Meet Dr. Marcus Hartmann
Dr. Marcus Hartmann has spent over two decades at the intersection of financial law and emerging technology. Based in Zug, Switzerland's Crypto Valley, he advises token issuers, exchanges, and funds on whether a digital asset is a security or a utility token, the single decision that determines the licence and the regulator that will govern it.
He has prepared token classification opinions under the US Howey test, the EU MiFID II and MiCA framework, and FINMA's Swiss token taxonomy, and has guided security token offerings and utility token launches across more than 60 jurisdictions.
A security token is a crypto-asset that represents an investment, such as tokenized equity, debt, or a fund, and is governed by securities law. A utility token gives access to a product, service, or network function and is meant to be used rather than held for profit. The legal classification, not the marketing label, sets the rules that apply.
- The label on a token is irrelevant; what matters is whether it legally qualifies as a security or a utility, which decides the regulator and the licence
- In the US the test is Howey: an investment of money, in a common enterprise, with an expectation of profit from the efforts of others
- The 2026 SEC and CFTC joint interpretation puts digital securities under the SEC and digital commodities, including Bitcoin and Ether, under the CFTC
- Under MiCA there are three categories, asset-referenced tokens, e-money tokens, and other crypto-assets, but security tokens are carved out into MiFID II
- A security token triggers registration, prospectus, and disclosure duties; a utility token works within the lighter crypto regime, which makes classification a licensing decision
The Core Distinction
The security token versus utility token question is the first fork in the road for any token project, and it is decided by substance, not by what the whitepaper calls the asset. A regulator looks past the name to the economic reality. If holders reasonably expect a return generated by the work of a promoter or team, the token behaves like a security and is treated as one. If holders acquire the token to use a live product or service, it behaves like a utility.
That single classification then drives everything downstream: which regulator has authority, which licence you apply for, what you must disclose, and how the token can legally be marketed and traded. Getting it wrong means applying for the wrong authorisation and facing enforcement. Our broader explainer on what crypto regulation is and how it works sets the wider context for where these rules sit.
The two leading frameworks approach the same question differently. The United States applies the judge-made Howey test and, since March 2026, a coordinated SEC and CFTC taxonomy. The European Union uses MiCA for crypto-assets that are not financial instruments, while pushing security tokens out into MiFID II. The rest of this guide works through each in turn.
Sources: SEC Framework for Investment Contract Analysis of Digital Assets (2019); SEC and CFTC joint interpretation of 17 March 2026; MiCA Regulation (EU) 2023/1114.
The Howey Test Explained
The Howey test comes from the 1946 US Supreme Court decision in SEC v. W.J. Howey Co. It defines an investment contract, and therefore a security, as an arrangement with four elements. There must be an investment of money, in a common enterprise, with a reasonable expectation of profits, derived from the efforts of others. If all four are present, the asset is a security under US federal law regardless of how it is packaged.
The SEC applied this test to tokens in its 2019 Framework for Investment Contract Analysis of Digital Assets, published by its FinHub innovation unit. For tokens, the first prong is almost always met, because buyers pay fiat or another digital asset for the token. The common enterprise prong is usually satisfied where investor funds are pooled and fortunes rise and fall together. The decisive question is the fourth prong: does the holder expect profit from the entrepreneurial or managerial efforts of a central team?
Factors weighing toward a security include an active development team essential to the network's success, marketing that emphasises price appreciation, a token that is not yet usable, and supply managed to support the price. Factors weighing toward a utility include a fully functional and decentralised network, a token used to access a good or service today, and pricing tied to usage rather than speculation. The framework also accepts that a token sold as a security can later cease to be one as a network matures, which is why the SEC has stated that Bitcoin and Ether are not securities.
Security Token vs Utility Token, Compared
The clearest way to see the distinction is to set the two side by side across the dimensions that actually matter for a licensing decision: the regulator, the test, the EU treatment, the type of offering, and typical examples. The table below summarises how each classification plays out in the two largest crypto markets.
| Dimension | Security Token | Utility Token |
|---|---|---|
| Definition | Represents an investment (equity, debt, fund) held for profit | Gives access to a product, service, or network; consumed in use |
| US regulator | SEC (digital security) | CFTC if a non-security digital commodity |
| Howey test | Meets all four prongs | Fails Howey (no profit from others' efforts) |
| EU framework | MiFID II / Prospectus Reg (carved out of MiCA) | MiCA "other crypto-asset" (white paper + CASP) |
| Offering | Security token offering (registration or exemption) | Token sale under a MiCA white paper |
| Examples | Tokenized shares, tokenized bonds, tokenized funds | Network access tokens, governance and platform-utility tokens |
Based on the SEC 2019 Framework, the 2026 SEC and CFTC interpretation, and MiCA Regulation (EU) 2023/1114 with the MiFID II carve-out. National rules vary.
"Founders want a definitive yes or no on whether their token is a utility, but classification is a spectrum and it moves. We ask a sharper question: at the moment of sale, does the buyer depend on your team to make the network valuable? If the answer is yes, you are issuing a security token, whatever the deck says, and you license accordingly."
Dr. Marcus Hartmann, Senior Licensing Advisor
SEC vs CFTC After the 2026 Interpretation
For years the US lacked a clear line between the Securities and Exchange Commission and the Commodity Futures Trading Commission. That changed in March 2026. The two agencies signed a memorandum of understanding on overlapping jurisdiction on 11 March 2026, and on 17 March 2026 issued a joint interpretation on the application of federal securities laws to crypto assets. Our US crypto regulation overview tracks how this fits the broader American framework.
The interpretation introduces a five-part taxonomy: digital commodities, digital collectibles, digital tools, payment stablecoins, and digital securities. Only digital securities fall fully within SEC jurisdiction and the full securities regime. The interpretation expressly named 18 major crypto assets as digital commodities, including Bitcoin, Ether, Solana, Cardano, XRP, Litecoin, and Dogecoin, placing them under CFTC oversight with lighter requirements such as reduced disclosure and simpler custody.
For token issuers the practical message is direct. A token that passes the Howey test as an investment contract is a digital security under the SEC, while a token used as a network commodity falls to the CFTC. Payment stablecoins sit in their own category, tied to compliance with the GENIUS Act enacted in July 2025. Separate market-structure legislation continued to advance through Congress during 2025 and 2026, so the boundary is still settling, but the security versus utility line is now far clearer than it was.
Why this matters for licensing: if your token is a digital security, you need securities-side authorisation and you cannot simply register as a money services business. If it is a digital commodity, the CFTC route is materially lighter. Pinning down the classification before you file is the difference between a clean application and a rejected one. See our crypto licensing overview for how token type shapes the route.
Not sure whether your token is a security or a utility? Get a free 30-minute consultation. We will assess your token against the Howey and MiFID II tests and map it to the right licence.
Get Free Consultation →MiCA vs MiFID II in the EU
The European Union takes a different route to the same answer. MiCA, Regulation (EU) 2023/1114, governs crypto-assets that are not financial instruments. It sorts them into three categories: asset-referenced tokens, which reference a basket or non-fiat values; e-money tokens, which are pegged to a single fiat currency; and other crypto-assets, the residual bucket that captures most utility, governance, and platform tokens. Our EU crypto regulation guide covers how MiCA licensing works in detail.
Security tokens never enter MiCA at all. Article 2(4)(a) of MiCA carves out crypto-assets that qualify as financial instruments under MiFID II, so a tokenized share or bond is regulated under MiFID II and the Prospectus Regulation, the same framework that governs traditional securities. For hybrid assets that share features with a financial instrument, the MiFID II qualification prevails over MiCA. This is the EU equivalent of the security token category.
To make the line workable, ESMA published guidelines on 19 March 2025 on when a crypto-asset qualifies as a financial instrument. For a transferable security, three cumulative criteria apply: the token is not a payment instrument, it belongs to a class of interchangeable securities issued by the same issuer, and it is negotiable on the capital market. ESMA applies a substance-over-form approach, so an asset with the economic function of a security is regulated as one. Note too that stablecoins, covered in our guide to stablecoin regulation, sit in the ART and EMT categories rather than being utility or security tokens.
| Category | Framework | What It Covers | Legal Basis |
|---|---|---|---|
| Other crypto-asset | MiCA | Utility, governance, platform tokens | Reg. (EU) 2023/1114 |
| E-money token (EMT) | MiCA | Single-fiat stablecoins | Reg. (EU) 2023/1114 |
| Asset-referenced token (ART) | MiCA | Basket or non-fiat stablecoins | Reg. (EU) 2023/1114 |
| Security token | MiFID II | Tokenized securities; carved out of MiCA | Directive 2014/65/EU |
In our token classification work across more than 60 jurisdictions, the single most common error we correct is a project that has built its entire licensing plan around being a utility token, only for the regulator to read the same facts as a securities offering. The whitepaper promises holders a share of network revenue, or the team controls supply and markets price upside, and that is enough to tip a token from the MiCA route into the MiFID II or SEC route.
We also see the reverse: genuinely consumptive tokens that are over-classified out of caution, saddling a simple access token with a securities prospectus it never needed. The fix in both directions is the same. We prepare a written classification opinion against the Howey test and the MiFID II and ESMA criteria before launch, so the licence application and the legal position match the economic reality of the token.
Legal Consequences of Each Classification
Classification is not an academic label; it changes what you legally must do. A security token triggers the full securities regime. The offering needs registration with a regulator, a prospectus, or a valid exemption, plus investor disclosures. Trading and custody must run through licensed intermediaries, and the issuer carries anti-fraud liability. A security token offering, or STO, is the regulated counterpart to the unregistered initial coin offerings of the previous cycle.
A utility token works within the lighter crypto regime. In the EU that means publishing a MiCA white paper and operating through an authorised crypto-asset service provider rather than filing a securities prospectus. In the US a non-security commodity token answers to the CFTC rather than the SEC. The compliance burden, the cost, and the time to market are all materially lower than for a security token, which is precisely why classification is contested.
The downside of getting it wrong is severe. Issuing or trading a security token without authorisation exposes a firm to regulatory enforcement, fines, rescission claims from investors, and in some jurisdictions criminal liability. Counterparties and banks also de-risk away from projects with unresolved classification. The prudent path is to settle the classification, and the licence that follows from it, before any token reaches the market.
How to Classify a Token
Classifying a token is a structured analysis, not a guess. The five steps below describe the workflow we run before any client launches, and the same logic underpins what a regulator will expect to see in your application. Our crypto licensing service runs this end to end as part of an engagement.
Security vs Utility Tokens: Common Questions
Sources & Official References
- SEC: Framework for "Investment Contract" Analysis of Digital Assets (2019)
- SEC: Statement on the Framework for Investment Contract Analysis of Digital Assets
- SEC: SEC and CFTC Clarify the Application of Federal Securities Laws to Crypto Assets (March 2026)
- ESMA: Markets in Crypto-Assets Regulation (MiCA)
- ESMA: Guidelines on the Qualification of Crypto-Assets as Financial Instruments (19 March 2025)
- EUR-Lex: Regulation (EU) 2023/1114 (Markets in Crypto-Assets, MiCA)
- EUR-Lex: Directive 2014/65/EU (MiFID II)