Skip to content
Article·Regulation

MiFID II or MiCA: Which License Actually Lets You Issue Securities in Europe

By Ciarán Hynes·July 2026·7 min read

The most expensive misunderstanding in European tokenization is a licensing one. A firm decides to tokenize a bond, a fund, or an equity, secures a MiCA authorization, and believes it is cleared to issue and distribute the instrument across Europe. It is not. A MiCA authorization does not permit you to issue a security. The two regimes govern different things, and confusing them puts everything downstream on the wrong legal footing.

This is not a technicality. It is the first competence test in this market, and a surprising number of well-funded firms fail it.

What MiCA actually covers, and what it deliberately does not

The Markets in Crypto-Assets Regulation, which began applying across the EU through 2024, was written to bring order to a category that previously had almost none. It covers crypto-assets that are not already financial instruments: utility tokens, asset-referenced tokens, and e-money tokens, along with the services around them such as custody, exchange, and transfer. A firm that provides those services registers as a Crypto-Asset Service Provider, a CASP.

The crucial word in that description is “not.” MiCA was drafted to sit alongside the existing financial regulatory framework, not to replace it. So it carves out, explicitly, any crypto-asset that already qualifies as a financial instrument. If your token is a security, MiCA steps back by design and hands the question to the regime that already governs securities.

A security token is a security first, and a token second

This is the point the market keeps missing. When you tokenize a bond, the tokenization does not change what the instrument is. It is still a bond. It is still a transferable security, which means it is a financial instrument under the Markets in Financial Instruments Directive, MiFID II. The blockchain is the settlement and record-keeping technology. It is not a new legal category that escapes securities law.

So a tokenized equity, a tokenized fund interest, a tokenized note: each is a financial instrument, and each is governed by MiFID II. Issuing, arranging, placing, and distributing those instruments requires the authorizations that MiFID II defines, held by an authorized investment firm. A CASP authorization does not grant any of those permissions, because a CASP, by definition, deals in the crypto-assets that are not financial instruments. It is the correct license for the wrong asset.

Put plainly: if you can only offer a MiCA CASP authorization and your product is a security token, you are not authorized to do the thing you are selling.

Why the passport makes this decisive rather than academic

Both regimes share one powerful feature. They passport. A single authorization in one member state extends across the EEA, without re-authorizing country by country. This is what makes Europe a genuine single market for these activities, and it is why holding the right license is such a durable advantage.

But the passport only carries the permissions the license actually contains. A MiCA CASP passport lets you provide crypto-asset services across the Union. A MiFID II passport lets you conduct investment services in financial instruments across the Union. One authorization, twenty-seven markets, in each case. What one cannot do is stand in for the other. A firm passporting a CASP authorization across Europe still cannot issue or distribute a security token anywhere in Europe, because that permission was never in the license to begin with.

For an issuer, this is the difference between a product you can lawfully bring to market across the EU and one you cannot bring to market at all.

The two regimes are complementary, not interchangeable

None of this means MiCA is unimportant to a securities business. It means the two regimes do different jobs, and a complete tokenized-securities operation needs both.

MiFID II governs the security itself: the issuance, the arranging, the placement, the distribution. MiCA and the payments framework govern the crypto-asset layer around it: the custody of crypto-assets and the euro on-ramps and off-ramps that let value move on-chain and settle in fiat. A firm that can issue a tokenized bond under MiFID II but cannot custody crypto-assets or settle in euros under the right authorizations has only half the stack. A firm with the crypto authorizations but no MiFID II permission has the other half, and cannot touch a security. The regimes are two halves of one operation.

Understanding that is the difference between assembling a compliant tokenized-securities business and discovering, after the build, that the licenses do not connect.

How this looks when it is built correctly

At COSIMO Digital we structured for both regimes deliberately, because the distinction above is not abstract to us. It is the architecture.

Black Manta Capital Partners is a BaFin-regulated Financial Services Institution (WpIG), with MiFID II passporting across the EEA. That is the authorization that permits the issuance and distribution of tokenized securities across Europe, and it is the reason the group can bring security tokens to market as securities, under the regime that actually governs them. Its authorization is for the investment activity; securities custody is arranged through partner custodian arrangements rather than held as a standalone service.

Fortuna Digital Custody sits on the other half. It is progressing through authorization with the Central Bank of Ireland, which has indicated it is minded to authorize the firm for MiCA CASP status and as a payment institution under PSD2. Those authorizations are pending and not yet effective. When granted, they would provide crypto-asset custody and euro payment rails, the crypto-asset layer that complements the MiFID II securities activity. We describe them as pending because they are, and because the distinction between a granted authorization and a promised one is exactly the kind of precision this whole subject demands.

Two regimes, two authorizations, one integrated operation. That is not redundancy. It is what issuing tokenized securities in Europe actually requires.

The takeaway

Before a single token is minted, the first question is not technical. It is legal. What is the asset, and which regime governs it? If it is a financial instrument, MiFID II applies and a crypto authorization will not substitute. If it is a crypto-asset that is not a financial instrument, MiCA applies. Most real tokenization businesses touch both, and need authorizations under both.

Get that first question right and the rest of the build has a foundation. Get it wrong and you have licensed the wrong activity, at real cost, before you have issued anything at all.

Ciarán Hynes is Managing Partner and Co-Founder of COSIMO Digital.

Sources
  • Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA), application through 2024.
  • Directive 2014/65/EU on Markets in Financial Instruments (MiFID II).
  • COSIMO Digital regulatory authorizations, described as of the date stated.

This article is for informational purposes only. Nothing in it is an offer to sell, or a solicitation of an offer to buy, any security, and nothing here is investment, legal, tax, or financial advice. Regulatory authorizations are described as of the date stated; pending authorizations are not effective until granted. This article is a general description of the regulatory framework and is not legal advice.

← All insights · Share
LinkedIn X