For an early-stage founder, the classification of a token is the single most consequential legal question in the entire build. A security token offering (an offer of digital tokens that qualify as regulated securities under applicable law) triggers a distinct set of obligations – prospectus or whitepaper requirements, investor eligibility rules, ongoing disclosure obligations and, critically, the need for regulatory authorisation before any sale. Mis-classifying a token converts a product launch into an unregistered securities offering, exposing founders, the issuing entity and sometimes the underlying protocol to enforcement action across multiple jurisdictions simultaneously.
The legal analysis turns on substance, not marketing. Regulators from the SEC and CFTC to ESMA and the SFC assess the rights a token actually confers – economic returns, profit participation, governance claims – not the label on the deck. Under the applicable regimes, the same token can be a security in one jurisdiction, an asset-referenced token (an ART under MiCA, the EU's Markets in Crypto-Assets Regulation) in a second, and an unregulated digital commodity in a third. This page sets out how early-stage founders should approach structuring, where the regulatory pressure points lie, and what a defensible offering looks like from day one.
What Makes a Token a Security?
A token is treated as a security when the substance of the rights it confers maps onto the definition of a regulated investment under the law of the relevant jurisdiction. In the United States, the standard long applied by the SEC derives from investment-contract analysis: consideration paid into a common enterprise with an expectation of profit from the efforts of others. The FCA in the United Kingdom applies a similar economic-substance test under its specified-investment regime. In the EU, MiCA's taxonomy distinguishes asset-referenced tokens (ARTs), e-money tokens (EMTs) and "other" crypto-assets, but tokens that qualify as transferable securities under existing EU financial-instruments law fall outside MiCA and into the prospectus and investment-services frameworks instead.
The critical insight for founders is that classification is not a one-time decision. A token that launches as a utility instrument can migrate into regulated territory as secondary-market liquidity develops, as the issuer's promises evolve, or as a court or regulator applies its own analytical framework retrospectively. ESMA has confirmed that token classification under MiCA will be assessed on a look-through basis, examining the economic reality of the instrument, not the issuer's stated intent. The SFC in Hong Kong and MAS in Singapore take materially the same position under their respective regimes.
In our practice, we see founders make two errors at this stage: they rely on a whitepaper utility narrative without mapping that narrative against each jurisdiction's specific test, and they fail to document the classification analysis contemporaneously. Both omissions are avoidable. A defensible classification memo – prepared before any marketing materials go out – is the single most valuable document in an early-stage token programme.
To map your token's classification exposure before you publish a single line of marketing, contact OBOLUS at info@oboluslaw.com. The process above describes the standard analysis. Your token's specific rights structure, your target investor base and the jurisdictions where you intend to distribute may change the conclusion materially. Map your options
The Regulated Perimeter: Which Regimes Apply to Your Offering?
Determining which regulatory regime governs a security token offering requires identifying three separate data points: where the issuing entity is incorporated, where the offering will be marketed, and where the anticipated investors reside. Each creates an independent jurisdictional hook. Founders who incorporate offshore to avoid domestic securities law routinely discover that marketing to EU residents triggers MiCA or the EU prospectus framework, that marketing to US persons triggers SEC jurisdiction regardless of issuer domicile, and that a Singapore-based exchange listing triggers a MAS review of whether the token constitutes a capital-markets product under the Payment Services Act.
The major frameworks founders need to assess in parallel include the following. In the EU, MiCA creates a single licence for crypto-asset service providers (CASPs) and imposes whitepaper-publication obligations on issuers of crypto-assets that do not qualify as financial instruments; where the token is a financial instrument, the EU Prospectus Regulation and MiFID II apply instead. In the UAE, the VARA regime in Dubai and the FSRA within the ADGM in Abu Dhabi each impose activity-based licensing for token issuers and service providers. In Hong Kong, the SFC applies its VASP licensing regime to trading platforms and scrutinises whether tokens offered through those platforms constitute securities. In Singapore, MAS applies the Payment Services Act to digital-payment-token services and the Securities and Futures Act where a token is a capital-markets product.
The practical consequence is that a single offering will often intersect with three or more regimes simultaneously. We regularly advise founders on exactly this multi-layered exposure – identifying which regimes generate hard compliance obligations and which generate only disclosure or notification requirements – before any external communication goes out.
How Should Founders Structure a Security Token Offering?
Structuring a security token offering involves five sequential decisions, each of which constrains the options available at the next stage. The sequence matters: reversing the order – choosing an investor-facing token design before settling the issuing entity and jurisdictional perimeter – is the most common structural mistake we encounter.
Step one: issuing entity selection. The entity that issues the token bears the regulated obligations. Common domiciles for issuance include the Cayman Islands (under CIMA's Virtual Asset framework), the BVI (under the VASP Act 2022 administered by the BVI FSC), Malta (where the MFSA administers the VFA framework transitioning to MiCA compliance) and ADGM. The choice interacts directly with where you can lawfully market: a Cayman issuer marketing to EU residents still needs to comply with MiCA's third-country access provisions.
Step two: token design and rights mapping. Before a single line of the offering document is drafted, the rights attached to the token – economic, governance and transferability – must be documented. This documentation becomes the foundation of the classification analysis and the basis for any whitepaper prepared under MiCA or equivalent regimes. Under MiCA, whitepaper obligations attach to most categories of crypto-asset issuance, with specific additional requirements for ARTs and EMTs.
Step three: investor eligibility and exemption mapping. Security token offerings directed at professional or institutional investors can use exemptions from full prospectus or registration requirements in most major jurisdictions. These exemptions are jurisdiction-specific and have conditions – minimum investment thresholds, investor categorisation requirements, volume caps and notification obligations – that must be satisfied at the point of sale and documented thereafter.
Step four: the disclosure document. Depending on classification and jurisdiction, this is a MiCA-compliant whitepaper, an offering memorandum, a prospectus or a combination. The document must be legally accurate, internally consistent with the token's actual rights structure, and filed or notified to the relevant regulator before distribution. Under MiCA, ESMA has published detailed guidance on the content requirements for whitepapers across asset classes.
Step five: ongoing obligations. A security token offering does not end at closing. Transfer restrictions, secondary-market trading permissions, periodic disclosure, AML/KYC record-keeping and, where applicable, Travel Rule compliance (the obligation to pass originator and beneficiary data with a token transfer) continue post-issuance. Founders who treat the offering as a point-in-time event routinely face enforcement action tied to post-closing secondary trading they did not anticipate.
Common Mistakes Founders Make Before Counsel Is Engaged
The most consequential mistakes in a security token programme are structural, not technical, and they are almost always made before legal counsel is engaged. Identifying them early – ideally before any public communication – is the difference between a compliant launch and an enforcement-driven restructuring.
The first and most frequent error is the utility-label fallacy: drafting a whitepaper that describes a token as a utility instrument and treating that description as determinative of the legal classification. No regulator – not the SEC, not ESMA, not the FCA, not the SFC – accepts a whitepaper label as the basis for exemption from securities regulation. Classification is assessed on the substance of the rights conferred, the economic expectations of purchasers and the manner in which the token is marketed. A whitepaper that overpromises secondary-market returns or conflates governance rights with profit participation can trigger a security classification regardless of the section heading that precedes it.
The second error is geography blindness. Founders often build a compliance analysis for their home jurisdiction and neglect the regulatory footprint created by their investor base. An offering distributed through a public token sale – even one conducted entirely online from an offshore entity – will reach investors in regulated jurisdictions. Each such investor creates a potential jurisdiction-of-sale nexus. The applicable regimes do not require physical presence of the issuer; they require only that the offer was directed at, or accessible to, persons within the jurisdiction.
The third error is treating AML/KYC obligations as a post-launch item. Under FATF Recommendation 15, virtual asset service providers are required to apply customer due diligence at the point of onboarding. An offering that completes before KYC is in place is an offering that retrospectively lacks the required compliance documentation for every investor it onboarded.
In a matter we handled recently, a technology company had published a whitepaper and begun a soft-marketing phase before any legal classification work was undertaken. By the time we were engaged, investor communications were already live and a secondary-market listing was being negotiated. We conducted an emergency classification analysis across four jurisdictions, restructured the investor eligibility criteria to confine the offering to professional investors in the relevant regimes, and revised the whitepaper accordingly. The offering proceeded – but on a materially more restricted basis and on a compressed timeline that generated additional cost. Early engagement would have avoided both.
Cross-Border Structuring: Where Should the Issuer Sit?
The issuing entity's domicile is not simply a tax question. It determines which regulator has primary jurisdiction over the offering, which exemptions are available to limit prospectus or registration obligations, and which secondary-market venues the token can access at launch. For an early-stage founder, the choice of issuer domicile is one of the most consequential decisions in the entire programme.
Several structural profiles recur in our cross-border practice. A founder building for a global investor base and seeking EU market access often structures with a MiCA-authorised CASP in a member state – Lithuania and Malta are frequently assessed at this stage, though each has distinct characteristics under MiCA's transition rules. A founder focused on institutional capital from the Middle East and Asia may structure through ADGM, accessing the FSRA's virtual-asset framework and benefiting from ADGM's common-law legal environment. A founder running a leaner early-stage programme with offshore investors may use a Cayman or BVI issuing vehicle, applying CIMA's or the BVI FSC's registration framework respectively, while relying on exemptions to restrict the offering to non-US, non-EU professional investors.
Each profile involves trade-offs. An EU CASP authorisation unlocks the MiCA passport – the ability to operate across EU member states from a single authorisation – but imposes whitepaper-publication and ongoing-disclosure obligations that a purely offshore structure may avoid for a period. A VARA licence in Dubai is activity-specific and covers a defined list of virtual-asset activities; a founder whose business spans advisory, exchange and custody functions may need multiple activity endorsements. We structure licensing, banking and the token programme as one integrated mandate rather than three disconnected workstreams, which is the only way to ensure that the entity, the offering and the banking stack are mutually consistent.
If the domicile decision is still open, a scoped structuring review with OBOLUS can identify the optimal issuer jurisdiction before any entity is incorporated. Write to us at info@oboluslaw.com. If a prior structuring decision has already created a compliance constraint, a second read of the structure can surface the issue and the route forward. Map your options
Self-Assessment Checklist for Early-Stage Founders
Before engaging counsel, founders can use the following checklist to identify the highest-priority questions in their specific programme. Each item that cannot be answered with confidence is a structural risk point that warrants legal input.
- Has the token been classified under the law of each jurisdiction where it will be marketed, not merely the issuer's home jurisdiction?
- Has that classification analysis been documented in a contemporaneous legal memorandum, separate from the whitepaper?
- Does the whitepaper accurately describe all rights attached to the token – including any economic, governance and transferability rights – without overstating utility?
- Have investor eligibility criteria been set by reference to the exemptions available in each target jurisdiction, not by internal preference?
- Is the AML/KYC programme in place before any investor onboarding begins?
- Has the Travel Rule compliance obligation been assessed, particularly if the token will be transferred between virtual asset service providers post-issuance?
- Has the post-issuance secondary-market trading environment been mapped – including which exchanges can list the token consistent with their own regulatory status?
- Is the issuing entity properly capitalised and structured to bear the ongoing obligations that attach post-offering?
- Has the banking stack – for both the issuing entity and the offering proceeds – been confirmed with a bank that accepts the relevant token programme?
In our experience, fewer than half of early-stage token programmes can answer all nine questions affirmatively before their first external communication. The gap between affirmative answers and the programme's actual state is, in most cases, the direct source of subsequent regulatory friction.
Decision Matrix: Which Founder Profile Should Choose Which Structure?
The optimal structure for a security token offering depends on the issuer's profile, target investor base, product stage and geographic ambitions. No single structure is universally correct. The following analysis identifies the considerations most relevant to each profile.
Profile A – Seed-stage issuer, primarily institutional investors, global remit. For a founder at the pre-Series A stage seeking capital from professional investors across the US, EU and Asia, a Cayman or BVI issuing vehicle – registered under CIMA or the BVI FSC respectively – combined with a tightly drafted private-placement memorandum and hard jurisdictional restrictions (no US persons, no retail EU investors) is often the most workable starting point. Timeline from entity incorporation to investor close is typically a matter of weeks to a few months depending on KYC complexity and investor onboarding. Key risk: geography creep – informal communications with investors in restricted jurisdictions undermining the exclusion.
Profile B – Growth-stage issuer, EU retail or institutional access required. A founder needing lawful access to EU investors must address MiCA directly. Depending on whether the token is an ART, an EMT or "other" crypto-asset, the obligations vary – but in all cases a MiCA-compliant whitepaper must be published before any marketing begins, and the issuer or a CASP acting on its behalf must satisfy ESMA's content and process requirements. Authorisation timelines under MiCA vary by national competent authority and by application complexity; founders should budget conservatively. Key risk: token reclassification by an NCA applying a stricter read of the financial-instruments carve-out.
Profile C – Middle East and Asia Pacific focus, institutional capital. A founder targeting sovereign wealth, family offices and institutional investors in the UAE and Singapore should assess ADGM (FSRA) and MAS in parallel. ADGM offers a common-law environment with well-developed judicial infrastructure; MAS applies a tiered payment-services framework with specific requirements at the major-payment-institution level. Key risk: dual-regime compliance cost, particularly where the token straddles the payment-token and capital-markets-product definitions differently under each regime.
FAQ
Is my token a security?
No single answer applies universally. Classification is assessed jurisdiction by jurisdiction, based on the substance of the rights the token confers – economic returns, profit participation, governance claims – not the label applied in the whitepaper. The same token can be a security under US law, an ART under MiCA and unregulated in a third jurisdiction. A contemporaneous, multi-jurisdiction classification analysis, prepared before any marketing begins, is the only reliable basis for proceeding.
Do I need a MiCA whitepaper?
Under MiCA, most issuers of crypto-assets targeting EU investors or EU-based buyers must publish a whitepaper that meets ESMA's content requirements before any marketing or sale. The obligation applies to issuers regardless of where they are incorporated, provided the crypto-asset is offered to persons in the EU. ART and EMT issuers face additional requirements, including authorisation from the relevant national competent authority. Tokens that qualify as financial instruments fall outside MiCA and into the EU prospectus and investment-services frameworks instead.
How should an airdrop be structured legally?
An airdrop is not legally neutral. If the tokens airdropped carry economic rights, are distributed to a defined class of recipients in exchange for any consideration – including past activity on a protocol – or are marketed as having future value, regulators in major jurisdictions may treat the distribution as an offer of securities or as a taxable event. The structure of an airdrop should be reviewed against the token's classification, the jurisdiction of recipients, applicable AML requirements and the tax consequences in the issuer's domicile before any distribution is announced.
Related at OBOLUS
- Token Offerings & Securities Practice – our full advisory practice for token issuers and digital-asset businesses seeking compliant offerings
- Security Token Offering Structuring in Gibraltar – jurisdiction-specific analysis of Gibraltar's DLT regulatory framework for token issuers
- Tax Treatment of Tokens in Malta – Malta's token tax regime under the MFSA framework and the transition to MiCA compliance
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label – which is the only standard that holds up under regulatory scrutiny. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – specialising in token classification analysis, security token offering structuring and the cross-border regulatory treatment of digital-asset instruments for early-stage issuers.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.