WASHINGTON D.C. — In a regulatory enforcement action underscoring the strict accountability demanded of critical market infrastructure providers, the U.S. Securities and Exchange Commission (SEC) announced today that it has formally censured New York-based broker-dealer OTC Link LLC. The firm has also been hit with a $575,000 civil monetary penalty and ordered to cease and desist from future violations.

The sanctions stem from nearly a decade of systemic non-compliance with Regulation Systems Compliance and Integrity (Regulation SCI), a cornerstone framework designed to ensure the technological resilience and security of the U.S. securities markets. According to the SEC’s settled administrative order, OTC Link LLC repeatedly neglected to establish, maintain, and enforce mandatory written policies and procedures governing its alternative trading system, OTC Link ATS, which facilitates trading in over-the-counter (OTC) securities.

Despite repeated warnings, examinations, and flags raised by SEC inspection staff over multiple years, the firm allegedly left critical system security, access control, and vulnerability management frameworks in perpetual draft formats or entirely unaddressed. The penalty highlights the Commission’s growing intolerance for regulated entities that drag their feet on cybersecurity and operational resilience remediation.


Main Facts of the Case

The regulatory enforcement action centers on OTC Link LLC’s operation of OTC Link ATS, an electronic alternative trading system that plays a vital role in the over-the-counter equity market. Because platforms like OTC Link ATS form the technological backbone of modern trading, they are designated as "SCI entities" under federal securities laws. This classification subjects them to rigorous oversight under Regulation SCI, which was adopted by the SEC to reduce the frequency and impact of technological glitches, security breaches, and systemic vulnerabilities.

According to the SEC’s findings, OTC Link LLC ran afoul of multiple provisions of Regulation SCI between August 2016 and March 2025. Specifically, the firm failed to:

  • Establish and Maintain Policies: Implement robust written policies and procedures concerning system security, physical and logical access controls, and application vulnerability management.
  • Conduct Effective Testing and Remediation: Establish structured protocols to test system integrity and promptly remediate identified software or structural flaws.
  • Periodic Review: Fail to conduct adequate periodic reviews of the effectiveness of its existing policies and procedures.

Under the terms of the settlement, OTC Link LLC agreed to the censure, a cease-and-desist order, and the payment of a $575,000 civil penalty without admitting or denying the SEC’s findings.


Chronology of Non-Compliance

The violations identified by the SEC were not isolated incidents but rather part of a protracted pattern of regulatory neglect spanning nearly nine years.

August 2016 – March 2025: The Foundation of Deficiencies

The timeline of non-compliance began in August 2016. During this period, OTC Link LLC operated OTC Link ATS without the comprehensive suite of written policies and procedures required under Regulation SCI. Key operational areas—including how the platform managed security controls, restricted logical access to core infrastructure, and identified or patched application vulnerabilities—lacked the formalized governance required by federal rules.

Multiple Examination Cycles

Throughout the relevant multi-year window, staff members from the SEC’s Division of Examinations conducted routine and targeted examinations of OTC Link ATS. During successive examination cycles, SEC examiners flagged specific, required policies and procedures that the firm had either omitted entirely or left in an incomplete, draft state.

According to the regulatory order, rather than treating these findings as urgent operational alerts, OTC Link LLC repeatedly failed to finalize, implement, or enforce the necessary frameworks. Draft documents languished unapproved, and identified vulnerabilities persisted across multiple calendar years, directly violating the statutory expectation that SCI entities maintain continuous and vigilant oversight of their technological ecosystems.

September 2026: Formal Enforcement and Resolution

The investigative trail culminated on September 22, 2026, when the SEC’s Division of Enforcement formally issued its settled administrative order, concluding years of back-and-forth examinations and securing financial and operational penalties against the broker-dealer.


Supporting Data and Regulatory Framework

To fully understand the gravity of the SEC’s order, it is necessary to examine the specific legal mechanisms under Regulation SCI that OTC Link LLC was found to have breached. Regulation SCI was enacted by the Commission to strengthen the technology infrastructure of the U.S. securities markets, minimize the risk of technological disruptions, and enhance transparency when outages or breaches occur.

Rule 1001(a)(1): Capacity, Integrity, and Security

Rule 1001(a)(1) requires each SCI entity to establish, maintain, and enforce written policies and procedures reasonably designed to ensure that its SCI systems—and, for security standards, its indirect SCI systems—have levels of capacity, integrity, resiliency, availability, and security adequate to maintain the entity’s operational capability. Furthermore, these systems must promote the maintenance of fair and orderly markets.

The SEC found that OTC Link LLC lacked policies reasonably tailored to meet these high standards, exposing its over-the-counter trading venue to unnecessary operational vulnerabilities.

Rules 1001(a)(2) and 1001(a)(3): Review and Prompt Remediation

Beyond the baseline requirement to have policies in place, Regulation SCI imposes ongoing maintenance and enforcement duties:

  • Rule 1001(a)(2) mandates that SCI entities periodically review the effectiveness of the policies and procedures required by paragraph (a)(1) and take prompt action to remedy any deficiencies.
  • Rule 1001(a)(3) requires that these policies and procedures be regularly updated and effectively enforced.

The SEC’s order emphasizes that OTC Link LLC fell short on all fronts. Not only did the firm fail to have the minimum required policies from the outset, but it also neglected to review and update its framework effectively, and—crucially—refused to take "prompt action" to remedy the deficiencies repeatedly highlighted by examiners.


Official Responses and Regulatory Posture

The enforcement action elicited sharp commentary from SEC leadership, signaling a clear message to the broader financial technology and alternative trading system community regarding regulatory compliance.

Laura D’Allaird, Chief of the Division of Enforcement’s Cyber and Emerging Technologies Unit, did not mince words when addressing the firm’s persistent disregard for examination findings.

"OTC Link’s continual failure to remediate deficiencies even after they were repeatedly flagged by Division of Examinations staff reflects a disregard for their findings and the overall examinations process and justifies a meaningful penalty," said Ms. D’Allaird.

She further emphasized that the regulatory expectations for market infrastructure providers are absolute, noting:

"All SCI entities are expected to take their regulatory responsibilities seriously and promptly fix issues when they’re identified."

The Cyber and Emerging Technologies Unit, which spearheaded the investigation, has increasingly focused on ensuring that market participants maintain robust cyber hygiene, secure access controls, and agile vulnerability management programs. By targeting OTC Link LLC, the SEC is signaling that drawing out the remediation process—or treating regulatory exam findings as optional recommendations rather than binding mandates—will invite swift enforcement action and significant financial penalties.


Broader Market Implications

The sanctions against OTC Link LLC carry profound implications for the wider financial services ecosystem, particularly for alternative trading systems (ATSs), electronic broker-dealers, and other entities classified under Regulation SCI.

1. The Cost of Ignoring Examination Findings

One of the most critical takeaways from this case is the severe penalty imposed for ignoring repeat warnings. Financial institutions frequently undergo examinations by regulatory bodies like the SEC or FINRA, resulting in comment letters, deficiency notices, and recommendations. Historically, some firms have treated these findings as low-priority items, leaving corrective actions in perpetual drafting stages.

The OTC Link LLC case demonstrates that failing to remediate issues flagged during successive examination cycles transforms routine administrative feedback into willful non-compliance, inviting aggressive enforcement actions and heightened financial sanctions.

2. Heightened Scrutiny on Over-the-Counter Infrastructure

While much of the public discourse surrounding market technology focuses on major national securities exchanges (such as the NYSE or Nasdaq), over-the-counter markets play a vital, liquidity-providing role for smaller, micro-cap, and international equities. Ensuring that systems like OTC Link ATS maintain robust integrity, security, and resiliency is essential for protecting retail and institutional investors who trade in these alternative venues. The SEC’s action underscores that regulatory oversight under Regulation SCI extends equally to niche and specialized trading platforms.

3. Operationalizing Cybersecurity and Vulnerability Management

As cyber threats grow increasingly sophisticated, regulatory bodies are moving away from purely check-the-box compliance and demanding operational proof of system security, access control, and vulnerability management. For SCI entities, this means that having written policies is only half the battle; those policies must be active, regularly tested, critically reviewed, and vigorously enforced.

If an entity identifies a vulnerability—or is told by examiners that its vulnerability management framework is inadequate—it must mobilize resources to resolve the issue immediately. Delaying remediation leaves firms vulnerable not only to cyber threats and operational outages but also to severe regulatory liability.

Conclusion

The SEC’s $575,000 penalty and censure of OTC Link LLC serves as a stark reminder of the legal and financial risks associated with lax technological governance. As financial markets become increasingly digitized and interconnected, the regulatory tolerance for unaddressed system vulnerabilities and ignored examination findings has evaporated. For OTC Link LLC, the settlement closes a nearly decade-long chapter of compliance failures, but for the broader industry, it marks an urgent call to audit, update, and strictly enforce the operational safeguards that underpin modern market integrity.