A token project preparing to raise capital in Dubai faces a foundational question before a single investor receives a pitch deck: does the instrument being offered qualify as a security token under the Virtual Assets Regulatory Authority (VARA) regime, and if so, what authorization does the issuer actually need? The answer shapes everything – the licence category, the offering document, the eligible investor base, and the cross-border legal exposure that follows the token into secondary markets.
Under the VARA regime, which governs virtual-asset activity on the Dubai mainland, security token offering structuring in UAE-VARA is a regulated activity. An issuer that mis-classifies its instrument risks conducting an unauthorized offering and triggering enforcement action by VARA, the Securities and Commodities Authority (SCA), or both. Token classification turns on the rights the instrument confers – not the label printed on the whitepaper.
This page maps the regulated basis for security token offerings in Dubai, the VARA authorization process, the cross-border interaction with tax and banking, and the decision points at which early legal structuring changes the outcome.
What is a security token under the VARA regime?
A security token under the VARA framework is a virtual asset that confers rights economically equivalent to a traditional security – an equity interest, a debt claim, a profit-sharing right, or a fractional ownership stake in an underlying asset. VARA's activity-based rulebooks place the issuance, management, and trading of such instruments within the regulated perimeter. The substance-over-form principle applies: a token labeled "utility" that promises revenue participation to holders will be assessed on what it actually does, not what the issuer calls it.
The Securities and Commodities Authority (SCA) retains jurisdiction over instruments that qualify as securities under UAE federal law. Where a token meets that threshold, both VARA and the SCA may have concurrent or overlapping authority depending on where the activity occurs and to whom the offer is made. In our cross-border practice, we see issuers consistently underestimate this dual-regulator dimension. Mapping the jurisdictional split between VARA (Dubai mainland) and the SCA (federal) is one of the first tasks in any Dubai security token engagement.
The VARA rulebooks distinguish several virtual-asset categories. Investment tokens – which map broadly onto the security-token concept – sit in the most regulated tier. Issuers must hold or work through an entity that holds the appropriate VARA licence for the activity being conducted: typically an advisory, broker-dealer, management, or exchange activity licence depending on the offering structure.
Which VARA licence category applies to a security token offering?
The VARA activity-based licensing model means that the issuer's conduct – not just its corporate form – determines what authorization is required. A primary issuance to investors involves different regulated activities than a secondary trading venue, and both differ from a custody arrangement for post-issuance token holders.
For a security token offering, the relevant VARA activities typically include:
- Advisory services – where the issuer or its arranger provides investment-related guidance to prospective investors;
- Broker-dealer activities – where the issuer places tokens with investors on a principal or agency basis;
- Management and investment services – where a fund-like vehicle issues tokens representing a managed pool;
- Exchange or transfer/settlement activities – where tokens are made available for secondary trading on a VARA-licensed platform.
Not every issuer needs to hold all of these licences directly. A common structure separates the issuing special-purpose vehicle (SPV) from a VARA-licensed arranger or placement agent who conducts the investor-facing regulated activity. Operators we advise routinely use this separation to keep the issuing entity's regulatory footprint narrow while ensuring that all investor-facing conduct sits within a licensed entity. The choice of structure has direct consequences for capitalization, ongoing compliance obligations, and the scope of VARA's supervision.
The process above describes the standard path. Your facts – the entity structure, the investor base, the underlying asset, the banking – change the analysis entirely. To map the VARA licence and structuring options for your offering, contact OBOLUS at info@oboluslaw.com.
How does token classification work in practice under UAE law?
Token classification in Dubai is a legal analysis, not a drafting exercise. The question is whether the rights embedded in the token – taken as a whole, across the whitepaper, the smart contract, the investor communications, and the economic structure of the project – constitute a security, a utility instrument, or a virtual asset that falls into one of VARA's other defined categories.
VARA's regulatory perimeter covers virtual assets broadly. Within that perimeter, the investment token tier attracts the most significant authorization requirements. Classification determines not only which VARA activity licences are needed but also whether federal SCA rules apply, whether a formal offering document is required, who may invest, and how secondary liquidity can lawfully be provided.
Several structural features push a token toward the investment-token classification: a fixed or variable return tied to the issuer's revenues or profits; a voting or governance right over the issuer's business (as distinct from a protocol parameter vote); a right to redeem at a determinable value; or a fractional interest in a specific real-world asset such as real estate or a fund. None of these features is conclusive in isolation. Classification requires assessing the total package of rights.
A common assumption among issuers is that attaching a utility function – platform access, a discount on fees, a governance vote – is sufficient to take a token outside the securities perimeter. In our practice, that assumption creates significant exposure. Regulators in the leading hubs, including VARA, assess the dominant purpose of the instrument and the reasonable expectation of profit among investors. A token with a genuine, operationally significant utility function and no profit-expectation mechanics may well be classified as a non-security virtual asset. The same token with a nominal utility feature bolted onto what is economically a revenue-share instrument will not.
What does the VARA authorization process look like for a security token offering?
The VARA authorization process for a security token offering involves several sequential phases, each with its own documentation and regulatory interaction requirements. The timeline from initial application to a first authorized close varies by the complexity of the structure and the completeness of the application; in our experience, operators should plan for a process measured in months rather than weeks.
The key phases are as follows:
- Pre-application structuring. The issuer determines the classification of the token, the activity licences required, the corporate structure (onshore VARA entity versus a DIFC or ADGM vehicle for a cross-border element), and the investor eligibility criteria. A thorough pre-application analysis reduces the likelihood of a material change request from VARA mid-review.
- Licence application. The relevant VARA activity application is submitted, including business plan, financial projections, governance and compliance documentation, AML/CFT program, and key personnel information. VARA's minimum standards for each licence category are set out in the applicable rulebook.
- Offering document preparation. A security token offering typically requires a formal offering memorandum or whitepaper-equivalent that satisfies VARA's disclosure expectations. This document addresses the rights conferred by the token, the risk factors, the use of proceeds, the tokenomics, and the redemption or liquidity mechanism if any exists.
- Investor eligibility and placement. VARA-regulated security token offerings may be restricted to professional or qualified investors depending on the instrument and the activity licence held by the arranger. Retail access, where permitted, attracts additional requirements.
- Post-issuance compliance. Once tokens are live, ongoing VARA obligations apply: periodic reporting, AML/KYC monitoring at the transfer level, and notification obligations for material changes to the offering or the underlying business.
In a recent engagement, a real-estate-linked token issuer sought to structure a primary offering to qualified investors across the GCC and Europe. We analyzed the instrument under both the VARA investment-token classification and the federal SCA framework, identified the dual-regulator exposure, and designed a structure with a VARA-licensed placement agent conducting the investor-facing activity while the issuing SPV held the underlying asset. The offering closed to its target investor count without a regulatory challenge – a result that depended on the classification analysis being completed before the first investor communication was drafted.
How does the cross-border dimension affect a Dubai security token offering?
A VARA-licensed security token offering does not exist in regulatory isolation. The moment a token is offered to investors in a second jurisdiction – whether in the EU, Singapore, the United Kingdom, or the United States – the issuer acquires regulatory exposure in that jurisdiction as well. Each of those regimes applies its own classification test. A token that VARA treats as a non-security virtual asset may nonetheless constitute a transferable security under MiCA (the EU's Markets in Crypto-Assets Regulation) or a security under the SEC's Howey analysis.
Issuers that limit their offering to UAE-domiciled qualified investors avoid much of this cross-border complexity, but they correspondingly limit their capital pool. The practical solution is a multi-jurisdiction classification memo produced before the offering opens – a document that maps the token's legal status in each target market, identifies the jurisdictions where a local exemption or registration is available, and flags the jurisdictions to exclude from the offer entirely.
Banking is a separate but related constraint. UAE banks have adopted varying appetites for security token issuers, particularly where the underlying asset is cross-border or the investor base is international. Operators we advise are increasingly using a combination of a UAE-regulated account for AED-denominated operational flows and an offshore account in a jurisdiction with clearer banking access for crypto-related businesses. The account structure must be disclosed to VARA and must be consistent with the AML/CFT program submitted at authorization.
Tax treatment of security token issuance proceeds, token holder distributions, and secondary transfers in the UAE is subject to the UAE corporate tax regime and the specific treatment of virtual-asset transactions under applicable guidance. We regularly advise issuers to obtain a tax opinion alongside the securities law analysis, particularly where the token structure involves profit distributions or redemption mechanics that may generate taxable events in multiple jurisdictions.
If a prior application stalled or a structuring analysis produced an inconclusive classification, a second read can surface the structural reason and the route forward. Write to OBOLUS at info@oboluslaw.com or message us at t.me/oboluslaw.
What AML, Travel Rule, and KYC obligations apply to security token issuers in Dubai?
Security token issuers operating under the VARA regime are subject to the Travel Rule – the obligation under the FATF Recommendations to transmit originator and beneficiary information with each virtual-asset transfer above the applicable threshold. VARA's AML/CFT expectations align with the FATF Recommendation 15 standard, which treats virtual-asset service providers as subject to the same customer due-diligence and transaction-monitoring requirements as conventional financial institutions.
For a security token offering, this means that the issuer or its VARA-licensed agent must conduct full KYC on each investor at subscription, apply enhanced due diligence to higher-risk investor profiles, and maintain transaction records sufficient to satisfy VARA's inspection requirements. Where tokens are transferred on a secondary basis – even peer-to-peer between investors – the Travel Rule data obligation follows the transfer.
VARA's rulebooks require a written AML/CFT program as part of the licence application, and that program must identify the compliance officer, the monitoring systems, the escalation procedures, and the jurisdictions from which investors will be excluded. Weaknesses in the AML program are among the most common reasons for VARA to issue a material change request during the authorization review.
Operators we advise incorporate Travel Rule compliance into the token architecture at the design stage, using transfer-restriction logic at the smart-contract level to block transfers to addresses that have not completed the required KYC and Travel Rule data exchange. Retrofitting these controls post-issuance is technically and legally more complex – and in some structures, impossible without a new token migration.
Self-assessment: is your token offering ready for VARA authorization?
Before engaging VARA, a security token issuer should be able to answer each of the following questions affirmatively – or know precisely why it cannot:
- Has the token been classified by counsel against the VARA investment-token criteria, the UAE federal SCA framework, and the regimes of each target investor jurisdiction?
- Is the corporate structure (issuing SPV, VARA-licensed arranger, custodian) finalized and consistent with VARA's activity-licence requirements for each function?
- Is the offering document complete, including risk factors, tokenomics, rights schedule, and redemption or liquidity mechanics?
- Is the investor eligibility criteria defined, and does it comply with the restrictions attached to the relevant VARA licence category?
- Is a written AML/CFT program in place, including a Travel Rule solution and transfer restrictions at the smart-contract level?
- Has the banking structure been confirmed, with accounts that are accessible, disclosed to VARA, and consistent with the AML program?
- Has a tax opinion been obtained covering the UAE corporate tax position of the issuer and the cross-border implications for distributable proceeds?
A "no" on any of these points is a preparation gap, not a disqualifier. We have seen offerings move from a negative checklist to a clean VARA submission in a matter of weeks when the structural decisions are made promptly and the documentation is produced in parallel.
Which structure fits which issuer profile?
Not every Dubai security token issuer follows the same path. The right structure depends on the nature of the underlying asset, the target investor base, and the issuer's existing regulatory footprint.
Profile A – Real-asset-backed issuer (real estate, infrastructure, trade receivables). The token represents a fractional interest in a specific underlying asset pool. The relevant structure typically involves a VARA-licensed SPV holding the assets, with a separate VARA-licensed broker-dealer conducting the placement. The offering is restricted to professional investors. The primary risk is dual-regulator exposure between VARA and the SCA where the underlying asset is a UAE-listed or UAE-registered security. Timeline from structuring engagement to first close: measured in months, contingent on VARA review pace and the complexity of the asset documentation.
Profile B – Fund-linked token issuer (managed pool, VC-style, yield fund). The token represents units in a managed vehicle. VARA's management and investment activity licence is the primary authorization required. The offering document must address the fund's strategy, the management fee and carry structure, the valuation methodology, and the liquidity or redemption terms. Cross-border exposure is high because fund tokens are likely to attract securities classification in most EU, US, and UK analysis. Offshore jurisdictions such as the Cayman Islands or BVI are frequently used as the issuing vehicle, with the VARA-licensed manager conducting the Dubai-nexus activity. Timeline: similar to Profile A; the offshore structuring adds a parallel workstream.
Profile C – Protocol or platform issuer (governance token with economic rights). This profile carries the highest classification risk. The token may be designed as a governance instrument but embed economic rights sufficient to trigger investment-token classification. Structural options include redesigning the economic rights (reducing or eliminating profit-sharing mechanics), obtaining a pre-application classification opinion from VARA, or restructuring the offering as a separate, explicitly non-security utility token alongside a privately placed security token to qualified investors only. Timeline: the classification analysis phase can extend the overall schedule materially if a redesign is required.
Related at OBOLUS
- Token Offerings & Securities practice – Legal structuring for token issuances across regulated and offshore markets
- Token classification: a legal guide – How security, utility and payment tokens are distinguished in practice
- Stablecoin freeze requests in Poland – Cross-border asset recovery using issuer freeze authority in a European context
FAQ
Is my token a security?
Whether a token is a security depends on the rights it confers – not its label. Under VARA's framework and UAE federal law, the analysis examines whether holders receive an equity-like interest, a debt claim, a profit-sharing right, or a return tied to the issuer's performance. A token with a genuine operational utility function and no profit expectation may avoid the security classification. One with economic return mechanics will almost always be treated as an investment token regardless of how the whitepaper describes it. Counsel should assess the full rights package before any investor communication is issued.
Do I need a MiCA whitepaper?
A MiCA whitepaper is required if your token qualifies as a crypto-asset under the MiCA regulation and is offered to persons in the EU or EEA. MiCA does not apply to instruments that are securities under EU law – those fall under existing securities directives and MiFID II. A Dubai-based issuer offering to EU investors must therefore determine, first, whether the token is a security or a MiCA crypto-asset under EU classification, and then comply with the applicable disclosure regime. A VARA-compliant offering document does not substitute for a MiCA whitepaper where EU investors are included in the offer.
How should an airdrop be structured legally?
An airdrop – a distribution of tokens without direct payment – is not automatically exempt from securities regulation. If the distributed token constitutes a security, the airdrop is a securities offering and requires authorization in each relevant jurisdiction, regardless of whether consideration was paid. A legally sound airdrop either distributes a token that has been properly classified as a non-security in each target jurisdiction or is limited to jurisdictions where a specific exemption covers gratuitous distributions. The structure of the airdrop – who receives tokens, on what basis, and in what jurisdictions – must be analyzed before distribution begins.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice – we assess classification against the substance of rights, not the marketing label, and we act only for businesses with real cross-border legal questions. To discuss your security token offering, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – specializing in token structuring, smart-contract legal architecture, and multi-jurisdiction offering analysis for digital-asset issuers.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.