General solicitation is broad advertising or public marketing used to reach potential investors in a securities offering. When a private placement uses it, issuers must verify accredited investor status instead of relying on check-the-box self-attestations. That verification step is intended to reduce the risk of selling to ineligible investors.
Expanded Definition
General solicitation is not a technical control, but a securities-law distribution method that changes how a private offering is conducted. In practice, it means the issuer, placement agent, or platform is actively marketing the opportunity to the public rather than limiting outreach to a pre-existing, substantive relationship. Under U.S. practice, that shift matters because public-facing promotion typically removes the assumption that investors are already known and eligible, so verification obligations become stricter.
Definitions vary across jurisdictions and offering structures, and no single standard governs this yet across all private-market channels. In compliance terms, the relevant issue is whether the communication is broad enough to be treated as solicitation, which can affect exemption eligibility, investor qualification, recordkeeping, and advertising review. For a governance baseline, practitioners often map these controls to the NIST Cybersecurity Framework 2.0 mindset of documented policy, evidence, and repeatable process. The most common misapplication is treating public marketing as if it were a private, relationship-based raise, which occurs when teams publish outreach without aligning the campaign to exemption rules and investor-verification procedures.
Examples and Use Cases
Implementing general solicitation rigorously often introduces friction in capital formation, requiring organisations to weigh broader investor reach against heavier verification and disclosure overhead.
- A startup runs a public webinar and follows up with a private placement, then verifies accredited status before allowing subscription documents to proceed.
- An issuer advertises on social media, which triggers review of whether the message constitutes public promotion and whether the exemption still applies.
- A portal lists a private offering for inbound leads, then requires documentary investor verification instead of relying on a self-certification checkbox.
- A fund manager uses email campaigns to reach prospects and documents when communications moved from relationship-based outreach to general solicitation.
- A compliance team references the Ultimate Guide to NHIs to compare how public exposure increases governance burden, even when the core asset being managed is different.
This is similar to identity governance in that broader exposure demands stronger proof before access is granted, a principle also echoed in the NIST Cybersecurity Framework 2.0 emphasis on controlled, auditable processes.
Why It Matters in NHI Security
General solicitation matters in NHI security because public-facing distribution amplifies risk when secrets, API keys, service accounts, or investor-adjacent workflows are exposed through marketing systems, shared portals, or unvetted automation. Once a process is broadly visible, attackers and opportunistic actors can use the same surface area that legitimate prospects use. The governance lesson is straightforward: when a process is opened to the public, verification and monitoring must become more rigorous, not less.
NHI Mgmt Group notes that 79% of organisations have experienced secrets leaks, with 77% of those incidents causing tangible damage, underscoring how quickly exposure can become operational harm. That pattern is relevant here because public distribution often expands the number of systems, people, and integrations that touch sensitive workflow data. Practitioners should also consider the control implications described in the Ultimate Guide to NHIs, especially where access paths and credential handling are involved.
Organisations typically encounter the compliance and security consequences only after a public campaign, investor complaint, or access incident, at which point general solicitation becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 provides the primary governance reference for this term.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 | General solicitation requires documented oversight and review of externally facing communications. |
Establish review and approval controls for public fundraising communications before publication.
Related resources from NHI Mgmt Group
- What breaks when organisations use fast general-purpose hashes for password storage?
- Why do age verification controls fail more often at the threshold than in general use?
- What is the difference between build-level blocking and general device compliance checks?
- How should teams decide between a general policy engine and a purpose-built authorization layer?