LEGAL NODES

Get yout crypto tax reporting guidance

Book a call to get started
Schedule free discovery call
400+ companies already use Legal Nodes

CARF and DAC8 reporting obligations took effect on 1 January 2026. Here's what each framework covers, who counts as a reporting crypto-asset service provider, and what has to be in place before the first filing.

Two acronyms quietly turned into working reality this year: CARF and DAC8. Neither sounds dramatic, but together they change how crypto activity gets reported to tax authorities – automatically, across borders, without anyone having to ask.

CARF is the OECD's global standard for exchanging crypto tax data between countries, built on the same logic banks already follow under CRS. DAC8 is the EU's version, folding crypto reporting into the bloc's existing tax cooperation directive. Both took effect on 1 January 2026, covering the whole EU plus roughly 48 countries worldwide, from the UK and Japan to Brazil and South Africa. More jurisdictions are lining up for the next waves in 2027 and 2028.

This guide is brought to you by our legal expert Olha Filipskykh and reviewed by the Legal Nodes team. Legal Nodes is a delegated legal department built into your GTM engine. We take care of incorporation, contracts, compliance (MiCA, DORA, GDPR), and vendor checks through our tech-driven platform and top legal experts

Please note: none of this information should be considered as legal, tax, or investment advice. Whilst we’ve done our best to make sure this information is accurate at the time of publishing, laws and practices may change. For help with the legal and compliance, speak to us.

Do I fall under CARF? Who the rules actually catch

Even if it sounds like a problem for licensed entities, this is incorrect. It reaches any crypto-asset service provider – exchanges, brokers, dealers, even crypto ATM operators, whether or not they hold a formal CASP authorisation. If a business lets people convert, trade, or transfer crypto for others, it's very likely in scope, sometimes without having thought of itself that way. The definition of "crypto assets" is just as wide: coins, tokens, stablecoins, and certain NFTs used for investment or payment. Central bank digital currencies are the main carve-out.

What counts as a Reporting Crypto-Asset Service Provider

The operative test is whether an entity or individual effectuates exchange transactions as a business for or on behalf of customers. That covers centralised exchanges, custodial wallet providers, brokers and dealers, OTC desks and crypto ATM operators — and, where a controlling entity can be identified, some DeFi front-ends and applications. Being unlicensed doesn't help: the framework tracks the activity, not the authorisation.

What is excluded

Beyond central bank digital currencies, the exclusions are narrow: specified electronic money products and closed-loop assets that can't be used for payment or investment outside a single ecosystem. Everything else that can be held and transferred in a decentralised manner is in scope, including asset classes built on comparable technology that don't exist yet.

What CARF and DAC8 reporting requirements mean day to day

In-scope providers now have to run proper due diligence on their customers, including identifying who ultimately owns and controls any corporate account, and to report crypto-to-fiat and crypto-to-crypto transactions to their local tax authority every year. That authority then shares the data automatically with wherever the customer is a tax resident. For most businesses, this means new onboarding data points, new internal processes, and a first filing that has to be right the first time.

What has to be collected and reported

Per user: full name, address, date of birth, jurisdiction(s) of tax residence and Taxpayer Identification Number. For entity accounts, the same for each reportable Controlling Person. Per transaction type and per crypto-asset: the gross amounts and number of units acquired and disposed of, and the value of transfers in and out. Due diligence records generally have to be retained for five years, and reporting uses the OECD's CARF XML schema.

The self-certification rule that can freeze an account

Both regimes require a valid self-certification of tax residence from every user, verified against existing AML/KYC data. Under the EU rules this has teeth: if a valid self-certification hasn't been obtained after two reminders and 60 days, the provider must block the user from transacting. That makes self-certification an onboarding problem, not a year-end reporting problem.

CARF reporting deadlines: what's already running

And the clock is already running.

The first reporting year closes at the end of 2026, under six months away, with the resulting exchange of information following shortly after. Whatever hasn't been set up yet – client onboarding flows, UBO records, internal reporting processes, needs to be sorted well before that deadline, not after.

How far the reporting actually reaches: UBOs, offshore structures and corporate accounts

It is also worth being realistic about how far the visibility now extends. Say the ultimate beneficial owner lives in Belgium, the holding company is registered in the BVI, and the crypto account sits on a major exchange like Kraken. Under CARF and DAC8, that ownership chain is no longer just theoretical paperwork sitting in a file somewhere. Because platforms like Kraken are now obligated to identify and report Ultimate Beneficial Owners (UBOs), Kraken will actively report the BVI company alongside its Belgian UBO. This information will then automatically flow through the reporting chain straight to the Belgian tax authority.

Consider another scenario: an offshore entity, say, a Web3 platform or broker incorporated outside Europe, that operates globally. If this offshore entity onboards users residing in the EU, it falls squarely under the extraterritorial reach of DAC8 (and CARF, depending on the jurisdiction's adoption status). This means the offshore platform itself becomes the reporting entity. It is legally required to collect tax residency data and report the transaction histories of those EU users directly to the relevant tax authorities.

Which is really the point of these frameworks: the structure itself is not the problem, but it does need to be accurate, properly documented, and ready to match what's being reported before someone else's filing does the explaining for you.

What to check before the first reporting cycle

  • Whether any entity in your group meets the RCASP test — including entities that don't hold a licence and don't think of themselves as service providers
  • Which jurisdiction you report to under the nexus rules, and whether more than one could claim you
  • Whether onboarding captures tax residence, TIN and date of birth, with valid self-certifications on file
  • Whether UBO and Controlling Person records for every corporate account are current and match what platforms hold about you
  • Whether the picture that will be reported about your structure matches what has been declared in each relevant jurisdiction

How Legal Nodes helps with CARF and DAC8 compliance

That is the gap Legal Nodes helps close. We work through what CARF and DAC8 actually require for your specific setup, whether you are a CASP, a business that qualifies without quite realising it, or simply hold crypto through a corporate structure – get your due diligence and UBO records in order, and make sure you're ready for the first reporting cycle rather than reacting to it afterwards.

Get in touch with Legal Nodes, and let's get you prepared.

CARF and DAC8: frequently asked questions

What is CARF (the Crypto-Asset Reporting Framework)?

CARF stands for the Crypto-Asset Reporting Framework — a standard developed by the OECD, approved in 2023 and endorsed by the G20 and the Global Forum. It extends automatic exchange of information (AEOI), the machinery that already moves bank account data between tax authorities under the Common Reporting Standard, into crypto.

The framework doesn't regulate crypto itself. It creates one obligated party — the Reporting Crypto-Asset Service Provider (RCASP) — and requires it to identify its users, determine where they are tax resident, and report their transactions annually to its own tax authority, which then passes the data on. Jurisdictional nexus rules decide which country a provider reports to, so the same activity isn't reported twice.

Three transaction categories are reportable: exchanges between crypto and fiat, exchanges between one crypto-asset and another, and transfers of crypto-assets — including retail payment transactions above USD 50,000, where the provider has to identify the merchant.

What is DAC8?

DAC8 is Council Directive (EU) 2023/2226, adopted on 17 October 2023. It is the eighth amendment to the EU's Directive on Administrative Cooperation (Directive 2011/16/EU) and it transposes CARF into EU law, borrowing its definitions of crypto-assets and service providers from MiCA.

Member states had to write DAC8 into national law by 31 December 2025, with the rules applying from 1 January 2026. In practice the transposition was uneven — around a dozen member states missed the deadline and passed their laws during 2026, several with retroactive effect back to 1 January. A late national law does not push back the obligation to have collected 2026 data.

Penalties are set nationally rather than harmonised across the EU, so exposure varies significantly by member state — from a few thousand euros for due diligence failures in some jurisdictions to six or seven figures in others.

Where the amended CRS fits

Alongside CARF, the OECD also amended the Common Reporting Standard (sometimes called "CRS 2.0"), and DAC8 implements those amendments too. The amended CRS pulls e-money products and central bank digital currencies into the existing financial account reporting regime. So the CBDC carve-out from CARF isn't an exemption from reporting — it's a reallocation to the other framework.

Do I fall under CARF?

If your business lets other people exchange crypto for fiat, exchange one crypto-asset for another, or transfer crypto — and you do it as a business — you are likely a Reporting Crypto-Asset Service Provider, licensed or not. If you simply hold crypto through a company, you aren't the reporting entity, but your platform is reporting your entity and its UBOs.

What is the difference between CARF and DAC8?

CARF is the OECD's global standard. DAC8 is the EU legal instrument that implements it across the 27 member states, using MiCA definitions. Non-EU jurisdictions implement CARF through their own domestic legislation.

When is the first CARF report due?

The first reporting period is calendar year 2026. UK providers must register with HMRC by 31 January 2027 and file by 31 May 2027. EU deadlines fall during 2027 and vary by member state. First exchanges between tax authorities take place in 2027.

Does CARF apply to NFTs?

It can. NFTs used for payment or investment purposes fall within the definition of crypto-assets. NFTs that can't be used that way generally sit outside it.

Does CARF apply to an offshore company?

Yes, in two ways. An offshore platform serving EU or other in-scope users can itself become the reporting entity. And an offshore holding company that holds a crypto account is reported by the platform, together with its ultimate beneficial owners.

What are the penalties for non-compliance?

There is no harmonised EU penalty regime — each member state sets its own, and amounts differ widely. The UK has its own penalty framework alongside registration and filing obligations.

TABLE OF CONTENTS