2026 GuideHow to tokenize an asset in Spain, reviewed by three law firms. Download it

Avoid being a security token: utility design guide

How to design your utility token so you don't accidentally fall into securities regulation (LMVSI) and stay in MiCA. Features to avoid, checklist, and table.

· 9 min read

Avoid being a security token: utility design guide

Whether a token is a transferable security or not does not depend on what it is called, but on the right it incorporates. A utility token that gives access to a specific product or function, without a promise of returns managed by a third party, does not fit the definition of a financial instrument. Prior design is what decides.

You launch a utility token. You give access to a product, a network, a specific function. And one thing terrifies you: that the CNMV looks at your token and treats it as a security. Because if it does, the prospectus, MiFID II, and a multi-month issuance you hadn't budgeted for fall on you. The good news: a security classification is not an accident. It is designed. And it is avoided with clean design from day one.

This article is the mirror of the one that compares the two types. If you want to understand the full boundary, read security token vs utility token: which type does your asset need?. Here the focus is different: how to stay on the utility side (MiCA) and not accidentally fall on the security side (LMVSI).

The rule in two lines

Your token becomes a security token when it incorporates an economic right typical of a security: an expectation of return tied to the efforts of a third party. Substance rules, not the label. If your token only gives access or real use and does not promise profitability, you stay in utility under MiCA. If it hints at profit, you cross into security under the LMVSI.

Substance prevails over form. MiFID II says so and the ESMA Guidelines confirm it: the legal nature is set by the rights you deliver, not the commercial name or the technology (art. 4 Directive 2014/65/EU; ESMA Guidelines ESMA75-453128700-1323). It doesn't matter if you write “utility” in the white paper. If the content smells of investment, it is a security.

What turns a token into a security

A token is a security when it works like a share, a bond, or a derivative: when it delivers an economic right that the investor buys hoping to make money thanks to what the issuer does. That is the heart of the classification.

The economic right is the red line

There are four rights that trigger the alarm. Profit sharing (like a dividend). Credit right (I lend you and you pay me back with interest). Expectation of return tied to the efforts of a third party (I put in money, you work, I earn). And rights over a financial underlying asset (the token tracks the value of an asset). If your token delivers any of these, it is a financial instrument (Annex I, Section C, Directive 2014/65/EU).

Substance, not the label

The test does not read your marketing. It reads what the token actually does. ESMA applies a technology-neutral approach: blockchain does not change the nature of the right you represent (ESMA Guidelines ESMA75-453128700-1323). A token that promises profitability is still a security even if you call it a “loyalty point” or an “access pass”.

What it means for you: before writing any marketing, define in writing what specific right your token delivers. If in that sentence the words “earn”, “profitability”, or “appreciation” appear, you have a design problem, not a copywriting problem.

The features that taint your utility

A clean utility token gets dirtied by features that look innocent on a landing page but that a supervisor reads as an investment promise. These are the ones that push you toward security without you looking for it.

Promise or expectation of appreciation

The most common and most dangerous feature. As soon as you suggest that the token “will rise”, “will appreciate”, or “will gain value over time”, you create an expectation of return. That is what defines a security (ESMA Guidelines ESMA75-453128700-1323). You don't need to promise it in a contract: it is enough for your communication to hint at it.

Revenue sharing or increasing buyback

If the token gives the right to a share of the project's revenue, it works like a dividend. If you commit to buying it back at a rising price, it works like a bond with a coupon. Both are economic rights typical of a security. The wrapper doesn't matter: the mechanics rule.

Linking to the issuer's financial metrics

Tying the token's value or benefits to your company's financial performance (revenue, profits, valuation) creates exactly the link that defines a security: the investor wins if you do well. That is the 'expectation of return tied to the effort of a third party' in its purest form.

Investor-focused presale

How you sell also matters. A presale that appeals to the investor (discounted rounds for getting in early, 'opportunity' language, price projections) casts an investment tint even on a token with real utility. The context of the offering is part of the substance the supervisor examines.

How to design the token to stay in utility

To stay under MiCA, your token must provide access or real use and nothing more. No investment component, no promise of gain, no economic right. Design is the defense: if the token grants no valuable right, there is no security classification to apply.

Anchor the token to a function, not a return

The token must serve a specific and present purpose: pay for a service, unlock a feature, access a network. Its value to the buyer is use, not resale. When utility is real and current, there is no expectation of return to sustain.

Remove investment language

Review every piece of communication. Out with 'profitability', 'appreciation', 'investment opportunity', 'will rise', 'ROI'. The white paper, the website, the ads and even social media messages are part of the substance. A single investment phrase can drag down the whole project.

Design the offering as a product sale

Present the token sale as you would sell a license or a subscription, not as an investment round. No discounts designed for speculators, no price projections, no promises of a liquid secondary market as a hook. You sell access, not expectation.

What it means for you: have a third party outside the project read your white paper and your website. Ask them one thing: 'would you buy this to use it or to make money?' If they answer the latter, redesign before launching.

Utility is not 'unregulated'

Avoiding security classification does not leave you in no man's land. A utility token is still a crypto-asset regulated by MiCA. You have obligations: a white paper with required content and format, notification to the CNMV and marketing communication rules. Staying in utility changes the framework, it does not eliminate it.

MiCA applies to crypto-assets that are not financial instruments (Regulation (EU) 2023/1114). A utility token falls squarely within that. That means a white paper, transparency and supervision by the CNMV as the competent authority in Spain. The difference with a security token is the framework you fall under, not the absence of a framework.

To understand why security tokens fall outside MiCA and come under the LMVSI, you have the details in why security tokens do not fall under MiCA. And if you are starting from scratch with the concept of tokenizing, start with what asset tokenization is.

Checklist: features to avoid in your utility

Review your token and your communication against this list. If you tick any, you are close to security classification:

  • You promise or suggest that the token will appreciate.
  • The token gives the right to a share of revenue or profits.
  • You commit to buying it back at an increasing price.
  • Its value is tied to your company's financial metrics.
  • The presale appeals to the investor, not the user.
  • The white paper or the website uses investment language ('ROI', 'profitability', 'opportunity').
  • The selling hook is the secondary market, not the use of the token.

Table: safe utility vs risk zone

Token featureSafe utility (MiCA)Risk zone (towards LMVSI)
What it is forReal and present access or useWait for the price to rise
Economic rightNoneProfits, credit or underlying
Promise to the buyerA specific functionAppreciation or return
BuybackNo buyback or at value in useBuyback at an increasing price
Link to the issuerIndependent of the balance sheetTied to financial metrics
How it is soldAs a product or licenseAs an investment opportunity
Framework that appliesMiCA: white paper and CNMVLMVSI + MiFID II: prospectus and CNMV

What to do now

Concrete steps to design your token outside the securities perimeter:

Frequently asked questions

Is it enough to put “utility” in the white paper to avoid being a security?

No. Substance prevails, not the label. The supervisor looks at the rights the token grants, not its commercial name (Art. 4 Directive 2014/65/EU; ESMA Guidelines ESMA75-453128700-1323). If the token promises a return, it is a security even if you call it utility.

Can I promise that my token will increase in value?

No, if you want to stay in utility. The promise or expectation of appreciation creates an expectation of return, which is what defines a security. That message, on the website or social media, pushes you toward the LMVSI.

Is it safe to distribute project revenue among holders?

Not for a utility token. Revenue sharing works like a dividend and is a typical economic right of a security. If you include it, your token stops being a utility token and becomes a security token.

Does a presale turn my token into a security?

It depends on how you structure it. A presale that appeals to the investor (early-entry discounts, price projections, opportunity language) gives the token an investment character. The context of the offering is part of the substance being assessed.

If I avoid being a security token, does that leave me unregulated?

No. A utility token is still under MiCA: white paper with required content, notification to the CNMV and marketing communication rules (Regulation (EU) 2023/1114). You switch frameworks; you do not leave regulation.

Who ultimately decides whether my token is a security?

The CNMV, as the competent authority in Spain, applying MiFID II and the ESMA Guidelines. The classification is based on the token's actual economic rights, with a technology-neutral approach (ESMA Guidelines ESMA75-453128700-1323).

Notice

Informational content. It does not constitute legal, tax or investment advice. HokenFi is a software and infrastructure provider; it does not provide regulated services. Check the current version of the rules cited in the BOE and EUR-Lex.

Cited regulations

  • Directive 2014/65/EU (MiFID II): art. 4 and Annex I, section C. CELEX 32014L0065.
  • ESMA Guidelines on the conditions and criteria for classifying crypto-assets as financial instruments: ESMA75-453128700-1323 (19/03/2025).
  • Regulation (EU) 2023/1114 (MiCA): art. 2(4). CELEX 32023R1114.
  • Ley 6/2023, de 17 de marzo, de los Mercados de Valores y de los Servicios de Inversión (LMVSI). BOE-A-2023-6536.
Get started

Do you have an asset to finance? Request your first offers.

Create your account, activate access and you will receive offers from law firms.