TL;DR:
- A Civil Investigative Demand is a mandatory tool used by U.S. agencies to compel documents and testimony during an investigation. Respondents must suspend data deletion, notify counsel, and avoid voluntary disclosures to preserve privilege and compliance. Engaging experienced legal counsel early and carefully managing scope are essential for a successful response.
A Civil Investigative Demand (CID) is a mandatory investigatory tool issued by U.S. agencies including the FTC, SEC, and CFPB to compel documents and testimony during an active investigation. Ignoring or mishandling one can result in contempt proceedings, expanded subpoenas, or criminal referral. The single immediate action: stop all routine data deletion, issue a litigation hold, and contact experienced outside counsel before responding to the agency in any form.
Immediate must-do items on receipt:
- Suspend all document-retention schedules and automated deletion policies across every relevant system
- Notify your General Counsel, Chief Compliance Officer, and CEO within hours, not days
- Identify custodians named or implied by the CID (employees, wallets, node operators, cloud vendors)
- Engage outside counsel with crypto regulatory experience before any agency contact
- Log the date, time, and method of CID receipt for the official response record
What to say and what not to say if an investigator contacts you: Say nothing substantive without counsel present. Confirm receipt if pressed, state that counsel has been engaged, and provide counsel’s contact information. Do not volunteer documents, data, or explanations.
Pro Tip: Treat every CID as high-risk from the first interaction. Privilege can be waived in a single unguarded phone call, and that waiver cannot be undone. Practitioners consistently warn against treating a CID as a routine information request — engage counsel immediately.

Table of Contents
- What should you do in the first 24–72 hours after receiving a CID?
- Phase 1 — How do you legally evaluate a CID before responding?
- Phase 2 — How do you negotiate with a regulator to narrow a CID’s scope?
- Phase 3 — How do you preserve and forensically collect crypto evidence?
- Phase 4 — How do you prepare a formal production and oral testimony?
- How do you coordinate simultaneous multi-agency crypto investigations?
- What are the typical timelines and costs for a CID response?
- Key Takeaways
- Why the conventional wisdom on CID response often fails crypto companies
- Murphyslawcrypto offers direct CID response support for crypto firms
- Authoritative U.S. sources and further reading
- FAQ
What should you do in the first 24–72 hours after receiving a CID?
The first three days set the trajectory of the entire response. Move fast on process, slow on substance.
Notification protocol: Inside the company, the GC, CCO, and CEO must be informed on day one. Outside, retain crypto-experienced regulatory counsel immediately. The benefits of early regulatory counsel are concrete: narrowed scope, preserved privilege, and lower total cost.
Litigation hold: Issue a written litigation hold order to all custodians covering emails, Slack, internal wikis, wallet keys, node logs, exchange API records, and cloud-provider data. Copy your IT and DevOps leads. The hold must be documented and acknowledged in writing by each recipient.
Initial triage: Determine whether the CID is administrative (FTC or CFPB) or securities-related (SEC), and whether parallel agencies are involved. CFPB CID language explicitly warns that information may be shared with other federal, state, or local law enforcement and used in civil or criminal proceedings.
Secure communications: Route all internal CID-related discussion through counsel-supervised channels. Mark communications as “Privileged and Confidential — Attorney-Client Communication.” Avoid group chats, shared drives, or any channel that lacks access controls.
Pro Tip: Do not allow any employee to contact agency staff directly before counsel has reviewed the full CID text. Even a well-intentioned clarifying call can create a record that narrows your negotiating position.
Phase 1 — How do you legally evaluate a CID before responding?
Legal evaluation is not a formality. It is the foundation of every subsequent negotiation and production decision.
Evaluation checklist:
- Confirm the issuing agency’s jurisdiction over your products and business model
- Map each document request to specific custodians, date ranges, and data systems
- Identify privilege categories: attorney-client communications, work product, and third-party materials shared under common interest
- Flag requests that are facially overbroad, seek foreign-located materials, or impose undue burden
- Assess whether the CID satisfies the Morton Salt standard: a plausible investigative purpose, relevance, and reasonable particularity
Courts have denied petitions to quash when recipients fail to meet and confer or withhold materials without documented justification. Build your record before you challenge anything. Nexo’s petition to modify a CFPB CID illustrates the jurisdictional angle: the company argued the CFPB lacked authority over certain products, but the CFPB denied the petition and required corporate testimony, underscoring how difficult it is to exclude products from investigation on jurisdictional grounds alone.
Pro Tip: Prepare a privilege sampling protocol before any collection begins. Producing large, unvetted datasets without a sampling review is one of the fastest ways to inadvertently waive privilege across an entire document category.
Phase 2 — How do you negotiate with a regulator to narrow a CID’s scope?
Negotiation is where well-prepared counsel earns its fee. The meet-and-confer is not a courtesy call; it is a structured negotiation with a documented record.
Negotiation objectives: Reduce the number of custodians, narrow date ranges, agree on acceptable production formats, and request a protective order or confidentiality designation for sensitive business information.
Effective meet-and-confer strategy requires disclosing enough to demonstrate good faith while reserving your strongest legal arguments for a petition to quash or motion to modify. Oral concessions must be confirmed in writing immediately after the call — an email summary sent to agency counsel the same day creates the record you will need if the agency later disputes what was agreed.
Practical concessions to seek: staggered productions by custodian or date range, agreed search terms with hit-count reporting before full review, sampling of large data sets, and explicit protocols for handling privileged materials inadvertently produced.
When to escalate: If the agency refuses reasonable narrowing and the burden is genuinely disproportionate, file a petition to modify. Document every refusal. A well-built meet-and-confer record is the predicate for any successful petition.
Pro Tip: Use narrow, verifiable technical proposals — ledger hashes, specific transaction ID lists, defined wallet address sets — rather than vague volume commitments. A precise technical production format gives the agency what it needs while limiting your exposure to bulk data exports.
Phase 3 — How do you preserve and forensically collect crypto evidence?
Crypto investigations probe both on-chain activity and internal communications. An integrated strategy pairing blockchain forensic snapshots with targeted custodian collections is more defensible than broad, unfocused data dumps.
Forensic preservation checklist:
- Take hash-verified on-chain snapshots of relevant wallet addresses and transaction histories at the time of the hold
- Secure wallet private and public keys under dual-control custody with a written access log
- Preserve node logs, exchange API records, and off-chain backups with write-blocking to prevent alteration
- Issue cloud-provider legal holds to AWS, Google Cloud, or other vendors hosting relevant data
- Capture volatile data (RAM states, temporary keys) immediately before systems are powered down or migrated
Custodian mapping: Identify both human custodians (developers, operations staff, executives) and system custodians (exchange accounts, custodial wallet providers, third-party KYC vendors). Document each custodian’s data sources and the hold acknowledgment date.
Chain-of-custody: Every collected item must carry a hash value, collection timestamp, collector identity, and storage location. Use forensic-grade tools and maintain a custody log that travels with the data through review and production.

Pro Tip: Isolate a minimal, defensible subset for early production while continuing targeted parallel collection. This controls cost, demonstrates good faith to the agency, and preserves your ability to negotiate the scope of later productions. See crypto fraud evidence preservation best practices for chain-of-custody templates.
Phase 4 — How do you prepare a formal production and oral testimony?
Production quality determines whether the agency closes its inquiry or expands it.
A privilege log is not a formality — it is a legal document. Every withheld item must be described with sufficient specificity to allow the agency to assess the privilege claim without revealing the privileged content itself. Over-claiming privilege invites a motion to compel; under-claiming waives protection you cannot recover.
Production format: Produce native files where agreed, with metadata intact. Use encrypted containers with documented decryption keys provided separately. Confirm acceptable formats in writing before transmitting anything.
Witness preparation: For oral testimony, prepare corporate representatives with mock examination sessions covering the likely scope of questions, document tie-ins, and talking points that preserve privilege. Review executive personal liability risks before any witness sits for testimony.
Pre-transmission QA: Run a final quality-assurance pass: verify search-term hit counts, review a random sample of produced documents, confirm redaction protocols, and check that no privileged materials are included in the production set.
Pro Tip: Prepare a short custodian affidavit or executive declaration to accompany complex technical productions. It contextualizes the data for agency reviewers and reduces follow-up requests.
How do you coordinate simultaneous multi-agency crypto investigations?
Crypto investigations frequently involve simultaneous audits by the SEC, FTC, CFPB, NYDFS, and state regulators. A single inconsistent statement across agencies can invite further inquiry across all of them.
Coordination checklist:
- Designate a single internal point of contact who owns all agency communications and escalation decisions
- Maintain a central, privileged document repository accessible only to counsel and authorized staff
- Establish consistent privilege positions across all agencies and document them in a written investigation playbook
- Track each agency’s requests, productions, and oral communications in a cross-agency intelligence log
- Map productions across agencies so one agency’s file does not create exposure to another
Jurisdictional overlap: SEC and CFPB jurisdiction can overlap on crypto products with both securities and consumer-finance characteristics. For SEC-related compliance risks, the analysis turns on whether the product is a security; for CFPB, the focus is consumer-finance activity. Conflicting positions on the same product across agencies is a serious strategic error. For cross-border dimensions, digital asset cross-border legal considerations add another layer of complexity that the investigation playbook must address.
Pro Tip: Build a centralized investigation playbook on day one. Assign clear decision rights: who can authorize a production, who escalates to the CEO, and who speaks to agency staff. Ambiguity in those roles is where costly mistakes happen.
What are the typical timelines and costs for a CID response?
| Phase | Typical Duration | Primary Cost Drivers |
|---|---|---|
| Evaluate | 1–3 weeks | Outside counsel review hours, privilege analysis |
| Negotiate | 2 weeks | Meet-and-confer calls, petition drafting if needed |
| Preserve and collect | 4–12 weeks | Forensic vendor fees, custodian count, data volume |
| Produce and testify | 4 weeks | Privilege review hours, redaction, witness prep |
Total elapsed time for a contested CID response commonly runs four to twelve months, depending on agency responsiveness and the complexity of the data environment.
Primary cost drivers: data volume, number of custodians, forensic vendor fees, privilege-review hours, and litigation motion risk if the agency rejects negotiated narrowing. Enterprise digital asset legal risks compound these costs when governance structures are immature.
Noncompliance risks:
- Contempt proceedings and monetary sanctions
- Expanded subpoenas covering additional custodians or time periods
- Referral to criminal authorities, particularly where obstruction is alleged
- Adverse inference instructions in subsequent civil litigation
Bring in outside forensic and litigation counsel before costs escalate. The single most common mistake is handling a CID in-house without outside counsel: misapplied privilege designations and poorly documented productions regularly lead to waiver and litigation exposure.
Key Takeaways
A successful crypto civil investigative demand response requires preserving evidence immediately, engaging outside counsel before any agency contact, negotiating scope aggressively, and documenting every step for the audit trail.
| Point | Details |
|---|---|
| Preserve first, always | Issue a litigation hold within hours of receipt; suspend all automated deletion policies. |
| Engage counsel immediately | Outside counsel with crypto regulatory experience must be retained before any agency communication. |
| Negotiate scope in writing | Convert every oral concession into a written confirmation the same day it is made. |
| Forensic integrity is non-negotiable | Hash-verified snapshots and chain-of-custody logs protect every production from challenge. |
| Murphyslawcrypto’s approach | Murphyslawcrypto applies a documentation-first, privilege-centric four-phase framework across all CID matters. |
Why the conventional wisdom on CID response often fails crypto companies
Most general-practice guides treat a CID as a document-production exercise. In crypto, that framing misses the real exposure. The on-chain record is permanent and publicly accessible, which means the agency often knows more about your transaction history before it sends the CID than most companies realize. The negotiation is not just about limiting what you produce; it is about controlling the narrative around what the agency already has.
The firms that handle CID responses well in this space do two things differently. First, they pair blockchain forensic analysis with legal strategy from day one, so counsel understands the on-chain record before the agency asks about it. Second, they treat the meet-and-confer as a strategic disclosure event, not an administrative hurdle. Disclosing a narrow, technically precise data set early often closes an inquiry faster than months of resistance.
Liam Murphy, Esq., founder of Murphyslawcrypto, has litigated major crypto matters including Celsius, Terraform Labs, and BitMEX. That courtroom experience shapes how the firm approaches CID responses: defensively, with documentation-first discipline, and with a clear view of where an investigation can escalate into civil or criminal proceedings. Clients who engage early consistently see narrower scopes, lower total costs, and less business disruption than those who wait.
Murphyslawcrypto offers direct CID response support for crypto firms
When a CID arrives, the gap between a firm with experienced crypto regulatory counsel and one without becomes apparent within the first 72 hours. Murphyslawcrypto provides immediate incident response, meet-and-confer negotiation, forensic collection coordination, and production and testimony preparation, mapped directly to the four phases described in this guide.

Liam Murphy, Esq. and the Murphyslawcrypto team have handled enforcement defense across the SEC, FTC, CFPB, and NYDFS, with litigation experience in some of the most significant crypto matters in U.S. history. The firm offers emergency engagement for CID recipients who need counsel in place before the first agency deadline. For crypto businesses that want to get ahead of regulatory risk before a demand arrives, the firm’s crypto compliance consulting practice builds the internal programs that reduce exposure at the source. Contact Murphyslawcrypto directly through the services page to discuss your situation and engage counsel today.
Authoritative U.S. sources and further reading
- FTC CID enforcement orders: The FTC’s order denying Spread Technologies’ petition to quash is the primary reference for understanding what happens when a recipient fails to meet and confer.
- CFPB CID materials: The Nexo Financial petition illustrates jurisdictional arguments and the CFPB’s investigative authority over crypto products.
- Federal Lawyer practitioner guide: The Federal Lawyer’s CID response guide covers the four-phase framework and privilege-preservation best practices in detail.
- IC3 cryptocurrency resources: The IC3 cryptocurrency page provides context on how law enforcement traces on-chain activity, relevant when assessing what agencies already know.
- Jurisdiction-specific guidance: For securities questions, consult SEC materials directly. For consumer-finance questions, consult CFPB orders. For state licensing and BitLicense issues, consult NYDFS guidance. Cross-reference these sources when preparing petitions or meet-and-confer correspondence.
FAQ
What is a civil investigative demand in crypto regulation?
A CID is a mandatory pre-litigation investigatory tool issued by agencies such as the FTC, SEC, and CFPB to compel documents, data, and testimony from crypto companies under investigation. Failure to comply can result in federal court enforcement and contempt sanctions.
Can you challenge or narrow a crypto CID?
Yes. Recipients can file a petition to quash or modify based on overbreadth, undue burden, jurisdictional limits, or privilege. A documented meet-and-confer record is a prerequisite; courts have denied petitions where recipients skipped that step.
How long does a CID response typically take?
The full response process commonly runs four to twelve months across the four phases: evaluation, negotiation, forensic collection, and production or testimony. Timeline depends on data volume, custodian count, and whether the agency accepts negotiated narrowing.
What happens if a crypto company ignores a CID?
Noncompliance can lead to contempt proceedings, monetary sanctions, expanded subpoenas, and referral to criminal authorities. Agencies can enforce CIDs in federal court, and courts have consistently granted enforcement petitions against non-responsive recipients.
When should a crypto company contact Murphyslawcrypto about a CID?
Immediately upon receipt. Murphyslawcrypto provides emergency CID response engagement covering all four phases, from litigation hold and privilege analysis through forensic collection and testimony preparation, with experience across SEC, FTC, CFPB, and NYDFS matters.
This article is general legal information, not legal advice for your specific situation. Confirm current regulatory requirements with a qualified attorney or the relevant primary source before taking action.