Legal & Tax Updates [Back to list]
SEC Issues Guidelines for Blockchain-Based Digital Signing and Authentication through VERITAS
The Securities and Exchange Commission (SEC) has promulgated Memorandum Circular No. 23, Series of 2026, providing guidelines of using the Verification of Electronic Records and Information Trust and Authentication System (“VERITAS”) for blockchain-based document signing and authentication. The regulatory initiative builds upon SEC Memorandum Circular No. 10, Series of 2024, which introduced the Electronic SEC Universal Registration Environment (“eSECURE”) to centralize digital identity and credentialing for transacting parties. Consistent with national efforts to improve regulatory efficiency, VERITAS uses blockchain technology to maintain decentralized, tamper-evident, and cryptographically secure records, thereby ensuring the authentication, integrity, and non-repudiation of electronic submissions.
The Circular applies broadly to all individuals with a credentialed eSECURE account including incorporators, directors, officers, authorized representatives, and other persons who will sign and submit documents to the SEC on behalf of a juridical entity. It also covers All corporations, partnerships, and other juridical entities registered with the SEC
To use the platform, signatories must have a valid, active, and credentialed eSECURE account and undergo an electronic Know Your Customer (eKYC) procedure involving government-issued identification verification and liveness detection. The system also requires digital signing certificates and public-private keypairs to be generated on-chain directly by VERITAS, expressly prohibiting the use of externally issued digital certificates, including those issued by Commercial Certificate Authorities.
Operationally, each uploaded document undergoes a cryptographic hashing process that generates a unique digital fingerprint. Authorized signatories then sequentially sign the fingerprint using their private keys. Each signing event modifies the document and generates a new hash, which is appended to the blockchain together with an immutable audit trail containing the signatory’s encrypted identity, timestamp, and IP address. After all signatories have executed the document, the SEC finalizes it by attaching a visible Philippine National Public Key Infrastructure (PNPKI) Agency Certificate seal and QR code to each page, signing the final hash, and storing the hashes of all versions on the blockchain.
The digital version executed through VERITAS is recognized as the official and original record, generally eliminating the need to submit physical hard copies. Printed reproductions are considered secondary duplicates and must bear a notation stating that the original is in digital format. Note that transactions recorded on the blockchain are permanent and immutable. Once a document is signed and recorded, it cannot be altered or deleted. Any amendments, supplements, or corrections require restarting the entire submission and signing process with a revised document. The SEC reserves the right to conduct post-evaluation verifications and may withhold recognition if a document is non-compliant or if the integrity of the signing process has been compromised.
The use of VERITAS for digital signing and authentication of documents is currently optional. The existing digital authentication via the Electronic Submission Authentication portal (“eSAP”) remains available and operational.
