Insights
Security Token vs Utility Token in 2026: Complete Comparison + EU Legal Framework
What's the difference between a security token and a utility token? Complete 2026 comparison covering MiCAR, BaFin classification, and real-world examples.

Lukas Wipf
CPO & Co-Founder
last updated on


Lukas Wipf
CPO & Co-Founder
Share
Contact Us
ONINO provides infrastructure for digital & tokenized financing across the EU and Switzerland.
On this page
Quick Takeaway
A security token represents an ownership right or financial claim in an underlying asset and is regulated as a financial instrument under MiFID II in the EU and the Howey test in the US. A utility token grants access to a product or service inside the issuer's ecosystem and falls under MiCAR in the EU. Both categories are now regulated. Classification is functional, based on what the token actually does, not on what the whitepaper calls it. Mislabelling a token as "utility" when it conveys investment rights is the single most common, most expensive structuring mistake in this market.
What "security token" and "utility token" mean in 2026
Cryptocurrency projects often issue digital tokens, but not all tokens serve the same purpose. Some represent ownership or investment rights, while others simply grant access to a platform or service. In 2026, the distinction is no longer a matter of marketing convenience. It maps directly onto two separate EU regulatory perimeters: financial-instrument law (MiFID II, Prospectus Regulation, national securities acts such as Germany's eWpG) and crypto-asset law (MiCAR).
Security tokens function like traditional financial securities such as shares, bonds, or profit-participating instruments. Utility tokens are designed to be used within a blockchain ecosystem to access products, services, or features, including paying transaction fees, accessing decentralised storage, or minting NFTs. The classification determines how a token is issued, distributed, traded, recorded, supervised, and reported, end to end.

What is a utility token
A utility token is a digital asset that provides access to a specific product, service, or functionality within a blockchain ecosystem. Instead of representing ownership in a company or asset, these tokens act as a kind of digital voucher for a platform. Under MiCAR they fall under the residual "crypto-asset" category covered by Title II, meaning the issuer must publish a crypto-asset whitepaper and notify the competent authority before offering the token to the public in the EU, but the token is not a financial instrument and does not trigger MiFID II, the Prospectus Regulation, or national securities acts.
Projects issue utility tokens to power decentralised applications or network services. Users may need the token to pay transaction fees, access premium features, or interact with a platform's infrastructure. A decentralised storage platform might require users to spend its native token to upload or retrieve files. In that case the token's value comes from its usefulness within the ecosystem rather than from profit rights, dividends, or claims on the issuer. Common examples include tokens used for protocol-fee payment, governance voting on protocol parameters, and in-app purchases inside blockchain-based platforms.
The MiCAR Title II perimeter is narrower than many issuers assume. A token that pays a yield, distributes revenue, or grants a claim on the issuer's cash flows falls out of the utility category and into MiFID II, regardless of what the whitepaper calls it. ESMA has signalled that substance prevails over form when assessing classification, and national competent authorities such as BaFin and AMF have publicly recharacterised tokens marketed as utilities into financial instruments.
What is a security token
A security token represents ownership or financial interest in an underlying asset. That asset could be equity in a company, a debt instrument such as a bond or bearer bond, revenue rights from a project, or ownership in real estate, private credit, infrastructure, or fund interests. Under MiFID II Article 4(1)(44), the test is whether the instrument is a "transferable security" that is negotiable on the capital market, which captures shares, bonds, depositary receipts, and any analogous instruments giving rise to a cash settlement determined by reference to transferable securities, currencies, interest rates, or yields.
In Germany, the eWpG (Electronic Securities Act) adds a parallel definition for the same instruments when they are issued in electronic form. §4 eWpG defines a crypto security as a bearer instrument recorded in a crypto-securities register (§16 eWpG) maintained by a registrar licensed under §17 eWpG. The crypto security is legally equivalent to a paper certificate; transfer happens via the registrar's electronic entries rather than via physical delivery.
Because security tokens function as investment instruments, they are subject to securities regulations: the Prospectus Regulation (EU 2017/1129), MiFID II, MAR (Market Abuse Regulation), MiFIR transaction reporting, the DLT Pilot Regime (Regulation 2022/858) where the issuer opts in, and national acts such as eWpG, VermAnlG (Asset Investment Act), and KAGB (Capital Investment Code). The issuer typically must publish a prospectus or qualifying alternative (securities information sheet under §4 WpPG, or asset information sheet under §13 VermAnlG), comply with disclosure and investor-protection rules, and route trading through a regulated venue or systematic internaliser.
Security tokens often grant holders rights such as dividend or coupon distributions, profit sharing, voting rights, or pre-emptive rights, mirroring traditional securities. They are commonly issued through Security Token Offerings (STOs) structured to comply with the relevant regulatory framework, often using ONINO's white-label issuance stack plugged into a §17 eWpG registrar.
Security tokens vs utility tokens: feature comparison
Feature | Utility Token | Security Token |
|---|---|---|
Legal classification (EU 2026) | Crypto-asset under MiCAR Title II | Financial instrument under MiFID II Art. 4(1)(44); crypto security under §4 eWpG |
Primary purpose | Access to a product or service | Investment, ownership, or claim on cash flows |
Ownership rights | None | Equity, debt, revenue, voting, or pre-emptive rights |
Issuer documentation | MiCAR whitepaper, NCA notification | Prospectus, WIB (§4 WpPG), or VIB (§13 VermAnlG); plus PRIIPs KID for retail |
Register | Not required | §16 eWpG crypto-securities register, kept by §17 registrar |
Supervisor (DE) | BaFin under MiCAR | BaFin under WpHG / eWpG / VermAnlG / KAGB |
Value source | Platform usage and demand | Underlying asset, issuer cash flows, market price |
Secondary market | Crypto-asset trading platforms under MiCAR | Regulated venue, MTF, OTF, or DLT Pilot trading system |
Investor protection | Limited (MiCAR consumer rules) | Full MiFID II suitability, appropriateness, best execution, MAR |
While the distinction looks clean, in practice the line blurs when tokens serve both functional and investment-related purposes. The decisive question is not what the project calls the token but what rights the holder receives.
The 2026 EU legal framework
By June 2026 the EU operates a two-track perimeter for digital assets. MiCAR has been fully applicable since 30 December 2024 and now governs crypto-asset issuance, service provision, and market integrity for everything that is not already a financial instrument. MiFID II, the Prospectus Regulation, and national securities acts continue to govern everything that is. The two regimes are mutually exclusive: an instrument is either a financial instrument (MiFID II family) or a crypto-asset (MiCAR), never both. The classification decision is therefore the first step in any tokenisation project.
MiCAR Title II: where utility tokens live
MiCAR splits crypto-assets into three categories: asset-referenced tokens (ARTs, backed by a basket of assets or rights), e-money tokens (EMTs, pegged to a single fiat currency), and the residual category of "other crypto-assets" covered by Title II, which captures most utility and governance tokens. Title II issuers must draft a whitepaper meeting Annex I requirements, notify the home-member-state competent authority at least 20 working days before publication, and disclose material changes through the lifecycle of the token. Marketing communications must be fair, clear, and not misleading, and must be consistent with the whitepaper.
What MiCAR does not impose on Title II issuers: no prospectus, no investor-protection regime equivalent to MiFID II, no securities-register requirement, no transaction reporting under MiFIR, no MAR insider-dealing perimeter (MiCAR has its own narrower market-abuse rules in Title VI), and no PRIIPs KID. This is why a correct utility classification carries meaningful regulatory cost advantages, and also why misclassification is policed strictly.
MiFID II Article 4(1)(44): what counts as a security
MiFID II Article 4(1)(44) defines "transferable securities" as classes of securities negotiable on the capital market, with the exception of instruments of payment. The article gives a non-exhaustive list: shares in companies and equivalents, bonds and other forms of securitised debt, and any other securities giving the right to acquire or sell any such transferable security or giving rise to a cash settlement determined by reference to transferable securities, currencies, interest rates, yields, commodities, or other indices or measures.
The two key tests are negotiability (the instrument must be capable of being traded on the capital market, even if it is not yet listed) and standardisation within a class. Bespoke, non-fungible obligations between two parties are not transferable securities. Tokens issued in identical, fungible series with the intent of being tradeable on a secondary market almost always are, regardless of whether the issuer ever lists them.
ESMA's 2019 Advice on Initial Coin Offerings and Crypto-Assets and subsequent national-authority statements (BaFin's interpretive notes, AMF's classification guides, CSSF in Luxembourg) have confirmed that tokens carrying profit, dividend, interest, or voting rights are transferable securities under Article 4(1)(44). This is the operative definition for any EU tokenisation project in 2026.
Germany's eWpG: the crypto-securities pillar
The German Electronic Securities Act (eWpG) entered into force in June 2021 and was extended in 2023 to cover shares. By 2026 the act covers bearer bonds, registered bonds (bearer bonds and registered bonds), shares (shares), and investment-fund units. The act replaces the requirement for a physical certificate with an electronic entry in either a central register (operated by a CSD such as Clearstream) or a crypto-securities register (§16 eWpG) maintained on a distributed ledger by a §17-licensed registrar.
Section 17 of the eWpG sets out the licence regime for crypto-securities registrars: registrars must be authorised by BaFin, meet capital, governance, and IT-security requirements (including BAIT compliance), and operate the register in a way that ensures integrity, authenticity, and disposability of the entries. As of 2026, a small number of registrars hold the §17 licence, including Cashlink, which operates as ONINO's registrar partner.
The key practical effect for issuers: an eWpG crypto security is a legally equivalent securitised instrument to a paper certificate. Pledge, transfer, and good-faith acquisition rules under the German Civil Code (BGB) and Securities Account Act apply. This is the structurally compliant path for issuing tokenised debt and equity to German investors under German law in 2026.
Prospectus Regulation: thresholds and exemptions
The Prospectus Regulation (EU 2017/1129) requires a prospectus for any public offer of transferable securities in the EU, with thresholds and exemptions that materially shape the issuance choice. In Germany, the headline rules in 2026 are:
Offers under EUR 8 million in any 12-month period are exempt from the prospectus duty (§3 Nr. 2 WpPG), but require a securities information sheet (WIB) filed with BaFin under §4 WpPG.
Offers solely to qualified investors (MiFID II professional clients and eligible counterparties) are exempt from the prospectus duty under Article 1(4)(a) of the Prospectus Regulation, with no upper limit.
Offers to fewer than 150 retail investors per member state are exempt under Article 1(4)(b).
Offers with a minimum denomination of EUR 100,000 per investor are exempt under Article 1(4)(c).
Asset Investment Act instruments (asset investments, not transferable securities) under EUR 6 million in any 12-month period require an asset information sheet (VIB) under §13 VermAnlG, not a prospectus.
The choice of exemption shapes everything downstream: investor pool, marketing channels, secondary-market structure, and the cost stack. For a Tier-2 DACH issuer placing a tokenised bearer bond to professional investors, the qualified-investor exemption combined with eWpG registration is the dominant pattern in 2026.
Howey vs. the EU classification test
Issuers familiar with US securities law often default to the Howey test (SEC v. W.J. Howey Co., 1946): an investment of money, in a common enterprise, with the expectation of profits, derived from the efforts of others. Howey is the SEC's operative classification test for crypto in the United States and underlies most of the high-profile enforcement actions of the 2020-2025 period.
The EU does not apply Howey. The EU test is whether the instrument falls within the MiFID II Article 4(1)(44) categories of transferable securities, units of collective investment undertakings (CIU), money-market instruments, or derivatives. The two regimes diverge in several practically important ways:
Howey is functional and intent-based ("expectation of profits derived from the efforts of others"); MiFID II is structural and class-based ("negotiable on the capital market"). A token with no profit promise but designed to trade on a secondary market is more likely to be a security in the EU than under Howey.
Howey treats the offering and the asset together; MiFID II treats the instrument's intrinsic features. A token can be a security in the EU even if the issuer disclaims any active managerial role, as long as the instrument is a standardised, transferable claim.
Howey has been the subject of intense litigation (SEC v. Ripple, SEC v. Coinbase) and the boundary is unstable; the EU boundary is set by statute and ESMA guidance and is more predictable, though not free of debate at the margin.
For a project issuing in both jurisdictions, the EU MiFID II analysis usually produces a broader securities perimeter than Howey. Projects that survive Howey as "sufficiently decentralised" utility tokens have repeatedly been classified as financial instruments by EU national authorities. The safe planning assumption is: if the token is a security in the US, it is also a security in the EU. The reverse does not hold.
Decision tree: which regime applies to your token
Issuers can resolve the classification by walking the rights conveyed by the token in order:
Does the token grant a claim on the issuer's cash flows (coupon, dividend, profit share, redemption at face value)? If yes, financial instrument under MiFID II. Continue to step 5.
Does the token grant voting rights on the issuer's commercial decisions or corporate matters? If yes, financial instrument (likely equity). Continue to step 5.
Is the token redeemable at par against a single fiat currency, on demand or at a fixed date? If yes, e-money token under MiCAR Title IV. Different rails.
Is the token backed by a basket of assets or currencies and maintains a reference value? If yes, asset-referenced token under MiCAR Title III. Different rails.
Is the token issued under German law and intended to be tradeable on a secondary market? If yes, crypto security under §4 eWpG; register required under §16 eWpG, operated by a §17 registrar. Continue to step 7.
Is the token a utility access right with no profit, voting, or redemption claim? If yes, crypto-asset under MiCAR Title II. Whitepaper + NCA notification. Stop.
Does the offering exceed the EUR 8 million / 12-month threshold and target retail? If yes, full prospectus under the Prospectus Regulation. If no, qualifying alternative (WIB under §4 WpPG, VIB under §13 VermAnlG, or qualified-investor exemption).
This is the working test ONINO and its registrar partner apply to every client classification. It is not a substitute for legal advice on the specific instrument, but it gives an issuer a defensible first-pass mapping that holds up in a BaFin pre-filing meeting.
Settlement and the cash leg
Token transfer on its own is not settlement. Under eWpG and MiFID II alike, the cash leg must close before delivery is final. For a regulated security token, the cash leg cannot run on an unregulated stablecoin: it must touch a supervised payment rail.
Three settlement patterns dominate in 2026, selected per issuance:
Bundesbank Trigger Solution (DvP via central bank money). The German central bank (Deutsche Bundesbank)'s Trigger Solution links the DLT to TARGET2, settling the euro leg in central bank money against the token transfer. The mechanism has been in production pilot since 2024 and is the preferred path for institutional-grade DvP under eWpG when both sides are within the TARGET2 perimeter.
Commercial bank money via paying agent. A licensed credit institution acts as paying agent. The cash leg settles via SEPA Instant Credit Transfer or T2 commercial-money rails, with the §16 registrar entry contingent on confirmed receipt. This pattern handles the majority of private-placement issuances in 2026.
Off-chain reconciliation against an escrow. For private placements where investors fund directly into a regulated escrow account, the issuer reconciles fiat receipts to on-chain allocations and the registrar entry is triggered only after funds clear. Slower than DvP, but operationally simple for smaller issuances.
Atomic on-chain DvP using unregulated stablecoins is not a compliant settlement option for eWpG securities. The Markets in Crypto-Assets Regulation permits e-money tokens issued by authorised electronic money institutions to clear DvP transactions, and pilot deployments of EURC (Circle Internet Financial Europe) and EURØP (Société Générale-FORGE) in trading systems under the DLT Pilot Regime have shown that this lane is opening, but mainstream eWpG settlement in 2026 still runs through central or commercial bank money.
Where misclassification still happens in 2026
One of the persistent challenges in EU crypto markets is that some tokens begin as utility tokens and migrate, in substance, into securities territory. Three recurring failure modes:
The yield migration. A platform launches a "utility" token for protocol access, then enables staking that pays a yield from protocol fees. Yield from the efforts of the issuer team turns the token into a transferable security under Article 4(1)(44). BaFin and AMF have both publicly recharacterised tokens on this basis.
The governance-with-economics migration. A governance token that votes on protocol parameters drifts into voting on treasury allocations, distributions, or commercial decisions of an issuing legal entity. Voting on commercial decisions of an issuer is an equity-like right.
The buyback migration. A platform commits to use a portion of revenues to buy back and burn the token. Buybacks funded by issuer revenues create an expectation of price support derived from the efforts of the issuer, which has been read by EU regulators as a financial-instrument feature.
Because the boundaries are not always clear, mature projects consult legal counsel and registrar partners early in design, before token mechanics are encoded into smart contracts. Recharacterisation after launch is expensive: it requires either restructuring the token to remove the security-like feature or filing retroactive disclosure and onboarding a registrar, often while supervisory enforcement is in motion.
For a detailed breakdown of how this classification works for regulated EU issuers, see ONINO's private credit and private markets playbooks.
Worked examples: how ONINO clients issue under MiFID II and eWpG
ONINO the company does not issue securities. ONINO the platform provides the regulated rails on which its clients issue security tokens. Four illustrative patterns:
Bank tokenising a bond
A German private bank tokenises a bearer bond on ONINO. The bank is the issuer of record under MiFID II Article 4(1)(44); the bond is a crypto security under §4 eWpG, recorded on a §16 eWpG crypto-securities register operated by ONINO's registrar partner Cashlink under §17 eWpG authorisation. The bank files the securities information sheet (WIB) or securities prospectus with BaFin depending on offering size and investor base, holds prospectus liability, and owns the investor relationship. ONINO and Cashlink carry the registry, the white-label issuance UI, the KYC/AML stack, the cap table, and the reporting layer. The cash leg settles either via Bundesbank Trigger Solution against central bank money or via the bank's own paying-agent role.
Real estate sponsor tokenising equity participations
A real estate sponsor tokenises equity participations in a property-holding SPV. The eWpG path applies to the participations themselves; if a fund wrapper is used (UCITS, AIF, or KAGB-licensed AIF), an AIFMD overlay attaches and an authorised AIFM must run the fund. The sponsor or AIFM owns the regulatory perimeter; ONINO and the §17 registrar carry the issuance, register, and lifecycle layers. Investor onboarding runs against the sponsor's existing KYC stack via ONINO's API.
Asset manager tokenising profit-sharing
An asset manager tokenises a profit-sharing instrument (profit participation right). The classification turns on whether the instrument meets the MiFID II "transferable security" threshold. If yes, the eWpG path applies and the instrument is a crypto security. If no (typically because of bespoke, non-fungible features), the instrument is a asset investment under the Asset Investment Act and requires an asset information sheet (VIB) under §13 VermAnlG. The asset manager files the appropriate disclosure with BaFin and holds the underlying liability. ONINO supports both paths on a single platform.
Cooperative tokenising memberships
A cooperative tokenises memberships under the German Cooperative Societies Act. The eWpG registry layer applies to the digital representations of the membership, which are transferable within the cooperative's bylaws. Member rights (voting, share of profits, dividend) are governed by the cooperative law itself, not by securities law, but the digital representation runs on the same crypto-securities register infrastructure. ONINO and Cashlink handle the registry, while the cooperative handles its member relationships and corporate-law disclosures.
Why the split matters in practice
For an issuer evaluating tokenisation platforms in the EU, the relevant question is not "does the platform have a token" but "under which regime does the platform let me issue my token". A platform built around its own equity-like token (Securitize SRT-style) and a platform built around client issuances on regulated rails (ONINO, Tokeny, Cashlink direct) are different products. ONINO sits in the second camp: ONI powers the chain, the chain hosts client securities, and the regulatory burden lives with the client and its registrar partner, not with ONINO GmbH.
For the reader still mapping their own token, the working test is the same one applied to ONI. List the rights conveyed. If the list includes a claim on cash flows, voting on the issuer, or a share of profits, the answer is MiFID II and, in Germany, eWpG. If the list is service access on a network with no issuer claim, the answer is MiCAR Title II. The label on the whitepaper does not move the result.
How ONINO supports regulated issuers
ONINO provides a white-label issuance, registry-integration, and lifecycle platform for regulated issuers in the EU. The platform combines:
Issuance UI and investor portal, branded to the issuer.
KYC/AML integration with the issuer's existing onboarding stack or ONINO's bundled providers.
§16 eWpG crypto-securities register entries via Cashlink as §17 registrar partner, with optional integration into other authorised registrars on request.
Cap-table maintenance, corporate-action processing (coupon, redemption, dividend), and investor communications.
Cash-leg orchestration across the three settlement patterns described above.
Reporting layer for issuer obligations under MiFID II, MAR, and eWpG, plus per-investor tax reporting where applicable.
The platform is designed for asset managers, banks, real estate sponsors, and corporate treasurers. Platforms go live in under 24 hours from contract signature, with no internal technical build required from the issuer. ONINO maintains operational resilience controls aligned with the Digital Operational Resilience Act (DORA, in force January 2025) and BaFin's IT supervisory requirements for banks (BAIT), and is on the SOC 2 Type II audit path for 2026. Current attestations and sub-processor disclosures are available on request.
ONINO's infrastructure handles compliance, investor onboarding, and reporting from day one, so you can focus on structuring your deal and building your investor base. Platforms go live in under 24 hours, with no internal technical build required.
Want to learn more how this can be applied to your business?
Read related Articles
What's the difference between a security token and a utility token? Complete 2026 comparison covering MiCAR, BaFin classification, and real-world examples.




