Securities Tokenization: The Legal Architecture
Securities tokenization in 2026 is the legal architecture that makes a distributed-ledger record correspond to a share, a note, a fund unit, or an Investment Token. The token is the record. The security is the relationship: who issued it, which register is conclusive, who holds title, how a transfer completes, which offering document was used, and who the investor sues if the chain and the books disagree. Statute wins that fight.
Digital-asset and tokenization legal support starts with that stack. A mill that promises to “tokenize stocks in ten minutes” is selling a wallet event.
What does the token represent?
A tokenized security is a financial instrument formatted as, or represented by, a crypto-asset on a blockchain or similar ledger. Investor.gov uses that wording. The SEC staff Statement on Tokenized Securities (28 January 2026) adds that stock, bond, note, and investment contract can all take that format. The format does not retire the instrument.
Issuer-sponsored: the company or its agent issues the security on the ledger. Class rights follow the documents. The investor’s claim is on the issuer. The register is the token record only if company law and offering rules accept that book.
Custodial: an intermediary holds the underlying instrument and issues a token that is a security entitlement. Rights run against the intermediary, to the extent the custody agreement and the insolvency statute say they do.
Synthetic: a third party issues a linked instrument whose price follows a referenced security. The holder has no claim on that issuer. Investor.gov states that rights may differ in material ways from those of a traditional owner. Price tracking is not title.
Medici’s note on the rose-colored glasses of tokenization draws the same cut: the token and the asset are different events. This article stays on the security.
An SPV often sits under the security. The token is then a share or a note in that vehicle. Investors sue the vehicle and its directors. The rest of SPV design is a separate problem.
Nataly Medici, Managing Partner and CEO, puts the day-one test this way: “Entering a regulated market is not just about registering a company or applying for a license. Your entity, business model, banking setup, compliance framework and jurisdictional logic must work together from day one.” A mint with no issuer logic fails that test.
Why does MiCA step aside for a tokenized security?
A tokenized share, note, or fund unit that meets the MiFID II definition of a financial instrument sits outside Markets in Crypto-Assets Regulation (EU) 2023/1114. Article 2(4)(a) states that the Regulation does not apply to crypto-assets that qualify as financial instruments. Recital 9 restates same activity, same risks, same rules. The ledger does not move the file from the securities stack into a CASP white paper. Founders who file a MiCA white paper for a transferable security have sent the wrong document to the wrong supervisor. The overlay is MiFID II, the Prospectus Regulation, CSDR, and market-abuse rules.
Article 2(4)(a) and the 2024 ESMA mandate
Article 2(5) of MiCA required ESMA, by 30 December 2024, to issue guidelines on that qualification using MiFID II Article 4(1)(15). ESMA published the Final Report on 17 December 2024 (ESMA75453128700-1323). The adopted guidelines of 19 March 2025 follow substance over form. The label, the chain, and the marketing site do not decide the file. The rights do.
Guideline 2 treats a crypto-asset as a transferable security where it is not an instrument of payment, forms part of a class of securities, and is negotiable on the capital market. Equivalent rights to shares or bonds pull the token into MiFID II Annex I, Section C. Access tokens with no dividend or coupon stay outside that box. Hybrid tokens follow the rights they confer.
The guidelines apply 60 calendar days from publication in all official EU languages. CSSF Circular 25/886 records the application date as 18 May 2025. As of August 2026 this is the working EU perimeter. Member State company law still fragments what “share” means. ESMA said so. Classification remains a case file.
The MiFID II, prospectus, and CSDR overlay
Once the token is a financial instrument, dealing, placing, advising, and operating a trading venue need MiFID II authorisation. A public offer needs a prospectus under Regulation (EU) 2017/1129 unless an Article 1(4) exemption fits. Instruments admitted to trading sit under CSDR (Regulation (EU) No 909/2014). Market-abuse duties attach to inside information and to the venue.
Regulation (EU) 2022/858, the DLT Pilot Regime, has applied since 23 March 2023 as a test bed for trading and settlement of crypto-assets that already qualify as financial instruments. Firms may operate a DLT MTF, CSDs a DLT securities settlement system, or both a combined DLT TSS. Competent authorities may grant listed exemptions from specified CSDR and MiFID provisions. The regime is optional. It does not rewrite CSDR for a private book.
Medici’s MiCA market-entry note covers CASP licensing for crypto-assets that remain inside MiCA. A tokenized security is the other door. The white paper, the capital, and the supervisor all mismatch if you walk through the CASP file.
What a CASP licence does not cover
A MiCA CASP authorisation covers crypto-asset services inside MiCA. It is not a licence to offer transferable securities to the public, to operate an MTF in financial instruments, or to run a CSD. Article 143 grandfathering, in Member States that opted in, runs until 1 July 2026 or until CASP authorisation is granted or refused. That clock does not create a holiday from prospectus law for a tokenized share.
A group that runs a crypto-asset book and a digital-securities book needs two perimeters, two application packs, and client-asset pools that do not mix. Counterparties will ask for that map before they open a rail.
How does the UAE split a tokenized security?
The UAE does not issue one crypto licence that covers a tokenized security. Dubai VARA governs virtual-asset service activity. A token that is a share, sukuk, note, or fund unit is a capital-markets instrument. Onshore, that file sits with the Securities and Commodities Authority. In the Dubai International Financial Centre it sits with the DFSA as an Investment Token. In Abu Dhabi Global Market it sits with the FSRA as a Digital Security. Each label names a DLT record of a securities right. Mix the perimeters and the application fails. Open the three live instruments below before a term sheet is signed.
Onshore SCA: security tokens, not virtual assets
On 22 January 2025 the SCA published a draft regulation on security tokens and commodity tokens and asked for comment by 14 February 2025. The live onshore instrument is Chairman’s Resolution No. (15/Chairman) of 2025, also cited as Decision No. 15/RM/2025, in force from July 2025. Open the texts on sca.gov.ae before you file. Practitioner notes that track the final text (Hadef; Lexis Middle East, 18 February 2026) describe a technology-neutral rule: a security recorded on a distributed ledger remains a security.
The decision applies to security tokens and commodity-token contracts. It excludes virtual assets, and it excludes real-world assets unless the tokenised RWA represents securities. Trading defaults to an SCA-licensed market or alternative trading facility. OTC is described as an exception through a licensed digital-wallet service provider. The issuer is responsible for ledger integrity and for telling investors what rights the token confers. A VARA VASP permission does not cover that file.
DIFC: DFSA Investment Tokens, not Crypto Tokens
The DFSA launched its Investment Token framework on 25 October 2021. GEN Rule A2.1.1 still carries the definition: an Investment is a Security or a Derivative, including a DLT token of those rights or a token with substantially similar rights or effect. An Investment Token is A2.1.1(2)(b) or (c). GEN App6 tells the applicant to name which Security or Derivative the token is.
Marketing, issuing, trading, or holding Investment Tokens in or from the DIFC, and Financial Services in those tokens, sit inside DFSA-administered law. Crypto Tokens are a different perimeter. The DFSA Crypto Token page (live August 2026) records updated rules from 12 January 2026 and firm-led suitability under GEN Rule 3A.2.1. A tokenized share is an Investment Token analysis.
ADGM: FSRA Digital Securities
The FSRA treats a digital token that exhibits the features of a Security as a Security under Schedule 1 of the Financial Services and Markets Regulations 2015 (shares, indebtedness instruments, sukuk, units in a collective investment fund, and related instruments). Section 58(2)(b) lets the FSRA deem other investments, including Digital Securities, to be Securities. The Guidance on Regulation of Digital Securities Activities in ADGM (24 February 2020, VER02.240220) remains the policy map for offers, listing, venues, Recognised Clearing Houses, and Digital Settlement Facilities. ADGM’s digital-assets page still presents Digital Securities as a separate suite from Virtual Assets.
A public Offer of Securities in or from ADGM runs through FSMR sections 58 to 71 and Markets Rules Chapter 4. Unless the offer is Exempt, the issuer needs an Approved Prospectus. The FSRA expects a Digital Securities issuer making a public offer to be incorporated in ADGM. An Exempt Offer still needs the s.58(2)(b) deeming. Exempt Offer types sit under the offering section below.
Custody and settlement of Digital Securities at a Recognised Investment Exchange may run through a Recognised Clearing House or a Digital Settlement Facility licensed for Providing Custody. A DSF may record ownership changes and maintain holder records. COBS Chapter 10: only an Authorised Person licensed for Providing Custody may act as a CSD in ADGM. Virtual Asset custody permission is not Digital Securities custody.
UAE company formation and licensing is the issuer-entity and permissions half of the same file. DIFC with a DFSA Investment Token permission, ADGM on the FSRA Digital Securities perimeter, and onshore SCA are three applications. Pick VARA for virtual-asset service, not for the security.
Who keeps the legally conclusive register?
Every tokenization deck shows a wallet balance. Courts, insolvency officers, and paying agents ask which record is conclusive as to who owns the security.
In the EU, CSDR Article 3 requires transferable securities admitted to trading or traded on trading venues to be recorded in book-entry form. A CSD operates a securities settlement system and provides at least one other core service in Annex Section A: notary (initial recording in a book-entry system) or central maintenance of securities accounts. Recital 26 is the line vendors skip. Registrars, transfer agents, and CCPs that do not operate a settlement system are not CSDs. They may keep a useful register. They are not, for CSDR instruments, the system of record.
If the issuer uses a DLT securities settlement system under the DLT Pilot, that permitted DLT SS can be the book. Exemptions are listed, time-bounded, and published by ESMA. If the DLT is a shadow copy of a conventional CSD, the statute follows the CSD. A smart-contract transfer that the CSD has not instructed is a message, not a settlement.
Private companies sit under company law and the articles. Many jurisdictions treat the statutory register of members as conclusive in the absence of rectification. A token that is not wired into that register by statute, articles, and a registrar agreement is a pointer. A permissionless transfer function that ignores pre-emption or drag creates two books. In a dispute the articles and the companies statute win.
ADGM’s DSF guidance expects the custody and settlement facility to maintain the issuer’s holder records. SCA’s 2025 decision, as described in the dual practitioner sources, assigns ledger integrity to the issuer and channels trading through licensed markets. DFSA Investment Token activity inherits DIFC register logic for the Security or Derivative the token constitutes.
Name the conclusive register in the term sheet. If you cannot name it, you have a database with a ticker.
Custody: private keys versus title to the security
Key control is safekeeping of a cryptographic secret. Title to a security is a legal relationship recorded on the conclusive register and in the custody agreement. A licensed custodian may hold keys, run a multi-party scheme, or appoint a sub-custodian. Client-asset rules of the licence (MiFID safekeeping, DFSA COB, FSRA COBS, SCA custody) decide segregation and what happens on the custodian’s failure. Self-custody, where the regime allows it, does not override transfer restrictions or an issuer register that remains authoritative.
US national banks may provide crypto-asset custody, including holding cryptographic keys. OCC Interpretive Letter 1170 (22 July 2020) said so. Interpretive Letter 1183 (7 March 2025) reaffirmed that custody and rescinded the old 1179 written non-objection gate. Holding the key is a bank-permissible safekeeping service. It is not title to the security. Title follows the register and the account agreement. That is the US-bank pointer this architecture needs.
Ksenia Babochkina, Commercial Director, has the line counterparties use: “Crypto companies don't get rejected by banks for being crypto companies. They get rejected for not being able to explain themselves clearly.”
A memo that says “the investor holds the keys, therefore the investor owns the share” fails. A memo that names the register, the custodian’s licence, the segregation clause, and the insolvency waterfall is the one a bank can file.
What offering document does a 2026 issuance need?
The chain does not invent a new exemption from securities offering law. An EU public offer of a tokenized transferable security still needs a prospectus under Regulation (EU) 2017/1129 unless an Article 1(4) exemption fits. An ADGM Offer of Digital Securities still runs through sections 58 to 71 of the Financial Services and Markets Regulations 2015 and the Markets Rules. Onshore UAE security tokens sit inside SCA capital-markets rules, including Chairman’s Resolution No. (15/Chairman) of 2025. US issuer-sponsored tokens remain securities, as the SEC staff statement of 28 January 2026 and the Investor.gov note of March 2026 both record. Name the exemption you use. Write an offering document whose rights match the register.
Prospectus and the usual exemptions
Regulation (EU) 2017/1129 Article 3(1) requires a prospectus before securities are offered to the public in the Union, subject to scope and exemptions. Article 1(4) is the working list for most private tokenized deals: qualified investors only; fewer than 150 persons per Member State other than qualified investors; denominations of at least EUR 100,000; or at least EUR 100,000 per investor per offer. Member States may set a 12-month total-consideration threshold not exceeding EUR 8 million; those offers do not receive the passport. Resale through intermediaries is a fresh offer unless an exemption still fits.
ADGM Exempt Offers are the free-zone analogue: Professional Clients other than natural persons; fewer than 50 persons in any 12-month period (excluding those Professional Clients); or total consideration of at least USD 100,000 per person. They are not a loophole for EU or US investors. A DIFC or ADGM issuer that solicits EU retail still meets EU prospectus and MiFID product-governance rules on that solicitation. A US person in the book still meets Regulation D, Regulation S, or a registered offer. The token does not carry the investor across the border.
Private placement remains a placement
A whitelist, a transfer restriction, and a “professionals only” banner are controls. They are not, by themselves, an exemption. Keep a record of who was solicited, who certified status, and which law of the offer was chosen. Secondary transfers on a permissionless pool will unwind the exemption if the resale is a public offer in a territory that cares. Tokenized listed stocks and public fund units on an exchange line add CSD and listing problems outside this issuer architecture.
What the document must say about the stack
FSRA Markets Rules Appendix 1 tells Digital Securities issuers to disclose other rights (including voting) with prominence, to avoid generic risk factors, and to state whether the issuer is an SPV for asset-backed securities. EU prospectus annexes demand the same honesty on rights, risks, and financial information. SCA’s 2025 decision, per the dual practitioner sources, requires information on the token’s rights and the ledger’s mechanics. Name the issuer, the register, the custodian, the transfer venue, lock-ups, corporate actions, the insolvency path, and the person the investor sues. A protocol white paper on block times is not that document.
Who does the investor have a claim on?
If the project fails, a regulator freezes the book, or two records disagree, the investor needs a defendant with legal personality and a duty. Planning map as of August 2026. Confirm each layer against the live instrument, the articles, the custody agreement, and the offering document before you issue.
Issuer
Typical instrument: share, note, sukuk, fund unit; DFSA Investment Token; FSRA Digital Security; SCA security token. Title or conclusive record: issuer’s statutory books, or the ledger if statute and articles accept that book. The investor sues the issuer and directors (misstatement, breach of duty).
SPV under the security
Share or note in the vehicle. SPV register / appointed registrar. The investor sues the SPV and its directors.
Conclusive register
CSDR book-entry; DLT SS (Reg. 2022/858); companies-law register of members; ADGM DSF records; SCA licensed-market record. Holder of the record: CSD, DLT SS, company/registrar, DSF, or licensed market as named. Sue the registrar/CSD for record failure; the issuer to rectify.
Shadow ledger
Unofficial token mirroring a CSD or company register. The official book holds title, not the token. Sue the operator on contract, if any; weak as title.
Custody of keys
Custody agreement; MiFID/DFSA/FSRA/SCA custody; OCC IL 1170/1183 for US bank-key safekeeping only. Custodian holds keys; title stays on the register. Sue the custodian for key loss or mixing; not a substitute for issuer liability.
Custody of title
Security entitlement; nominee account. Intermediary’s customer account. Sue the intermediary; the underlying issuer only if rights pass through.
Transfer / settlement
CSDR SSS; DLT Pilot SS/TSS; SCA market or ATS; ADGM RIE/MTF plus RCH or DSF; DFSA venue. The settlement system of record. Operator for failed settlement; counterparty for failed delivery.
Offering document
EU prospectus or Art. 1(4) pack; ADGM Approved Prospectus or Exempt Offer; SCA disclosures; US Reg D/S or registration. Disclosure, not title. Issuer, offeror, and responsible persons for untrue or omitted facts.
Trading platform
MiFID venue; CASP only if the asset is inside MiCA; VASP/VARA only for virtual-asset activity. Venue rulebook; does not replace the register. The venue for rulebook breach.
Synthetic token
Derivative or linked note (Investor.gov). Issuer of the token, not the referenced company. The token issuer; no claim on the referenced issuer.
FATF / AML overlay
Rec. 15 licensing of the VASP/CASP that operates the platform. Conduct, not title. Supervisory action against the platform; does not rewrite ownership.
Read the synthetic token twice. A token that tracks a listed stock without a claim on that issuer is a product. It is not that stock.
What does FATF Recommendation 15 add?
FATF Recommendation 15 and its Interpretive Note extend AML/CFT duties to virtual assets and VASPs: licensing or registration, supervision, customer due diligence, record-keeping, suspicious-transaction reporting, and the Travel Rule. The seventh Targeted Update (16 July 2026) records that 83 percent of surveyed jurisdictions had Travel Rule legislation, up from 73 percent in 2025, with a further 11 reporting implementation under way.
That overlay sits on the platform that deals, custodians, or transfers. It does not reclassify the security. A tokenized note can be a MiFID financial instrument while the matching venue is a VASP for FATF and a CASP or investment firm for EU law. An AML policy does not make the token a valid security.
The security needs the register, the offering document, and a defendant. The platform needs CDD and Travel Rule controls that match the territories it touches.
Who is this architecture for, and who should stop?
This stack fits a founder who can name the instrument, the issuer, the conclusive register, the custodian, the offering exemption or prospectus, and the investor claim, and who will take a DFSA, FSRA, SCA, MiFID, or equivalent permission for the activity performed.
Stop if you cannot name the register, if the token tracks someone else’s equity without that issuer’s participation, or if the only permission on the shelf is a VARA VASP or a MiCA CASP.
Before you mint, write one sentence you can defend: the token is a named security issued by a named legal person, governed by a named law, recorded on a named register. Name the supervisor for that security in each territory you will solicit. Name the exemption or prospectus, and keep the solicitation log. Name who holds keys and who holds title, and put both in the custody agreement. Name the transfer venue and the settlement system of record. Name the defendant in insolvency; if the answer is only a protocol, stop. Keep the VASP, CASP and AML file apart from the securities file, and confirm SCA, DFSA, FSRA, ESMA and CSD pages on the day you file.
FAQ
Does a token on a blockchain mean I own the security?
You own the security if the law of the issuer, the articles, and the conclusive register treat the token (or the account it represents) as the record of that security. A wallet balance that is not wired into that register is a pointer. If the chain and the statutory books disagree, the statute wins.
Is a MiCA CASP licence enough to issue a tokenized share?
No. MiCA Article 2(4)(a) excludes crypto-assets that are financial instruments. Issuing or trading a tokenized share is a MiFID II and prospectus problem, plus CSDR if admitted to trading. A CASP authorisation covers crypto-asset services inside MiCA.
What is the difference between a DFSA Investment Token and a DFSA Crypto Token?
An Investment Token is a Security or Derivative in token form, or a token with substantially similar rights or effect (GEN A2.1.1). Crypto Tokens are the DFSA’s separate perimeter, with firm-led suitability under GEN 3A from 12 January 2026. A tokenized share is an Investment Token analysis.
If I hold the private keys, do I hold title?
Key control is safekeeping. Title sits on the conclusive register and in the account documents. A licensed custodian can hold keys without owning the security. A holder can control keys and still be a mere entitlement holder, or a synthetic claimant with no rights against the referenced issuer.
Can the token avoid securities law if we only sell to a whitelist?
A whitelist is a control. EU Article 1(4), ADGM Exempt Offers, and US private-placement rules are exemptions with conditions. Secondary transfers that become a public offer will pull the exemption apart. The token does not create a new safe harbour.
Are issuer-sponsored, custodial, and synthetic tokens all “tokenized securities”?
The market uses the phrase for all three. Only the first is a direct claim on the original issuer. The second is a claim on an intermediary. The third is a separate instrument. Price correlation is not title.
