Compliance12 min read
MB
Editorial Team
·July 31, 2026

What Are the Four SEC Tokenization Models?

The SEC's January 28, 2026 staff statement on tokenized securities is best known for a principle everyone already expected: a security remains a security whether it is recorded on a blockchain or a traditional ledger. Its real contribution is a taxonomy. The staff mapped tokenization into four models — integration, notification, custodial, and synthetic — and the model an issuer picks determines whether the token is the security itself, a receipt for one held elsewhere, a mere notification device conveying no rights at all, or a separate security that may qualify as a security-based swap. This guide covers each model and the consequences that follow.

TL;DR — Key Takeaways

  • What It Is: A joint staff statement from the Divisions of Corporation Finance, Investment Management, and Trading and Markets, issued January 28, 2026. It creates no new rules, exemptions, or bespoke regime.
  • Integration Method: The issuer formats the security itself as a crypto asset and keeps the master securityholder file on-chain. The only model where the token genuinely is the security.
  • Notification Method: A traditional off-chain security with an accompanying token that only notifies the issuer of transfers — it conveys no rights, obligations, or benefits whatsoever.
  • Custodial vs Synthetic: Custodial tokens are assumed NOT to be a separate security. Synthetic tokens are assumed to BE one — and may meet the statutory criteria for a security-based swap.
  • Substance Over Form: The staff assesses the economic reality of the instrument rather than the name given to it. Calling a product a tokenized share does not settle what it legally is.

Ready to get started?

Join others who are already using our platform.

What Are the Four SEC Tokenization Models?

The Headline Was Obvious. The Taxonomy Was Not.

On January 28, 2026, the Divisions of Corporation Finance, Investment Management, and Trading and Markets issued a joint staff statement confirming that federal securities laws apply whether ownership is tracked on a blockchain or a traditional ledger. Changing a security's format to a token does not change whether, or how, those laws apply. Registration or a valid exemption, disclosure obligations, and trading rules all apply equally, and the statement creates no new rules, exemptions, or bespoke regime.

That principle surprised nobody. The part worth reading closely is the taxonomy underneath it: the staff mapped tokenization into four distinct models, and the one an issuer has built determines whether its token is the security, a receipt for a security held elsewhere, a notification device with no legal content, or a separate security that may itself be a security-based swap. Programs frequently do not know which of the four they have implemented.

Changing the format of a security to a token or other crypto asset “does not change whether, or how, the federal securities laws apply.”

— SEC staff statement on tokenized securities, January 28, 2026

The Four Models, and What Each One Legally Is

The staff split tokenization into two issuer-sponsored models and two third-party models. The dividing question is whether the entity issuing the token is the same entity that issued the underlying security — and, within each branch, whether the token carries legal rights or merely points at something that does.

ModelWho issues the tokenWhat the token is
IntegrationThe issuerThe security itself, with the master securityholder file maintained on-chain
NotificationThe issuerA notification device conveying no rights, obligations, or benefits
CustodialA third party holding the securityAn indirect ownership interest; assumed NOT a separate security
SyntheticA third partyA value-tracking claim against that party; assumed to BE a separate security

Only the integration method makes the token legally operative as the security. Under it, the issuer formats the security as a crypto asset and maintains the master securityholder file on the blockchain, with linkage between on-chain and off-chain records. Everything else is a pointer of some kind — and pointers have counterparties.

The Notification Method Is the Easiest Model to Misdescribe

Under the notification method the security remains a traditional off-chain instrument, and the accompanying crypto asset does not convey any rights, obligations, or benefits — it exists to notify the issuer of ownership transfers. The token is a signalling device. It is not the asset, and holding it is not holding the security.

This is the model most likely to be presented to investors as something it is not. A program can build the notification method competently, ship it, and still create real exposure by describing the token as ownership of the underlying security in its marketing. Nothing technical has failed; the mismatch is entirely between what the instrument does and what buyers were led to believe. Getting this right is a disclosure discipline problem before it is an engineering one.

Key Insight

Ask one question of any tokenized securities program: if the token is transferred and the issuer's off-chain register is never updated, who owns the security? Under integration, the question is incoherent — the on-chain record is the register. Under notification, the answer is that the transferor still owns it and the token holder owns nothing. Programs that cannot answer this cleanly have not established which model they built.

Why Synthetic Tokens Attract a Second Regulatory Regime

Third-party tokenized securities may — or may not — represent the issuance of a separate security, and the staff drew the line between the two third-party models. Custodial tokens are assumed not to be a separate security, because a third party actually holds the underlying instrument and the token represents an indirect interest in it. Synthetic tokens are assumed to be a separate security, because the holder owns a claim against the third party that is not directly tied to the reference asset.

That assumption carries a further consequence. A synthetic tokenized security may meet the statutory criteria for a security-based swap, bringing its own registration, reporting, and counterparty requirements. The staff emphasized assessing the economic reality of the instrument rather than the name given to it, citing the Commodity Exchange Act exclusions for notes, bonds, and options on securities. Calling the product a tokenized share settles nothing.

1. Identify who holds the underlying

If a custodian genuinely holds the security, the token is an indirect interest. If nothing is held and the token merely tracks a price, it is synthetic.

2. Test the claim, not the label

A synthetic token is a claim against the issuing third party, not against the reference asset — which is why it is assumed to be a separate security.

3. Run the security-based swap analysis

Assess the instrument's economic reality against the statutory criteria and the CEA exclusions for notes, bonds, and options on securities.

4. Check UCC Article 8 alignment

The statement assumes compliance with state law on securities entitlements; the federal analysis does not substitute for it.

5. For registered funds, check Section 18

The staff raised multi-class issues under Section 18 of the Investment Company Act where a registered fund's shares are tokenized.

A synthetic tokenized security represents “a claim against the third-party not directly tied to the reference asset.”

— Analysis of the SEC staff tokenization taxonomy, February 2026

What the Statement Deliberately Leaves Open

The statement is a map, not a rulebook, and its silences are as important as its content. It does not address disclosure obligations specific to tokenized issuances, transfer agent responsibilities, broker-dealer regulatory impacts, or Exchange Act registration details. It assumes compliance with state law under UCC Article 8 rather than resolving it, and it raises multi-class issues under Section 18 of the Investment Company Act for registered funds without settling them.

An issuer that has correctly identified its model has therefore completed the first step, not the analysis. The practical sequence is to fix the model, confirm the state-law position on securities entitlements, then work through the transfer agent and trading-venue questions the statement leaves untouched. The permissioned transfer mechanics that make any of this enforceable on-chain are covered in the RWA token standards guide.

Who This Matters To — and When Programs Get It Wrong

The taxonomy matters most to issuers deciding how to bring a security on-chain, to platforms creating tokens referencing securities they did not issue, and to investors trying to determine what they actually hold. It is least useful to anyone hoping for a bespoke regime — the staff explicitly declined to create one.

Who it's for

  • Issuers choosing between integration and notification
  • Platforms tokenizing securities they did not issue
  • Investors determining what their token legally conveys
  • Counsel running the security-based swap analysis

Who it's NOT for

  • Anyone expecting a bespoke tokenized-securities regime
  • Programs seeking relief from registration or disclosure
  • Issuers wanting transfer agent questions resolved
  • Platforms treating the label as the legal analysis

When it breaks

  • Notification-method token marketed as ownership
  • Synthetic token issued without the swap analysis
  • On-chain transfer with no linkage to the off-chain register
  • Registered fund tokenized without a Section 18 review

How Blockmaze Handles Tokenized Securities Model Compliance

Blockmaze structures a tokenized securities program around four protocol-level controls — model declaration, register linkage enforcement, rights-conveyance documentation, and third-party claim disclosure — making the chosen model an explicit, verifiable property of the issuance rather than something inferred later from the code.

Model Declaration

The tokenization model is recorded at issuance, so integration, notification, custodial, and synthetic structures are distinguishable on their face rather than by reverse-engineering the contract.

Register Linkage Enforcement

For integration-method issuances, the linkage between the on-chain record and the master securityholder file is enforced, closing the gap where a token moves and the register does not.

Rights-Conveyance Documentation

What the token does and does not convey is documented alongside it, so a notification-method instrument is never presented as ownership of the underlying security.

Third-Party Claim Disclosure

For custodial and synthetic structures, the identity of the obligor and the nature of the holder's claim against it are disclosed, reflecting that a synthetic token is a claim on a counterparty.

Choosing a Tokenization Model for a Securities Issuance?

Blockmaze provides the compliance framework for tokenized securities — model declaration, register linkage enforcement, rights-conveyance documentation, and third-party claim disclosure.

Frequently Asked Questions

What did the SEC's January 28, 2026 staff statement on tokenized securities say?

On January 28, 2026, the Divisions of Corporation Finance, Investment Management, and Trading and Markets issued a joint staff statement confirming that existing federal securities laws apply regardless of whether ownership is tracked on a blockchain or a traditional ledger. Changing the format of a security to a token does not change whether, or how, the federal securities laws apply — registration or a valid exemption, disclosure obligations, and trading rules apply equally. The statement establishes no new rules, exemptions, or bespoke regime for tokenized securities. Its practical value is not the headline principle but the taxonomy it lays out: four distinct tokenization models with materially different legal consequences.

What are the four tokenization models the SEC staff identified?

The staff split tokenization into two issuer-sponsored models and two third-party models. Issuer-sponsored: the integration method, where the issuer formats the security itself as a crypto asset and maintains the master securityholder file on-chain with linkage between on-chain and off-chain records; and the notification method, where a traditional off-chain security is accompanied by a crypto asset that merely notifies the issuer of ownership transfers and conveys no rights, obligations, or benefits. Third-party: the custodial model, where a third party holds the underlying security and the crypto asset represents an indirect ownership interest; and the synthetic model, where the crypto asset tracks the value of a reference asset but conveys no ownership or legal rights to the underlying security.

Is a third-party tokenized security a separate security?

It depends on which third-party model is used, and the staff drew the line clearly. Custodial tokens are assumed not to constitute a separate security — the token represents an indirect interest in a security the custodian actually holds. Synthetic tokens are assumed to be a separate security, because the holder owns a claim against the third party that is not directly tied to the reference asset. That difference cascades: a synthetic token may also meet the statutory criteria for a security-based swap, bringing an entirely separate regulatory regime with it. Two products that look identical to a buyer on a screen can sit on opposite sides of this line.

Why does the notification method matter if the token conveys no rights?

Because it is the model most likely to be misdescribed to investors. Under the notification method, the security remains a traditional off-chain instrument and the accompanying crypto asset does not convey any rights, obligations, or benefits — it exists to notify the issuer of ownership transfers. The token is a signalling device, not the asset. A program using this model and marketing the token as ownership of the underlying security has mischaracterized the instrument, even if every technical component works exactly as designed. The gap between what the token does and what buyers believe it does is the compliance exposure.

How does the staff decide whether an instrument is a security-based swap?

The staff emphasized assessing the economic reality of the instrument rather than the name given to it, citing the statutory exclusions in the Commodity Exchange Act for notes, bonds, and options on securities. A synthetic tokenized security that tracks a reference asset's value without conveying ownership can meet the statutory criteria for a security-based swap, which carries its own registration, reporting, and counterparty requirements. Labelling the product a 'tokenized share' does not resolve the question. The analysis runs on what the instrument economically does for its holder — a familiar substance-over-form test now applied to on-chain products.

Which model should an issuer choose, and what else does the statement leave open?

The integration method is the only model where the token is genuinely the security rather than a reference to it, making it the cleanest fit for an issuer that wants on-chain transfer to be legally operative. The statement assumes compliance with state law under UCC Article 8 and raises multi-class issues under Section 18 of the Investment Company Act for registered funds. It does not address disclosure obligations for tokenized issuances, transfer agent responsibilities, broker-dealer impacts, or Exchange Act registration details — so an issuer resolving its model still has substantial unaddressed ground to cover with counsel.

Ready to get started?

Join others who are already using our platform.