play a special role in the U.S. securities markets, and as such, are subject to certain requirements under the Exchange Act and are able to enjoy certain unique benefits.
116

Accordingly, as discussed above, the Commission believes it is appropriate to subject all national securities exchanges to the requirements of Regulation SCI regardless of trading volume.
117

In contrast, in recognition of the more limited role that certain ATSs may play in the securities markets and the costs that will result from compliance with the requirements of the regulation, the Commission believes that it is appropriate to adopt volume thresholds, as discussed below, to identify those ATSs that have the potential to significantly impact the market should an SCI event occur, therefore warranting inclusion within the scope of the regulation. One commenter, in advocating for the application of the regulation to all ATSs, stated that the Commission should not adopt volume thresholds because ATSs may limit trading so as to avoid being subject to the requirements of Regulation SCI.
118

The Commission does not believe that the possibility of some ATSs structuring their business to fall below the thresholds of the rule is a sufficient justification for applying the rule to all ATSs. The Commission notes that, to the extent that an ATS limits its trading so as not to reach the volume thresholds for SCI ATSs, it would have less potential to impact investors and the market and may appropriately not be subject to the requirements of the rules. As discussed further below, the Commission believes that the dual dollar volume threshold for NMS stocks being adopted today is appropriately designed to ensure that ATSs that have either the potential to significantly impact the market as a whole or the potential to significantly impact the market for a single NMS stock (and have some impact on the market as a whole at the same time) will be subject to the requirements of Regulation SCI. Thus, only those ATSs that limit their trading so as to fall below both the single NMS stock threshold and the broad NMS stocks threshold will not be subject to the requirements of Regulation SCI.

116

See supra
Section IV.A.1.a (discussing the definition of “SCI SRO”) and
infra
notes 120-121 and accompanying text. As identified by one commenter, benefits afforded to SROs include, among others, the ability to receive market data revenue and immunity from private liability for regulatory activities.
See supra
note 100.
See also
ATS Release,
supra
note 2, at 70902-03 (discussing generally some of the obligations and benefits to be considered when determining whether to register as a national securities exchange or as a broker-dealer acting as an ATS).

117

See supra
notes 81-83 and accompanying text.

118

See supra
notes 95-96 and accompanying text.

As noted above, one commenter asserted that, if ATSs are subject to the same requirements of Regulation SCI as exchanges, they similarly should be entitled to the benefits afforded to SROs.
119

The Commission notes that, as discussed above, SROs are subject to a variety of obligations as self-regulatory organizations under the Exchange Act—including filing proposed rules with the Commission and enforcing those rules and the federal securities laws with respect to their members—that do not apply to other market participants, including ATSs.
120

Although SRO and non-SRO markets are subject to different regulatory regimes, with a different mix of benefits and obligations, the Commission believes it is appropriate to subject them to comparable requirements for purposes of Regulation SCI given the importance of assuring that the technology of key trading centers, regardless of regulatory status, is reliable, secure, and functions in compliance with the law.
121

At the same time, while questions have been raised as to whether the broader regulatory regimes for exchanges and ATSs should be harmonized, the Commission does not believe it appropriate to delay implementing Regulation SCI or necessary to resolve these issues before proceeding with Regulation SCI. The Commission notes that ATSs have the ability to apply for registration as a SRO should they so wish and, if such application were to be approved by the Commission, such entities could assume the additional responsibilities that are imposed on SROs, as well as avail themselves of the same benefits.

119

See supra
note 100 and accompanying text.

120

See supra
Section IV.A.1.a (discussing the definition of “SCI SRO”);
see also
Section 19(b) of the Exchange Act, 15 U.S.C. 78s(b)(1), and Section 6(b) of the Exchange Act, 15 U.S.C. 78f(b). Because these important regulatory responsibilities are imposed upon SROs, SROs also are afforded certain unique benefits, such as immunity from private liability with respect to their regulatory functions and the ability to receive market data revenue.
See supra
note 116 and accompanying text.

121

But see
discussion
supra
regarding potentially different requirements for ATSs and exchanges, including those relating to SCI ATSs and critical SCI systems.

As noted above, one commenter objected to the regulation's inclusion of ATSs while excluding certain other entities that the commenter believed similarly had the potential to impact the market, concluding that the proposal was therefore arbitrary, capricious, and unfairly discriminatory in nature.
122

At the same time, this commenter stated that it did not recommend that additional entities be included within the scope of the regulation.
123

First, as noted above, the Commission has determined to include ATSs meeting the adopted volume thresholds within the scope of Regulation SCI because of their unique role as markets rather than because of their role as traditional broker-dealers. All broker-dealers are subject to Rule 15c3-5 and other FINRA rules as noted by some commenters, which impose certain requirements

related to the capacity, integrity and/or security of a broker-dealer's systems appropriately tailored to their role as broker-dealers. Further, as noted above, the scope of Regulation SCI is rooted in the historical reach of the ARP Inspection Program and Rule 301 of Regulation ATS (which applies to significant-volume ATSs).
124

The Commission acknowledged in the SCI Proposal that there may be other categories of broker-dealers not included within the definition of SCI entity that, given their increasing size and importance, could pose a significant risk to the market should an SCI event occur.
125

The Commission solicited comment on whether there are additional categories of market participants that should be subject to all or some of the requirements of Regulation SCI and noted that, were the Commission to decide to apply the requirements of Regulation SCI to such additional entities, it would issue a separate release outlining such a proposal and the rationale therefor.
126

As discussed above, the Commission believes that, at this time, the entities included within the scope of Regulation SCI, because of their current role in the U.S. securities markets and/or their level of trading activity, have the potential to pose the most significant risk in the event of a systems issue. Further, the Commission believes that a measured approach that takes an incremental expansion from the entities covered under the ARP Inspection Program is an appropriate method for imposing the mandatory requirements of Regulation SCI at this time. As such, while the Commission believes that the types of entities subject to Regulation SCI as adopted are appropriate, the Commission may consider extending the types of requirements in Regulation SCI to additional market participants in the future.

122

See supra
note 103 and accompanying text.

123

See supra
note 103 and accompanying text.

124

See supra
notes 60-67 and accompanying text.

125

See
Proposing Release,
supra
note 13, at 18138-39.

126

See id.

SCI ATS Thresholds

Several commenters discussed the specific proposed volume thresholds for SCI ATSs, and many offered what they believed to be more appropriate alternative methods for including ATSs within Regulation SCI.
127

For example, some commenters urged the Commission to retain the existing 20 percent threshold under Regulation ATS for purposes of Regulation SCI or asked the Commission to provide further explanation as to why the current threshold under Regulation ATS should be altered.
128

One commenter agreed with the Commission that the 20 percent threshold currently in Regulation ATS might be too high, and suggested using a threshold for ATSs trading NMS stocks of five percent or more of the volume in all NMS stocks during a 12-month period, to be determined once a year in the same given month.
129

Another commenter suggested that the Commission apply its ATS threshold for NMS stocks to only the 500 most active securities.
130

An additional recommendation by one commenter with regard to NMS stocks was to include only those ATSs with five percent or more of at least five NMS stocks with an aggregate average daily share volume greater than 500,000 shares and 0.25 percent or more of all NMS stocks for four of the previous six months, or those ATSs that have three percent or more of all NMS stocks in four of the previous six months.
131

Another commenter suggested retaining Rule 301(b)(6) as part of Regulation ATS, but amending the rule by lowering the average daily volume threshold to 2.5 percent.
132

127

See, e.g.,
Direct Edge Letter at 2; SIFMA Letter at 6-7; BIDS Letter at 6; ITG Letter at 10; and OTC Markets Letter at 11.
But see
BlackRock Letter at 4 (agreeing with the Commission's approach in the SCI Proposal of lowering the thresholds for SCI ATSs from the thresholds in Rule 301(b)(6) of Regulation ATS).

128

See, e.g.,
Direct Edge Letter at 2; and KCG Letter at 10-11.

129

See
SIFMA Letter at 6.

130

See
BIDS Letter at 6.

131

See
ITG Letter at 10.

132

See
OTC Markets Letter at 11. This commenter also suggested leaving in place the existing five percent average daily share volume threshold for the display requirement of Rule 301(b)(3) under Regulation ATS.

One commenter requested clarification on the phrase “0.25 percent or more in all NMS stocks, of the average daily dollar volume reported by an effective transaction reporting plan.”
133

Because there is more than one transaction reporting plan, this commenter asked whether the proposed volume thresholds would be calculated per plan or calculated based on all NMS volume.
134

133

See
SIFMA Letter at 6-7.

134

See
SIFMA Letter at 6-7.

Some commenters provided suggestions with regard to the proposed measurement methodology for the thresholds.
135

A few commenters argued that the proposed time period measurement of “at least four of the preceding six calendar months” is cumbersome to apply in practice and believed that the time period should be over a longer term.
136

For example, two commenters stated that the rule should utilize a 12-month measurement period.
137

Conversely, another commenter generally opposed the thresholds stating that all ATSs should be subject to the rule, but noted that if the rule includes a trading volume metric, the measurement period should be much shorter (such as two to four weeks).
138

In addition, one commenter stated that the measurement should be based on number of shares traded rather than dollar value.
139

135

See, e.g.,
BIDS Letter at 6; KCG Letter at 19; SIFMA Letter at 7; and Lauer Letter at 4-5.

136

See, e.g.,
BIDS Letter at 6; and KCG Letter at 19.

137

See
BIDS Letter at 6; and KCG Letter at 19.

138

See
Lauer Letter at 4-5.

139

See
BIDS Letter at 6.

Two commenters also suggested that ATSs should be given six months after meeting the given threshold in the definition of SCI ATS to come into compliance with Regulation SCI.
140

140

See
KCG Letter at 19; and SIFMA Letter at 7.

The Commission is adopting the thresholds for ATSs that trade NMS stocks and non-NMSs stock as proposed. In setting the thresholds for Regulation SCI, the Commission believes it is establishing an appropriate and reasonable scope for the application of the regulation. Although commenters provided various suggestions for different thresholds, nothing persuaded the Commission that these suggestions would better accomplish the goals of Regulation SCI than the thresholds the Commission is adopting. As discussed below, the Commission has analyzed the number of entities it believes are likely to be covered by the thresholds it is establishing. The Commission recognizes that these thresholds ultimately represent a matter of judgment by the Commission as it takes the step of promulgating Regulation SCI, and the Commission intends to monitor these thresholds to determine whether they continue to be appropriate.

With regard to the threshold for ATSs trading NMS stocks, the Commission has determined to adopt this threshold as proposed. After careful consideration of the comments, the Commission continues to believe that this threshold is an appropriate measure of when a market is of sufficient significance so as to warrant the protections and requirements of Regulation SCI.
141

[Text truncated at 120,000 characters. The full text is on the page linked above.]

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/documents/fr%3A2014-27767. Public record. Not legal advice.
