A regulated entity preparing a security token offering faces a classification decision that cannot be deferred. Get it wrong, and a product launch becomes an unregistered securities offering — with enforcement exposure across every jurisdiction where tokens reach investors. Get it right, and the same instrument can access capital markets that remain closed to conventional equity. The legal question is not whether your token looks like a security; it is whether the rights it confers make it one under the applicable regime.
A security token offering (an STO — the issuance of a blockchain-based token that represents regulated financial rights, such as equity, debt or profit participation) sits at the intersection of capital-markets law, digital-asset supervision and cross-border compliance. The classification analysis must run before the offering structure is designed, not after the whitepaper is drafted. OBOLUS advises regulated entities on the full arc: from token classification through issuance structure, disclosure obligations and post-issuance compliance.
This page sets out the regulated basis for STOs, the structuring process, the common mistakes we see in practice, the cross-border interaction with tax and banking, a decision matrix by issuer profile, and a self-assessment checklist for entities preparing to engage counsel.
Why token classification must precede everything else
Token classification is the foundational legal act in any STO — and it is the step most frequently compressed or skipped by issuers who assume a utility label forecloses the analysis. It does not. Regulators in every major jurisdiction apply a substance-over-form test: the rights conferred by the token determine its legal character, not the name on the documentation.
Under MiCA, the European Union's Markets in Crypto-Assets Regulation (administered by ESMA and national competent authorities), tokens that qualify as financial instruments under existing securities law fall outside MiCA's perimeter and into the existing prospectus and markets regime. The boundary between a MiCA "other crypto-asset" and a security is therefore both critical and fact-specific. A token conferring profit-participation rights, governance rights linked to economic value, or a right to a share of revenues will in most analyses cross that boundary.
In the UAE, VARA (the Virtual Assets Regulatory Authority, Dubai's primary digital-asset regulator) distinguishes virtual assets from investment contracts and applies its own activity-based licence taxonomy. A token that is an investment contract in substance will attract a different regulatory track than a utility or exchange token. Operators we advise routinely encounter the same instrument described differently by the issuer's marketing team and by the applicable securities regulator — the regulator's view governs.
Singapore's MAS, Hong Kong's SFC, the FCA in the UK, and the SEC and CFTC in the US each apply their own classification tests. In our cross-border practice, we treat the issuer's largest addressable markets as the classification jurisdictions — because tokens travel, and residency of the issuer is not the ceiling of enforcement exposure.
The practical rule: classify first, structure second, document third. Any other sequence inverts the risk.
For a scoped classification analysis of your token — before you commit to a structure — contact OBOLUS at info@oboluslaw.com. The classification memo is the document that anchors every downstream decision in your STO.
What the regulated perimeter for an STO actually covers
An STO involving a token that is a financial instrument engages, simultaneously, capital-markets law, AML/CFT obligations, investor protection rules, and — depending on the issuance structure — fund regulation. Regulated entities issuing security tokens are not stepping outside their existing regulatory perimeter; they are extending it into on-chain infrastructure.
Under MiCA, a token classified as a financial instrument is governed by existing EU directives and regulations — the prospectus regime, the markets abuse framework, and the relevant investment services directive. MiCA's whitepaper obligation applies to crypto-assets that fall within its scope, but tokens classified as securities carry a higher disclosure standard: the prospectus, not just the whitepaper. Regulated entities already authorised as CASPs (Crypto-Asset Service Providers) under MiCA still need to comply with the securities perimeter for any token that crosses it.
In the UK, the FCA's treatment of security tokens under the financial-promotion rules and the existing regulated-activities regime means that a token representing equity or debt in a UK-nexus issuer requires either registration as a prospectus or an applicable exemption. The FCA's cryptoasset registration under the Money Laundering Regulations is a floor, not a ceiling — it does not substitute for the securities authorisation a token may require.
Across the ADGM framework (the Financial Services Regulatory Authority in Abu Dhabi), the AIFC/AFSA framework in Kazakhstan, and the BVI FSC's VASP Act 2022, security tokens attract regime-specific treatment. None of those regimes treats a securities token as a simple digital asset for AML purposes only. In our practice, we see issuers underestimate the depth of the regulated perimeter — particularly when the token is issued from an offshore structure but offered to investors in regulated markets.
The cross-border reality is this: a token offering that touches EU investors, US persons, UK residents, and UAE-based institutions may engage five or more regulatory regimes simultaneously. The issuer's legal seat determines where the primary authorisation sits; the investor base determines the compliance perimeter. Those two variables define the structure.
How an STO is structured: the process step by step
Structuring a compliant security token offering follows a defined sequence — and compressing any step creates compounding risk downstream.
Step 1 — Classification memo. A written legal analysis of the token's rights, the issuer's structure, and the intended investor base, assessed against the applicable regimes. This memo drives every subsequent decision. It is not a whitepaper; it is a confidential legal document.
Step 2 — Issuer entity and jurisdiction selection. The classification result determines which jurisdictions can house the issuer. A security token issued by an EU-authorised entity will engage MiCA and the relevant securities regime from day one. An issuer choosing to domicile in the ADGM, the AIFC or the Cayman Islands does so because those regimes offer a pathway that matches the token's legal character and the target investor base.
Step 3 — Disclosure document preparation. Depending on the regime: a prospectus (securities law compliance), a whitepaper (the disclosure document required under MiCA for in-scope tokens, containing the issuer, token rights, risks and technical specifications), or both. The whitepaper under MiCA is not a marketing document — it carries regulatory liability.
Step 4 — Regulatory filing or exemption analysis. Where the token is a security in the primary jurisdiction, the issuer either files a prospectus with the competent authority, relies on an available exemption (by investor type, size of offering or qualified-investor restriction), or structures to avoid the obligation. Each path has a different risk and cost profile.
Step 5 — Smart-contract and token architecture review. The legal rights documented in the prospectus or whitepaper must be reflected in the on-chain mechanics. Rights that exist in documentation but not in the token's code create contractual inconsistency. We review the token architecture against the legal documentation as a standard step.
Step 6 — Transfer restrictions and secondary-market compliance. Security tokens often carry transfer restrictions — by investor jurisdiction, by lock-up period or by KYC gate. Those restrictions must be coded at the token level and documented in the offering materials. Secondary trading of security tokens may engage a separate regulated-market or MTF obligation.
Step 7 — Post-issuance ongoing compliance. Reporting obligations, material-change notifications, investor communication requirements and AML/Travel-Rule compliance for the token's ongoing lifecycle. Regulated entities issuing security tokens inherit the same ongoing disclosure obligations they would have in a conventional securities issuance.
In our cross-border practice, we manage the interaction between the issuer's home-jurisdiction counsel and allied counsel in the relevant jurisdictions where investors are located — because no single-jurisdiction analysis is sufficient for an offering with multi-market reach.
What goes wrong: the four structuring mistakes we see most often
Most STO failures in practice do not arise from deliberate non-compliance — they arise from a small set of recurring analytical errors.
Mistake 1 — Labelling before analysing. The most prevalent error. An issuer decides the token is a "utility token," drafts a whitepaper on that basis, and only engages legal counsel to review the document rather than the underlying analysis. By that stage, the whitepaper may already contain representations inconsistent with the token's actual legal character. The label does not bind the regulator.
Mistake 2 — Single-jurisdiction analysis for a multi-market offering. An issuer obtains a legal opinion in one jurisdiction and treats it as global clearance. It is not. A token that is not a security in the Cayman Islands may still be a security in the UK, the EU, or the US — and those jurisdictions' enforcement arms will apply their own tests to their own residents.
Mistake 3 — Treating the whitepaper as the compliance instrument. Under MiCA, a whitepaper is a mandatory disclosure document for certain crypto-assets, not a substitute for securities-law compliance. An issuer who files a MiCA whitepaper and believes that satisfies all obligations across the EU has not accounted for the financial-instrument carve-out.
Mistake 4 — Deferred AML integration. The Travel Rule (the obligation, derived from FATF Recommendation 15, to pass originator and beneficiary data with a virtual-asset transfer) applies to transfers of security tokens where the issuer or transfer agent is a VASP. Issuers frequently build the token architecture before integrating Travel-Rule compliance, requiring costly retrofitting. The correct sequencing is to build Travel-Rule capability into the token infrastructure before the offering launches.
A common assumption in the market is that slapping a utility label on a whitepaper resolves the classification question. It does not — and the enforcement record in the EU, UK, US and Singapore makes clear that regulators will look through the label to the substance of the rights.
The cross-border interaction: tax, banking and secondary markets
For a business sitting between a regulated issuer jurisdiction and a multi-market investor base, the cross-border interaction is not a peripheral concern — it is the core structuring problem.
Tax treatment of security tokens varies materially by jurisdiction. In most OECD-aligned regimes, a token representing equity or debt is taxed on the same basis as conventional securities — capital gains on disposal, income tax or withholding on distributions. But the timing of tax events (does a token transfer trigger a disposal?), the characterization of staking or yield (income or capital?), and the VAT/GST treatment of the offering itself are all jurisdiction-specific and require analysis before the structure is finalised. We advise on the tax architecture in parallel with the legal structuring — because the two are interdependent.
Banking for STO issuers is a persistent operational challenge. Banks in most regulated markets apply enhanced due diligence to digital-asset businesses. A regulated entity issuing a security token should expect to address questions about the token's legal classification, the AML framework around the offering, the investor base's KYC treatment, and the fiat flow mechanics for subscription proceeds. We work with issuers to prepare the banking narrative — the documentation package that explains the offering to a correspondent bank — before the account is needed, not after the application is declined.
Secondary markets present a further layer. A security token that is freely tradeable on a secondary platform may require that platform to hold a regulated-market or multilateral trading facility authorisation under the applicable securities regime. If the issuer intends secondary liquidity, the secondary-market compliance question must be addressed in the initial structuring — not treated as a post-issuance add-on.
In a recent STO matter, a financial-services firm domiciled in a common-law offshore jurisdiction issued a token representing profit-participation rights to qualified investors across three continents. We structured the offering documentation to address EU, UK and Singapore nexus simultaneously, coordinated with allied counsel in the relevant jurisdictions, and built the transfer-restriction architecture into the token's smart contract before launch. The offering closed with a compliant secondary-trading pathway already in place.
Decision matrix: which structure fits which issuer profile
No single STO structure suits every regulated entity. The right instrument and disclosure path turns on four variables: the token's legal character, the issuer's regulatory seat, the target investor profile, and the intended secondary-market treatment.
Profile A — EU-authorised regulated entity, token is a financial instrument, offering to qualified investors across the EEA. The applicable regime is the EU prospectus framework with the MiCA overlay for the disclosure document. The issuer relies on the qualified-investor exemption to avoid a full public prospectus. The CASP authorisation under MiCA runs in parallel for any in-scope service activity. Timeline from classification memo to offering launch is typically measured in months, not weeks. Key risk: underestimating the scope of the prospectus exemption conditions.
Profile B — Offshore issuer (Cayman, BVI, ADGM), token is a security in substance, offering to global institutional investors with US-person exclusion. The issuer structures the offering under the applicable offshore securities regime and a Regulation S equivalent restriction for US persons. The VARA or ADGM framework governs if the issuer is Dubai or Abu Dhabi-based. The offering document is a private placement memorandum aligned with the primary jurisdiction's requirements. Transfer restrictions are coded at token level. Key risk: insufficient geo-fencing of the US-person exclusion in practice.
Profile C — Singapore or Hong Kong-regulated entity, token represents fund interests, offering to professional investors. The MAS Payment Services Act governs any DPT service activity, but the fund interests themselves fall under the securities and collective investment scheme regime. The SFC in Hong Kong applies its own VATP licensing framework. The offering requires both the securities authorisation (or applicable exemption) and the AML/VASP registration. Timeline depends on whether the fund is already authorised. Key risk: assuming the existing fund authorisation extends to the on-chain representation without further regulatory clearance.
Profile D — UK-nexus issuer, token is a structured financial product, offering under financial-promotion rules. The FCA's financial-promotion restrictions apply to communications about the token. The issuer either relies on a financial-promotion exemption or uses an FCA-authorised approver. The MLR cryptoasset registration is a necessary floor condition. Key risk: communication materials reviewed without analysis of the financial-promotion obligations, leading to unlawful promotions before the offering opens.
For a structured assessment of which profile matches your entity and which instrument is appropriate, write to OBOLUS at info@oboluslaw.com. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back.
Self-assessment checklist for entities preparing an STO
Before engaging counsel for a security token offering, a regulated entity should be able to answer — or at least frame — the following questions. Where the answer is uncertain, that uncertainty is itself a structuring input.
- Has a written classification analysis been completed for the token, assessed against the regimes of the issuer's primary jurisdiction and the largest investor-nexus jurisdictions?
- Is the issuer already authorised in the primary jurisdiction for the relevant activity, or does the offering require a new authorisation or registration?
- What rights does the token confer on holders — economic, governance, or both — and are those rights reflected in both the documentation and the smart contract?
- Has the target investor profile been defined: professional/qualified investors only, or retail access?
- What is the intended secondary-market pathway, and has the regulated-market or MTF question been addressed?
- Has the tax treatment of the token — at the issuer level and at the investor level — been analysed in each relevant jurisdiction?
- Is the issuer's banking relationship prepared for the STO transaction flow, including enhanced due diligence questions?
- Has the Travel-Rule compliance architecture been designed into the token infrastructure before launch?
Regulated entities that can answer all eight questions with documented analysis are ready to move to the documentation phase. Entities that cannot are at the structuring phase — which is the correct starting point for counsel engagement.
Related at OBOLUS
- Token offerings and securities practice overview – the full scope of OBOLUS's token-offering and securities advisory work
- Airdrop legal structuring: cross-border perspective – legal structuring for token distributions across multiple jurisdictions
- STO structuring counsel for digital-asset financial institutions – deep-dive advisory for licensed digital-asset firms issuing security tokens
FAQ
Is my token a security?
Whether a token is a security depends on the rights it confers, not the label applied to it. Regulators in the EU (under MiCA and the existing securities regime), the US (SEC and CFTC), the UK (FCA), Singapore (MAS) and Hong Kong (SFC) each apply a substance-over-form test. A token that confers profit participation, equity rights or debt entitlements will in most analyses be treated as a financial instrument. Classification requires a written legal analysis assessed against every jurisdiction where the token will reach investors.
Do I need a MiCA whitepaper?
Under the MiCA regime, a whitepaper is required for crypto-assets within MiCA's scope — broadly, tokens that are not financial instruments, e-money tokens or asset-referenced tokens under the dedicated MiCA tracks. If your token is a financial instrument under EU securities law, it falls outside MiCA's perimeter and requires a prospectus (or an applicable exemption), not a whitepaper. If it falls within MiCA's "other crypto-assets" category, a whitepaper with defined mandatory content must be prepared and notified to the relevant national competent authority before the offering.
How should an airdrop be structured legally?
An airdrop's legal treatment depends on the token being distributed and the basis of distribution. If the airdropped token is a security in the recipient's jurisdiction, the distribution may constitute an unregistered securities offering. Even where the token is not a security, airdrop mechanics can trigger AML obligations, tax events and promotional-communication rules. A legally sound airdrop requires a classification analysis of the token, a jurisdictional screen of the recipient base, documentation of the distribution rationale, and a review of the financial-promotion position in each material jurisdiction.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and regulated entities on offerings, licensing and structuring across more than 70 jurisdictions, and on disputes and on-chain asset recovery across more than 25 forums. Digital assets are the entirety of our practice. We assess token classification against the substance of rights, not the marketing label — because that is what regulators do. To discuss your security token offering, contact info@oboluslaw.com or message us via t.me/oboluslaw.
By Roman Levitt, Technology & DeFi Counsel — specialising in the legal architecture of on-chain instruments, token classification, and smart-contract alignment with regulatory documentation requirements in multi-jurisdictional offerings.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.