EST · MMXXVI
Home/Services/Token Offerings Securities/MiCA whitepaper review for Regulated Entities
Token Offerings & Securities

MiCA whitepaper review for Regulated Entities

Mica whitepaper review for Regulated Entities. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

What a MiCA whitepaper review actually means for a regulated entity

A MiCA whitepaper – the mandated disclosure document required under the Markets in Crypto-Assets Regulation (MiCA) before a crypto-asset is offered to the public or admitted to trading in the EU or EEA – is not a marketing exercise. For a regulated entity, it is a legal instrument. ESMA and the relevant national competent authority will read it as a liability document. If the rights described in the whitepaper are inconsistent with the token classification the issuer claims, the consequences range from a supervisory halt to a referral for enforcement. Getting the analysis right before notification is not optional.

Token issuers that have already obtained a CASP authorisation (Crypto-Asset Service Provider) in one EU member state, or that are applying for one, face an additional layer of scrutiny: their whitepapers must be consistent with the CASP regulatory perimeter and, where passporting is involved, must satisfy multiple competent authorities simultaneously. In our cross-border practice, we see classification errors introduced at the drafting stage surface only at the competent authority review, adding weeks to a launch timeline that was already tight.

This page explains the legal basis for the MiCA whitepaper obligation, the review process we run, the cross-border interactions that complicate it, and the mistakes that most commonly stall or derail an offering.

The classification gate: why the whitepaper starts before the whitepaper

Every MiCA whitepaper begins with a classification decision that determines which whitepaper regime – if any – applies. MiCA establishes three principal token categories: asset-referenced tokens (ARTs, which reference a basket of assets, currencies or commodities), e-money tokens (EMTs, which reference a single fiat currency and function as electronic money), and all other crypto-assets, including utility tokens. Each category carries a distinct whitepaper obligation, a distinct authorisation or notification pathway, and a distinct set of ongoing issuer obligations.

The classification is not chosen by the issuer. ESMA and national competent authorities apply a substance-over-label analysis: the test turns on the rights the token confers and the economic reality of how it functions, not the name the marketing team assigned it. A token described as a "utility token" in a white paper may be reclassified as an ART if it is designed to maintain a stable value by reference to a basket of currencies. A token described as a "governance token" may attract securities law analysis under MiFID II if it confers profit participation rights – and where that is the conclusion, MiCA does not apply at all: the Financial Instruments test runs first.

This is the single most consequential step in any whitepaper review engagement. We conduct it before a single line of the whitepaper is drafted or revised.

For a regulated entity – a licensed exchange, a custodian, or an existing CASP – misclassification is materially more serious than it is for an unregulated issuer. The competent authority that supervises the CASP licence will expect the whitepaper classification to be coherent with the entity's regulated perimeter. A classification error can raise questions about the entity's compliance culture and trigger a broader supervisory review.

For a scoped classification assessment ahead of your whitepaper review, contact OBOLUS at info@oboluslaw.com. The analysis above describes the standard path. Your entity, your token mechanics and your user base change the answer.

Who must notify whom – and when

The notification or authorisation requirement under MiCA depends on both the token category and the issuer's existing regulatory status. For issuers of "other crypto-assets" (which includes most utility tokens), the obligation is to notify the competent authority in the issuer's home member state before the offer and to publish the whitepaper. No pre-approval is required, but the competent authority retains powers to object, to require modifications, and to halt an offering where the whitepaper is misleading, incomplete or inconsistent with the token's actual characteristics.

For ART issuers, a full authorisation application to the home-state competent authority is required before any offer to the public. The process is closer in depth to a licence application than to a notification. ESMA publishes guidelines on the information content expected in an ART authorisation file. For EMT issuers, the issuer must be an authorised credit institution or an e-money institution under the applicable EU directive – a structural constraint that eliminates the option for most pure-play crypto entities.

The cross-border dimension is significant. A CASP passporting across the EU/EEA after authorisation in one member state does not automatically extend whitepaper approval to every jurisdiction in which it operates. Where a regulated entity intends to offer tokens in multiple member states, the home-state competent authority remains the primary interlocutor, but notification to host-state competent authorities is required in parallel. We routinely coordinate that multi-authority process on behalf of issuers to prevent parallel objection timelines from colliding.

For entities structured outside the EU – a Singapore MAS-licensed exchange or an ADGM FSRA-regulated issuer seeking EU market access, for example – the whitepaper and authorisation file must be prepared in a way that satisfies the EU home-member-state regime, regardless of the issuer's primary regulatory home. This adds a layer of analysis: which rights and restrictions in the home jurisdiction interact with MiCA's requirements, and where do they conflict?

What our MiCA whitepaper review covers

A whitepaper review engagement at OBOLUS follows a consistent structure, adjusted to the token category, the issuer's regulatory status and the target markets.

The first stage is the classification memo. We analyse the token's technical architecture, the rights and obligations it confers, the stabilisation mechanism (if any) and the distribution plan. The output is a written classification opinion that identifies the applicable MiCA category (or the reason MiCA does not apply) and maps the resulting whitepaper and authorisation obligations.

The second stage is the whitepaper gap analysis or drafting review. For issuers with an existing draft, we run a structured review against the mandatory content requirements under MiCA and ESMA's technical standards. For issuers starting from a blank document, we draft the whitepaper to standard, working with the issuer's technical team on the token mechanics disclosures and with the finance team on the financial and reserve disclosures where ART requirements apply.

The third stage addresses the cross-jurisdictional overlay. Where the issuer operates under a non-EU licence, we map the interactions between that regime and MiCA's whitepaper requirements. Where the offering involves non-EU investors – notably US investors, where the SEC's analysis may run independently – we flag the parallel securities law questions and coordinate with allied counsel in the relevant jurisdiction where needed.

The fourth stage is pre-notification review. Before the whitepaper is filed with the competent authority, we review the complete notification package against the competent authority's published guidance and, where the competent authority has issued prior informal comments, against those comments. The objective is a clean notification that does not generate a request for information or a halt.

What mistakes most commonly stall a MiCA offering?

In our cross-border practice, four errors appear repeatedly in whitepaper files that return from competent authorities with requests for amendment.

The first is a classification assertion without supporting legal analysis. A whitepaper that states "this token is a utility token and is not subject to ART or EMT requirements" without substantive analysis is treated by ESMA-aligned competent authorities as an unsubstantiated claim. The whitepaper should either contain the analysis in summary form or be accompanied by a legal opinion available to the competent authority on request. We have seen competent authorities put offers on hold solely because the classification rationale was absent.

The second is inconsistency between the whitepaper and the issuer's other documentation. Marketing materials, a previously published "lite paper," a tokenomics deck and the whitepaper must describe the same token. Where the marketing materials describe rights or stabilisation features that the whitepaper does not disclose, the competent authority's review team will identify the discrepancy. In a recent matter, a digital-asset issuer preparing for an EU token offering discovered that a tokenomics presentation shared with early investors described a value-maintenance mechanism that, on legal analysis, brought the token within the ART definition. We identified the inconsistency at the gap-analysis stage, before any regulatory filing, and the structure was revised accordingly. The offering proceeded on the correct classification basis.

The third common error is inadequate disclosure on the rights of token holders. MiCA's mandatory content requirements for whitepapers are detailed. Disclosures relating to the token holder's rights, the issuer's obligations, the risks of the offering, the conflicts of interest of the project team and the complaint-handling procedures must each satisfy the level of detail ESMA's technical standards require. Issuers preparing their first EU whitepaper consistently underestimate the granularity required in the rights and obligations section.

The fourth error is timing. The whitepaper must be published before the offer to the public, not alongside it. For ART authorisations, the timeline is measured in months, not days. Issuers that treat the whitepaper as a post-fundraise compliance step – common in US-market-first token launches – find they cannot legally offer to EU investors until a retrospective process is complete. That process is materially more difficult than a pre-launch filing.

How does MiCA whitepaper review interact with securities law?

MiCA explicitly excludes financial instruments within the meaning of MiFID II from its scope. If a token is characterised as a transferable security or another financial instrument under MiFID II, MiCA's whitepaper regime does not apply – instead, the Prospectus Regulation and the full securities law regime govern the offering. The classification question is therefore not merely a choice between ART, EMT and utility token: it is first a question of whether the token falls inside MiCA at all.

Token classification under MiFID II turns on the Howey-analogue analysis each national competent authority applies, overlaid with ESMA guidance on the criteria for transferable security status. A token that confers a right to dividends, a right to vote on profit distribution, or an expectation of return derived from the efforts of the issuer is likely to be treated as a transferable security in most EU member states, regardless of the token's technical structure. This is the outcome a mis-labelled utility token is most at risk of. In our practice, we assess classification against the substance of rights, not the marketing label – because the competent authority will do exactly the same.

The cross-border complexity intensifies where the issuer has US investors or intends US market access. The SEC's analysis of token classification runs independently of the MiCA framework, under the Howey test as developed through SEC guidance and enforcement. An offering that qualifies as a utility token under MiCA may still attract securities analysis under US federal law. We map both analyses in parallel and, where US securities law is in scope, coordinate with allied counsel in the relevant jurisdiction.

For token issuers operating under a Singapore MAS Payment Services Act licence or a BVI FSC registration, the interaction between the home-jurisdiction classification and the EU classification requires particular care. The MAS's DPT (Digital Payment Token) category does not map cleanly onto MiCA's token taxonomy, and a token cleared for distribution under the Payment Services Act regime may still require full ART authorisation in the EU if its mechanics satisfy the ART definition.

Which whitepaper route fits your profile?

The appropriate MiCA whitepaper process depends on the combination of token category, issuer status and distribution plan. The following profiles reflect the fact patterns we encounter most often.

A utility token issuer with no existing EU regulated status, offering a token that grants access rights to a protocol without any stabilisation mechanism, follows the notification track. The timeline from a clean, well-prepared whitepaper notification to offer-open is measured in weeks in most member states, though competent authority workload varies. The primary risk is a classification challenge at notification: the analysis in the whitepaper must be watertight before filing.

An existing CASP – a licenced exchange passporting across the EU – that also issues a platform token faces a compounded analysis. The token's classification must be consistent with the CASP's regulated perimeter. If the platform token confers fee discounts and governance rights, the classification memo must address both the MiCA token analysis and any MiFID II financial instrument question. The whitepaper, once notified, sits alongside the CASP's supervisory file. A competent authority that supervises both will read both.

A stablecoin issuer – a business proposing to issue a token that references the value of a single fiat currency – is in the EMT track. This requires the issuer to be an authorised e-money institution or credit institution. For most non-bank crypto entities, this means either acquiring or partnering with an existing EMI. The structural and timeline implications are significant: the authorisation process is not a whitepaper notification, and the capital and reserve requirements under the EMT regime are material. This profile requires early engagement, well ahead of any intended launch date.

An ART issuer – a business proposing to issue a token referencing a basket of assets – faces the most demanding process. Full authorisation is required. The file must address the issuer's governance, its reserve management framework, its redemption rights for token holders, and its own-funds requirements. The competent authority review process is iterative. Issuers in this track who have not engaged counsel at the structural design stage consistently encounter the longest delays.

If you have already drafted a whitepaper and encountered a competent authority request for information, contact OBOLUS at info@oboluslaw.com. A second read of the classification analysis and the disclosure sections often identifies the structural reason for the request and the path to resolution.

How should an airdrop be structured to avoid triggering MiCA?

An airdrop – a gratuitous distribution of tokens to wallet holders without consideration – does not automatically fall outside MiCA. The question is whether the distribution constitutes an "offer to the public" as defined under the regulation. MiCA contains an explicit exemption for distributions where tokens are offered for free, but the exemption is narrowly construed: where there is any element of consideration – including data provision, social media engagement or a referral obligation – the exemption will not apply.

An airdrop structured as a marketing campaign in which recipients are required to follow accounts, complete tasks or provide personal data is likely to be treated as a conditional offer, removing it from the free-distribution exemption. The whitepaper obligation – and, depending on the token, the authorisation requirement – is then triggered.

The interaction with AML obligations compounds the analysis. Even where a distribution is genuinely gratuitous, the issuer may still be a VASP (virtual asset service provider) for purposes of the applicable FATF-aligned AML regime in the jurisdiction of establishment. Where recipients are numerous and spread across multiple member states, the KYC and Travel Rule interactions require separate assessment. In our cross-border practice, we regularly advise issuers on airdrop structuring that is legally clean across the EU, the UK FCA's financial promotion rules, and one or more additional jurisdictions where the issuer has a regulated presence.

The practical advice: airdrop mechanics should be locked legally before they are locked technically. The cost of restructuring a smart-contract-based distribution after deployment is high. The cost of a regulatory challenge to a completed airdrop is higher.

Related at OBOLUS

FAQ

Is my token a security?

The answer turns on what rights the token confers, not what it is called. In the EU, a token that grants profit participation, voting rights tied to profit distribution, or an expectation of return derived from the issuer's efforts is likely to be a transferable security under MiFID II – placing it outside MiCA entirely and inside the Prospectus Regulation. In the US, the Howey test applies independently. Classification requires a substance-based legal analysis. A utility label does not resolve the question; it only describes the issuer's intention.

Do I need a MiCA whitepaper?

If you are offering a crypto-asset to the public in the EU or EEA, or seeking admission to trading on an EU platform, you will generally need a MiCA whitepaper unless a specific exemption applies. Exemptions exist for offers below defined thresholds, for offers to fewer than a specified number of persons, and for genuinely free distributions. Each exemption has conditions. The applicable category – utility token, ART or EMT – determines whether notification or full authorisation is required. Confirm the position with legal counsel before relying on an exemption.

How should an airdrop be structured legally?

A legally clean airdrop under MiCA requires that the distribution be genuinely gratuitous – no data, no task, no referral condition attached. Where any conditional element is present, the free-distribution exemption is likely unavailable and the whitepaper obligation is triggered. Separately, AML and KYC obligations may apply at the establishment-jurisdiction level even for free distributions. Airdrop mechanics should be reviewed before technical deployment, not after: restructuring a live smart-contract distribution is costly and reputationally exposed.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. Our classification work is conducted against the substance of rights – not the marketing label – because that is how ESMA-aligned competent authorities read a whitepaper. To discuss your token structure or whitepaper review, contact info@oboluslaw.com or message us via t.me/oboluslaw.

By Roman Levitt, Technology & DeFi Counsel – specialising in token classification, MiCA compliance and smart-contract legal architecture for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours