AEOI Reporting

DAC8 · CARF · first period is calendar 2026

DAC8 reporting

DAC8 is the EU’s implementation of the OECD Crypto-Asset Reporting Framework. The rules are the same rules: the same schema, the same code lists, the same corrections mechanism. What DAC8 adds is a set of EU-specific elements and the obligation to report to a Member State rather than under a bilateral agreement.

The first reporting period is calendar 2026. It is running now, which means the data is accruing whether or not anyone is collecting it.

2026
First reporting period
Calendar year. Data is accruing now.
v1.5
CARF XML Schema
The OECD schema DAC8 adopts.
8
Transaction categories
Reported as annual totals per user, per asset.
67+
Committed jurisdictions
Rolling out through 2027–2028.

Who has to report

The obligation attaches to Reporting Crypto-Asset Service Providers — a definition wider than “exchange”. Whether you are one is a question for an adviser; these are the shapes it commonly catches.

Exchanges and brokers

Anyone effecting exchange transactions for or on behalf of customers, whether against fiat or against other crypto-assets.

Custodial wallet providers

Holding crypto-assets on a customer's behalf brings transfers in and out into scope, including transfers to wallets not known to be associated with a service provider.

OTC desks

Effecting transactions bilaterally rather than on an order book does not remove the obligation. The transactions are still reportable.

ATM operators

A crypto ATM is a service provider effecting exchange transactions, and the retail payment threshold applies.

Payment processors

Accepting crypto for merchants can make a firm a service provider for the transfer, and reportable retail payments above USD 50 000 are a category of their own.

Non-EU firms with EU customers

A firm outside the EU can have a DAC8 nexus through a branch, a place of business, or single registration. Being headquartered elsewhere is not an answer.

What surprises people

Most of the effort is not in the filing. It is in the two things the filing depends on: identity you were not collecting, and transaction aggregates in a shape your systems were not built to produce.

Totals, not trades

CARF reports annual aggregates per user, per crypto-asset, per category — not a transaction list. Two blocks sharing a category is a rejection cause, so the aggregation has to be right at source.

Transfers to unhosted wallets

Transfers to addresses not known to be associated with a service provider are their own category. It is frequently the one nobody has been recording.

Self-certification is a record

Tax residence and TIN have to be collected, chased, and evidenced. Two reminders over 60 days is the pattern the rules anticipate, and a real share of customers never answer the first.

Customers who left

The population is fixed by what happened during the period, not by who is still a customer when you file. People who closed accounts in 2026 are still reportable for 2026.

Identifiers you cannot reuse

A correction points at the DocRefID of the record it replaces. That identifier has to be unique in space and time, and still findable two years later.

Registration is separate

Several jurisdictions require registration months before the first return. The UK deadline is 31 January 2027, ahead of a 31 May 2027 filing date.

We collect the self-certifications, chase the people who ignore them, keep the evidence trail, generate the XML with stable DocRefIDs and handle the corrections afterwards. The validator and the readiness check stay free and need no account — the paid product starts at EUR 59 a month, and the price is on the page.