Whether a token is a transferable security or not does not depend on what it is called, but on the right it incorporates. A utility token that gives access to a specific product or function, without a promise of returns managed by a third party, does not fit the definition of a financial instrument. Prior design is what decides.
You launch a utility token. You give access to a product, a network, a specific function. And one thing terrifies you: that the CNMV looks at your token and treats it as a security. Because if it does, the prospectus, MiFID II, and a multi-month issuance you hadn't budgeted for fall on you. The good news: a security classification is not an accident. It is designed. And it is avoided with clean design from day one.
This article is the mirror of the one that compares the two types. If you want to understand the full boundary, read security token vs utility token: which type does your asset need?. Here the focus is different: how to stay on the utility side (MiCA) and not accidentally fall on the security side (LMVSI).
The rule in two lines
Your token becomes a security token when it incorporates an economic right typical of a security: an expectation of return tied to the efforts of a third party. Substance rules, not the label. If your token only gives access or real use and does not promise profitability, you stay in utility under MiCA. If it hints at profit, you cross into security under the LMVSI.
Substance prevails over form. MiFID II says so and the ESMA Guidelines confirm it: the legal nature is set by the rights you deliver, not the commercial name or the technology (art. 4 Directive 2014/65/EU; ESMA Guidelines ESMA75-453128700-1323). It doesn't matter if you write “utility” in the white paper. If the content smells of investment, it is a security.
What turns a token into a security
A token is a security when it works like a share, a bond, or a derivative: when it delivers an economic right that the investor buys hoping to make money thanks to what the issuer does. That is the heart of the classification.
The economic right is the red line
There are four rights that trigger the alarm. Profit sharing (like a dividend). Credit right (I lend you and you pay me back with interest). Expectation of return tied to the efforts of a third party (I put in money, you work, I earn). And rights over a financial underlying asset (the token tracks the value of an asset). If your token delivers any of these, it is a financial instrument (Annex I, Section C, Directive 2014/65/EU).
Substance, not the label
The test does not read your marketing. It reads what the token actually does. ESMA applies a technology-neutral approach: blockchain does not change the nature of the right you represent (ESMA Guidelines ESMA75-453128700-1323). A token that promises profitability is still a security even if you call it a “loyalty point” or an “access pass”.
What it means for you: before writing any marketing, define in writing what specific right your token delivers. If in that sentence the words “earn”, “profitability”, or “appreciation” appear, you have a design problem, not a copywriting problem.
The features that taint your utility
A clean utility token gets dirtied by features that look innocent on a landing page but that a supervisor reads as an investment promise. These are the ones that push you toward security without you looking for it.
Promise or expectation of appreciation
The most common and most dangerous feature. As soon as you suggest that the token “will rise”, “will appreciate”, or “will gain value over time”, you create an expectation of return. That is what defines a security (ESMA Guidelines ESMA75-453128700-1323). You don't need to promise it in a contract: it is enough for your communication to hint at it.
Revenue sharing or increasing buyback
If the token gives the right to a share of the project's revenue, it works like a dividend. If you commit to buying it back at a rising price, it works like a bond with a coupon. Both are economic rights typical of a security. The wrapper doesn't matter: the mechanics rule.
Linking to the issuer's financial metrics
Tying the token's value or benefits to your company's financial performance (revenue, profits, valuation) creates exactly the link that defines a security: the investor wins if you do well. That is the 'expectation of return tied to the effort of a third party' in its purest form.
Investor-focused presale
How you sell also matters. A presale that appeals to the investor (discounted rounds for getting in early, 'opportunity' language, price projections) casts an investment tint even on a token with real utility. The context of the offering is part of the substance the supervisor examines.
How to design the token to stay in utility
To stay under MiCA, your token must provide access or real use and nothing more. No investment component, no promise of gain, no economic right. Design is the defense: if the token grants no valuable right, there is no security classification to apply.
Anchor the token to a function, not a return
The token must serve a specific and present purpose: pay for a service, unlock a feature, access a network. Its value to the buyer is use, not resale. When utility is real and current, there is no expectation of return to sustain.
Remove investment language
Review every piece of communication. Out with 'profitability', 'appreciation', 'investment opportunity', 'will rise', 'ROI'. The white paper, the website, the ads and even social media messages are part of the substance. A single investment phrase can drag down the whole project.
Design the offering as a product sale
Present the token sale as you would sell a license or a subscription, not as an investment round. No discounts designed for speculators, no price projections, no promises of a liquid secondary market as a hook. You sell access, not expectation.
What it means for you: have a third party outside the project read your white paper and your website. Ask them one thing: 'would you buy this to use it or to make money?' If they answer the latter, redesign before launching.
Utility is not 'unregulated'
Avoiding security classification does not leave you in no man's land. A utility token is still a crypto-asset regulated by MiCA. You have obligations: a white paper with required content and format, notification to the CNMV and marketing communication rules. Staying in utility changes the framework, it does not eliminate it.
MiCA applies to crypto-assets that are not financial instruments (Regulation (EU) 2023/1114). A utility token falls squarely within that. That means a white paper, transparency and supervision by the CNMV as the competent authority in Spain. The difference with a security token is the framework you fall under, not the absence of a framework.
To understand why security tokens fall outside MiCA and come under the LMVSI, you have the details in why security tokens do not fall under MiCA. And if you are starting from scratch with the concept of tokenizing, start with what asset tokenization is.
Checklist: features to avoid in your utility
Review your token and your communication against this list. If you tick any, you are close to security classification:
- You promise or suggest that the token will appreciate.
- The token gives the right to a share of revenue or profits.
- You commit to buying it back at an increasing price.
- Its value is tied to your company's financial metrics.
- The presale appeals to the investor, not the user.
- The white paper or the website uses investment language ('ROI', 'profitability', 'opportunity').
- The selling hook is the secondary market, not the use of the token.
Table: safe utility vs risk zone
| Token feature | Safe utility (MiCA) | Risk zone (towards LMVSI) |
|---|---|---|
| What it is for | Real and present access or use | Wait for the price to rise |
| Economic right | None | Profits, credit or underlying |
| Promise to the buyer | A specific function | Appreciation or return |
| Buyback | No buyback or at value in use | Buyback at an increasing price |
| Link to the issuer | Independent of the balance sheet | Tied to financial metrics |
| How it is sold | As a product or license | As an investment opportunity |
| Framework that applies | MiCA: white paper and CNMV | LMVSI + MiFID II: prospectus and CNMV |
What to do now
Concrete steps to design your token outside the securities perimeter:
- Write in one sentence what right your token grants. If it mentions profit, redesign it.
- Compare your case with the full boundary: security token vs utility token.
- Understand why a security leaves MiCA and enters the LMVSI: security tokens do not fall under MiCA.
- If you start from scratch, begin with what asset tokenization is.
- Resolve the terminology in the glossary.
Frequently asked questions
Is it enough to put “utility” in the white paper to avoid being a security?
No. Substance prevails, not the label. The supervisor looks at the rights the token grants, not its commercial name (Art. 4 Directive 2014/65/EU; ESMA Guidelines ESMA75-453128700-1323). If the token promises a return, it is a security even if you call it utility.
Can I promise that my token will increase in value?
No, if you want to stay in utility. The promise or expectation of appreciation creates an expectation of return, which is what defines a security. That message, on the website or social media, pushes you toward the LMVSI.
Is it safe to distribute project revenue among holders?
Not for a utility token. Revenue sharing works like a dividend and is a typical economic right of a security. If you include it, your token stops being a utility token and becomes a security token.
Does a presale turn my token into a security?
It depends on how you structure it. A presale that appeals to the investor (early-entry discounts, price projections, opportunity language) gives the token an investment character. The context of the offering is part of the substance being assessed.
If I avoid being a security token, does that leave me unregulated?
No. A utility token is still under MiCA: white paper with required content, notification to the CNMV and marketing communication rules (Regulation (EU) 2023/1114). You switch frameworks; you do not leave regulation.
Who ultimately decides whether my token is a security?
The CNMV, as the competent authority in Spain, applying MiFID II and the ESMA Guidelines. The classification is based on the token's actual economic rights, with a technology-neutral approach (ESMA Guidelines ESMA75-453128700-1323).
Notice
Informational content. It does not constitute legal, tax or investment advice. HokenFi is a software and infrastructure provider; it does not provide regulated services. Check the current version of the rules cited in the BOE and EUR-Lex.
Cited regulations
- Directive 2014/65/EU (MiFID II): art. 4 and Annex I, section C. CELEX 32014L0065.
- ESMA Guidelines on the conditions and criteria for classifying crypto-assets as financial instruments: ESMA75-453128700-1323 (19/03/2025).
- Regulation (EU) 2023/1114 (MiCA): art. 2(4). CELEX 32023R1114.
- Ley 6/2023, de 17 de marzo, de los Mercados de Valores y de los Servicios de Inversión (LMVSI). BOE-A-2023-6536.




