Who can custody tokenized securities in Europe?
Custody of a financial instrument and custody of a crypto-asset are different permissions. Which one applies.
It depends on what the instrument legally is. A tokenized security is a financial instrument, so custody requires MiFID II permissions and, at settlement, engages CSDR. A crypto-asset that is not a financial instrument requires a MiCA CASP authorisation covering custody. These are different permissions, often held by different firms. Many tokens are misclassified.
Who can custody tokenized securities in Europe?
A firm authorised under MiFID II to provide safekeeping and administration of financial instruments for the account of clients, or a credit institution with the equivalent permission. Where the instrument is a fund unit, the depositary appointed under AIFMD or the UCITS Directive carries the safekeeping and oversight duties over the fund’s assets.
What is not sufficient: a MiCA authorisation for crypto-asset custody, because MiCA excludes financial instruments from its scope by Article 2(4); and a national VASP registration, which is anti-money-laundering supervision rather than a custody permission. Both have been presented as sufficient in marketing material.
The market shape follows from that. Conventional custodians and depositaries hold the assets. A transfer agent or registrar maintains the register of holders. Technology providers supply the ledger infrastructure and the token standard. Three roles, three sets of obligations, in most structures three separate firms.
So the first question in any custody conversation is not "can you hold this" but "what is this". Classification comes before permission, and a firm that cannot state the instrument’s legal character should not be selecting a custodian yet. Read how the MiFID II and MiCA boundary is drawn.
What is the difference between custody of a financial instrument and custody of a crypto-asset?
Different regimes, different obligations, different supervisory expectations, and in most cases different firms. Custody of a financial instrument is a long-established MiFID II ancillary service with decades of supervisory practice behind it. Custody of a crypto-asset is a MiCA service created in 2023 and in application since 30 December 2024.
| Financial instrument | Crypto-asset (not a financial instrument) | |
|---|---|---|
| Regime | MiFID II (ancillary service); AIFMD or UCITS for fund depositaries | MiCA (crypto-asset service) |
| Permission needed | Investment firm or credit institution authorisation covering safekeeping and administration | CASP authorisation covering custody and administration of crypto-assets |
| Settlement rules engaged | CSDR, unless exempted under the DLT Pilot Regime | None equivalent; MiCA has no settlement-finality regime |
| Client-asset rules | MiFID II client-asset rules and national implementations | MiCA segregation, position register and liability provisions |
| Passport | MiFID II passport | MiCA passport |
| Typical provider | Custodian bank, depositary, investment firm | Authorised crypto custodian |
The practical consequence for a group holding both is that neither authorisation substitutes for the other, and the perimeter runs between entities rather than around the group. A firm may hold tokenized bonds under a MiFID II permission and the fund’s digital-asset holdings under a MiCA permission, and those are two different licences with two different supervisors.
Which permission applies to your instrument?
Work from the instrument, not the technology. If the token carries a claim on an issuer, a pool of assets, a share of profits, or a return determined by portfolio performance, it is almost certainly a financial instrument and MiFID II applies. If it does not — a payment token, an asset-referenced token, an e-money token — MiCA applies.
| Instrument | Legal character | Custody permission |
|---|---|---|
| Tokenized fund unit | Unit in a collective investment undertaking | MiFID II safekeeping; depositary duties under AIFMD or UCITS |
| Tokenized bond or note | Transferable security | MiFID II safekeeping; CSDR at settlement |
| Tokenized equity | Transferable security | MiFID II safekeeping; CSDR at settlement |
| E-money token | Crypto-asset under MiCA | MiCA CASP custody permission |
| Asset-referenced token | Crypto-asset under MiCA | MiCA CASP custody permission |
| Payment or utility token with no claim | Crypto-asset under MiCA | MiCA CASP custody permission |
Where the analysis is close, it is a legal opinion rather than a preference, and it should be obtained in writing before providers are appointed. ESMA published guidelines in December 2024 on the conditions and criteria for qualifying crypto-assets as financial instruments, and those guidelines are what national authorities apply.
The expensive direction of error is treating a security as a crypto-asset: the custody arrangement then sits outside the correct regime, and the client-asset protections the instrument requires may not apply at all.
What does MiCA require of a crypto-asset custodian?
A written agreement with each client, a custody policy, an accurate register of positions per client, segregation of client holdings from the firm’s own assets, and liability to the client for loss of crypto-assets or means of access arising from an incident attributable to the firm. Alongside those sit the general CASP obligations: own funds, fit-and-proper management, governance, complaints handling, outsourcing oversight and ICT resilience.
Two requirements carry most operational weight. Segregation must be demonstrable at the level of keys and wallets rather than only in the firm’s books, and supervisors ask how a firm evidences that a specific holding belongs to a client. And the position register must be reconcilable to the ledger at any time, with a documented process and named accountability, because that register is what a liquidator or supervisor would rely on.
Our own position, stated in full
Fortuna is registered as a Virtual Asset Service Provider with the Central Bank of Ireland (register ref C459043, under s.106A of the Criminal Justice (Money Laundering and Terrorist Financing) Acts), with MiCA CASP authorisation in process and not yet effective. Until that authorisation is granted, Fortuna is not authorised to provide MiCA crypto-asset custody services, and we do not present it as though it were. The group’s live regulated capability for tokenized securities is issuance and placement through Black Manta Capital Partners, which is BaFin-licensed and operates under MiFID II. Institutions needing authorised crypto-asset custody today should work with a firm that already holds that authorisation.
We state it in those exact terms wherever custody is discussed, because a page that explains the VASP-versus-CASP distinction and then applies a softer version of it to its own group has explained nothing.
What do MiFID II and CSDR require for financial instruments?
MiFID II requires the custodian to hold client financial instruments under a permission covering safekeeping and administration, to keep records and accounts enabling it to distinguish client assets from its own and from other clients’, to conduct regular reconciliations, and not to use client instruments for its own account without express consent. National implementations add detail on registration of client assets and on the use of third parties.
CSDR engages at settlement and central registration. Transferable securities admitted to trading must be represented in book-entry form, settlement must occur in a securities settlement system, and settlement discipline applies. Those requirements assume a central securities depository, which is why a ledger-native structure either uses a CSD or operates under the pilot regime’s exemptions.
For fund structures, the depositary’s duties are additional and unchanged by tokenization: safekeeping, ownership verification for assets it cannot hold, cash-flow monitoring, and oversight of subscription, redemption and valuation. Its operational due diligence on a tokenized register is the single longest item in most launch plans, and it is a risk decision rather than a formality.
Where an instrument sits inside a DLT market infrastructure, read the permission. The ESMA register of authorised DLT market infrastructures records which CSDR articles were disapplied for each operator, including account segregation and settlement finality — which changes the custody analysis materially.
How are client assets segregated and protected in insolvency?
Segregation is intended to make client holdings identifiable as belonging to specific clients and therefore unavailable to the custodian’s general creditors. Whether that outcome is achieved depends on insolvency law as well as on regulation, and insolvency law is national.
Four questions determine the answer in practice. Are client assets held in wallets or accounts distinguishable from the firm’s own? Does the register identify each client’s entitlement at every point in time? Is the arrangement documented as custody rather than as a transfer of title? And has the custodian obtained a legal opinion on the position under its governing law?
Omnibus and wallet-per-client structures are the specific design choice. Omnibus pools holdings and relies on the register to allocate entitlements, which is efficient and places weight on register integrity. Wallet-per-client is easier to demonstrate and operationally heavier. Both are used by authorised firms; what matters is that the choice is documented and the client knows which applies.
Ask for the insolvency opinion. Institutional allocators do, and it is the document that distinguishes a considered custody arrangement from a technically capable one.
What should an allocator ask a custodian?
- Which legal entity holds the authorisation, on which register, covering which services, from what date?
- Is the instrument a financial instrument or a crypto-asset, and does your permission match that classification?
- Are client assets segregated from house assets at the wallet or account level, and how is that evidenced to a supervisor?
- Is the structure omnibus or client-segregated, and what does the position register record?
- What is the insolvency analysis under the governing law, and is there an opinion we can read?
- How are keys generated, stored and recovered, and who can authorise a transfer?
- What is the liability position for loss of assets or means of access, and how is it limited?
- Which functions are outsourced, to whom, and under what oversight?
- How often is the position register reconciled to the ledger, and who signs it off?
Two follow-ups separate serious answers from polished ones. Ask for evidence that a control has been tested rather than described — a reconciliation report, an audit finding, a recovery rehearsal. And ask what the custodian will not do: which assets it will not hold, which chains it does not support, which jurisdictions it cannot serve.
Read next: what a MiCA CASP authorisation covers, who is accountable for the register, or the eight allocator questions with our own answers.
The cluster hub: where custody sits in the stack.
The crypto-asset side of the custody question.
Custody is question five, answered in public.
- Directive 2014/65/EU (MiFID II); Regulation (EU) 2023/1114 (MiCA); Regulation (EU) 909/2014 (CSDR); Regulation (EU) 2022/858 (DLT Pilot Regime) — EU Official Journal.
- COSIMO Digital regulatory authorisations, described as of 28 July 2026. Pending authorisations are not effective until granted.
- ESMA, guidelines on the conditions and criteria for the qualification of crypto-assets as financial instruments, December 2024.
- ESMA, register of authorised DLT market infrastructures, January 2026.
This page is for informational purposes only. Nothing in it is an offer to sell, or a solicitation of an offer to buy, any security, and nothing here is investment, legal, tax, or financial advice. Regulatory authorisations are described as of the date stated; pending authorisations are not effective until granted.
← All Learn articles