The MiCA transition period ended for good on July 1, 2026. Any entity providing crypto-asset services to EU clients now needs proper authorisation from a national competent authority, and there is no informal buffer left to operate in. For founders launching a token or digital asset project today, the real question isn't when to comply, but which MiCA category their token actually falls into, and whether their structure matches it.

Classification is where most founders go wrong, and it's just the start. Beyond MiCA's categories for asset-referenced tokens, e-money tokens and other crypto-assets, founders face a broader structuring puzzle: where the protocol or issuing entity sits, where distribution actually reaches, and whether "crypto-friendly" jurisdictions are being chosen on substance or on reputation alone. Get that wrong, and the gap tends to surface at the worst possible moment, a funding round or an exchange listing.

María Jose Ruiz de Olano, an Argentine lawyer based in Madrid and founder of Etherea Legal, a jurisdiction-agnostic legal consultancy advising DAOs, DeFi protocols and digital asset projects worldwide, walks through how founders should actually think about jurisdiction fit, the biggest structuring mistakes she sees in cross-border projects, and why token economics and legal structure need to be designed together rather than in sequence. Before founding Etherea Legal, she led international legal structuring and multi-jurisdictional compliance at karpatkey, working across the Cayman Islands, Dubai, Panama, Switzerland, the EU and the US.

Crypto Law Summit runs live webinar sessions with practitioners from across the digital asset legal space throughout the year, covering the regulatory questions founders are actually facing. Join us for the next session to ask questions directly.

Q: What should Web3 founders understand about MiCA compliance before launching a token or digital asset project in the EU?

The first thing founders need to understand is that MiCA is no longer a "coming regulation" to prepare for, it is fully in force. The transitional grandfathering window closed for good on 1 July 2026. Any entity providing crypto-asset services to EU clients now needs proper authorisation from a national competent authority; there is no informal buffer left to operate in. For anyone launching today, the relevant question isn't "when do we need to comply" but "which MiCA category does our token actually fall into, and does our structure match it."

That classification exercise is where founders most often go wrong. MiCA doesn't treat all tokens the same way, you can find asset-referenced tokens, e-money tokens, and the broader catch-all category of "other crypto-assets".  Each one carries different obligations around whitepapers, capital requirements, custody, and ongoing disclosure. Founders frequently design the tokenomics first and only later ask which bucket they've landed in, when it should be the other way around: token design should be informed by the regulatory consequence from day one, not retrofitted to it.

Finally, founders should understand that MiCA authorisation is not a one-off filing but an ongoing supervisory relationship. Once authorised in one member state, a CASP can passport services across the EU, which is the regulation's central promise, but that authorisation comes with continuing obligations on governance, conduct, and AML/CFT alignment. Treating MiCA as a licence to obtain rather than a compliance posture to sustain is one of the more expensive misconceptions I still see.

Q: How should companies evaluate whether a jurisdiction is truly a good fit for their token design and investor profile, beyond just being "crypto-friendly"?

"Crypto-friendly" is a buzzword, not a legal test, and founders who select a jurisdiction on that basis alone tend to discover the gap later (usually at the worst possible moment), such as a funding round or an exchange listing. The better starting question is structural: what is this token actually doing, who is it reaching, and does it need to sit inside the EU's regulatory perimeter at all, or does it interact with it from outside?  A governance token and a yield-bearing token lead to genuinely different analyses, and each one splits again depending on whether the relevant entity is based in the EU or approaching it from a third country.

For a governance token tied to a genuinely decentralised protocol, with no claim on cash flows or expectation of profit, the token itself may sit outside MiCA's CASP perimeter (the regulation targets services and issuers, not code). But if there's an identifiable entity behind it as a foundation, a development company, anyone distributing the token or managing a treasury, that entity still needs a jurisdiction.

Within the EU, Malta, the Netherlands, Ireland and France currently hold the deepest concentration of CASP authorisations and the most regulatory familiarity with crypto-native structures; Malta in particular carries over experience from its earlier VFA regime and tends to offer more predictable processing timelines. Outside the EU, the Cayman Islands and the British Virgin Islands remain the most established pairing for housing the protocol layer itself. A Cayman foundation company, increasingly the industry-standard vehicle for DAOs, holds the treasury and protocol IP without a traditional shareholder structure, while a BVI company is often used alongside it for the token issuance and sale mechanics. The combination is well understood by investors, exchanges and counsel alike, which reduces friction at listing and fundraising stages. The structure only holds up, though, if the actual interaction with EU users stays on the decentralised, protocol side of the line. MiCA does not extend any passporting to third-country entities, so the moment an identifiable non-EU entity is providing services to EU clients, it needs its own EU authorisation regardless of where the protocol itself is based.

For a yield-bearing token, the analysis shifts considerably, because an explicit return pulls the token toward e-money token or "other crypto-asset" treatment, with whitepaper, capital, and disclosure obligations attached; and the investor base becomes central. Within the EU, France and Germany have more mature regulatory experience with financial-product-style tokens and investor protection questions, which matters where distribution is retail; Luxembourg is a further option where the token resembles a structured investment product more than a purely crypto-native one. Outside the EU, jurisdictions like the UAE (VARA) or Singapore (MAS) offer sophisticated frameworks for structuring the issuing vehicle or the yield mechanism itself, but any active distribution toward EU investors (marketing, onboarding or promotion) still requires either EU CASP authorisation or an authorised EU distribution partner. The "reverse solicitation" exemption, which allows an unauthorised third-country entity to serve EU clients only where the client initiates contact entirely on their own initiative, is interpreted narrowly by regulators such as the AMF and BaFin and cannot function as a distribution strategy. Tether's continued absence from the EU's regulated market, having declined to pursue MiCA authorisation for USDT, is the clearest visible example of what happens when a globally based issuer leaves this layer unresolved.

The practical takeaway is that "jurisdiction fit" is never a single decision for either token type. It's a question of where the protocol or issuing entity sits, where the distribution actually reaches, and whether those two things are properly separated or quietly conflated.

Q: What are the biggest legal structuring mistakes you see founders make when approaching cross-border digital asset projects?

The most common mistake is sequencing: founders build the product and the token economics first, then look for legal structuring to wrap around a design that's already fixed. By that point, the range of viable structures has narrowed considerably, and what should have been a design input becomes an expensive retrofit (sometimes requiring the tokenomics themselves to be reworked).

The second is treating "jurisdiction-agnostic" or "decentralised" as a status a project can simply declare rather than one it has to demonstrate. I see founders assume that because a protocol is described as decentralised, it sits outside conventional regulatory reach, but regulators, and increasingly courts, look at substance: who controls upgrade keys, who can pause the protocol, where governance actually concentrates. A project that hasn't genuinely decentralised those functions but relies on the label is exposed precisely where it thought it was protected.

The third is underestimating coordination costs across jurisdictions. Founders will often get excellent advice in each individual jurisdiction: one lawyer for the foundation's home base, another for a subsidiary, another for a licensing question without anyone reconciling those pieces into a single coherent structure. The result is a set of locally sound decisions that don't hold together as a whole: conflicting obligations, duplicated compliance work, or gaps that only surface once a regulator or counterparty asks how the pieces actually fit.

About the Author

María Jose is an Argentine lawyer based in Madrid and the founder of Etherea Legal, a jurisdiction-agnostic legal consultancy advising DAOs, DeFi protocols, blockchain infrastructure providers, and digital asset projects on structuring, compliance, and governance. She previously led international legal structuring and multi-jurisdictional compliance at karpatkey, working across the Cayman Islands, Dubai, Panama, Switzerland, the EU, and the US, and brings a combined public and private sector background spanning litigation, corporate advisory, and institutional relations across Argentina, Chile, and Paraguay.