On paper, producing a whitepaper for a token launch looks like a documentation exercise. In practice, under the Markets in Crypto-Assets Regulation (MiCA – the EU-wide regime governing crypto-asset issuances and service providers), it is the central compliance event of the entire offering. The whitepaper is not a marketing document. It is a regulated disclosure instrument that triggers liability, classification obligations and, in some configurations, a prior notification or authorisation requirement. Getting it wrong does not produce a cleaner filing; it produces an unlawful offer.
The MiCA whitepaper review – the compliance burden falls on every issuer targeting EU or EEA persons, regardless of where the issuer entity is incorporated. A token issued from a BVI company, a Cayman foundation or a Singapore entity is still caught if it is marketed to persons in Germany, France or any member state. That is the cross-border reality that most founding teams discover late. This analysis works through the classification logic, the disclosure requirements, the common structural mistakes, and the decision axes that determine how large the burden actually is for a given token and a given issuer profile.
What the MiCA whitepaper actually requires – and what it does not
A MiCA whitepaper is a prescribed disclosure document that must accompany any public offer of crypto-assets to persons in the EU, subject to limited exemptions. The issuer must publish it, notify the relevant national competent authority (NCA) before the offer, and accept civil liability for material omissions or misleading statements. The obligation is not a voluntary best-practice standard. It is a condition of a lawful offer.
The regulation distinguishes three token categories, each with a different disclosure and authorisation regime. Asset-referenced tokens (ARTs) and e-money tokens (EMTs) face the heaviest requirements, including prior authorisation from the relevant NCA coordinated through ESMA, mandatory reserve rules and ongoing governance obligations. "Other crypto-assets" – the category that captures most utility and governance tokens – require a whitepaper and prior notification, but not full authorisation, provided they remain below the applicable thresholds.
That distinction matters enormously. An issuer that correctly identifies its token as a "other crypto-asset" can proceed to a public offer after notification without seeking a bespoke licence. An issuer that mis-classifies an ART as a utility token faces the full authorisation regime, possible suspension and potential civil liability to purchasers. The classification question is not a technicality at the margin of the compliance project – it is the compliance project.
What the whitepaper does not do is protect the issuer against securities law. MiCA expressly excludes financial instruments within the meaning of the Markets in Financial Instruments Directive (MiFID II) from its scope. If a token is a security under the laws of any relevant member state – or under US federal securities law for any US-nexus offering – MiCA provides no safe harbour. The issuer must work through the securities regime independently, in parallel. We return to that cross-border complication in the section on classification below.
Token classification: the threshold question every issuer faces
Token classification under MiCA turns on the economic substance of the rights the token confers, not on what the issuer calls it. A token labelled "utility" in a whitepaper is not therefore a utility token. ESMA and national competent authorities assess the reality of the instrument: what does the holder actually receive, what rights does the token represent, and against what reference value does it purport to hold its price?
The practical classification analysis runs along three axes. First: does the token represent a claim on a basket of assets, currencies or commodities designed to stabilise its value? If so, it is likely an ART regardless of the label. Second: does it reference a single fiat currency and is it used for payment? That is the EMT path, which places the issuer squarely in the domain of authorised e-money institutions. Third: if neither, the token falls into the "other crypto-asset" category – but only if it is also not a financial instrument under MiFID II.
That third filter is where most complex tokens stall. A token that carries governance rights over a protocol treasury, revenue-sharing rights or any form of profit participation begins to look like a transferable security. The analysis is jurisdictionally variable: French, German and Dutch regulators do not apply identical standards to the same instrument. An issuer selling into multiple EU member states must therefore consider the most restrictive position, not the average.
In our cross-border practice, we consistently see founding teams rely on the label their product counsel assigned at the seed stage. That label was often accurate at seed. By the time the token reaches a public offer, the protocol has matured, the treasury has grown and the economic substance of the instrument has shifted. The classification analysis must be re-run against the token as it exists at the time of the offer, not as it was described eighteen months earlier.
To map your token's classification against MiCA and the parallel MiFID II filter, contact OBOLUS at Map your options. The classification question is best resolved before the whitepaper is drafted, not after. Your token's structure – the entity, the rights attached, the target geography – determines whether you face a notification, an authorisation or a securities-law analysis.
MiCA whitepaper content obligations: what must appear
A compliant MiCA whitepaper for "other crypto-assets" must contain, at minimum, a defined set of disclosures covering the issuer, the project, the token, the offer terms, the rights and obligations of holders, the underlying technology, the risks and the use of proceeds. ESMA has published regulatory technical standards specifying the format and content requirements in detail. The prescribed structure is not optional.
Several of those content obligations create meaningful drafting complexity. The description of rights must be legally precise. "Holders may participate in governance" is not sufficient. The whitepaper must describe the specific rights, the mechanism by which they are exercised, any limitations and the legal basis under which they are enforceable. A vague description exposes the issuer to the same civil liability as a false description.
The risk section is frequently underweight in first drafts. Teams default to boilerplate technology risk disclosures. The MiCA regime expects issuer-specific risks: concentration risk in the token supply, smart-contract risk with an assessment of the specific code, liquidity risk in secondary markets, and regulatory risk given the evolving treatment of the asset class. Generic risk factors drawn from a prior ICO whitepaper will not satisfy an NCA reviewer.
The use-of-proceeds disclosure is another pressure point. If the issuer cannot state, with specificity, how the funds raised will be deployed, the whitepaper fails a core transparency requirement. For projects at an early stage of development, this requires working through the roadmap carefully and being honest about contingencies. Aspirational roadmap language is not a substitute for a credible deployment plan.
Finally, the whitepaper must include a plain-language summary – a defined short-form disclosure suitable for retail readers. This is not the executive summary from the business plan. It is a regulated document in its own right, subject to the same liability standard as the full whitepaper. In our practice, we see the summary treated as an afterthought. It is not.
How does MiCA interact with securities law for token offerings?
MiCA and EU securities law operate as parallel, non-overlapping regimes: a token that qualifies as a financial instrument exits MiCA entirely and enters the prospectus and MiFID II universe. The boundary is not always a clear line, and a token can sit close to it.
For an EU-domiciled issuer, the securities-law analysis runs under the Prospectus Regulation and applicable national implementing legislation. For a non-EU issuer selling to EU persons, the analysis also includes the laws of the member states where the offer reaches investors. A Singapore foundation offering a governance token to German retail purchasers faces both MiCA (if the token is a "other crypto-asset") and, potentially, German securities law (if the token edges toward a transferable security).
The US layer compounds this. A token offered globally that reaches any US person – through a public website, a Telegram group or a centralised exchange accessible from the US – may attract SEC jurisdiction. The SEC's analytical approach under the Howey test assesses whether purchasers invest money in a common enterprise with an expectation of profit derived from the efforts of others. That test runs independently of MiCA classification. A token that is a "other crypto-asset" under MiCA may simultaneously be a security under US federal law.
The practical consequence is that a whitepaper compliant under MiCA is not sufficient for a global offer. An issuer must layer a US securities-law analysis, a geographic restriction strategy (geofencing, IP blocking, purchaser representations) and, where applicable, a separate legal opinion on the token's status in other material jurisdictions. The whitepaper is the EU compliance document. It does not substitute for the broader multi-jurisdictional analysis.
Notification and authorisation: what is the process for EU offers?
For "other crypto-assets," the issuer must notify the NCA of the member state in which it is incorporated at least a defined period before the offer opens. The NCA reviews the whitepaper but does not formally approve it. The regime is disclosure-based, not authorisation-based, for this category. The NCA may raise questions or flag deficiencies; the issuer must address them before proceeding. Publication without notification is an unlawful offer.
For ART and EMT issuers, the process is materially heavier. Prior authorisation from the NCA is required. The application requires a detailed programme of operations, governance documentation, reserve management arrangements and a capital base that meets the regime's requirements. ESMA coordinates on cross-border aspects and can object to a national authorisation in defined circumstances. The authorisation timeline varies by member state and by the complexity of the application, but it is measured in months rather than weeks.
Choice of jurisdiction matters here. Different member states have built different NCA capacities for MiCA applications. Some have developed dedicated crypto-asset supervisory units and published guidance on their review process. Others are working through the regime with less established infrastructure. An ART or EMT issuer choosing its EU base of operations should factor regulatory engagement quality – not just headline speed – into the decision. That choice also determines the passporting footprint: the authorisation in one member state passes to all others, so the quality of the initial authorisation process carries long-term implications.
A non-EU issuer wishing to make a public offer of "other crypto-assets" into the EU must appoint an authorised representative in the EU. That is not a rubber-stamp arrangement. The representative carries regulatory responsibilities and must be satisfied with the whitepaper before filing. Finding a willing, competent representative is a practical obstacle that adds time and cost to the process. We have seen projects fail to account for this entirely and discover the requirement only during NCA pre-notification engagement.
If your application has stalled or your prior notification raised NCA questions, a second read of the whitepaper can surface the structural reason. Reach the OBOLUS regulatory desk at Map your options. We have seen applications recover from NCA objections with a targeted revision – but only where the underlying classification was sound to begin with.
Cross-border compliance: the multi-jurisdictional burden on a global token issuer
A token issuer based outside the EU, selling to a global audience, faces a compliance stack that MiCA alone does not resolve. The MiCA whitepaper obligation covers the EU offer. It does not address the parallel requirements in the UK, Singapore, Hong Kong, Switzerland, the UAE or the United States.
Under the FCA regime in the UK, financial promotions for qualifying cryptoassets must be approved by an authorised person or issued by a registered cryptoasset firm. A whitepaper published for MiCA purposes does not satisfy UK financial promotion requirements without separate compliance steps. The UK is no longer in the EU's regulatory perimeter; MiCA passporting does not extend to it.
Under the MAS Payment Services Act in Singapore, a token that constitutes a digital payment token or a security token attracts distinct licensing and disclosure requirements. The whitepaper may need to be adapted or supplemented to satisfy MAS expectations – or the offer may need to be structured to exclude Singapore persons entirely. The same logic applies under the SFC regime in Hong Kong for tokens with security characteristics.
In the UAE, the VARA regime in Dubai and the FSRA in ADGM each have their own token-offer requirements. An issuer with UAE operations or UAE-based investors cannot rely on a MiCA whitepaper to satisfy VARA or FSRA obligations. The documentation, the regulatory notifications and the structural requirements differ.
The practical consequence for a global token issuer is a compliance matrix: each jurisdiction in scope requires a separate legal analysis, a determination of whether the token is regulated and in what category, and a decision on either complying with the local regime or structuring the offer to exclude that jurisdiction. The whitepaper is the most visible output of that matrix, but it is downstream of the classification and geographic strategy decisions that should come first.
In our cross-border practice, we map the full regulatory exposure before any document is drafted. The whitepaper then reflects those decisions. The alternative – drafting the whitepaper first and then discovering that the offer structure is problematic in three jurisdictions – produces expensive rework and, sometimes, a delayed or aborted launch.
Common mistakes in MiCA whitepaper compliance
The most consequential mistake is treating classification as a legal formality rather than a substantive analysis. Teams that carry a seed-stage "utility token" label into a public offer without re-examining the token's economics are betting the launch on a legal conclusion that may have been superseded by product development. Regulators and, increasingly, private litigants examine substance.
A common structural error is misaligning the issuer entity with the offering entity. MiCA imposes obligations on the person making the offer to the public. If the entity that signs the whitepaper is not the entity that issues the tokens and receives the proceeds, there is a potential liability gap. The corporate structure must be clean and consistent with the whitepaper disclosures before the document is published.
Many issuers underinvest in the ongoing obligations that follow the whitepaper. A published whitepaper is not a one-time document. Material changes to the project – new use of proceeds, changed governance structure, a shift in the underlying technology – may require a revised whitepaper, a new notification and, depending on the change, a suspension of the offer while the revision is processed. Failing to maintain the whitepaper as a live compliance document creates exposure that compounds over time.
A common assumption is that a utility label on a whitepaper settles the legal classification. It does not. The label is a starting point for the analysis, not the conclusion. Both MiCA and parallel securities-law regimes assess the economic substance of the instrument. In our practice, we see the label treated as a shield; regulators treat it as one input among many. The analysis must be defensible at the level of rights, economics and marketing – not just at the level of the word chosen to describe the token.
Decision matrix: which whitepaper regime applies to your token?
An issuer's whitepaper obligations depend on three variables: token classification, issuer domicile and target geography. The following profiles illustrate the main decision branches.
Profile A – EU-incorporated issuer, "other crypto-asset," offer to EU retail persons. The issuer prepares a full MiCA whitepaper meeting the prescribed content requirements, publishes it and notifies the relevant NCA before the offer opens. No authorisation is required, but the NCA may raise questions during the notification period. The issuer accepts civil liability for material inaccuracies. If the offer also reaches UK, Singapore or US persons, separate local compliance steps are required in parallel. Timeline from whitepaper completion to a lawful offer is measured in weeks, but NCA engagement can extend that materially.
Profile B – non-EU issuer, "other crypto-asset," offer reaching EU persons via a public website. The issuer must appoint an EU authorised representative, who files the whitepaper notification with the NCA of the member state where the representative is established. The representative's due-diligence process adds time and cost. The issuer also needs a global geographic restriction strategy for jurisdictions outside MiCA scope. Timeline is typically longer than Profile A given the representative engagement step.
Profile C – any issuer, ART or EMT. Prior authorisation is mandatory. The issuer must be incorporated in the EU or, in certain configurations, appoint an EU authorised entity. The application involves a detailed supervisory review. Capital requirements, reserve arrangements and governance structures must be in place before authorisation is granted. This is a multi-month process. A non-EU issuer wishing to issue an ART or EMT at scale into the EU faces a choice: establish an EU entity and go through full authorisation, or restructure the token to fall outside the ART/EMT definitions.
Profile D – token with security characteristics, any jurisdiction. MiCA does not apply. The issuer enters the prospectus and MiFID II regime in the EU and the relevant securities regime in every other jurisdiction where the offer is made. This is the highest-cost path and the one most frequently arrived at by accident rather than by design. Early classification work avoids it.
Practical illustration: recovering a stalled MiCA notification
In a recent matter, a token issuer incorporated outside the EU had published a whitepaper and opened a public sale before receiving confirmation that its notification with the relevant NCA had been processed. The NCA had raised classification concerns – specifically, that certain revenue-sharing features of the token placed it closer to an ART than to a "other crypto-asset." We were engaged after the fact. We reviewed the token economics, restructured the governance provisions to remove the revenue-distribution feature, and prepared a revised whitepaper with a substantive classification memorandum. The issuer re-notified, addressed the NCA's follow-up questions and resumed the offer under a defensible legal basis. The window between the NCA's initial query and a compliant re-launch was a matter of weeks – shorter than the team anticipated – but only because the underlying economics could be restructured without breaking the product. Not every situation allows for that. Early classification work is significantly less expensive than remediation after an NCA challenge.
Addressing the most common misconceptions about MiCA whitepaper compliance
A common assumption is that a utility label on a whitepaper settles the legal classification. It does not, as the classification analysis above makes clear. The label is a declaration; the regime requires a defensible analysis behind it.
A second misconception is that MiCA applies only to EU-incorporated issuers. It does not. Any issuer making a public offer of crypto-assets to persons in the EU falls within the regulation's reach, regardless of the issuer's domicile. The trigger is the offer to EU persons, not the issuer's address.
A third misconception is that a whitepaper published for one member state automatically satisfies the requirements in all member states. MiCA passporting for "other crypto-assets" does not work that way. The whitepaper notification is made to the NCA of the issuer's home member state, and the offer may then be made across the EU. But the notification and the legal position are anchored in the home-state NCA relationship. An issuer without an EU establishment must think carefully about which member state's NCA is the right notification forum.
Finally, teams sometimes assume that a MiCA-compliant whitepaper eliminates ongoing compliance obligations. It does not. The whitepaper creates obligations that persist for the life of the token: update obligations on material changes, ongoing reporting to the NCA and, for ART/EMT issuers, continuous prudential and governance requirements. The whitepaper is an entry document, not a terminal compliance event.
Related at OBOLUS
- Token offerings and securities for digital-asset businesses – end-to-end legal structuring for token issuers and funds
- Utility token legal opinion in the United States – federal and state-level classification analysis for US-nexus token offers
- Sanctions screening for crypto in Estonia – AML and sanctions compliance for digital-asset operators in the EU
FAQ
Is my token a security?
Whether a token is a security depends on the substance of the rights it confers and the jurisdiction in which the offer is made. Under EU law, MiCA excludes financial instruments from its scope; a token that grants profit-participation, revenue-sharing or equity-like rights may fall under the Prospectus Regulation and MiFID II instead. Under US federal law, the Howey analysis runs independently. A classification opinion must assess the token as it actually functions, not as it is labelled. We assess classification against the substance of rights, not the marketing label.
Do I need a MiCA whitepaper?
An issuer making a public offer of crypto-assets to persons in the EU generally needs a MiCA whitepaper, regardless of where the issuer is incorporated. Limited exemptions apply – for example, offers directed exclusively at qualified investors, offers below a defined number of persons or offers below a value threshold. If your token is an ART or EMT, you need prior authorisation, not merely notification. If your token is a financial instrument under MiFID II, MiCA does not apply and the prospectus regime governs instead. The starting point is always classification.
How should an airdrop be structured legally?
An airdrop that distributes tokens free of charge to existing holders or community members may fall outside MiCA's definition of a public offer, because no consideration is paid. However, if the airdrop is conditioned on promotional activity, wallet connection or other acts of value, regulators may treat it as a conditional sale. A secondary market listing shortly after the airdrop also affects the analysis. The structure should be reviewed against MiCA's offer definition and, for any US-nexus, against SEC guidance on token distributions. Do not assume that "free" means unregulated.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than 70 jurisdictions, on disputes and on-chain asset recovery across more than 25 forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label – and we advise global issuers on the full multi-jurisdictional compliance stack, not just the EU component. To discuss your whitepaper or token structure, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – specialist in MiCA compliance, token classification and cross-border digital-asset structuring for issuers and protocol operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.