Decide what your token legally is before you write any code. Most expensive rebuilds I've seen start with skipping that step.
Here's the order I'd follow for an EU launch.
1. Classify the token first: If it gives holders ownership, a return, or a legal claim on an asset, it's usually a financial instrument. That puts it under MiFID II, and MiCA steps aside. Teams that plan around MiCA and find this out late have to redesign.
2. Check whether you're running a fund: If you pool investor money, buy assets, and have a manager making decisions, AIFMD likely applies too. That brings an independent depositary and independent valuation.
3. Decide who you're selling to: A public offer above €12M over 12 months (the threshold from 5 June 2026, though some member states set it lower) needs an approved prospectus. Smaller or qualified-investor-only offers can use exemptions.
4. Decide whether it trades: Issuing and holding is lighter than running a secondary market. If you want on-chain trading and settlement, the DLT Pilot Regime is the route.
5. Build the compliance into the product:
KYC and eligibility checks before a wallet can hold the token.
Transfer rules that block ineligible buyers automatically.
No personal data on-chain. Store a hash and keep the details off-chain, so GDPR erasure requests stay possible.
An emergency pause and clear contracts with oracle and cloud providers if DORA applies to you.
6. Bring legal counsel in before the developers: The regulator conversation should start months before launch, not after the audit.
When you're choosing a Blockchain development company, ask who covers the legal structure, not only the smart contracts. Ask what happens when an ineligible wallet tries to receive tokens. Ask to see a live project. Vague answers usually mean the team hasn't done it before.