Skip to content
European regulation

MiFID II or MiCA — which one applies to your token?

MiCA excludes crypto-assets that qualify as financial instruments. Tokenized securities are financial instruments. So the regime is MiFID II, and a MiCA authorisation gives no permission over them. The classification is not a preference; here is how it is actually made, with five worked examples.

Last updated:
By Ciarán Hynes · 10 min read

Does MiCA apply to tokenized securities?

No. Tokenized securities are financial instruments, and Regulation (EU) 2023/1114 (MiCA) excludes financial instruments from its own scope. Article 2(4)(a) states it directly: the Regulation does not apply to crypto-assets that qualify as financial instruments within the meaning of Directive 2014/65/EU (MiFID II). A token that is a security is therefore regulated as a security, and a MiCA authorisation confers no permission over it.

This is the opposite of the answer the market repeats. Search results, vendor decks and a good deal of conference commentary treat MiCA as the European regime for tokenization generally, because MiCA is newer and better publicised. The effect is that firms procure the wrong licence, appoint providers who cannot legally perform the service, and discover it at the placement stage, which is the most expensive moment to discover it.

The practical rule has two halves. If the token carries a claim on an issuer, a pool of assets, a stream of profits or a return determined by portfolio performance, treat it as a financial instrument and start from MiFID II. If it does not — a payment token, a utility with no claim, an asset-referenced or e-money token — start from MiCA. Where the analysis is close, the classification is a legal opinion and not a preference, and it should be obtained in writing before providers are appointed.

Two regimes, no overlap
MiCA Article 2(4)(a) excludes crypto-assets qualifying as financial instruments under MiFID II. Regulation (EU) 2023/1114 and Directive 2014/65/EU, EU Official Journal.

What makes a token a MiFID II financial instrument?

Annex I Section C of MiFID II lists the financial instruments, and the first item — transferable securities — captures most tokenized instruments in practice. A transferable security is a class of securities negotiable on the capital market: shares, bonds and other debt instruments, and securities giving a right to acquire or sell them or giving rise to a cash settlement determined by reference to securities, currencies, rates or indices.

Three features do most of the work in the analysis. Negotiability: is the instrument transferable to others, in a class rather than as a bespoke bilateral contract. Claim: does the holder have a right against an issuer or against a pool of assets. Return dependency: is the holder’s outcome determined by the performance of assets, an enterprise or a reference value. An instrument with all three is a transferable security in almost every European analysis.

What does not matter: the ledger it sits on, the token standard used, the word in the name, whether the holder is called an investor or a member, and whether the offering documents describe the instrument as a utility. ESMA has published guidance on the conditions and criteria for qualifying crypto-assets as financial instruments precisely because form-over-substance arguments kept being made. Substance governs, and national competent authorities apply it.

One further category deserves a note. Units in collective investment undertakings appear in Annex I Section C as their own item. A tokenized fund unit is therefore a financial instrument even where an argument might be made that it is not a transferable security. There is no version of the analysis in which a tokenized fund unit falls under MiCA.

Where exactly is the boundary? Five worked examples

The boundary is clearer in worked cases than in the abstract. Five instruments, each described the way it is usually pitched, with the classification that actually applies.

1. A token representing units in a venture fund

A unit in a collective investment undertaking. MiFID II applies; issuance and placement require an investment firm authorisation, and the fund itself requires an authorised AIFM under AIFMD. MiCA is not engaged by the unit. This is the least ambiguous case on the list and it is still routinely misclassified.

2. A token backed one-to-one by euro deposits, redeemable at par on demand

An e-money token under MiCA. It references a single official currency and functions as electronic money, so the issuer must be an authorised credit institution or electronic money institution, with full backing in low-risk liquid reserves and redemption at par at any time. Not a security, and not a MiFID II instrument.

3. A token referencing a basket of currencies and commodities to hold its value stable

An asset-referenced token under MiCA, with reserve, governance, disclosure and own-funds obligations, and EU-level supervision if it is deemed significant. The line between this and a fund unit is intent and structure: an ART exists to stabilise value for payment-like use, while a fund unit exists to deliver investment return.

4. A token giving holders a share of revenue from a portfolio of loans

A financial instrument. The holder’s return depends on the performance of underlying assets and there is a claim on a pool, so it is a transferable security or a fund unit depending on the wrapper. Describing it as a revenue-share or a protocol incentive does not move it out of MiFID II.

5. A token giving access to a software platform, with no claim and no return

Genuinely outside MiFID II, and within MiCA as a crypto-asset. But the test is strict: if the token is marketed on the basis of expected appreciation, if holders are promised any share of proceeds, or if a secondary market is created and supported by the issuer, the analysis can shift. This category is real and much smaller than the market believes.

Classification summary for the five examples.
Instrument as pitchedActual classificationApplicable regimePermission needed to issue and place
Tokenized venture fund unitUnit in a collective investment undertakingMiFID II (plus AIFMD for the manager)MiFID II investment firm; authorised AIFM
Euro-backed token redeemable at parE-money tokenMiCACredit institution or electronic money institution
Basket-referenced stable tokenAsset-referenced tokenMiCAMiCA ART issuer authorisation
Loan-portfolio revenue shareTransferable security or fund unitMiFID IIMiFID II investment firm
Pure platform access token, no claimCrypto-assetMiCAMiCA offeror obligations; CASP for services

Which licence do you actually need?

For tokenized securities: a MiFID II investment firm authorisation covering the specific services you perform, held by whichever entity performs them. For crypto-asset services: a MiCA CASP authorisation. These are different licences, obtained from different processes, and holding one tells you nothing about the other.

Map the services rather than the project. Placing units with investors is a MiFID II service. Receiving and transmitting orders is a MiFID II service. Safekeeping financial instruments is a MiFID II ancillary service, while safekeeping crypto-assets is a MiCA service. Operating a venue is a separate authorisation again. A single tokenized issuance can therefore touch three or four permissions across three or four entities, which is normal and needs to be documented.

An anti-money-laundering registration is not a substitute for either. Registration as a Virtual Asset Service Provider under national implementing law is an AML supervision status and does not permit investment services or MiCA services. We state our own position on this in the same terms we would want from a counterparty: Black Manta Capital Partners is BaFin-licensed and operates under MiFID II for the regulated issuance and placement of tokenized securities, and is live. Fortuna is registered as a Virtual Asset Service Provider with the Central Bank of Ireland (register ref C459043, under s.106A of the Criminal Justice (Money Laundering and Terrorist Financing) Acts), with MiCA CASP authorisation in process and not yet effective.

What happens if you get the classification wrong?

Treating a security as a crypto-asset means conducting an unauthorised investment service. The consequences run in three directions: supervisory action against the firm and its management, civil exposure to investors whose instruments were placed without the required authorisation, and the practical collapse of the offering — banks, depositaries and venues withdraw once the perimeter is in question.

The reverse error is less dangerous and still costly. Treating a genuine crypto-asset as a security means over-engineering: a prospectus or an offering memorandum nobody required, an investment firm engaged for work it did not need to do, and a distribution channel narrowed for no regulatory reason. Firms rarely get sanctioned for this. They simply spend more and reach fewer investors.

Remediation of the first error is possible and unpleasant. It generally means suspending the offering, appointing an authorised firm, re-papering the instrument, and in some cases offering rescission to investors who were placed into it. The cost is an order of magnitude above the cost of a written classification opinion obtained at the outset, and the reputational cost with institutional allocators is harder to price and slower to repair.

The safeguard is unglamorous: a written classification view from EU counsel, obtained before providers are appointed, refreshed if the instrument’s economics change, and shared with the depositary and the bank. Every experienced allocator asks for it during due diligence. Having it on hand answers the question and signals the discipline behind the rest of the structure.

What is changing in 2026?

The boundary itself is stable; the practice around it is consolidating. Three developments matter for the classification question this year. ESMA guidance on qualifying crypto-assets as financial instruments is now the reference point national authorities apply, which has narrowed the space for form-over-substance arguments. The MiCA authorisation cohort has become visible, and it is small. And the DLT Pilot Regime continues to generate the evidence base for permanent market-infrastructure reform.

About one in six
Roughly 210 of approximately 1,200 pre-MiCA firms have secured MiCA authorisation. COSIMO Digital analysis of regulator registers and market data, 2026.

The authorisation numbers are the more consequential fact for anyone choosing a counterparty. A market that has gone from roughly 1,200 pre-MiCA firms to roughly 210 authorised ones has not shrunk by accident: authorisation is expensive, slow and demanding of governance, and most firms could not carry it. The firms that did are now the ones institutions can transact with, which is a structural advantage that did not exist before MiCA applied.

What is not changing in 2026: MiCA will not begin to cover tokenized securities, and MiFID II will not cede the securities perimeter. Anyone waiting for a single unified tokenization regime in Europe is waiting for something that is not on any legislative agenda. The correct planning assumption is two regimes, a hard boundary between them, and a written opinion telling you which side you are on. Read next how to tokenize a fund in Europe step by step, or what a tokenized fund actually is.

Related
Sources
  • Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA), Article 2(4)(a), EU Official Journal, 2023.
  • Directive 2014/65/EU on Markets in Financial Instruments (MiFID II), Annex I Section C, EU Official Journal, 2014.
  • European Securities and Markets Authority, guidance on the conditions and criteria for the qualification of crypto-assets as financial instruments.
  • Regulation (EU) 2022/858 on a pilot regime for DLT market infrastructures, EU Official Journal, 2022.
  • MiCA authorisation counts: COSIMO Digital analysis of regulator registers and market data, 2026 (approximately 210 authorised of approximately 1,200 pre-MiCA firms).
  • COSIMO Digital regulatory authorisations, described as of 28 July 2026.

This page is for informational purposes only. Nothing in it is an offer to sell, or a solicitation of an offer to buy, any security, and nothing here is investment, legal, tax, or financial advice. Regulatory authorisations are described as of the date stated; pending authorisations are not effective until granted.

← All Learn articles