Legal tests for securities classification are the judicial and regulatory criteria used to determine whether a financial instrument or digital asset qualifies as a “security” under the law. This matters because securities are subject to strict rules on issuance, trading, disclosure, investor protection, and licensing. If an instrument is a security, its issuance, distribution, and trading must comply with securities law – through registration or a valid exemption.
The four frameworks below are the ones that most often govern Stobox issuers. For deeper jurisdiction-by-jurisdiction detail, see the jurisdiction guides.
European Union – MiFID II and MiCA
In the EU, the classification of tokenized assets is primarily governed by two frameworks that operate side by side.
MiFID II (Markets in Financial Instruments Directive II). Security tokens that meet the definition of a financial instrument – shares, bonds, derivatives, or units in investment funds – fall under MiFID II and are treated like traditional securities. They must comply with licensing and authorization requirements, investor-protection and suitability rules, prospectus and disclosure obligations, and reporting, custody, and market-conduct standards. Issuers, brokers, and trading platforms must operate under appropriate permissions within the EU or via passporting across member states.
MiCA (Markets in Crypto-Assets Regulation). MiCA provides a harmonized framework for non-security crypto-assets – utility tokens, asset-referenced tokens, and e-money tokens – and for Crypto-Asset Service Providers (CASPs). MiCA’s provisions for asset-referenced and e-money tokens applied from 30 June 2024, and the regulation became fully applicable for CASPs from 30 December 2024. Critically, MiCA does not apply to crypto-assets already classified as financial instruments under MiFID II – it fills the gaps for digital assets previously outside the scope of EU financial law.
The dividing line for issuers: if a token represents ownership, profit rights, debt, or investment exposure, it is likely a security under MiFID II and must comply with those obligations in full. Only non-security tokens fall under MiCA. Proper classification is essential for lawful issuance, trading, and investor onboarding across the EU.
United Kingdom – FCA
The Financial Conduct Authority (FCA) classifies digital assets as either regulated or unregulated tokens. Security tokens are regulated tokens, because they confer rights akin to traditional financial instruments – shares, debt instruments, or units in a collective investment scheme – and therefore fall within existing UK securities legislation and financial-promotion rules.
Key compliance requirements for security tokens in the UK:
- Must be issued and marketed in accordance with UK financial-services regulations.
- May require approval or exemption under the UK Prospectus rules or the Financial Services and Markets Act (FSMA).
- Issuers and distributors may need to be authorized or registered with the FCA.
- Investors must receive appropriate risk disclosures and offering documents, and may be restricted by classification (retail vs. professional).
The UK does not yet have a bespoke legislative regime for tokenized securities; the FCA applies existing law so that blockchain-based instruments meet the same standards as traditional assets. Issuers offering security tokens in or from the UK should engage qualified counsel to confirm structure, marketing, and offering terms.
United States – SEC and the Howey Test
In the U.S., classification is governed by the Securities and Exchange Commission (SEC), which applies the Howey Test – derived from a 1946 Supreme Court decision – to determine whether a digital asset is a security. A token is a security if it satisfies all four prongs:
- Investment of money – a contribution of capital or other value by investors.
- Common enterprise – the investment is pooled or relies on a shared project or entity.
- Expectation of profit – investors anticipate income, appreciation, or distributions.
- Efforts of others – that expected profit is driven primarily by the efforts of the issuer or project team.
If a token meets the Howey Test, it must either be registered with the SEC (e.g. an S-1 public offering or a qualified Regulation A+ offering) or issued under a valid exemption – Regulation D (private placements to accredited investors), Regulation S (offshore offerings to non-U.S. investors), Regulation A+ (tiered exemptions with raise caps), or Regulation CF (crowdfunding with limits). Issuers must also implement investor disclosures, transfer restrictions, KYC/AML, and secondary-trading compliance such as ATS listing.
The practical reality: the vast majority of tokens offering ownership, profit participation, or debt repayment are securities in the U.S. If yours meets the Howey Test, structure and offer it in full compliance to avoid enforcement, investor claims, and penalties.
Switzerland – FINMA
The Swiss Financial Market Supervisory Authority (FINMA) classifies tokens by their economic function rather than by creating new legal categories, mapping each token onto Switzerland’s established financial and securities frameworks. FINMA recognizes three primary types:
- Payment tokens – a means of exchange or payment (e.g. Bitcoin, Litecoin); not tied to a project or claim on an issuer. Typically outside securities regulation but subject to AML law.
- Utility tokens – provide access to a digital application, platform, or service, and must serve a genuine utility function at issuance. May be unregulated if they carry no investment characteristics.
- Asset tokens (security tokens) – represent ownership, debt claims, or economic-participation rights; functionally similar to stocks, bonds, or derivatives, and regulated as securities under Swiss law.
Tokens with overlapping characteristics (utility plus investment return) may be treated as hybrids, in which case the stricter regime applies. Where a token is an asset token, it triggers securities-law disclosures, KYC/AML and investor onboarding controls, potential licensing for issuance, custody, or secondary trading, and prospectus filing or exemption under the Swiss Financial Services Act (FinSA). In practice, most tokenized equity, real estate, debt, or revenue claims are asset tokens; issuers must align with FinSA, FinIA, and AMLA obligations where applicable. In 2021 Switzerland’s DLT Act made it one of the first jurisdictions to legally recognize DLT-based securities and blockchain-native trading venues.