What Is a Security Token Offering (STO)? Process and Regulation
A security token offering (STO) raises capital by issuing tokens that represent a security. How an STO differs from an ICO, and which SEC rules apply.

A security token offering (STO) is a regulated fundraising process in which a company sells blockchain-based tokens that represent a security: an equity stake, a debt claim, or a right to profit or revenue. The offering runs under a securities exemption or a registration, not as an open public sale. Founders run an STO when the token they are issuing counts as a security under the Howey test and they want to raise capital through a compliant structure rather than an unregistered one.
An STO is a fundraising and compliance structure. It is not a substitute for a business with a real product or revenue model underneath. The token is the instrument. The business is what gives it value, and a security token offering that raises against a thin business is still a thin business with tokens attached.
#What a Security Token Offering Actually Is
A security token offering pairs two things: a securities offering and a blockchain-based token used as the instrument. The token is the wrapper. The underlying legal claim, the equity, the debt, the revenue share, or another investment contract, is what triggers securities treatment.
It helps to separate two terms that get used interchangeably. A security token is the asset: a token built to carry compliance rules, ownership records, and transfer restrictions. A security token offering is the event that issues that asset and raises the capital. One is the instrument. The other is the transaction that sells it.
Whether an offering counts as a security token offering in the first place comes down to the Howey test, the framework courts and regulators apply to decide if an arrangement is an investment contract. We cover that test in the regulatory section below. For now the point is narrow: if the token is a security, selling it is a regulated token sale, and the STO is the structure that keeps that sale inside a securities framework.
#STO vs ICO: Key Differences
An initial coin offering (ICO) and a security token offering answer the same question, how to raise capital by issuing a token, from opposite starting points. An ICO historically issued a utility token with little or no securities analysis attached. An STO issues a security token and is built around a securities exemption from day one.
| Dimension | ICO | STO |
|---|---|---|
| What is offered | Utility token, typically with no securities exemption claimed | Security token, offered under a securities exemption or registration |
| Regulatory posture | Historically offered with minimal securities analysis | Structured around Reg D, Reg A+, or Reg S |
| Investor eligibility | Often open to any purchaser | Frequently restricted to accredited or qualified investors |
| Disclosure | Typically a whitepaper, no mandated format | Offering documents shaped by the exemption's disclosure rules |
| Regulatory history | Multiple ICOs became subjects of SEC enforcement in the 2017 to 2019 period | Designed from the outset to fit an existing securities framework |
The tradeoff here is not which one wins. It is process and cost against regulatory durability. A security token offering carries legal, disclosure, and exemption-compliance overhead that an unregistered ICO does not. In exchange, its structure is built to answer the classification question up front rather than after the fact. Which side of that tradeoff fits depends on whether the token is a security, and that is a fact-specific question for your legal team.
#Regulatory Frameworks That Apply to a Security Token Offering
Four frameworks do the work in a US security token offering. Three are exemptions that let you offer securities without a full public registration. One is the test that decides whether you need them at all.
The Howey test is the starting point. It asks whether there is an investment of money, in a common enterprise, with an expectation of profit derived from the efforts of others. When an arrangement meets those elements, it is an investment contract, and the token that represents it is treated as a security. The test is the framework regulators and courts apply. It does not, on its own, declare that a specific token is or is not a security. That remains a fact-specific, jurisdiction-specific question.
Regulation D is the private-placement exemption commonly used for an STO. Under Rule 506(b), you raise from accredited investors without general solicitation. Under Rule 506(c), you can advertise the raise, but you have to verify that every investor is accredited. Reg D restricts the investor pool to accredited investors, which narrows reach and reduces the disclosure burden relative to a registered public offering.
Regulation A+, sometimes called a mini-IPO, lets you offer to non-accredited investors up to defined annual caps. It requires SEC qualification and ongoing reporting. The tradeoff runs the other way from Reg D: a wider investor pool in exchange for a heavier qualification and reporting load. Regulation S covers offerings made entirely outside the United States to non-US persons, and projects often layer Reg S alongside Reg D to run a combined US and international raise from one structure.
None of these frameworks makes a token compliant on its own. They set the conditions an offering has to meet. Whether a given structure actually fits an exemption is your legal team's call, applied to your facts and your jurisdiction. Getting the surrounding documentation in order is what makes that review faster, and that is the work we treat as tokenomics compliance.
#The STO Issuance Process, Step by Step
The mechanics of a security token offering follow a consistent sequence. The order matters, because the early steps constrain the later ones.
- Determine securities status. Run the Howey analysis, typically with securities counsel, before you structure anything. This decision drives every step that follows.
- Select the exemption or registration path. Reg D, Reg A+, Reg S, or a combination, chosen against your target investor base and the jurisdictions you are raising in.
- Draft the offering documents. A private placement memorandum or an offering circular, depending on the exemption, disclosing the business, the use of proceeds, and the risk factors.
- Select and implement the token standard. The standard that enforces your offering's compliance rules on-chain, transfer restrictions and whitelisting, is chosen here. We cover the specific standards below.
- Verify investors. Accreditation checks and KYC/AML appropriate to the exemption you selected.
- Execute the offering. Run the raise and close the round on the terms in the offering documents.
- Meet ongoing obligations. Transfer restrictions and reporting where applicable continue after the tokens are issued.
Each step is a gate, not a suggestion. Skip the securities analysis in step one and every downstream decision inherits a risk you did not price.
#Who Can Invest, and What Compliance Requires
The eligibility gate is where security token issuance visibly departs from an open token sale. Under a Reg D offering, investors generally have to be accredited, meaning they meet income or net-worth thresholds, or qualify through one of the professional-certification routes added in 2020. Reg A+ Tier 2 opens the door to non-accredited investors, subject to per-investor caps. Reg S restricts the offering to non-US persons.
On top of the securities-exemption check sits KYC/AML verification. It is a distinct legal basis, but for the investor it is the same practical gate: prove who you are, and prove you are eligible, before you can hold the token. In an STO, that eligibility is usually enforced at the token level, through transfer restrictions and whitelisting written into the contract. Which brings us to the standard the offering runs on.
#How an STO Relates to the Token Standard You Choose
A security token offering is the offering event and its regulatory wrapper. The token standard is the on-chain mechanism that enforces the offering's rules after the tokens exist. The STO decides who is allowed to hold the token and under what conditions. The standard is what actually blocks a transfer to a wallet that has not been verified.
Two standards come up frequently. ERC-1400 is a partition-based model for security tokens that splits a single contract into separately controlled balances. ERC-3643 takes a different approach, enforcing compliance through an on-chain identity registry rather than partitions. Both belong to the broader family of token standards that define how a token behaves on-chain.
Read this post first if the question is whether to run a security token offering at all, and under which exemption. Read the standard posts next, once the offering structure is set and the question becomes which mechanism enforces it.
#Structure the Offering Before You Structure the Token
A security token offering is a capital-raising structure, not a shortcut around the securities question. The token is infrastructure. The business underneath is the engine. Regulators, exchanges, and institutional investors read the offering with that in mind, and the projects that build the raise around a real revenue model, documented in a complete data room, are the ones that hold up under review.
If you're building onchain and need your token structure and documentation to hold up under institutional scrutiny, book a discovery call. We'll assess your project and tell you whether we're the right fit. Sometimes we're not. We'll tell you that too.
