Stablecoin issuance has moved from a niche engineering exercise to one of the most closely supervised activities in digital-asset markets. Regulators across every major hub – from ESMA enforcing the MiCA regime across the EU to VARA in Dubai and the Monetary Authority of Singapore applying the Payment Services Act – now treat stablecoin issuers as systemically significant actors, not merely another class of virtual asset service provider (VASP, meaning an entity providing services involving digital assets on behalf of others). Getting the authorisation architecture right before launch is no longer optional. Getting it wrong converts a product launch into an unregistered financial instrument offering, with enforcement consequences that travel across borders.
This page sets out the regulated basis for stablecoin issuance, the authorisation process across the leading regimes, the cross-border complexity operators consistently underestimate, and the structural decisions that determine whether a stablecoin is launched legally or not at all. A brief decision matrix by issuer profile and a real-world micro-matter illustrate how the analysis applies in practice.
What Is a Stablecoin, Legally Speaking?
A stablecoin is not a single legal category. It is a marketing term for a token whose value is designed to remain stable relative to a reference asset – typically a fiat currency, a basket of currencies or a commodity. The legal classification depends on the rights the token confers, not the name on the whitepaper. Under MiCA, the EU's Markets in Crypto-Assets Regulation, stablecoins divide into two regulated sub-types: asset-referenced tokens (ARTs, meaning tokens referencing a basket or non-currency asset) and e-money tokens (EMTs, meaning tokens referencing a single fiat currency). Both require issuer authorisation before the token may be offered to the public in the EU or admitted to trading on a regulated platform.
Outside the EU, the same substance-over-label principle applies. A stablecoin that pays interest, confers governance rights over a reserve pool, or provides a claim on a share of protocol revenue may cross into securities territory under the applicable domestic regime – whether that is the SEC and CFTC frameworks in the United States, the SFC's classification guidance in Hong Kong, or FINMA's token taxonomy in Switzerland. The legal classification question must be answered jurisdiction by jurisdiction, and the answer drives every downstream decision: which licence, which disclosure document, which reserve and redemption regime.
In our practice, the single most common early mistake is assuming that a utility label on a whitepaper settles the classification. It does not. Classification is determined by the economic substance of the rights the token holder actually holds. We assess that substance first, before the issuer commits to a structure.
The Regulated Perimeter: Which Regimes Apply?
Stablecoin issuers face a layered perimeter: the regime governing the token itself, the regime governing the activities around it, and the regimes of every jurisdiction where the token is offered, traded or held. No single authorisation solves all three layers.
Under MiCA, an EMT issuer must be authorised either as a credit institution or as an electronic money institution. An ART issuer requires a dedicated MiCA authorisation from the relevant national competent authority, which may be supplemented by ESMA oversight where issuance reaches significant thresholds. VARA in Dubai regulates stablecoin activities as a subset of its activity-based licensing regime; an entity issuing, transferring or managing a stablecoin in mainland Dubai must hold the relevant VARA licence category. The FSRA within ADGM operates a parallel framework for the Abu Dhabi financial free zone. MAS in Singapore has introduced specific stablecoin regulatory requirements under the Payment Services Act for single-currency stablecoins pegged to the Singapore dollar or a G10 currency – a distinct track from the general digital payment token licensing regime.
In the United Kingdom, the FCA's financial-promotion regime applies to stablecoins communicated to UK persons, and HM Treasury has signalled a dedicated stablecoin authorisation regime. In the United States, the picture remains fragmented: FinCEN, the SEC and the CFTC may each assert jurisdiction depending on the token's design, and state money-transmitter licensing may apply in parallel. NYDFS's BitLicense framework covers virtual currency activities in New York.
The cross-border reality is that an issuer domiciled in one jurisdiction and serving users in five others must hold – or be exempt from – a licence in each relevant market. The entity structure, the contractual terms, the reserve location and the onboarding flow all affect which jurisdictions are triggered.
For a scoped mapping of which regimes apply to your issuance structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard perimeter. Your specific token design, user base and reserve architecture change the analysis materially. Map your options.
The Authorisation Process: What Does It Actually Involve?
Stablecoin authorisation is a multi-stage process that begins well before an application is submitted and continues well after a licence is issued. The sequence across the major regimes follows a recognisable pattern, even if the specific requirements differ.
The first stage is token classification and structural design. Before any application is drafted, the issuer must determine how the token is classified under each relevant regime, which licence category or authorisation track applies, and whether any exemptions are available. This analysis drives entity structuring: where the issuer is incorporated, where the reserve assets are held, and how the smart contract architecture interacts with the legal documentation.
The second stage is regulatory documentation. Under MiCA, an ART or EMT issuer must prepare a whitepaper – the disclosure document required under the regulation – containing prescribed information about the token, the issuer, the reserve composition, the redemption mechanism and the rights of holders. The whitepaper is notified to the national competent authority before publication. Separately, the authorisation application requires a business plan, governance and risk-management documentation, and evidence of the required own funds. VARA's application process requires comparable documentation: a detailed regulatory business plan, AML/CFT programme, technology and security assessments, and evidence of capital adequacy.
The third stage is ongoing compliance architecture. Authorisation is not a one-time event. MiCA imposes ongoing obligations: reserve composition and segregation requirements, redemption-on-demand obligations, significant-stablecoin oversight triggers, and periodic reporting. VARA's rulebooks impose equivalent operational requirements. The Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary data with a virtual asset transfer – applies to stablecoin transfers above the applicable threshold in most flagship jurisdictions.
In our cross-border practice, we structure the authorisation workstream as a single mandate covering the regulatory application, the whitepaper or disclosure document, the AML/CFT programme and the banking and reserve arrangement. Treating these as separate workstreams is one of the most consistent sources of delay and rework we observe.
Common Mistakes That Derail Stablecoin Authorisation
Mis-classifying the token is the foundational error, but it is rarely the only one. Several other structural mistakes appear repeatedly in the matters we review.
Reserve architecture mismatches. The legal regime governing the reserve assets may differ from the regime the issuer anticipated. A reserve held in a bank account in a jurisdiction without deposit-insurance coverage, or in assets that fail to meet the liquidity composition requirements under the applicable framework, creates a compliance deficiency that an application cannot paper over. Under MiCA, EMT issuers face specific reserve composition requirements; ART issuers face a distinct set. FINMA applies its own reserve and safeguarding analysis for Swiss-issued stablecoins.
Ignoring the securities overlay. Even where a stablecoin is not classified as a security under its primary regime, it may be treated as one by another jurisdiction's regulator. An issuer offering globally must assess the US, Hong Kong and Singapore positions independently. The SFC in Hong Kong applies a substance-over-form analysis aligned broadly to the securities law framework. The SEC's position on stablecoins has evolved and continues to develop; issuers with US-person exposure cannot rely on a single foreign classification.
Premature product launch. Operators we advise regularly encounter the assumption that a soft launch or restricted-access beta is outside the regulated perimeter. In most regimes, offering a token to the public – even in beta – triggers the disclosure and authorisation obligations. The relevant test is whether the token is made available, not whether full-scale marketing has begun.
Disconnected banking and reserve arrangements. Banking for stablecoin issuers is genuinely difficult. Reserve accounts require banking relationships with institutions that understand the product and the regulatory expectations around segregation and reporting. We see issuers reach advanced stages of an application before discovering that their proposed banking partner will not serve the structure as designed. Reserve and banking architecture must be resolved early, not late.
Cross-Border Stablecoin Issuance: The Multi-Jurisdiction Stack
A stablecoin issued from a single jurisdiction is almost never a single-jurisdiction problem. The issuer is typically incorporated in one place, the reserve is held in another, the smart contract is deployed on a global network, and users are distributed across dozens of markets. Each of those facts has a legal consequence.
The EU's MiCA regime applies to any stablecoin offered to persons in the EU, regardless of where the issuer is incorporated. A Cayman-incorporated issuer offering an EMT to French or German users is within scope of MiCA's authorisation requirement. VARA's jurisdiction extends to activities conducted in or from mainland Dubai. MAS's stablecoin requirements apply to Singapore-issued stablecoins or to stablecoins that are offered in Singapore above a de-minimis threshold defined under the Payment Services Act. Each of these regimes must be assessed independently, not assumed away on the basis of an offshore domicile.
Tax is a further layer. The issuance of tokens, the reserve management activity, and the redemption mechanism may each have distinct VAT or GST treatment, corporation tax implications, and transfer-pricing consequences depending on where the issuer entity sits and where the economic activity is treated as occurring. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – because the decisions interact. An entity structure that minimises the tax on reserve income may create a licensing problem in the target market, or vice versa.
Allied counsel in the relevant jurisdiction – engaged through our cross-border network – handle local regulatory filings where in-country presence or qualification is required. The strategy, the overall structure and the coordination are managed by a single team at OBOLUS.
Decision Matrix: Which Issuer Profile Needs What?
Not every stablecoin issuer faces the same authorisation burden. The appropriate structure and the priority jurisdictions depend on the issuer's profile.
Profile A – Fiat-referenced stablecoin, EU distribution. An issuer of a euro- or dollar-pegged EMT targeting EU users faces the full MiCA EMT authorisation track. The entity must be incorporated in an EU or EEA member state and authorised as a credit institution or e-money institution. The whitepaper obligation applies before any public offering. Reserve composition and redemption-on-demand requirements are ongoing. Timeline to authorisation is typically measured in months and depends heavily on the national competent authority selected and the completeness of the application at submission.
Profile B – Multi-currency basket token, global distribution. A token referencing a basket of currencies or assets may be classified as an ART under MiCA, a structured product under FINMA guidance, or a security in one or more common-law jurisdictions. This profile requires a classification analysis across all target markets before any structural decision is made. The issuer may need to restrict certain jurisdictions entirely or operate through separate legal entities for different market segments.
Profile C – Algorithmic or crypto-collateralised stablecoin. This profile faces the most uncertain regulatory treatment globally. Several flagship regimes either prohibit or impose heightened restrictions on non-reserve-backed stablecoins. MiCA's treatment of algorithmic stablecoins is restrictive. The US regulatory environment is actively evolving. An issuer in this category must monitor the regulatory trajectory in each target market and build the legal architecture to adapt quickly.
Profile D – Institutional or permissioned stablecoin. A stablecoin issued for use within a defined institutional network – for instance, as a settlement instrument between regulated entities – may qualify for a narrower set of obligations in some regimes, or may benefit from an exemption applicable to closed-network instruments. The qualification analysis is fact-specific and should not be assumed without legal review.
If your structure does not fit cleanly into one of these profiles, contact OBOLUS at info@oboluslaw.com. Many issuers we see have a hybrid design that does not map neatly to any single track, and the analysis of where it sits is the most consequential work we do. Map your options.
A Common Assumption: The Utility Label Objection
A common assumption among issuers approaching authorisation is that the legal classification of their token is determined by what they call it. A stablecoin labelled as a "utility token" on a whitepaper, the assumption goes, avoids the securities overlay and simplifies the authorisation path. That assumption is incorrect and carries material risk.
Every major regulator with jurisdiction over token offerings applies a substance-over-form analysis. The FCA, the SFC in Hong Kong, FINMA, ESMA under MiCA, and the SEC in the United States all assess the economic rights the token confers, the expectation of profit or return it creates, and the degree to which holders are dependent on the efforts of a third party. A utility label that does not reflect the actual mechanics of the token does not change that analysis. In some cases, a misleading label exacerbates regulatory exposure by suggesting the issuer was aware of the classification risk and chose to disregard it.
Our assessment of token classification begins with the smart contract mechanics and the economic rights on the token's face, not with the marketing documentation. Where a stablecoin sits in an uncertain zone between EMT, ART and security, we map the position in each target jurisdiction and advise on structural adjustments that bring the token clearly within a known, authorised category. That is a more durable position than relying on a label.
Micro-Matter: Cross-Border Stablecoin Authorisation
In a recent matter, a payments business with operations spanning two jurisdictions had issued a dollar-referenced stablecoin and was distributing it to users in both the EU and Southeast Asia without a regulatory authorisation in either market. The token had been structured on the basis of an internal classification as a utility instrument. When a user base threshold triggered regulator inquiries in both markets simultaneously, the issuer needed rapid advice on classification, the authorisation path and the steps required to avoid enforcement action.
We mapped the classification position under MiCA – concluding that the token met the definition of an EMT under the regulation – and under the Payment Services Act in Singapore, where a separate digital payment token analysis applied. We structured a sequenced authorisation plan: EU authorisation through a suitable member-state NCA as the priority filing, with a parallel application in Singapore, and interim distribution restrictions to limit ongoing exposure while the applications progressed. The reserve architecture was restructured to meet the segregation and composition requirements under both regimes. The issuer completed the dual-track filing within a quarter of instruction.
What OBOLUS Does in a Stablecoin Authorisation Mandate
Our stablecoin authorisation practice covers the full pre-launch and post-authorisation cycle. We begin with a classification and perimeter analysis: assessing how the token is treated under each relevant regime, identifying which authorisations are required, and advising on entity and reserve structures that are both legally compliant and operationally practical.
We draft and review the whitepaper or equivalent disclosure document required under the applicable regime. Under MiCA, this is a prescribed document with specific content requirements; we ensure it reflects both the regulatory requirements and the commercial substance of the token accurately. We prepare the regulatory application, coordinate with allied counsel in the relevant jurisdiction where local filings require in-country representation, and engage with the regulator through the review process.
Operators we advise on authorisation regularly ask us to remain as ongoing regulatory counsel post-launch, monitoring the compliance obligations – reserve reporting, Travel Rule implementation, significant-stablecoin threshold tracking – and advising on product changes that may require regulatory notification or an amended authorisation. We also advise on the banking relationships required to hold the reserve: identifying suitable institutional counterparties, reviewing account terms for consistency with the legal obligations, and advising where a proposed arrangement creates a structural gap.
The pricing model is transparent: fixed-scope packages for defined workstreams, with a stated starting fee, and a free initial strategy call under NDA to scope the engagement before any commitment.
Related at OBOLUS
- Token Offerings & Securities Practice – full regulatory counsel for token issuers across securities and crypto-asset frameworks
- Security Token: A Legal Guide for Digital Asset Businesses – how security token classification works in practice and what it means for your offering
- NFT Project Legal Structuring – legal counsel for digital-asset firms launching NFT and tokenization projects
FAQ
Is my token a security?
Whether a token is a security depends on the economic rights it confers, not its label. Regulators including the FCA, SFC, FINMA and ESMA apply a substance-over-form analysis: if the token creates an expectation of profit derived from the efforts of a third party, it is likely treated as a security in that jurisdiction. Classification must be assessed separately in each market where the token is offered, held or traded, and a utility designation in one regime does not bind another.
Do I need a MiCA whitepaper?
Under MiCA, an issuer of an ART or EMT must publish a whitepaper containing prescribed disclosures about the token, the issuer, the reserve and the rights of holders before any public offering in the EU or EEA. The whitepaper must be notified to the relevant national competent authority. Certain exemptions apply – for instance, to offerings below a defined threshold or to tokens offered only to qualified investors – but those exemptions are narrow and fact-specific. Issuers should not assume an exemption applies without legal review.
How should an airdrop be structured legally?
An airdrop is not automatically outside the regulated perimeter. If the tokens distributed have economic value and are received by persons in regulated jurisdictions, the distribution may trigger disclosure obligations or constitute a public offering under the applicable regime. The key factors are whether consideration is given, what rights the token carries, and who receives it. A carefully structured airdrop – limiting recipients to non-restricted jurisdictions, ensuring the token does not carry investment-return characteristics, and documenting the basis for any exemption relied upon – reduces regulatory exposure materially.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance architecture that surrounds every digital-asset operation. We assess token classification against the substance of rights, not the marketing label, and we structure licensing, banking and tax as one integrated mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. To discuss your stablecoin issuance or token offering, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Roman Levitt, Technology & DeFi Counsel – advises on token classification, smart-contract legal architecture and regulatory authorisation for stablecoin and DeFi protocol issuers across multiple jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.