Crypto tax transparency, 2026

The Crypto-Asset Reporting Framework (CARF) is the OECD standard that makes crypto activity visible to tax authorities. It requires crypto platforms — exchanges, brokers, custodians, payment processors — to collect user transaction data and report it to their tax authority, which then automatically exchanges that data with each user’s country of residence. The model mirrors the Common Reporting Standard (CRS) already used for bank accounts. If your business facilitates crypto transactions for other people, you are almost certainly a Reporting Crypto-Asset Service Provider (RCASP) and the obligation applies to you now, because data collection begins before the first reporting deadline.

Book a free 30-minute consultation
Who it applies to
Crypto exchanges, brokers, dealers, custodian wallet providers and payment processors (RCASPs), and the founders who run them.
What is reported
User identity plus per-asset transaction and balance data, exchanged automatically with each user’s residence-country tax authority.
Cost of preparing
Operational changes to KYC, TIN collection, data storage and reporting output; in-house build, CARF reporting software, or an outsourced compliance provider.
Timeline
Early adopters collect from 2025 and report from 2026; the EU collects from 2026 (via DAC8) and reports from 2027.
Verdict
Treat RCASP status as the default if you intermediate crypto for third parties, and start TIN collection and reporting readiness before the collection window opens.

The era of crypto as a reporting-free zone has closed. For founders and investors who assumed holdings were invisible to tax authorities, the practical effect is the same as CRS did for offshore bank accounts: residence-country authorities receive a complete year-end picture of activity on every reporting platform. This page explains what CARF covers, who has to report, what data flows, and how to prepare.

What CARF is

CARF is an OECD-developed international tax transparency framework built specifically for crypto assets. It was published in final form in October 2022 as part of the OECD’s expansion of CRS to asset classes the original 2014 standard never captured. Each country must implement CARF into domestic law, so the exact timeline and scope vary by jurisdiction.

Under CARF, a Reporting Crypto-Asset Service Provider collects information on its users’ crypto transactions and reports it to its domestic tax authority. That authority then automatically exchanges the data with the tax authorities of the users’ countries of residence — the same architecture CRS uses for traditional financial accounts.

What the framework covers

In scopeOut of scope (base framework)
Exchanges between crypto and fiat currenciesDecentralized exchanges with no intermediary
Exchanges between different crypto assetsDirect wallet-to-wallet transfers with no reporting entity in the chain
Transfers of crypto assets, including to unhosted wallets subject to implementation choicesNFTs in many implementations, though some jurisdictions include them
Retail payments made using cryptoMiners, validators and stakers running infrastructure for others

The boundary between operating a decentralized protocol and providing a crypto-asset service is actively disputed, and the regulatory trend runs toward broader definitions.

Who must report

CARF defines RCASPs broadly. If you run a business that facilitates crypto transactions for customers and earns fees for it, you are likely an RCASP.

  • Crypto exchanges — centralized platforms where users swap crypto for fiat or other crypto.
  • Brokers and dealers — businesses that intermediate crypto purchases and sales for customers.
  • Custodians — businesses that hold crypto on behalf of customers (wallets, custody services).
  • Payment processors — businesses that let merchants accept crypto payments.
  • Token issuers — under some implementations, entities that issued tokens and keep holder records.

Reporting reaches customers who are tax-resident in a jurisdiction that has adopted CARF and exchanges information with the reporting jurisdiction. Both natural persons and legal entities are reportable.

Outside the RCASP definition: miners, validators and stakers who operate infrastructure; individual holders (they are subjects of reporting); pure software developers of non-custodial tools; and fully decentralized protocols with no identifiable operator.

Timeline: when CARF takes effect

Implementation is happening in waves. The OECD published the framework; each adopting country sets its own effective dates. Because data collection precedes the first report, businesses with customers in early-adopting countries are affected today.

TrackJurisdictionsData collection fromFirst reports
CARF early adoptersUnited Kingdom, Australia, Canada, Switzerland, Singapore, Japan20252026
EU (via DAC8)All 27 member states20262027
Second waveFurther OECD and G20 members; Global Forum participants2027 onward2028 onward

Jurisdictions with mature AML/KYC rules for crypto (EU states under MiCA/AMLD, the US under FinCEN rules) layer CARF on top of existing obligations, creating a dual reporting environment. The EU implements CARF through DAC8, the eighth iteration of the Directive on Administrative Cooperation — see our DAC8 explainer for the EU-specific rules, penalties and MiCA interaction.

What data is reported

CARF requires collection and reporting of user identity and transaction data for each reportable customer.

For each customer

  • Full legal name
  • Date and place of birth (for individuals)
  • Tax identification number (TIN) in the country of residence
  • Country of tax residence
  • Account identifier (wallet address or exchange account ID)

For each reportable transaction

  • Type of crypto asset
  • Type of transaction (exchange to fiat, exchange to crypto, transfer)
  • Number of units transacted
  • Fiat equivalent value at the time of the transaction
  • For transfers, the counterparty wallet address where a transfer to an unhosted wallet is reportable in that jurisdiction

Many implementations permit annual aggregate reporting per user per asset class rather than transaction-by-transaction filing. The net effect: each user’s residence-country authority receives a full picture of exchanges, transfers and year-end holdings on your platform, equivalent to the CRS bank-statement data it already receives.

How to prepare

CARF compliance is an operational programme, not a single filing. It touches KYC, data collection, storage and reporting infrastructure.

Step 1 — Determine your RCASP status. Map your activities against the RCASP definition in every jurisdiction where you operate. If you facilitate crypto transactions for third parties and collect fees, treat RCASP status as the working assumption; regulators are interpreting the term broadly.
Step 2 — Audit KYC and customer data. CARF requires a TIN for every reportable customer. Many platforms verify identity thoroughly yet have never systematically collected TINs. Build a TIN collection process for new customers and a retrospective campaign for existing active ones. A missing TIN cannot simply be omitted — you must document the attempt, apply due diligence, and may need to restrict or close accounts where collection fails.
Step 3 — Build or buy reporting infrastructure. Data volumes are high, formats are jurisdiction-specific (XML schemas, portal submissions, intermediaries), and deadlines are annual, with some jurisdictions requiring semi-annual filing. Options range from an in-house build for large platforms, to CARF reporting software, to an outsourced compliance provider that handles aggregation, TIN validation and submission.
Step 4 — Reconcile incorporation against customer residency. You report based on where customers reside, not only where you are incorporated. A UAE-incorporated exchange with German customers may need to report those customers to UAE authorities, who exchange with Germany. Even where your jurisdiction has not adopted CARF, your customers in adopting countries will be captured once exchange begins.
Step 5 — Update your terms and privacy policy. Customers must be told their transaction data is shared with tax authorities. Reporting is a legal obligation, so your documentation should state it accurately.
Step 6 — Engage advisors for cross-jurisdiction analysis. CARF intersects with local AML rules, GDPR data-transfer constraints in the EU, and domestic reporting such as US Form 1099-DA and UK third-party data reporting. A workable strategy accounts for every applicable framework at once.

What non-compliance costs

  • Penalties under domestic law where you operate; the UK and EU frameworks impose per-record penalties that add up quickly.
  • Regulatory action from crypto licensing authorities (VARA, FSRA, FCA, CySEC), which increasingly fold tax-reporting compliance into the licensing fitness test.
  • Reputational exposure, as regulators publicly flag non-compliant platforms.
  • Liability for facilitating tax evasion where non-reporting is found to be deliberate.

Map your CARF obligations before the collection window opens

Crystal Tax helps crypto businesses determine RCASP status, design TIN collection and reporting infrastructure, and coordinate multi-jurisdiction obligations. Start with a free 30-minute call.

Book a free 30-minute consultation
Or reach us directly: +380 67 885 5300 · WhatsApp · Telegram · info@crystal.tax

Frequently asked questions

What is CARF in plain terms?

CARF is the OECD Crypto-Asset Reporting Framework. It requires crypto platforms to collect user transaction data and report it to their tax authority, which then exchanges it automatically with each user’s country of residence — the same model CRS uses for bank accounts.

Is my crypto business a Reporting Crypto-Asset Service Provider?

If you facilitate crypto transactions for customers and earn fees — as an exchange, broker, custodian or payment processor — you are almost certainly an RCASP in jurisdictions that have adopted CARF. Miners, validators, individual holders and non-custodial tool developers generally fall outside the definition.

When does CARF reporting actually start?

Early adopters such as the UK, Australia, Canada, Switzerland, Singapore and Japan collect data from 2025 and file first reports in 2026. The EU collects from 2026 through DAC8 and files first reports in 2027. Because collection precedes reporting, preparation is a 2026 priority.

What data has to be reported?

Customer identity (name, date and place of birth, TIN, country of residence, account identifier) plus per-asset transaction and balance data: asset type, transaction type, units, fiat value, and transfers in and out. Many jurisdictions accept annual aggregates per user per asset.

Does CARF apply if I am incorporated in a non-adopting country?

Reporting follows customer residence, not only your place of incorporation. Even where your jurisdiction has not adopted CARF, customers resident in adopting countries can be captured once information exchange begins, and if your jurisdiction has adopted CARF you must report customers resident in partner jurisdictions.

What is the difference between CARF and DAC8?

CARF is the OECD model framework each country chooses to adopt. DAC8 is the EU’s binding implementation of CARF across all 27 member states, with EU-wide mandatory exchange and some wider scope. Our DAC8 explainer covers the EU-specific detail.

What happens if we do not comply?

Consequences include per-record penalties under domestic law, regulatory action from crypto licensing authorities that treat tax reporting as part of the fitness test, public flagging of non-compliant platforms, and liability where non-reporting is deliberate.

How can Crystal Tax help?

We assess RCASP status across your jurisdictions, design TIN collection and reporting output, and coordinate CARF alongside AML, GDPR and domestic reporting rules. Start with a free consultation.

Crystal Tax has advised online and e-commerce founders on international structuring since 2014. For crypto platforms, that means aligning CARF reporting with your licensing, banking and corporate structure in one coherent plan — see how we work.
Related pages
/
Maxim Stepanenko

Maxim Stepanenko

Managing partner of Crystal.tax

A wide range of legal services from Crystal Tax: registration of offshore companies in all world jurisdictions, solving issues related to taxation, opening bank accounts and many others.

Order service

Our advantages

Full range of services

We provide a wide range of legal services, including the registration of companies in foreign jurisdictions, legal support for activities, opening bank accounts, consultations and much more. others

Professional team

Crystal Tax employs a team of highly qualified professionals, experts in all matters related to offshore. We have many years of successful experience.

Optimal choice

We offer only the best solutions for your business - the best jurisdiction and type of company for offshore registration.

Speed and reliability

We register a company in any jurisdiction as quickly as possible. We guarantee confidentiality of data for each client

Efficiency

An individual approach to clients, solving non-standard tasks and the vast experience of our lawyers can lead your business to success.

Affordable prices

The cost of services is agreed between us and the client. You pay only for the work done, which allows you to minimize costs. We work without intermediaries and overpayments.

Write to Email Write to Telegram Write to Whatsapp Write to Skype