
July 27, 2026
Blockchain securities are often described as conventional investments with a digital wrapper. Germany’s Electronic Securities Act, commonly known by its German abbreviation eWpG, goes further. It provides a legal route for certain securities to exist without a paper certificate, with the authoritative ownership record held in an electronic securities register. Where that register meets the statutory requirements for a crypto securities register, distributed ledger technology can become part of the security’s legal infrastructure rather than a parallel database maintained for convenience.
That distinction matters. A token can be technically transferable without being a legally recognised security, while a security can be legally valid without using blockchain at all. The eWpG connects these two layers by giving a qualifying electronic register entry consequences under German securities and property law. It does not make compliance disappear; it makes dematerialised issuance legally intelligible.
For issuers, investment firms, asset managers and tokenisation platforms, the practical question is therefore not simply whether a smart contract can mint tokens. It is whether the instrument, register, service providers, offering process and investor journey form one coherent legal system. This guide explains what the eWpG does, which blockchain securities it can support, how issuance works, and where the law’s advantages stop.
The Gesetz über elektronische Wertpapiere, or eWpG, is Germany’s Electronic Securities Act. It entered into force in June 2021 and removed the need for a physical certificate for securities within its scope. Under the current consolidated text of the eWpG, an issuer can create an electronic security by entering it in an electronic securities register instead of issuing a paper certificate.
The law was a structural reform, not a new crypto-asset regime. It modernised the legal machinery through which a security is constituted and evidenced. The investor’s claim still comes from the terms of the bond, the rights attached to a share, or the applicable fund documentation. The register replaces the certificate; it does not replace the underlying obligation.
This is why “blockchain securities” is useful shorthand but not a complete legal description. The eWpG is technology-neutral and recognises two broad register models: central registers and crypto securities registers. A crypto securities register will normally use distributed ledger technology because the law requires a system in which data is recorded chronologically and protected against unauthorised deletion and later alteration. Blockchain is a natural fit, but the statute regulates the required outcome rather than endorsing a particular network or token standard.
Traditional German securities law developed around the idea that an enforceable security was embodied in a physical certificate. Capital markets had already made that certificate practically invisible through global notes, central securities depositories and book-entry custody, but the legal architecture remained tied to paper. Market infrastructure had become digital while the law still treated a document in a vault as the anchor.
The eWpG removed that mismatch for covered instruments. Section 2 treats an electronic security as having the same legal effect as a security issued by certificate, and German law applies a statutory property-law fiction to it. This gives the electronic entry a role that a spreadsheet record or conventional database token does not automatically possess.
The reform is less dramatic than “code replaces law,” but far more useful. Capital markets rarely need law to disappear; they need law to recognise better infrastructure. The eWpG turns dematerialisation from an operational shortcut into an express legal option.
The eWpG began with bearer bonds and was subsequently expanded. Its current scope covers bearer bonds, registered shares, and bearer shares entered in a central register. The distinction for shares is important: registered shares can use the crypto securities register route when the corporate-law requirements are satisfied, while bearer shares are limited to the central-register route. Issuers must examine the company’s articles, the German Stock Corporation Act and the eWpG together rather than assuming every digital share can use the same infrastructure.
Certain investment fund units can also be issued electronically through the German Investment Code and the related crypto fund-unit framework. The legal route for fund units therefore involves the KAGB and the Crypto Fund Unit Regulation in addition to relevant eWpG concepts. Calling every fund token an “eWpG security” can obscure these cross-references and the separate regulatory obligations of the fund and its service providers.
In practice, debt remains one of the clearest applications. A company can issue a conventional fixed-rate bond, profit-participating note or other qualifying bearer debt security without a paper certificate and have it entered in an electronic register. The economic terms may be traditional; the issuance and ownership infrastructure is digital.
The eWpG is not a universal statute for tokenising every asset or contractual claim. A token representing a loan participation, limited partnership interest, receivable, commodity entitlement or revenue-sharing arrangement does not enter the eWpG merely because it is recorded on a blockchain. The legal classification of the underlying instrument must be established first.
Nor does the Act convert a utility token into a security. The ESMA guidelines on classifying crypto-assets as financial instruments require a substance-over-form and technology-neutral analysis. A transferable token with rights equivalent to shares, bonds or other securities may qualify as a financial instrument regardless of its label. Conversely, a token does not become a transferable security merely because an issuer calls it one.
The order of analysis matters: define the investor’s legal rights, classify the instrument, determine the applicable issuance law, and only then select the register and blockchain architecture. Starting with a token standard and reverse-engineering the legal rights later is how apparently elegant platforms accumulate expensive legal ambiguity.
An eWpG blockchain security has three connected layers. The first is the instrument: the bond, share or other covered security and the rights it gives investors. The second is the authoritative electronic register that legally records the issue and, depending on the entry model, its holders. The third is the technical system used to operate that register, which may include a blockchain, smart contracts, identity controls and interfaces with custody and payment systems.
These layers should agree, but they are not interchangeable. The smart contract may automate transfers or corporate actions, yet the issuance terms determine payment obligations and investor rights. The register provides the legally relevant record, while the user interface merely displays information taken from it. If an interface, wallet balance and authoritative register disagree, the project needs clear reconciliation and correction rules.
The strongest structures therefore treat the token as part of a controlled securities lifecycle. Minting, allocation, transfer, interest or dividend processing, redemption, cancellation and register updates are designed together. “Tokenisation” is not the minting event; it is the operating model that survives every event after minting.
A central-register security is entered in a register maintained within regulated centralised market infrastructure. The model is close to familiar book-entry securities and can integrate with collective custody and established settlement systems. It offers a relatively direct bridge to existing intermediaries, which is valuable when an issuer wants digital issuance without redesigning the entire custody chain.
The underlying system can still be technologically advanced, but legal and operational control remains centralised. For widely distributed instruments, exchange trading or integration with conventional securities accounts, this model may be more practical than a wallet-based structure. Innovation is not measured by how many intermediaries are removed; it is measured by whether the chosen infrastructure makes the instrument safer and easier to operate.
A crypto security is an electronic security entered in a crypto securities register. Under the eWpG, that register must use a tamper-resistant recording system in which data is logged chronologically and protected against unauthorised deletion and subsequent modification. DLT can satisfy that architecture by distributing validated records across controlled network participants, although the legal requirements extend well beyond running a blockchain node.
The register must contain prescribed information about the issue and ownership structure. Depending on the instrument and entry model, this includes the security’s essential rights, issue volume, denomination or number of units, issuer, holder, restrictions on disposal and third-party rights. The system must support accurate updates and give entitled parties appropriate access to information.
Maintaining a crypto securities register is a regulated activity requiring the appropriate BaFin authorisation. BaFin’s authorisation information for crypto securities registrars makes clear that applicants must demonstrate compliance with both the eWpG and its implementing regulation. An issuer cannot avoid the regulated registrar function by describing a public blockchain as self-administering.
The eWpG accommodates collective entry and individual entry structures. In a collective model, a securities depository or custodian is entered as the holder for an issue or part of it, while investors hold beneficial positions through securities accounts. This preserves familiar custody chains and can make integration with banks and market infrastructure easier.
Individual entry can record a specific investor as the holder in the electronic register. That opens the door to more direct ownership models, but it does not eliminate the need for identity, wallet recovery, succession, sanctions screening, data protection and legally valid transfer instructions. Direct entry moves responsibilities; it does not make them disappear.
The choice affects far more than database design. It influences custody, insolvency analysis, investor onboarding, transfer formalities, reconciliation, corporate actions and the user experience. Issuers should make it during legal structuring, not after a token contract has already been deployed.
A successful issuance starts with the instrument, not the chain. The issuer must determine what investors are buying, how returns are calculated, when redemption occurs, what security or subordination applies, and which events can modify the terms. Those commercial decisions drive the legal classification, disclosures and technical lifecycle.
The following sequence is a practical model rather than a substitute for transaction-specific advice:
The sequence looks longer than “mint and distribute” because a security is a long-lived legal product. A two-minute transaction can create a ten-year servicing obligation. The best issuance architecture is the one that remains boringly reliable throughout those ten years.
The eWpG supplies the statutory architecture, while the Regulation on Requirements for Electronic Securities Registers, known as the eWpRV, adds operational detail. It entered into force in October 2022 and addresses documentation, identity checks, register information, technical descriptions, integrity and business-continuity expectations. The combination is important because a broad statutory requirement for a tamper-resistant register is not enough to run one safely.
As explained in a detailed analysis of the eWpRV’s register requirements, a registrar may need to provide regulators with intelligible information about source code, consensus rules and the division between on-chain and off-chain storage. The regulation also addresses exportability so register data can be moved when systems fail or a provider changes.
This is a useful antidote to a common blockchain assumption: immutability does not equal operational resilience. A ledger can be difficult to alter while its interfaces, key-management process or operator remain fragile. The eWpRV focuses attention on the whole system, including who can instruct changes, how identity is checked, what information is retained, and whether the register can continue through disruption.
The eWpG answers a securities-law question about how certain German electronic securities can be issued and registered. MiFID II answers questions about financial-instrument classification, investment services, trading and investor protection. MiCA regulates crypto-assets that are not already financial instruments and the services connected with them. These regimes can touch the same technology without governing the same legal issue.
ESMA’s classification guidelines state that tokenised financial instruments remain financial instruments for regulatory purposes. If a blockchain token confers rights equivalent to a transferable bond or share and meets the relevant criteria, technology does not move it into MiCA. The principle is simple: the legal substance of the instrument outranks the vocabulary used in its marketing.
MiCA can still matter around an eWpG project. A settlement asset may be a regulated e-money token, a wallet provider may offer separate crypto-asset services, or the wider platform may support non-security tokens. Each service needs its own perimeter analysis. One blockchain stack can contain both MiFID financial instruments and MiCA crypto-assets, but they should not be treated as one undifferentiated product category.
An electronic security may still require an approved prospectus for a public offer or admission to trading unless an exemption applies. A retail product may require a PRIIPs KID. Marketing and distribution may trigger MiFID II governance, target-market, appropriateness, suitability, inducement and communications requirements. AML, sanctions, GDPR and consumer-protection rules remain relevant to the investor journey.
The eWpG also does not create secondary liquidity. A technically transferable token needs eligible buyers, compliant transfer processes, custody support and an appropriate trading or bilateral execution model. If trading occurs through regulated DLT market infrastructure, the EU DLT Pilot Regime addresses market-infrastructure questions that the eWpG does not.
This is the contrarian but commercially useful conclusion: the eWpG is valuable because it does one job well. It gives electronic securities a credible issuance and ownership foundation. Asking it to solve prospectus, distribution, custody, trading and liquidity at once only produces poor structuring.
A generic security token can represent rights under a contract without being the legally constitutive record of the security. The token may function as a digital receipt, access key or transfer instruction, while the authoritative register remains elsewhere. Such a structure can be valid, but investors and operators must understand which record prevails.
For an eWpG crypto security, entry in the qualifying register is part of the statutory issuance mechanism. The register is not merely evidence generated after the legal instrument exists in another form. This provides stronger alignment between the digital record and the legal security, subject to compliance with the Act.
That difference affects due diligence. Investors should ask whether the token itself is integrated with the legally authoritative register, who maintains that register, what happens if keys are lost, how errors are corrected, and how an insolvency of the issuer or technology provider would affect access. “On-chain” is a description of location; it is not an answer to any of those questions.
The most direct benefit is the removal of the physical certificate. Issuers can create qualifying securities through a register entry and design issuance, allocation and lifecycle processes around structured digital data. This can reduce document handling and make ownership information easier to reconcile across authorised participants.
Native digital issuance also creates a cleaner foundation for automation. Interest calculations, payment notices, voting, consent solicitations, transfer controls and redemption instructions can be connected to the register. Automation should execute the legal terms, not rewrite them, but that still represents a meaningful operational improvement.
A well-designed register gives issuers and authorised service providers a timely view of outstanding units, holders or custody positions, restrictions and transaction history. That can reduce breaks between an issuer’s records, a paying agent and intermediaries. It may also improve the evidence available for audits and corporate actions.
Transparency must be calibrated against privacy. Publicly exposing investor identities or transaction details would create legal and commercial problems. Mature structures separate public verification from confidential holder data, using permissioning and off-chain storage where appropriate.
Electronic securities can support fractional denominations and controlled transfers between verified investors. For private markets, that may reduce minimum ticket sizes and make periodic liquidity windows operationally feasible. For institutional markets, integration with existing custody and settlement remains more important than a consumer wallet.
Broader technical access does not mean unrestricted legal access. An issuer still needs a defined target market, compliant distribution channels and controls that prevent ineligible transfers. The real opportunity is not borderless selling; it is making regulated distribution less fragmented.
The first risk is selecting the eWpG before confirming that the instrument falls within its scope. A tokenised contractual claim can look like a bond economically while failing to meet the necessary legal characteristics. Cross-border issuers also need careful governing-law analysis because the eWpG is rooted in German securities and property law.
Projects should document why the instrument qualifies, which law governs its creation and transfer, and how foreign investors or courts will recognise the resulting position. Legal certainty is not achieved by citing the eWpG in a white paper; it is achieved by connecting every transaction document to the statutory mechanics.
A crypto securities registrar performs a critical regulated function. An issuer depends on its operational resilience, permissions, key management, data quality and ability to migrate the register. Smart-contract audits help, but they do not assess governance, staffing, change management or financial continuity.
Issuers should perform due diligence comparable to the review of a custodian or paying agent. Service-level agreements, incident response, data export, handover assistance, liability allocation and termination support are commercial terms with legal consequences.
Tokenisation can make a security transferable without making it liquid. Liquidity requires demand, credible valuation, continuous information, executable settlement and an appropriate venue or counterparty network. A wallet-to-wallet transfer function is not a secondary market.
This is especially important for retail communications. Issuers should not present blockchain as a guarantee of exit, continuous pricing or lower risk. Controlled transferability can improve optionality, but private-market securities may remain illiquid for their entire term.
Different registers, token standards, wallet systems and custody providers can recreate the silos that tokenisation was supposed to remove. The German market has been working on technical standards for token-based crypto securities, but practical interoperability still requires commercial adoption and common processes. A token that cannot move into an investor’s preferred custody environment may be legally valid and commercially inconvenient.
The current policy debate reflects these limitations. Five years after enactment, Germany began evaluating the eWpG’s practical operation, with market participants calling for clearer cross-border treatment, greater standardisation and more efficient rules. A 2026 Deutsche Börse response to the eWpG evaluation supports the framework while identifying areas where international reach and operational rules could improve.
The law’s development shows a deliberate, staged approach. Germany began with electronic bearer bonds in 2021, added detailed register requirements through the eWpRV in 2022, and expanded the framework to electronic shares through the Future Financing Act. Further changes under the 2026 Location Promotion Act reduced administrative requirements, including the former statutory public-list mechanism for crypto securities.
That last point matters for anyone relying on older explainers. A BaFin crypto securities list was previously linked to section 20 eWpG, but the statutory provision was repealed in February 2026. The parliamentary record for the Location Promotion Act should be read alongside the current consolidated eWpG when assessing present notification and publication duties.
The broader direction remains clear: Germany is moving from legally recognised electronic debt toward a fuller digital capital-markets framework. The unresolved question is not whether securities can be digital. It is how national register laws, EU market infrastructure, custody and cross-border distribution can interoperate without rebuilding twenty-seven separate digital islands.
The eWpG is a strong candidate when an issuer wants a qualifying German electronic security, values a legally native digital register, and can assemble the required regulated service-provider stack. It is particularly compelling where ongoing ownership updates, controlled transfers and automated lifecycle events justify the additional structuring work.
A central-register route may fit issuers prioritising compatibility with established securities accounts and institutional settlement. A crypto-register route may fit private-market or digital-native issuance where individual entry, programmable controls and DLT-based workflows add material value. The decision should follow the investor and operating model rather than a preference for decentralisation.
The eWpG may be less attractive where the instrument falls outside its scope, the issuer needs another jurisdiction’s company or securities law, the distribution is very small, or a conventional note programme already provides efficient infrastructure. Tokenisation is not a virtue in isolation. If the digital register does not improve issuance, servicing, governance or access, it is probably decorative technology.
If those answers are clear, the blockchain implementation becomes considerably easier. If they are unclear, a smart contract will only automate the uncertainty.
The next phase of the eWpG will be less about proving that a bond can exist without paper and more about making electronic securities portable across institutions and borders. Standardised issue data, interoperable registers, custody connectivity and machine-readable terms could turn today’s bespoke projects into repeatable capital-markets infrastructure.
European policy will shape that evolution. MiFID II already treats financial instruments issued through DLT as financial instruments, the DLT Pilot Regime gives regulated market infrastructures space to test new models, and ESMA’s classification guidance reinforces technological neutrality. National issuance law and EU market rules are slowly learning to speak the same language.
The likely winner is not a fully decentralised market with no accountable operators. It is a market where regulated responsibilities are clear, ownership records are resilient, and software removes repetitive friction. The eWpG’s deeper contribution is showing that blockchain securities can be legally conventional and operationally modern at the same time.
So, what is the eWpG? It is Germany’s legal framework for issuing specified securities electronically, without a physical certificate, through an authoritative electronic register. For blockchain securities entered in a crypto securities register, it gives DLT-based records a defined role in the legal creation, ownership and transfer architecture of the instrument.
Its value lies in precision. The eWpG does not legalise every token, replace financial regulation or manufacture liquidity. It connects a qualifying security to a regulated digital register while allowing prospectus, MiFID, PRIIPs, custody, AML and market rules to continue doing their respective jobs.
For serious issuers, that is a feature rather than a limitation. Capital markets scale when law, operations and technology reinforce one another. The eWpG provides one of Europe’s clearest examples of how that alignment can work.
If you are considering launching a tokenised investment product, speak with Lympid.
Lympid is the best tokenization solution availlable and provides end-to-end tokenization-as-a-service for issuers who want to raise capital or distribute investment products across the EU, without having to build the legal, operational, and on-chain stack themselves. On the structuring side, Lympid helps design the instrument (equity, debt/notes, profit-participation, fund-like products, securitization/SPV set-ups), prepares the distribution-ready documentation package (incl. PRIIPs/KID where required), and aligns the workflow with EU securities rules (MiFID distribution model via licensed partners / tied-agent rails, plus AML/KYC/KYB and investor suitability/appropriateness where applicable). On the technology side, Lympid issues and manages the token representation (multi-chain support, corporate actions, transfers/allowlists, investor registers/allocations), provides compliant investor onboarding and whitelabel front-ends or APIs, and integrates payments so investors can subscribe via SEPA/SWIFT and stablecoins, with the right reconciliation and reporting layer for the issuer and for downstream compliance needs.The benefit is a single, pragmatic solution that turns traditionally “slow and bespoke” capital raising into a repeatable, scalable distribution machine: faster time-to-market, lower operational friction, and a cleaner cross-border path to EU investors because the product, marketing flow, and custody/settlement assumptions are designed around regulated distribution from day one. Tokenization adds real utility on top: configurable transfer rules (e.g., private placement vs broader distribution), programmable lifecycle management (interest/profit payments, redemption, conversions), and a foundation for secondary liquidity options when feasible, while still keeping the legal reality of the instrument and investor protections intact. For issuers, that means a broader investor reach, better transparency and reporting, and fewer moving parts; for investors, it means clearer disclosures, smoother onboarding, and a more accessible investment experience, without sacrificing the compliance perimeter that serious offerings need in Europe.