A token founder preparing to launch in Europe faces a deceptively simple-looking question: does the project require a MiCA whitepaper (a disclosure document mandated under the EU's Markets in Crypto-Assets Regulation), and if so, what must it contain? The answer turns on token classification, the rights the token confers, and the jurisdictions in which it will be offered. Getting that analysis wrong before launch is not a compliance footnote – it can convert a product release into an unregistered securities offering or an unlicensed public offer of crypto-assets, with enforcement consequences that are difficult to unwind.
Under MiCA, supervised by ESMA and the relevant national competent authority in the member state of the issuer, every public offer of crypto-assets that does not qualify for an exemption requires a compliant whitepaper. The document must be notified to the competent authority, published, and maintained. For early-stage founders, the process starts well before drafting: it starts with classification.
This page sets out the regulatory basis, the review process, the most common mistakes we see, the cross-border dimensions that matter for a founder whose users, entity, or banking sit outside the EU, and a decision matrix to help you map your position before the first call.
Why Token Classification Comes First
Token classification determines whether MiCA applies at all – and, if it does, which part of MiCA applies. MiCA distinguishes three principal categories: asset-referenced tokens (ARTs, which reference a basket of assets or currencies), e-money tokens (EMTs, which reference a single fiat currency), and a residual "other crypto-assets" category that captures most utility and governance tokens. Securities-like instruments fall outside MiCA entirely and into existing EU financial instruments legislation.
The classification test is substance-over-label. Calling a token "utility" does not make it a utility token for regulatory purposes. What matters is the bundle of rights the token holder actually receives: profit participation, voting on economic decisions, claims against the issuer, or returns from a common enterprise can all push a token toward the securities perimeter, regardless of the marketing document. We assess classification against that rights analysis before we touch the whitepaper draft.
A common assumption among founders is that a utility label on a whitepaper settles the legal classification. It does not. Regulators across the EU, and in supervisory guidance published by ESMA, apply a functional analysis. The label is relevant evidence, but the substance controls. An issuer who discovers post-launch that their token was mis-classified faces the prospect of unwinding a public offer, engaging in remediation with the competent authority, and, in some member states, facing administrative sanction. The cost of a pre-launch classification opinion is a fraction of the cost of that outcome.
What Does a MiCA Whitepaper Review Actually Cover?
A MiCA whitepaper review for early-stage founders is not a proofreading exercise. It is a structured legal assessment of the document against the mandatory disclosure requirements under the applicable MiCA provisions, the classification analysis that underpins the filing, and the regulatory risk that remains after the document is published.
In our practice, a whitepaper review engagement covers six functional layers. First, we confirm or revise the token classification and identify which MiCA category – ART, EMT, or other crypto-asset – governs the offering. Second, we assess whether any exemption applies: MiCA provides for exemptions covering free offers, small-scale offers below the applicable threshold, and offers limited to qualified investors, among others. Third, where a whitepaper is required, we review the document against the mandatory content items – the description of the issuer, the token, the rights attaching, the technology, the risks, and the rights of holders. Fourth, we assess the notification procedure with the relevant national competent authority, because the process differs between member states. Fifth, we review the marketing communication rules, which apply in addition to the whitepaper requirement and carry their own fairness and accuracy standards. Sixth, we address the cross-border dimension: where the founder's entity is domiciled, where users will be located, and whether EU passporting is available or necessary.
The related practices block below sets out how this service connects to our broader token offerings and exchange listing work, where the whitepaper review is often the first step in a longer regulatory process.
If you are mapping your token's classification and disclosure obligations ahead of a European launch, a scoped review with OBOLUS is the fastest way to surface the gaps. The process above describes the standard path. Your facts – the entity structure, the user base, the banking, the rights architecture – change the analysis materially. Map your options.
How Does the Whitepaper Notification Process Work?
For "other crypto-assets" – the category that covers most utility and governance tokens – the whitepaper must be notified to the competent authority of the member state where the issuer is established, but it is not subject to prior approval; the authority receives the notification and may raise objections, but the issuer can proceed to publish. The distinction between notification and approval is operationally significant. It means the timeline is driven by the issuer's own readiness and the competent authority's review window, not by a licensing queue.
The process, in practice, runs as follows. The founder finalises the entity structure – typically a special-purpose vehicle or an operating company in the chosen member state. The whitepaper is drafted and reviewed against the mandatory content checklist. The issuer notifies the competent authority at least a defined period before the public offer begins. The whitepaper is then published on the issuer's website and kept current for the life of the offering. Material changes require a revised whitepaper and a new notification cycle.
ART and EMT issuers face a stricter path. Both categories require prior authorisation from the competent authority before offering or issuing tokens to the public. That authorisation involves a more detailed file – a business plan, governance documentation, own-funds evidence, custody and reserve arrangements, and a recovery and redemption plan. The timelines for ART and EMT authorisation are longer and the capital requirements more substantial. Founders proposing a stablecoin or a multi-currency reference instrument should factor that into their launch planning from day one.
Lithuania and Malta are both EU member states with active MiCA implementation pipelines. Lithuania's Bank of Lithuania supervised the prior VASP registration regime and is now the competent authority for MiCA CASP authorisation; Malta's MFSA is transitioning the prior VFA framework to MiCA. Both jurisdictions have handled significant volumes of crypto-asset business, and their competent authority processes are well-documented. However, the notification experience varies, and founders should not assume that prior familiarity with a member state's previous regime translates directly to the MiCA process.
What Are the Most Common Mistakes in MiCA Whitepaper Drafts?
The most damaging mistake in a MiCA whitepaper draft is a mis-classification that the drafter did not recognise as contested. A founder who has been advised informally – or who has self-assessed – that the token is a utility token may draft a whitepaper for the "other crypto-assets" regime, then discover on review that the token's rights architecture sits in the ART or securities perimeter. That discovery mid-process is disruptive; post-launch, it is potentially critical.
The second most common problem is incomplete risk disclosure. MiCA requires the whitepaper to describe the main risks associated with the offer. Founders routinely underestimate the specificity required. A generic "crypto markets are volatile" statement does not satisfy the regime. The risk section must address project-specific risks: smart contract risk, concentration risk, key-person dependencies, treasury management, and the risks specific to the token's use case.
A third recurrent issue is the failure to address the rights of token holders with the precision MiCA requires. The whitepaper must describe what the holder can do with the token, what claims or entitlements attach, and – critically – what happens on the issuer's insolvency or project failure. Founders who draft these sections from a commercial perspective, emphasising utility features, often fail to address the legal mechanics of the holder's position. That gap is exactly what a competent authority reviewer looks for.
Marketing communications present a fourth risk. Many founders publish social media content, video announcements, and community updates that constitute marketing communications under MiCA. These must be consistent with the whitepaper, clearly identified as marketing, and compliant with the fairness standards set by the applicable regime. A whitepaper that passes review is undermined by a promotional campaign that overstates the token's prospects or omits material risks.
Cross-Border Dimension: Entity, Users, and Banking
Early-stage founders rarely sit neatly within one jurisdiction. The founding team may be in one country, the entity in another, the users distributed across several, and the banking relationship in a fourth. Each of those facts is legally material under MiCA and under the securities laws of the jurisdictions where users receive the token.
MiCA governs offers to the public in the EU/EEA. A non-EU entity making a public offer to EU residents is within scope. The obligation to produce a compliant whitepaper does not depend on where the issuer is incorporated; it depends on where the offer is made and where investors or users are located. A founder with a BVI or Cayman holding company who intends to offer tokens to European users cannot rely on the offshore domicile of the issuer to avoid the whitepaper obligation.
Passporting is a significant structural benefit available once a CASP is authorised in one EU member state. Under the applicable MiCA provisions, a crypto-asset service provider authorised in one member state may offer its services across the EU/EEA without requiring separate authorisation in each target jurisdiction. For a token issuer who also intends to operate exchange or custody services, the choice of initial authorisation jurisdiction therefore carries weight beyond the whitepaper filing.
The banking dimension intersects in a way founders often miss. EU banks and electronic money institutions are increasingly applying their own internal policies to digital-asset clients. A token issuer who has completed a MiCA-compliant whitepaper process and holds a CASP authorisation is in a materially better position when approaching regulated account providers than one operating on a pre-MiCA registration. The compliance trail supports the account-opening file. In our cross-border practice, we regularly see this dynamic at work: the regulatory approval process and the banking relationship are not separate tracks.
For founders sitting between a non-EU hub – say, a VARA-regulated entity in Dubai or an ADGM-regulated entity in Abu Dhabi – and EU users, the analysis requires mapping both regimes. VARA and ADGM each have their own disclosure and marketing rules. A whitepaper prepared for the EU offering may need to be assessed separately against VARA's rulebooks or the FSRA's framework before it is used in UAE-facing marketing. Allied counsel in the relevant jurisdiction supports that parallel review where needed.
Decision Matrix: Which Founders Need What
Not every early-stage token project requires the same level of engagement. The matrix below maps the principal founder profiles to the instrument, the process, and the primary risk at each position.
Profile A: Utility token, small EU offer, sub-threshold volume. A founder planning a limited offer below the applicable exemption threshold, to a restricted group, may qualify for the small-offer or qualified-investor exemption under MiCA. The instrument here is a classification opinion confirming exemption availability and an exemption-eligibility memo. The risk is that the exemption conditions are not maintained as the project grows, triggering a retrospective obligation to file a whitepaper. Founders who begin exempt and scale into the public offer category need a monitoring mechanism and a clear trigger point for engagement.
Profile B: Utility or governance token, public EU offer, non-EU entity. A founder with an offshore entity intending to offer tokens publicly to EU users needs a full MiCA whitepaper, a notification to the relevant national competent authority, and an EU nexus – typically an EU-established subsidiary or an authorised representative arrangement. The instrument is a whitepaper review plus entity structuring advice. The timeline from initial instruction to notification-ready document is typically a matter of weeks, depending on the complexity of the rights architecture and the founder's readiness to provide project documentation.
Profile C: ART or EMT issuer. A stablecoin founder or multi-asset reference instrument issuer faces the most demanding path. Full prior authorisation is required. The instrument is a full authorisation application file, including business plan, governance, capital evidence, and recovery plan. This is a multi-month process, and the capital and organisational requirements are substantially higher than for other crypto-assets. Founders in this profile should begin pre-application dialogue with the competent authority as early as possible.
Profile D: Token with securities characteristics. A founder whose token analysis surfaces profit-participation rights, a claim against the issuer's revenues, or a return from a common enterprise exits the MiCA perimeter and enters the securities regime. The instrument here is a securities law assessment across each target jurisdiction, which may require prospectus analysis under EU financial instruments law, a Regulation D or Regulation S analysis for US exposure, and equivalent reviews for any other jurisdiction where the offer reaches investors. This is the highest-risk profile for an early-stage founder, and the one where early counsel pays for itself most clearly.
If a prior whitepaper draft has already been prepared and you are not confident in the classification underpinning it, a second-read review can surface the structural risk before you file. If an application has stalled or a banking relationship has been refused on compliance grounds, there is usually a structural reason that an experienced review can identify and address. Map your options.
Self-Assessment Checklist Before the First Call
Before engaging counsel for a MiCA whitepaper review, founders should be able to answer – or identify as unanswered – the following questions. The gap between what you can answer and what you cannot is the scope of the first engagement.
First: what rights does the token confer on its holder, specifically? Draft those rights as a list of legal entitlements, not marketing benefits. Second: where will the token be publicly offered, and to which categories of persons? Third: in which jurisdiction is the issuing entity incorporated, and is there an EU-established entity in the structure? Fourth: have any marketing communications about the token already been published? Fifth: does the project involve a reserve, a redemption mechanism, or a peg to any asset or currency? Sixth: have any informal opinions on token classification already been obtained, and from whom?
A founder who has worked through those six questions before the first call will get materially more out of the initial scoping session. It also shortens the time to a usable classification opinion, which shortens the time to a notification-ready whitepaper.
In a recent matter, a token issuer expanding into European markets had prepared a draft whitepaper in-house, classifying the token as a utility instrument. On review, we identified that the token's governance rights – specifically, the right to vote on the distribution of a protocol revenue pool – introduced a profit-participation element that required a revised classification analysis. We restructured the rights architecture with the founding team, revised the whitepaper to reflect the corrected classification, and managed the notification process with the relevant national competent authority. The launch proceeded on the revised schedule without incident.
Related at OBOLUS
- Token Offerings & Securities Practice – the full practice overview for token issuers across jurisdictions
- Exchange Listing Legal Counsel Under Heightened Scrutiny – managing exchange listing requirements when regulatory scrutiny is elevated
- MiCA Whitepaper Review – Legal Counsel for Digital-Asset Firms – the broader MiCA whitepaper service for established digital-asset businesses
FAQ
Is my token a security?
Whether a token is a security depends on the rights it confers, not on what it is called. The analysis applies the relevant legal test – in the EU, this means assessing whether the token constitutes a transferable security or other financial instrument under applicable financial instruments legislation; in the US, it involves the Howey analysis applied by the SEC and CFTC. A governance or utility token that includes profit-participation rights or a claim on issuer revenues can meet the securities threshold. Substance controls, not the label.
Do I need a MiCA whitepaper?
If you are making a public offer of crypto-assets to persons in the EU/EEA and your token is not a financial instrument under existing EU securities law, you likely need a MiCA-compliant whitepaper unless a specific exemption applies. Exemptions exist for free offers, small-scale offers below the applicable threshold, and offers limited to qualified investors. The exemption analysis must be done carefully – exemptions have conditions, and exceeding them without a whitepaper in place creates compliance risk. ESMA and national competent authorities are the supervisory reference points.
How should an airdrop be structured legally?
An airdrop – a free distribution of tokens to a defined recipient list – can qualify for the "free offer" exemption under MiCA's applicable provisions, provided it is genuinely free and the recipient provides no consideration. However, if the airdrop functions as a marketing mechanism for a subsequent sale, regulators may look through the free structure to the overall offering. The recipient pool, the eligibility conditions, the connection to any prior or subsequent sale, and the jurisdiction of recipients all bear on whether the exemption holds. Structuring an airdrop correctly requires the same classification analysis as any other distribution.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label – and we advise clients across more than seventy licensing jurisdictions on exactly the issues this page addresses. To discuss your situation, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – specialising in token classification, MiCA whitepaper review, and the regulatory treatment of novel digital-asset instruments across EU and cross-border structures.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.