Bitcoin, Ethereum and Ripple crypto coins, security token vs utility token classification in 2026
Guides: Regulation & Classification

Security Token vs Utility Token: Regulation, Howey Test & Classification in 2026

Whether a crypto-asset is a security token or a utility token decides which regulator governs it and which licence you need. This guide explains the Howey test, how the SEC and CFTC split jurisdiction after their 2026 joint interpretation, the MiCA token categories, the MiFID II carve-out for security tokens, and the legal consequences of each classification.

Reading time~9 minutes
Last updatedJune 2026
CategoryRegulation & Classification

Meet Dr. Marcus Hartmann

Dr. Marcus Hartmann, Senior Crypto Licensing Advisor
Dr. Marcus Hartmann
Senior Licensing Advisor · Zug, Switzerland
LL.M. International Financial Law · Dr. iur. · Zurich Bar

Dr. Marcus Hartmann has spent over two decades at the intersection of financial law and emerging technology. Based in Zug, Switzerland's Crypto Valley, he advises token issuers, exchanges, and funds on whether a digital asset is a security or a utility token, the single decision that determines the licence and the regulator that will govern it.

He has prepared token classification opinions under the US Howey test, the EU MiFID II and MiCA framework, and FINMA's Swiss token taxonomy, and has guided security token offerings and utility token launches across more than 60 jurisdictions.

22 years in financial services regulation
400+ crypto licensing mandates across 60+ jurisdictions
Certified AML Officer (ACAMS), FINMA-registered
Fluent in English, German, and French
View Full Profile →
Definition · Security Token vs Utility Token

A security token is a crypto-asset that represents an investment, such as tokenized equity, debt, or a fund, and is governed by securities law. A utility token gives access to a product, service, or network function and is meant to be used rather than held for profit. The legal classification, not the marketing label, sets the rules that apply.

Key Takeaways
  • The label on a token is irrelevant; what matters is whether it legally qualifies as a security or a utility, which decides the regulator and the licence
  • In the US the test is Howey: an investment of money, in a common enterprise, with an expectation of profit from the efforts of others
  • The 2026 SEC and CFTC joint interpretation puts digital securities under the SEC and digital commodities, including Bitcoin and Ether, under the CFTC
  • Under MiCA there are three categories, asset-referenced tokens, e-money tokens, and other crypto-assets, but security tokens are carved out into MiFID II
  • A security token triggers registration, prospectus, and disclosure duties; a utility token works within the lighter crypto regime, which makes classification a licensing decision

The Core Distinction

The security token versus utility token question is the first fork in the road for any token project, and it is decided by substance, not by what the whitepaper calls the asset. A regulator looks past the name to the economic reality. If holders reasonably expect a return generated by the work of a promoter or team, the token behaves like a security and is treated as one. If holders acquire the token to use a live product or service, it behaves like a utility.

That single classification then drives everything downstream: which regulator has authority, which licence you apply for, what you must disclose, and how the token can legally be marketed and traded. Getting it wrong means applying for the wrong authorisation and facing enforcement. Our broader explainer on what crypto regulation is and how it works sets the wider context for where these rules sit.

The two leading frameworks approach the same question differently. The United States applies the judge-made Howey test and, since March 2026, a coordinated SEC and CFTC taxonomy. The European Union uses MiCA for crypto-assets that are not financial instruments, while pushing security tokens out into MiFID II. The rest of this guide works through each in turn.

4
Howey Test Prongs
1946
Howey Origin (SEC v Howey)
5
US Token Categories (2026)
18
Named Digital Commodities
3
MiCA Token Categories
Mar 2026
SEC / CFTC Joint Rule

Sources: SEC Framework for Investment Contract Analysis of Digital Assets (2019); SEC and CFTC joint interpretation of 17 March 2026; MiCA Regulation (EU) 2023/1114.

The Howey Test Explained

The Howey test comes from the 1946 US Supreme Court decision in SEC v. W.J. Howey Co. It defines an investment contract, and therefore a security, as an arrangement with four elements. There must be an investment of money, in a common enterprise, with a reasonable expectation of profits, derived from the efforts of others. If all four are present, the asset is a security under US federal law regardless of how it is packaged.

The SEC applied this test to tokens in its 2019 Framework for Investment Contract Analysis of Digital Assets, published by its FinHub innovation unit. For tokens, the first prong is almost always met, because buyers pay fiat or another digital asset for the token. The common enterprise prong is usually satisfied where investor funds are pooled and fortunes rise and fall together. The decisive question is the fourth prong: does the holder expect profit from the entrepreneurial or managerial efforts of a central team?

Factors weighing toward a security include an active development team essential to the network's success, marketing that emphasises price appreciation, a token that is not yet usable, and supply managed to support the price. Factors weighing toward a utility include a fully functional and decentralised network, a token used to access a good or service today, and pricing tied to usage rather than speculation. The framework also accepts that a token sold as a security can later cease to be one as a network matures, which is why the SEC has stated that Bitcoin and Ether are not securities.

Security Token vs Utility Token, Compared

The clearest way to see the distinction is to set the two side by side across the dimensions that actually matter for a licensing decision: the regulator, the test, the EU treatment, the type of offering, and typical examples. The table below summarises how each classification plays out in the two largest crypto markets.

Dimension Security Token Utility Token
Definition Represents an investment (equity, debt, fund) held for profit Gives access to a product, service, or network; consumed in use
US regulator SEC (digital security) CFTC if a non-security digital commodity
Howey test Meets all four prongs Fails Howey (no profit from others' efforts)
EU framework MiFID II / Prospectus Reg (carved out of MiCA) MiCA "other crypto-asset" (white paper + CASP)
Offering Security token offering (registration or exemption) Token sale under a MiCA white paper
Examples Tokenized shares, tokenized bonds, tokenized funds Network access tokens, governance and platform-utility tokens

Based on the SEC 2019 Framework, the 2026 SEC and CFTC interpretation, and MiCA Regulation (EU) 2023/1114 with the MiFID II carve-out. National rules vary.

"Founders want a definitive yes or no on whether their token is a utility, but classification is a spectrum and it moves. We ask a sharper question: at the moment of sale, does the buyer depend on your team to make the network valuable? If the answer is yes, you are issuing a security token, whatever the deck says, and you license accordingly."

Dr. Marcus Hartmann, Senior Licensing Advisor

SEC vs CFTC After the 2026 Interpretation

For years the US lacked a clear line between the Securities and Exchange Commission and the Commodity Futures Trading Commission. That changed in March 2026. The two agencies signed a memorandum of understanding on overlapping jurisdiction on 11 March 2026, and on 17 March 2026 issued a joint interpretation on the application of federal securities laws to crypto assets. Our US crypto regulation overview tracks how this fits the broader American framework.

The interpretation introduces a five-part taxonomy: digital commodities, digital collectibles, digital tools, payment stablecoins, and digital securities. Only digital securities fall fully within SEC jurisdiction and the full securities regime. The interpretation expressly named 18 major crypto assets as digital commodities, including Bitcoin, Ether, Solana, Cardano, XRP, Litecoin, and Dogecoin, placing them under CFTC oversight with lighter requirements such as reduced disclosure and simpler custody.

For token issuers the practical message is direct. A token that passes the Howey test as an investment contract is a digital security under the SEC, while a token used as a network commodity falls to the CFTC. Payment stablecoins sit in their own category, tied to compliance with the GENIUS Act enacted in July 2025. Separate market-structure legislation continued to advance through Congress during 2025 and 2026, so the boundary is still settling, but the security versus utility line is now far clearer than it was.

Why this matters for licensing: if your token is a digital security, you need securities-side authorisation and you cannot simply register as a money services business. If it is a digital commodity, the CFTC route is materially lighter. Pinning down the classification before you file is the difference between a clean application and a rejected one. See our crypto licensing overview for how token type shapes the route.

◆ Need Help?

Not sure whether your token is a security or a utility? Get a free 30-minute consultation. We will assess your token against the Howey and MiFID II tests and map it to the right licence.

Get Free Consultation →

MiCA vs MiFID II in the EU

The European Union takes a different route to the same answer. MiCA, Regulation (EU) 2023/1114, governs crypto-assets that are not financial instruments. It sorts them into three categories: asset-referenced tokens, which reference a basket or non-fiat values; e-money tokens, which are pegged to a single fiat currency; and other crypto-assets, the residual bucket that captures most utility, governance, and platform tokens. Our EU crypto regulation guide covers how MiCA licensing works in detail.

Security tokens never enter MiCA at all. Article 2(4)(a) of MiCA carves out crypto-assets that qualify as financial instruments under MiFID II, so a tokenized share or bond is regulated under MiFID II and the Prospectus Regulation, the same framework that governs traditional securities. For hybrid assets that share features with a financial instrument, the MiFID II qualification prevails over MiCA. This is the EU equivalent of the security token category.

To make the line workable, ESMA published guidelines on 19 March 2025 on when a crypto-asset qualifies as a financial instrument. For a transferable security, three cumulative criteria apply: the token is not a payment instrument, it belongs to a class of interchangeable securities issued by the same issuer, and it is negotiable on the capital market. ESMA applies a substance-over-form approach, so an asset with the economic function of a security is regulated as one. Note too that stablecoins, covered in our guide to stablecoin regulation, sit in the ART and EMT categories rather than being utility or security tokens.

Category Framework What It Covers Legal Basis
Other crypto-asset MiCA Utility, governance, platform tokens Reg. (EU) 2023/1114
E-money token (EMT) MiCA Single-fiat stablecoins Reg. (EU) 2023/1114
Asset-referenced token (ART) MiCA Basket or non-fiat stablecoins Reg. (EU) 2023/1114
Security token MiFID II Tokenized securities; carved out of MiCA Directive 2014/65/EU
From Our Practice

In our token classification work across more than 60 jurisdictions, the single most common error we correct is a project that has built its entire licensing plan around being a utility token, only for the regulator to read the same facts as a securities offering. The whitepaper promises holders a share of network revenue, or the team controls supply and markets price upside, and that is enough to tip a token from the MiCA route into the MiFID II or SEC route.

We also see the reverse: genuinely consumptive tokens that are over-classified out of caution, saddling a simple access token with a securities prospectus it never needed. The fix in both directions is the same. We prepare a written classification opinion against the Howey test and the MiFID II and ESMA criteria before launch, so the licence application and the legal position match the economic reality of the token.

Legal Consequences of Each Classification

Classification is not an academic label; it changes what you legally must do. A security token triggers the full securities regime. The offering needs registration with a regulator, a prospectus, or a valid exemption, plus investor disclosures. Trading and custody must run through licensed intermediaries, and the issuer carries anti-fraud liability. A security token offering, or STO, is the regulated counterpart to the unregistered initial coin offerings of the previous cycle.

A utility token works within the lighter crypto regime. In the EU that means publishing a MiCA white paper and operating through an authorised crypto-asset service provider rather than filing a securities prospectus. In the US a non-security commodity token answers to the CFTC rather than the SEC. The compliance burden, the cost, and the time to market are all materially lower than for a security token, which is precisely why classification is contested.

The downside of getting it wrong is severe. Issuing or trading a security token without authorisation exposes a firm to regulatory enforcement, fines, rescission claims from investors, and in some jurisdictions criminal liability. Counterparties and banks also de-risk away from projects with unresolved classification. The prudent path is to settle the classification, and the licence that follows from it, before any token reaches the market.

How to Classify a Token

Classifying a token is a structured analysis, not a guess. The five steps below describe the workflow we run before any client launches, and the same logic underpins what a regulator will expect to see in your application. Our crypto licensing service runs this end to end as part of an engagement.

1
Map the rights
Document what the token actually does
Set out the legal and economic rights the token confers: access, governance, revenue share, profit, or redemption. Substance, not the marketing label, drives every later step.
2
Apply Howey
Run the four-prong investment-contract test
Test the token against investment of money, common enterprise, expectation of profit, and reliance on the efforts of others. Focus on whether the team's work drives value.
3
Apply MiFID / MiCA
Test against the EU criteria
Check the ESMA financial-instrument criteria. If the token is a transferable security it is carved out into MiFID II; if not, place it in the right MiCA category.
4
Document the opinion
Produce a written classification opinion
Record the reasoning and conclusion in a legal opinion. This evidences your position to regulators and banks and is the foundation of the licence application.
5
License to match
Choose the authorisation that fits
Apply for securities-side authorisation for a security token or the crypto regime for a utility token, and align the offering documents with the classification.

Security vs Utility Tokens: Common Questions

A security token represents an investment, such as tokenized equity, debt, or a fund, and triggers full securities law. A utility token provides access to a product, service, or network function and is consumed rather than held for profit. The classification, not the marketing label, determines which regulator and rules apply to the token.
The Howey test comes from the 1946 US Supreme Court case SEC v. W.J. Howey Co. It asks whether an arrangement involves an investment of money, in a common enterprise, with a reasonable expectation of profits, derived from the efforts of others. If all four prongs are met, the asset is an investment contract and therefore a security.
A genuine utility token should fail the Howey test, because buyers acquire it to use a functioning network rather than to profit from the efforts of a promoter. In practice many tokens sold before the network is live fail this standard and are treated as securities at sale, even if they later become consumptive utility tokens.
On 17 March 2026 the SEC and CFTC issued a joint interpretation introducing a five-part taxonomy: digital commodities, digital collectibles, digital tools, payment stablecoins, and digital securities. Only digital securities fall fully within SEC jurisdiction. The interpretation expressly named 18 major crypto assets, including Bitcoin and Ether, as digital commodities.
The SEC regulates digital securities under the full securities regime, with registration, disclosure, and anti-fraud rules. The CFTC oversees digital commodities under the Commodity Exchange Act, with lighter requirements such as reduced disclosure and simpler custody. The 2026 SEC and CFTC memorandum of understanding coordinates this split of jurisdiction.
MiCA covers three categories: asset-referenced tokens, which reference a basket or non-fiat values; e-money tokens, which are pegged to a single fiat currency; and other crypto-assets, which is the residual category covering most utility, governance, and platform tokens. Crypto-assets that qualify as MiFID II financial instruments fall outside MiCA entirely.
No. Crypto-assets that qualify as financial instruments under MiFID II are carved out of MiCA by Article 2(4)(a). Security tokens are therefore regulated under MiFID II and the Prospectus Regulation, not MiCA. For hybrid assets that share features with a financial instrument, the MiFID II qualification prevails over the MiCA regime.
ESMA published guidelines on 19 March 2025 setting the conditions and criteria. For a transferable security, three cumulative tests apply: the token is not a payment instrument, it belongs to a class of interchangeable securities from the same issuer, and it is negotiable on the capital market. ESMA uses a substance-over-form approach.
A security token offering is the issuance and sale of tokens that qualify as securities. Because the token is a security, the offering must comply with securities law, meaning registration with a regulator, a prospectus, or a valid exemption, plus investor disclosures. An STO is the regulated counterpart to an unregistered initial coin offering.
Yes. The SEC framework accepts that a digital asset sold as part of a securities offering can later cease to be a security if the network becomes sufficiently functional and decentralised, so that profits no longer depend on the efforts of a central promoter. The SEC has stated that Bitcoin and Ether are not securities.
A security token triggers the full securities regime: registration or an exemption, prospectus and disclosure duties, licensed intermediaries for trading and custody, and anti-fraud liability. Issuing or trading a security token without authorisation exposes the firm to enforcement, fines, rescission claims, and potential criminal liability in some jurisdictions.
Usually neither. Under MiCA, fiat-pegged stablecoins are e-money tokens and basket-pegged stablecoins are asset-referenced tokens, each with their own regime. The 2026 US interpretation treats payment stablecoins as a distinct category tied to GENIUS Act compliance. They are generally not classed as utility tokens or as securities.
Yes, decisively. A security token issuer needs securities-side authorisation, such as a MiFID II investment firm permission or a securities exemption, while a utility token issuer works within MiCA or a comparable crypto regime. Misclassifying the token leads to applying for the wrong licence and a failed or delayed authorisation.
The relevant regulator in your licensing jurisdiction decides, applying its own test: the Howey analysis in the US, the MiFID II and ESMA criteria in the EU, and equivalent tests elsewhere. A legal classification opinion obtained before launch is the standard way to evidence your position and reduce regulatory risk.

Sources & Official References

MH
Senior Licensing Advisor · LL.M. International Financial Law
22 years in financial services regulation. Advised 400+ crypto licensing mandates across 60+ jurisdictions. Based in Zug, Switzerland.
Free Consultation

Classify Your Token Before You Apply

Share what your token does and where you plan to launch, and we will classify it against the Howey and MiFID II tests, recommend a licensing route, and build the framework regulators expect to see. No obligation.

  • 🇨🇭 Swiss-registered firm, Zug
  • ⚡ Response within 24 hours
  • 🔒 Strictly confidential
  • ✓ 80+ jurisdictions covered

Confidential · No obligation · No spam