A software company in Prague prepares to tokenize a tranche of corporate bonds. The project looks clean on paper – the tokens carry defined yield rights, a fixed redemption date and a named issuer. Then the lawyers arrive. The question is no longer "how do we sell these tokens?" It is "are we issuing transferable securities under Czech and EU law, and if so, to whom, on what prospectus basis, and through which distribution chain?" Get that classification wrong and the offering becomes an unregistered securities distribution, with consequences that reach the issuer's directors personally.
Security token offering structuring in Czech Republic turns on a layered analysis: Czech civil and capital-markets law, the EU prospectus and MiFID II regimes, and – since January 2025 – the live MiCA (Markets in Crypto-Assets Regulation) framework supervised by the Czech National Bank (CNB) as the national competent authority. The classification outcome determines whether the issuer needs a prospectus, a MiCA whitepaper, or both – and shapes every downstream decision on legal entity, investor eligibility, distribution model and banking. This page sets out the structured path through that analysis for a business-stage issuer.
The sections below address the regulated perimeter, the classification engine, the document set, the cross-border reality of token distribution, common structural mistakes, and the decision point at which outside counsel becomes essential.
What is the regulated perimeter for security token offerings in Czech Republic?
In Czech Republic, a token that embeds or represents transferable-security rights falls inside the capital-markets perimeter regulated by the CNB – and simultaneously inside the EU-wide regime built on the Prospectus Regulation, MiFID II and, where the token does not qualify as a financial instrument, MiCA. The CNB administers all three layers as the national competent authority.
Czech law defines a transferable security by reference to EU frameworks: a financial instrument that is capable of being traded on a capital market and that confers rights equivalent to a share, debt instrument or other enumerated category. A token that digitally represents any such instrument is a security token under that analysis – regardless of what the issuer calls it in the whitepaper. The CNB has signalled alignment with ESMA's approach to token classification, which rests on substance over form.
Tokens that do not meet the transferable-security test are assessed under MiCA. MiCA distinguishes three non-security categories: asset-referenced tokens (ARTs), e-money tokens (EMTs) and "other" crypto-assets – the last category covering most utility and payment tokens. An issuer of an ART or EMT requires authorisation under MiCA. An issuer of an "other" crypto-asset must publish a MiCA-compliant whitepaper notified to the CNB.
In our cross-border practice, the most common error at this stage is assuming that the classification analysis is binary – security or not. In practice, a token can satisfy multiple definitional tests simultaneously, particularly when it carries yield rights alongside governance or access features. Each right has to be assessed independently.
How does token classification actually work under Czech and EU law?
Token classification under Czech and EU law applies a substance-over-label test: the legal character of a token is determined by the rights it confers on the holder, not the name the issuer assigns to it. A "utility token" that pays a fixed quarterly yield is not utility. It is debt.
The analytical steps are as follows. First, the issuer maps every right the token confers: economic rights (yield, redemption, profit-share), governance rights (voting, approval), access rights (services, discounts) and any combination. Second, those rights are tested against the Czech and MiFID II definitions of financial instruments – specifically shares, bonds, depositary receipts and related instruments. Third, where rights are ambiguous, ESMA guidance on the classification of crypto-assets as financial instruments provides the interpretive benchmark the CNB follows.
The decisive question is whether the token gives the holder a claim on the economic performance of the issuer or a third party – because that structure typically satisfies the transferable-security or collective-investment-scheme tests, regardless of any utility wrapper. Governance rights alone do not typically trigger the securities regime, but they can affect the MiCA whitepaper content requirements.
A common structural pressure-point: token issuers often want to include a secondary-market trading mechanism in the smart contract. The moment tokens become tradeable on a secondary market, the "capable of being traded on a capital market" limb of the transferable-security definition becomes live. That changes the prospectus analysis even for instruments that might otherwise qualify for a MiCA whitepaper route.
We assess classification against the substance of rights, not the marketing label. That means reviewing the token's constitutional documents – the smart contract, the terms and conditions, the issuer's articles – alongside the whitepaper draft. The legal opinion that emerges from this process is what a reputable custodian, exchange and institutional investor will require before touching the token.
Related at OBOLUS
- Token Offerings & Securities practice – end-to-end legal structuring for digital-asset issuances across jurisdictions
- Token sale agreement drafting under UAE VARA – how the VARA regime structures token sale documentation in Dubai
- MLRO and compliance officer function – the disputes angle – what happens to compliance officers when token structures are challenged
The classification analysis above describes the standard path. Your facts – the entity structure, the investor profile, the secondary-market design – change the analysis materially. For a scoped classification review of your token, contact OBOLUS at info@oboluslaw.com.
What does the full securities route require for a Czech STO?
Where a token qualifies as a transferable security, the Czech offering falls inside the Prospectus Regulation, administered by the CNB as competent authority for Czech-domiciled issuers. The issuer must either produce a full prospectus approved by the CNB or rely on one of the recognized exemptions – each of which imposes its own investor-eligibility and denomination conditions.
The main exemptions available to an inbound issuer include the qualified-investor-only route (limiting distribution to professional and institutional counterparties), the small-offer exemption for offers below the applicable EU threshold, and the denomination-per-unit exemption for high-face-value securities. Each exemption narrows the distribution strategy and affects the secondary-market design.
Beyond the prospectus question, a security token offering in Czech Republic engages MiFID II. The issuer or its distribution partner typically needs to be either an authorized investment firm or to engage a regulated intermediary as the placing agent. Distributing transferable securities to Czech-resident retail investors through a non-authorized channel is a regulatory violation – and, again, it is not cured by calling the token a utility instrument.
The document set for a securities-route STO includes the prospectus or the legally grounded exemption memorandum, the token terms (a legally binding instrument setting out every right the token confers), the subscription agreement, the smart-contract audit report, and – where the issuer is relying on an exemption – a register of eligible investors. Czech law requires the prospectus to be published in Czech or in a language accepted by the CNB.
One micro-matter illustrates the sequencing risk. In a recent transaction, a mid-sized Central European technology company approached us after issuing corporate yield tokens to approximately 200 investors across several EU member states. The tokens had been distributed under a whitepaper alone, without prospectus or exemption analysis. We worked through a structured remediation: a CNB engagement letter, a voluntary filing of the relevant exemption basis, a restated term sheet issued to all existing holders, and a revised token structure for the next issuance tranche. The business avoided enforcement action; the next tranche closed on a clean legal basis within a matter of months.
When does the MiCA whitepaper route apply – and what does it demand?
Where the token does not qualify as a transferable security, MiCA applies, and the issuer of an "other" crypto-asset must publish a compliant whitepaper and notify it to the CNB before any public offer in Czech Republic or elsewhere in the EU. The passporting mechanics of MiCA mean that a single notification to one EU national competent authority covers the entire EU/EEA market – a significant structural advantage for issuers seeking pan-European distribution.
MiCA's whitepaper requirements are prescriptive: the document must include a detailed description of the issuer, the token, the rights and obligations attached to it, the technology and smart contract, the risks and the redemption mechanics. The CNB reviews and may request amendments within the statutory review window before publication is permitted.
The MiCA whitepaper route is not available for tokens that, on proper classification, are transferable securities. Issuers who publish a MiCA whitepaper for a token that a regulator subsequently classifies as a security have not cured the securities-law exposure – they have added a second regulatory failure. This is precisely the scenario that a structured classification analysis prevents.
For ART and EMT issuers, MiCA requires a full authorization from the CNB (or another EU NCA), with ongoing capital, reserve, and governance requirements that go well beyond the whitepaper path. We regularly advise stablecoin issuers and payment-token projects on whether their instruments fall into the ART or EMT categories and on the implications for their corporate structure.
How does cross-border distribution affect the Czech STO structure?
Very few Czech-domiciled token offerings are sold exclusively to Czech-resident investors. The practical reality is that a token issuer in Prague may be targeting institutional investors in Germany and Austria, retail participants in Slovakia and Poland, and structuring treasury through a holding entity in Luxembourg or the Netherlands. Each additional jurisdiction adds a regulatory layer that must be mapped before the offer goes live.
For transferable-security tokens, the EU Prospectus Regulation's passporting mechanism is the primary tool: a prospectus approved by the CNB may be notified to NCAs in any other member state for cross-border distribution, subject to translation requirements. This makes Czech Republic a viable home-state jurisdiction for pan-European STOs – provided the issuer is prepared to meet the CNB's approval standards and timeline.
For MiCA-route tokens, passporting works directly through the whitepaper notification: notify the CNB, receive no objection within the statutory window, and the offer can proceed across the EU. Non-EU distribution – to US persons, UK residents or investors in jurisdictions outside MiCA scope – requires a separate analysis under the laws of each target jurisdiction. Distribution to US persons almost always raises Securities Act questions; UK distribution engages FCA financial-promotion rules.
The banking and custody dimension compounds the cross-border complexity. Czech banks remain cautious about STO-related accounts. In our experience, issuers who approach a bank without a completed legal opinion, a clean KYC/AML package and a documented investor eligibility process will find account-opening difficult, regardless of the legal merit of the structure. We work with issuers to prepare that package before the first bank conversation – and, where Czech banking relationships are unavailable, we engage allied counsel in jurisdictions where regulated digital-asset banking is more established.
What are the most common structural mistakes in Czech Republic STOs?
Four structural mistakes recur in the Czech STO market, and each one creates a different category of legal exposure.
The first is label-driven classification. An issuer decides that the token is "utility" because it grants access to a platform, then adds yield and governance rights because investors want them. The label is not updated. The legal position is that the token is a security. The market launch is an unregistered securities offering. This is the most frequent error we encounter, and it is the one AUDIENCE_PAIN addresses directly: mis-classifying a token converts a product launch into a regulatory incident.
The second is premature publication of a whitepaper. An issuer publishes a MiCA-format whitepaper before the CNB notification window has been observed, or publishes a whitepaper for an instrument that should have a prospectus. Either path invites enforcement.
The third is unstructured secondary-market design. Issuers build token-to-token swap mechanisms or list on a non-EU exchange without considering whether those secondary activities trigger additional licensing obligations in Czech Republic or in the jurisdictions where the exchange operates.
The fourth is inadequate investor eligibility control. An STO that relies on the qualified-investor exemption must have a documented process for verifying that every subscriber meets the definition. Tokens distributed to non-qualified investors under a qualified-investor exemption defeat the exemption entirely.
A common assumption is that a utility label on a whitepaper settles the legal classification. It does not. The CNB – and any court asked to review the matter – will look through the label to the actual rights the token delivers. An issuer who cannot demonstrate that the classification analysis was conducted rigorously, by reference to the applicable legal tests, has no durable answer to a regulatory challenge.
If a prior structuring attempt stalled or an exchange refused to list the token, a second read of the classification and documentation can identify the structural reason. To discuss a remediation or a clean-start structure, write to OBOLUS at info@oboluslaw.com.
Which issuer profile should choose which STO structure?
The right structure depends on the token's rights profile, the target investor base and the issuer's appetite for regulatory process. The following profiles capture the main decision axes.
Profile A – corporate debt token with fixed yield, institutional distribution only. This token is almost certainly a transferable security. The appropriate structure is a prospectus-exempt issuance under the qualified-investor or denomination exemption, with a CNB-acknowledged exemption basis, a placing agent that is a MiFID II-authorized investment firm, and full KYC/AML documentation on every subscriber. Timeline from mandate to close depends on document complexity and CNB responsiveness, but issuers should plan for a multi-month process. Key risk: a retail leak through a secondary-market platform undoes the exemption.
Profile B – governance and access token for a software platform, no economic rights. If properly structured, this token avoids the transferable-security analysis and falls under MiCA as an "other" crypto-asset. The required steps are a MiCA-compliant whitepaper, CNB notification, and the statutory observation period before public offer. EU passporting is available immediately. Key risk: any yield or redemption mechanism added post-launch reclassifies the token.
Profile C – payment token with reserve backing, European retail market. If the token is redeemable at par against a fiat reserve, the ART or EMT classification under MiCA is likely, requiring CNB authorization rather than a whitepaper-only route. This is the most capital-intensive and time-consuming path; issuers should assess whether the Cayman or ADGM structuring routes offer a faster initial path with a separate EU distribution wrapper. For that kind of dual-structure analysis, we engage allied counsel in the relevant jurisdiction alongside our EU regulatory work.
Profile D – real-estate-backed token, mixed retail and institutional distribution. This profile typically requires a prospectus (the underlying real-estate rights constitute transferable-security characteristics), a CNB-approved document, and a regulated placing agent. The corporate structure beneath the token – whether a Czech joint-stock company, a Luxembourg SARL or a Cayman SPV – materially affects the prospectus liability chain and the tax treatment of token proceeds.
Self-assessment: is your Czech STO structure legally sound?
Before committing to a launch timeline, an issuer should be able to answer yes to each of the following questions with documented support.
- Has a qualified legal opinion addressed token classification under Czech capital-markets law and the MiFID II financial-instrument definitions?
- Where the token is a transferable security, has the prospectus requirement been satisfied by either full approval or a documented exemption basis?
- Where the token falls under MiCA, has the whitepaper been prepared to the prescribed content standard and notified to the CNB before any public communication constituting a "public offer"?
- Has the distribution model – including any secondary-market mechanism – been reviewed against Czech capital-markets and MiFID II requirements?
- Does the entity structure support the intended banking relationship, and has the issuer's AML/KYC framework been designed to meet CNB expectations?
- For cross-border distribution, has each non-Czech target jurisdiction been assessed under its own securities, crypto-asset and marketing laws?
- Is there a defined process for monitoring post-issuance compliance obligations, including ongoing MiCA disclosure duties or prospectus supplementation obligations?
A no answer to any item is a project risk. In our practice, the issuers who reach closing fastest are those who invest in this analysis at the outset, not after a bank or exchange has raised a concern.
Related at OBOLUS
- Token Offerings & Securities practice – end-to-end legal structuring for digital-asset issuances across jurisdictions
- Token sale agreement drafting under UAE VARA – how the VARA regime structures token sale documentation in Dubai
- MLRO and compliance officer function – the disputes angle – what happens to compliance officers when token structures are challenged
FAQ
Is my token a security?
The answer turns on the rights the token confers, not its name. Under Czech law and the MiFID II definitions applied by the CNB, a token is a transferable security if it carries economic rights – yield, redemption, profit-share – and is capable of being traded on a capital market. A legal opinion reviewing the token's constitutional documents, smart contract and terms is the only reliable basis for the determination. A whitepaper label is not.
Do I need a MiCA whitepaper?
If your token does not qualify as a transferable security or an e-money instrument, and you intend to make a public offer in Czech Republic or elsewhere in the EU, MiCA requires a compliant whitepaper notified to the CNB before the offer opens. The whitepaper must meet prescribed content standards covering the issuer, the token's rights, the technology, and the risks. A single CNB notification covers EU-wide distribution via MiCA's passporting mechanism. Tokens classified as ARTs or EMTs require full CNB authorisation, not just a whitepaper.
How should an airdrop be structured legally?
An airdrop is not automatically exempt from securities or MiCA obligations. If the airdropped token is a transferable security, distributing it for no consideration does not remove the prospectus requirement – the exemption analysis still applies. For MiCA-route tokens, a gratuitous distribution to fewer than 150 persons per member state may qualify for an exemption from the whitepaper requirement, but the conditions must be documented and monitored. Airdrops that constitute marketing communications also engage MiCA's promotion rules.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label – and we advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. To discuss your situation, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – specialising in token structuring, smart-contract legal analysis and the intersection of DeFi protocol design with EU and cross-border securities law.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.