Lukas Wipf

CPO & Co-Founder

Share

Contact Us

ONINO provides infrastructure for digital & tokenized financing across the EU and Switzerland.

On this page

Key Takeaways

Tokenized securities are financial instruments and are therefore excluded from MiCA by Art. 2(4)(a) of Regulation (EU) 2023/1114; they are governed by MiFID II and, in Germany, issued under the eWpG. In the MiCA vs eWpG question, instrument type decides everything: - MiCA governs utility tokens, asset-referenced tokens, and e-money tokens, not security tokens. - The eWpG provides the electronic form and register layer for German securities: a BaFin-supervised register entry replaces the paper certificate. - Bonds and fund units route to the eWpG and MiFID II stack; utility tokens and stablecoins route to MiCA. - Some instruments, such as tokenized Nachrangdarlehen structured as Vermögensanlagen, typically fall outside both regimes, the most dangerous trap. - Misclassification costs issuers time and legal budget, and it is the most common error ONINO sees in inbound issuer conversations.

MiCA vs eWpG: Which Regime Applies to Tokenized Securities?

MiCA (Regulation (EU) 2023/1114, Markets in Crypto-Assets) is the EU-wide framework for crypto-assets that are not financial instruments. The eWpG (Electronic Securities Act) is Germany's 2021 framework, which lets securities exist as entries in an electronic register, including a blockchain-based register, instead of paper certificates. The two sit on different layers of how Europe regulates raising capital: MiCA decides which rulebook applies to a crypto-asset, while the eWpG supplies the legal form for instruments that are already securities. So which regulation applies to a security token in the EU depends on what the token legally is, not on the technology it runs on.

Reviewed by Lukas Wipf, CPO & Co-Founder at ONINO, 14.07.2026.

Does MiCA apply to security tokens?

No. MiCA does not apply to security tokens. Art. 2(4)(a) of Regulation (EU) 2023/1114, the MiCA financial-instruments exclusion, expressly removes crypto-assets that qualify as financial instruments from MiCA's scope. A tokenized bond or tokenized share is regulated like the bond or share it is, under MiFID II, the Prospectus Regulation (EU) 2017/1129, and national securities law, which in Germany means the eWpG. The exclusion is written into the regulation itself:

"This Regulation does not apply to crypto-assets that qualify as one or more of the following: (a) financial instruments; (b) deposits, including structured deposits; (c) funds, except if they qualify as e-money tokens; …" (Art. 2(4), Regulation (EU) 2023/1114. The list continues with (d) securitisation positions, (e) insurance products, (f) to (i) pension products, and (j) social security schemes.)

In practice, MiCA governs utility tokens, asset-referenced tokens (ARTs), and e-money tokens (EMTs), while anything that already counts as a financial instrument keeps its existing rulebook. MiCA also carves out crypto-assets that are unique and not fungible with other crypto-assets (Art. 2(3)), the NFT carve-out, which is a separate discussion.

What counts as a financial instrument is defined by MiFID II (Directive 2014/65/EU), and the definition is deliberately technology-inclusive. Art. 4(1)(15), as amended by Regulation (EU) 2022/858, reads:

"'financial instrument' means those instruments specified in Section C of Annex I, including such instruments issued by means of distributed ledger technology"

ESMA's guidelines on the qualification of crypto-assets as financial instruments (ESMA75-453128700-1323, Final Report 17 December 2024, applicable since 18 May 2025) confirm the approach: classification goes by substance over form, stays technology-neutral, and national competent authorities assess it case by case. The token wrapper changes nothing about the qualification. For a tokenized security, the MiFID II obligations for digital securities issuers apply exactly as they would to the conventional instrument.

What does the eWpG cover?


As shown in the graphic, § 1 eWpG sets the scope, with registered shares added by the ZuFinG in December 2023; § 4 eWpG opens two register routes; § 32 KWG requires a licensed registrar; § 20 eWpG adds BaFin notification. Form, not classification.

The eWpG governs the electronic form of securities in Germany: it replaces the paper certificate with an entry in an electronic securities register, so a bond or share can exist and transfer as a purely digital instrument. The eWpG does not decide whether something is a security; it gives instruments that already are securities a digital form. The core building blocks:

  • Scope (eWpG § 1): Applies to bearer bonds and registered shares; bearer shares only if entered in a central register. Shares entered the scope through the Zukunftsfinanzierungsgesetz (ZuFinG, in force since December 2023), which made electronic shares, including crypto shares, possible.

  • Two register routes (eWpG § 4): A central-register security is entered in a central register kept by a central securities depository or an authorized custodian. A crypto security is entered in a crypto-securities register running on a decentralized, tamper-proof recording system such as a blockchain.

  • Licensed registrar required: Keeping a crypto-securities register is a licensed financial service under KWG § 1(1a) sentence 2 no. 8, requiring BaFin authorization under § 32 KWG, so every crypto security needs a licensed registrar.

  • BaFin supervision: Crypto-securities registers are kept under BaFin supervision (eWpG § 11). The § 20 notification duty and the public BaFin list of crypto securities that went with it were both abolished by the StoFöG with effect from 10 February 2026, so there is no longer a public list of issued crypto securities to consult.

  • Outlook: The eWpG's most recent change came through the Location Promotion Act (Standortfördergesetz, StoFöG) of 4 February 2026, published in BGBl. I 2026 No. 33 and in force since 10 February 2026: its Art. 26 repealed the § 20 notification duty rather than widening the Act's scope. The broader eWpG reform drafted in the second Future Financing Act (ZuFinG II) lapsed with the 2025 Bundestag dissolution and was not carried into the StoFöG, so the register architecture described above is the one currently in force. For quick definitional questions around electronic securities and token issuance, see our guide to German crypto securities.

Do eWpG crypto securities require audited smart contracts, and which blockchains are BaFin-compliant?

The eWpG is technology-neutral: it names no specific blockchain and does not require a smart-contract audit. BaFin does not certify or approve blockchains. A crypto-securities register may run on any decentralized, tamper-proof recording system, and in practice the licensed crypto-securities registrar's setup and the register it operates determine which chain is actually used. Ethereum and Polygon are the chains most commonly seen in eWpG crypto securities issuance. Smart-contract audits are market practice and a registrar and investor expectation, not a statutory eWpG requirement.

There is no list of "approved" chains, and no compliance stamp attaches to a particular network. What matters legally is that the register is kept by a registrar licensed under § 32 KWG (KWG § 1(1a) sentence 2 no. 8), that the register is kept under BaFin supervision (eWpG § 11), and that the recording system the registrar chooses is decentralized and tamper-proof. Chain selection and smart-contract auditing are therefore practical decisions driven by the registrar's setup and by investor due diligence, not conditions the eWpG itself imposes.

Which regulation applies to a security token in the EU?

Which regime applies comes down to one question: is the token a financial instrument? If it is (a bond, share, or fund unit), MiFID II and, in Germany, the eWpG govern it, and MiCA is excluded by Art. 2(4)(a). If it is not, it falls under MiCA or a national product regime such as the VermAnlG. The ONINO Regime Check resolves this in four questions:

  1. Does the token grant rights that make it a MiFID II financial instrument (a transferable security under Art. 4(1)(44), or a fund unit under Annex I Section C(3))? If yes, MiCA is out by Art. 2(4)(a); continue with question 2.

  2. Which form route applies? For German issuance: central register or crypto-securities register under the eWpG, or the KryptoFAV route for fund units.

  3. If it is not a financial instrument: is it a nationally regulated product, such as a German regulated investment product under the VermAnlG, a category that includes subordinated loans and many profit-participation rights? These sit outside MiCA's securities logic and outside the eWpG.

  4. If none of the above: which MiCA title applies? Title II for utility tokens and other crypto-assets, Title III for ARTs, Title IV for EMTs.

Applied by instrument type:

Tokenized bond. A bond is a transferable security, MiFID II Art. 4(1)(44)(b) ("bonds or other forms of securitised debt"), so the token sits outside MiCA. In Germany, a tokenized bond is issued as an electronic bearer bond under eWpG § 1 and entered in a central register or a crypto-securities register.

Tokenized share. Since the ZuFinG, registered shares can be issued as central-register securities or as crypto securities (the crypto share). Bearer shares can only take the central-register route, a restriction the legislator justified with anti-money-laundering and beneficial-ownership concerns.

Tokenized fund unit. The KAGB governs the fund itself when an asset manager sets out to tokenize a fund. Fund units are not in eWpG § 1; instead the KryptoFAV (Kryptofondsanteileverordnung, based on KAGB § 95(5)) declares the eWpG rules correspondingly applicable to crypto fund units. MiCA does not apply, because units in collective investment undertakings are MiFID II Annex I Section C(3) instruments.

Tokenized subordinated loan or profit-participation right. A subordinated loan or profit-participation right is often a regulated investment product under the VermAnlG rather than a security (a fungible, tradeable profit-participation right can instead qualify as a security, which flips it into the eWpG/MiFID stack). A tokenized subordinated loan is then typically outside both MiCA and the eWpG's securities scope, but BaFin assesses token by token, so this classification is strictly case by case and needs counsel per structure.

Utility token. This is a MiCA case: Title II, the white-paper notification and publication regime, applicable since 30 December 2024.

Stablecoin. Also a MiCA case, with the heaviest obligations: e-money tokens under Title IV and asset-referenced tokens under Title III, applicable since 30 June 2024, with issuer authorization required. The Art. 2(4) exclusion does not help stablecoin issuers.

For trading-venue and settlement experiments there is additionally the DLT Pilot Regime (Regulation (EU) 2022/858), which ESMA proposed making permanent in June 2025; it is a market-infrastructure sandbox, not an issuance regime. And one caveat in plain terms: the tree resolves the standard cases, but classification of edge cases needs counsel.

What are the most common misclassifications?

The two most common misclassifications both stem from treating MiCA as the default tokenization law: assuming a security token needs a MiCA white paper, and assuming any token outside MiCA is automatically an eWpG crypto security. Both are wrong, and both are expensive.

  • Error 1: Treating a security token as a MiCA crypto-asset: Preparing a MiCA white paper or budgeting a CASP (crypto-asset service provider) authorization for what is legally a digital security. Neither attaches to a financial instrument. A tokenized bond offer runs under prospectus and securities rules, and the register side needs a licensed crypto-securities registrar, not a CASP license.

  • Root cause: The market misreads MiCA as "the EU tokenization law." MiCA is the EU framework for crypto-assets that are not financial instruments; for tokenized securities it decides precisely nothing. ONINO sees this first-hand in inbound issuer conversations: issuers arrive with MiCA deliverables drafted or budgeted for instruments that were never in MiCA's scope.

  • Error 2: Assuming a token outside MiCA is automatically an eWpG crypto security: A tokenized subordinated loan structured as a regulated investment product is typically outside MiCA and outside the eWpG at the same time; regime mapping has to be done per instrument, not by elimination. The boundary is genuinely contested in edge cases, as practitioner analyses such as Cerha Hempel's "MiCA: Unresolved Questions" (June 2025) document, which is exactly why classification belongs at the start of structuring, not the end. A structured approach to regulatory compliance in tokenization starts with this classification step.

  • Error 3: Datedness: Guides written before full MiCA application still circulate, some still announcing that the ESMA classification guidelines are "expected end-2024." The guidelines have applied since 18 May 2025; advice based on pre-2025 material misstates the current state of play.

What is the difference between MiCA and eWpG?

MiCA and the eWpG are different layers, not competing regimes. MiCA is EU market regulation for crypto-assets that are not financial instruments; the eWpG is German law that lets financial instruments exist in electronic, tokenized form. One decides which rulebook applies to a token; the other provides the legal form under the securities rulebook. Asking "MiCA vs eWpG" for a single instrument is therefore usually a category error: a token is either in MiCA's world or in the securities world, and the eWpG only ever appears in the second. The comparison below shows how the two frameworks divide the work for issuers.

Dimension

MiCA (Reg. (EU) 2023/1114)

eWpG + MiFID II stack

What it regulates

Crypto-assets that are not financial instruments: issuance, offers, and crypto-asset services

The electronic form of securities (eWpG) plus investment services and disclosure (MiFID II, Prospectus Regulation)

Instrument types

Utility tokens, asset-referenced tokens (ARTs), e-money tokens (EMTs)

Bonds, shares (incl. the crypto share), fund units via the KryptoFAV

Key issuer obligations

Crypto-asset white paper notification and publication; authorization for ART and EMT issuers; CASP licensing for service providers

Prospectus or exemption; register entry (central or crypto-securities register); licensed crypto-securities registrar (KWG § 1(1a) s. 2 no. 8); BaFin supervision under eWpG § 11

Regulator

National competent authorities, with ESMA and EBA coordination

BaFin under German law; national competent authorities under MiFID II

Legal nature

EU regulation, directly applicable in all member states

German statute (eWpG) within an EU directive and regulation stack

Applicable since

30 June 2024 (Titles III and IV); 30 December 2024 (remainder)

10 June 2021 (eWpG); shares added December 2023 (ZuFinG)

How ONINO ensures the right regime

ONINO operates on both sides of the boundary: eWpG-based register workflows for digital securities and a MiCA-aware compliance stack for tokens outside the financial-instrument definition. Every issuance on the asset tokenization platform starts with regime classification at intake, the ONINO Regime Check applied to the concrete instrument, before any structuring or technical setup begins. That sequencing is what prevents the misclassifications described above from turning into wasted legal budget. ONINO does not provide legal advice, and edge cases still go to counsel; the platform's job is to make sure the issuance is built on the correct regime from day one.

Frequently asked questions

Do I need a BaFin license to issue tokenized securities in Germany?

Issuers themselves usually do not need their own BaFin license to issue a tokenized security. However, the crypto-securities register must be kept by a registrar licensed under § 32 KWG (KWG § 1(1a) sentence 2 no. 8), and a public offer may still require a prospectus under Regulation (EU) 2017/1129.

Do eWpG crypto securities require audited smart contracts, and which blockchains (e.g. Ethereum, Polygon) are BaFin-compliant?

The eWpG is technology-neutral: it prescribes no specific blockchain and mandates no smart-contract audit, and BaFin does not certify or approve blockchains. A crypto-securities register may run on any decentralized, tamper-proof system. In practice the licensed registrar's setup and the register it operates determine the chain, with Ethereum and Polygon commonly used. Audits are market practice, not a statutory precondition.

How can an asset manager tokenize a fund or fund shares under EU regulation?

Fund units are MiFID II financial instruments, so MiCA does not apply. The fund stays governed by the KAGB (and the AIFMD or UCITS regime), while the KryptoFAV extends the eWpG rules to crypto fund units, letting shares be issued in a crypto-securities register with a licensed registrar under BaFin supervision.

Is a tokenized bond regulated under MiCA or the eWpG?

A tokenized bond is regulated under the eWpG and MiFID II, not MiCA. Because a bond is a transferable security under MiFID II Art. 4(1)(44)(b), the MiCA Art. 2(4)(a) exclusion applies. In Germany it is issued as an electronic bearer bond under eWpG § 1, entered in a central or crypto-securities register.

Structuring a tokenized bond, fund, or participation right? Read our guide to regulated infrastructure for tokenized securities and see how ONINO classifies the regime and runs the issuance end to end.

Want to learn more how this can be applied to your business?