A tokenized instrument that confers rights in an issuer or a third party — a tokenized share, bond, or derivative — falls under MiFID II, not MiCA. MiCA governs crypto-assets that do not qualify as financial instruments. The classification test is the nature of the rights the token conveys, not the technology used to record them. A security on a blockchain is still a security.
The exclusion: Article 2(3) MiCA
Article 2(3) MiCA excludes from the regulation's scope crypto-assets that qualify as financial instruments under Article 4(1)(15) of Directive 2014/65/EU (MiFID II). That MiFID II provision defines financial instruments to include transferable securities, money-market instruments, units in collective investment undertakings, and derivatives. A token that meets one of those definitions is not a crypto-asset for MiCA purposes, regardless of how it is issued or transferred.
The consequence: a firm that offers or trades tokenized shares, bonds, or derivatives must hold a MiFID II licence (typically as an investment firm under Article 5 MiFID II), not a MiCA crypto-asset service provider authorization. The home Member State competent authority applying MiFID II is the same authority that would authorize MiCA CASPs, but the regime is different.
The classification test in practice
The test turns on whether the token confers rights in the issuer or a third party. A tokenized equity share gives the holder voting rights, dividend rights, or a claim on residual assets — all rights in the issuer. A tokenized bond creates a debt obligation from the issuer to the holder. A tokenized derivative references an underlying asset or index and creates a payment obligation between parties. Each of these meets the MiFID II definition of a financial instrument.
By contrast, a utility token that grants access to a service without conferring rights in the issuer, or a payment token used solely as a medium of exchange, does not meet that definition. Neither does an asset-referenced token (ART) or an e-money token (EMT) — both are explicitly defined in MiCA (Articles 3(1)(4) and 3(1)(5)) and fall under MiCA's separate regimes.
The technology used to issue or transfer the token does not change the classification. A share issued on a permissioned blockchain, a bond recorded in a distributed ledger, or a derivative settled through a smart contract remains a financial instrument if it confers the relevant rights. ESMA's October 2022 advice to the European Commission on crypto-assets (ESMA50-164-4417) confirmed that the classification depends on the legal and economic characteristics of the asset, not the technical infrastructure.
Who must hold a MiFID II licence
A firm that operates a trading platform for tokenized securities, provides custody or execution services, or advises clients on such instruments must hold authorization under MiFID II. The relevant service categories are those listed in Section A of Annex I to MiFID II: reception and transmission of orders, execution of orders on behalf of clients, portfolio management, investment advice, and operation of a multilateral trading facility (MTF) or organized trading facility (OTF).
Custody of tokenized financial instruments falls under the safekeeping and administration service in Section B of Annex I to MiFID II, which investment firms may provide as an ancillary service if authorized for a core investment service. A firm that offers custody alone — without trading, execution, or advice — may instead require authorization as a central securities depository under Regulation (EU) No 909/2014 (CSDR), depending on how the tokenized instruments are recorded and settled.
A MiCA CASP authorization does not permit a firm to offer services in financial instruments. Article 60 MiCA lists the crypto-asset services a CASP may provide: custody and administration of crypto-assets on behalf of clients, operation of a trading platform for crypto-assets, exchange of crypto-assets for funds or other crypto-assets, execution of orders for crypto-assets on behalf of clients, placing of crypto-assets, reception and transmission of orders for crypto-assets on behalf of clients, and providing advice on crypto-assets. None of these services extends to financial instruments as defined in MiFID II.
The custody boundary: Article 75 MiCA vs MiFID II safeguarding
Custody obligations differ between the two regimes. Article 75 MiCA requires a CASP providing custody to maintain a register of positions per client, segregate client crypto-assets from the CASP's own holdings, and ensure that client assets are transferable on request. The CASP bears liability for the loss of crypto-assets unless it proves the loss resulted from an event beyond its control. This is a strict-liability standard.
MiFID II safeguarding rules, set out in Article 16(8) and (9) of MiFID II and detailed in Commission Delegated Regulation (EU) 2017/565 (the MiFID II Delegated Regulation), require investment firms to segregate client financial instruments from the firm's own instruments and from those of third parties, and to keep records that permit individual client positions to be identified at all times. The firm must also make adequate arrangements to safeguard clients' ownership rights, particularly in the event of the firm's insolvency. Liability standards follow national law in each Member State, typically with a fault-based rather than strict-liability approach.
Where a firm holds both crypto-assets (under MiCA) and tokenized financial instruments (under MiFID II) for the same client, it must apply the relevant regime to each asset class. The two sets of obligations do not merge; they run in parallel. A compliance framework that conflates them will fail supervision in both.
For the current ESMA register count of authorized CASPs and a breakdown by Member State, see the live registry. For the specific Article 75 custody obligations, including the segregation and liability requirements, the custody obligations post sets out the operational detail.
Hybrid instruments and the grey zone
Some tokenized instruments do not fit cleanly into either category. A token that confers both a financial return linked to the issuer's performance and a utility function within a platform may meet the financial-instrument definition if the financial rights are the primary characteristic. The test is whether the economic substance of the arrangement is closer to a security or to a service-access right.
ESMA's 2019 advice on initial coin offerings and crypto-assets (ESMA50-157-1391) noted that the qualification depends on the specific terms of the token, including any rights to profit-sharing, voting, or claims on assets. A profit-sharing mechanism that depends on the issuer's revenue or assets typically brings the token within the financial-instrument definition, even if the token also grants access to a service.
Where uncertainty exists, the prudent approach is to seek a classification from the home Member State competent authority before offering the instrument. Most authorities provide a non-binding opinion or no-action letter in response to a detailed factual submission. Proceeding without clarity risks enforcement for operating without the correct authorization — a breach that carries both administrative sanctions and potential criminal liability in some Member States.
Transitional deadlines and grandfathering
MiCA's transitional provisions, set out in Article 143, permit firms that were lawfully providing crypto-asset services before 30 December 2024 under national law to continue operating until 1 July 2026 without a MiCA authorization, provided they notify their competent authority by 1 July 2024. This grandfathering applies only to crypto-asset services within MiCA's scope. It does not extend to services in financial instruments, which remained subject to MiFID II throughout.
A firm that was offering custody or trading of tokenized securities under a national licence before MiCA entered into force must hold a MiFID II authorization to continue that activity. The MiCA transitional period does not apply. If the firm also offered services in non-financial-instrument crypto-assets, it may rely on the MiCA transitional regime for those services, but the two regimes do not cross over.
For the full MiCA transitional timeline, including the 1 July 2026 deadline for existing CASPs and the separate deadlines for stablecoin issuers, see the AMLR 2027 crypto timeline, which tracks the parallel AMLR obligations that apply from July 2027.
Notification and supervision: which authority, which form
A firm that provides services in both crypto-assets and tokenized financial instruments deals with the same competent authority for both regimes in most Member States. The authority that authorizes MiCA CASPs (typically the national financial supervisor) is also the authority that authorizes investment firms under MiFID II. The firm submits separate applications: one for MiCA services, one for MiFID II services. The two authorizations do not merge into a single licence.
In Germany, BaFin authorizes both CASPs under Article 63 MiCA and investment firms under MiFID II. In France, the AMF issues both MiCA and MiFID II authorizations. In Ireland, the Central Bank of Ireland is the competent authority for both regimes. A firm may apply for both authorizations in parallel, but the assessment criteria, the ongoing obligations, and the supervision programs differ.
Supervision follows the authorization. A CASP providing custody of crypto-assets is supervised for compliance with Article 75 MiCA. An investment firm providing custody of tokenized securities is supervised for compliance with Article 16 MiFID II and the MiFID II Delegated Regulation. If the firm holds both authorizations, it is supervised under both regimes, with separate reporting, capital, and governance requirements for each.
To check whether a firm holds MiCA authorization and for which services, use the firm verification tool, which queries the live ESMA register and shows the authorized service categories.
Capital and governance: separate calculations
Initial capital requirements differ. A MiCA CASP must hold initial capital of at least EUR 50,000 under Article 67(1) MiCA, increased to EUR 125,000 if the CASP provides custody or operates a trading platform, and further increased to EUR 150,000 if the CASP is authorized for more than one service. The calculation is set out in Article 67 and does not depend on the volume of client assets.
A MiFID II investment firm must hold initial capital of at least EUR 75,000 under Article 9 of the MiFID II Delegated Regulation if the firm holds client funds or securities, deals on own account, or underwrites financial instruments. The ongoing own-funds requirement, introduced by Regulation (EU) 2019/2033 (the Investment Firms Regulation, IFR), is the higher of the initial capital requirement, the fixed overheads requirement, or the K-factor requirement based on the firm's risk exposure. The K-factor requirement scales with the firm's activities and client assets.
A firm holding both authorizations must meet both sets of capital requirements. The capital held for MiFID II purposes does not count toward the MiCA requirement, and vice versa. The firm maintains separate calculations and reports each to the competent authority.
Governance requirements also run in parallel. MiCA Article 70 requires a CASP to have robust governance arrangements, including a clear organizational structure, effective procedures to identify and manage conflicts of interest, and adequate internal control mechanisms. MiFID II Article 16(2) imposes similar requirements, detailed further in the MiFID II Delegated Regulation, including policies on outsourcing, record-keeping, and complaints handling. A firm authorized under both regimes must document compliance with both sets of governance standards.
The reverse-solicitation boundary
Reverse solicitation — where an EU client initiates contact with a non-EU firm without prior marketing by that firm — is analysed separately under each regime. Under MiFID II, Article 42 permits third-country firms to provide investment services to eligible counterparties and professional clients in the EU without authorization if the service is provided at the client's exclusive initiative. National law in each Member State determines whether retail clients may also access third-country firms on a reverse-solicitation basis; most Member States permit it, but the conditions vary.
Under MiCA, Article 63 requires any firm providing crypto-asset services to clients in the EU to hold authorization from an EU competent authority. There is no express reverse-solicitation exemption in MiCA. ESMA's guidance on the application of MiCA to third-country firms (still under development as of this writing) will clarify whether Member States may apply a reverse-solicitation principle under national law during the transitional period. Until that guidance is published, the safer course is to assume that a third-country firm serving EU clients in crypto-assets must either obtain MiCA authorization or restrict its activities to services that fall outside MiCA's scope.
A third-country firm that offers both tokenized securities (MiFID II) and crypto-assets (MiCA) to EU clients must analyse the reverse-solicitation question separately for each service. The firm may rely on MiFID II reverse solicitation for the tokenized securities if the client initiates contact and the firm meets the Article 42 conditions. It cannot assume the same principle applies to the crypto-asset services without further legal analysis.
For the post-transition reverse-solicitation hot spots and the questions supervisors are now asking, see the reverse-solicitation guide.
Enforcement and precedent
Enforcement actions to date have focused on firms that offered tokenized instruments without a MiFID II licence, not on misclassification between MiCA and MiFID II (MiCA's full application began only on 30 December 2024, so MiCA-specific enforcement is still building). National authorities have issued cease-and-desist orders and administrative fines where firms operated trading platforms for tokenized shares or bonds without investment-firm authorization.
In 2023, BaFin ordered a platform offering tokenized real-estate shares to cease operations until it obtained a MiFID II licence, on the basis that the tokens conferred profit-sharing rights and thus met the transferable-securities definition. The firm's argument that the tokens were utility instruments because they also granted governance rights in the underlying real-estate project was rejected; the economic substance was a security.
In France, the AMF issued a public warning in 2024 against a firm offering tokenized bonds without authorization, noting that the use of blockchain technology does not alter the classification of a financial instrument. The firm subsequently applied for MiFID II authorization and suspended its services pending the outcome.
These cases establish that supervisors will look through the technical implementation to the rights conferred by the token. A firm that structures an offering to avoid MiFID II by calling the instrument a utility token, while in substance offering equity or debt rights, will not succeed.
The decision table
| Instrument type | Rights conferred | Regime | Authorization required | Custody obligations |
|---|---|---|---|---|
| Tokenized share | Voting, dividends, residual claim on issuer | MiFID II | Investment firm (Article 5 MiFID II) | Article 16 MiFID II + Delegated Regulation |
| Tokenized bond | Debt claim on issuer | MiFID II | Investment firm (Article 5 MiFID II) | Article 16 MiFID II + Delegated Regulation |
| Tokenized derivative | Payment obligation referencing underlying | MiFID II | Investment firm (Article 5 MiFID II) | Article 16 MiFID II + Delegated Regulation |
| Utility token (service access only) | Access to platform or service, no issuer rights | MiCA | CASP (Article 63 MiCA) | Article 75 MiCA |
| Payment token (exchange medium only) | None beyond transfer of value | MiCA | CASP (Article 63 MiCA) | Article 75 MiCA |
| Asset-referenced token (ART) | Stabilization via asset basket | MiCA | ART issuer or CASP (Articles 17, 63 MiCA) | Article 75 MiCA (if CASP) |
| E-money token (EMT) | Stabilization via fiat currency | MiCA | EMT issuer or CASP (Articles 48, 63 MiCA) | Article 75 MiCA (if CASP) |
| Hybrid (financial + utility rights) | Mixed — test depends on primary substance | MiFID II if financial rights dominate | Competent authority classification required | Regime follows classification |
What the firm must determine
The classification question is a threshold decision. A firm that launches a tokenized instrument without determining which regime applies has no legal basis to operate. The firm must:
- Document the legal and economic characteristics of the token — what rights it confers, what obligations it creates, and what risks it carries.
- Map those characteristics against the MiFID II financial-instrument definitions in Article 4(1)(15) and the Annexes to MiFID II.
- If the token does not meet a financial-instrument definition, confirm that it falls within MiCA's scope as a crypto-asset under Article 3(1)(5), excluding ARTs and EMTs unless separately authorized.
- Apply for the correct authorization before offering the token to EU clients or providing related services.
- Implement the custody, governance, and capital obligations of the applicable regime.
A firm that operates first and classifies later will face enforcement. The correct order is classify, apply, wait for authorization, then launch.