← Back to Blog

    Crypto Reporting Obligations in Cyprus: DAC8, MiCA, AML and the New 8% Tax

    Title card reading Crypto Reporting Obligations, Cyprus 2026, DAC8, MiCA, AML and Tax, beside a stylised regulatory filing document and a ring of EU stars, over a navy background with a teal blockchain network

    By Iraklis Anastasiou · September 1, 2026

    "Crypto reporting" in Cyprus is not one obligation. It is four, owed to four different authorities, on four different clocks, and the firms that get into trouble are usually the ones that assumed satisfying one of them satisfied the others.

    Key takeaways

    • Crypto reporting in Cyprus is four separate obligations to four authorities: DAC8 to the Tax Department (about your users), MiCA reporting to CySEC (about your firm), suspicious transaction reports to MOKAS, and your own tax return.
    • The first DAC8 report, covering calendar year 2026, is due by 30 June 2027; self-certifications from pre-existing users by 1 January 2027.
    • The MiCA transitional period ended on 1 July 2026; unauthorised provision of crypto-asset services from Cyprus is now unlawful.
    • Gains on crypto disposals are taxed at a flat 8% under Article 20E from 1 January 2026, and crypto-to-crypto exchanges count as disposals.

    We are asked some version of the same question every month. A crypto firm in Cyprus, often newly authorised or midway through an application, wants to know what it actually has to report. The honest answer is that the question needs splitting before it can be answered, because the word "reporting" is doing four separate jobs at once.

    A tax report under DAC8 goes to the Cyprus Tax Department and describes your users. Regulatory reporting goes to CySEC and describes your firm. A suspicious transaction report goes to MOKAS and describes one customer's behaviour, urgently. Your own tax return describes your own income. Different data, different owners, different deadlines, and very different consequences for getting each one wrong.

    All four moved in 2026, which is why so much of the guidance still circulating is wrong. Cyprus transposed DAC8 in March, backdated to January. The MiCA transitional window closed on 1 July. And a new Article 20E introduced a flat 8% tax on crypto disposals from 1 January, ending years of the island being described as a place where crypto gains are simply untaxed.

    This is a map of all four as they stand in September 2026. It is written for compliance officers, finance leads and the boards that sign off on what they produce. It is not tax or legal advice, and where a position is genuinely unsettled we say so rather than presenting one reading as settled law.

    The Four Regimes at a Glance

    If you take one thing from this page, take this table. Most of the confusion we see resolves the moment someone sees the four obligations side by side and understands that they are not substitutes for one another.

    Table 1: The four crypto reporting regimes in Cyprus, as at September 2026
    Regime What is reported Who files Goes to Timing
    DAC8 tax reporting Your users: identity, tax residence, taxpayer identification number, and aggregated crypto transactions valued per user and per asset. Reporting crypto-asset service providers and crypto-asset operators serving EU-resident users. Cyprus Tax Department, for automatic exchange with other member states. Data collection since 1 Jan 2026. Self-certifications for pre-existing users by 1 Jan 2027. First report, covering 2026, by 30 June 2027.
    MiCA supervisory reporting Your firm: own funds, safeguarding of client assets, business volumes, material changes, complaints, and operational or ICT incidents. CASPs authorised under MiCA, plus issuers of asset-referenced and e-money tokens. CySEC. Ongoing and periodic. Frequency and content depend on your permissions and the circulars in force.
    AML suspicious transaction reporting A specific customer or transaction giving rise to knowledge or suspicion of money laundering or terrorist financing. All obliged entities, CASPs included. MOKAS, the Cyprus financial intelligence unit. Promptly, on suspicion. No monetary threshold and no reporting calendar.
    Your own tax return Your own position, including gains on crypto disposals taxed at 8% under Article 20E of the Income Tax Law. Cyprus tax resident individuals and companies, including non-domiciled residents. Cyprus Tax Department. Annually, on the ordinary return deadlines for your taxpayer type.

    Note what the table implies. Only the first regime is triggered by having users, only the second by being licensed, and only the third by seeing something suspicious. The fourth applies to you whether or not you run a crypto business at all. A firm can owe all four, and an individual investor with no business at all can still owe the fourth.

    1. DAC8: Reporting Your Users to the Tax Department

    DAC8 is the EU's crypto tax transparency regime, and it is the obligation Cyprus firms are least prepared for. Partly because it is new, and partly because its first filing deadline sits far enough away to feel unreal while the data collection behind it is already running.

    What Cyprus Did, and When

    Cyprus missed the original transposition deadline of 31 December 2025 and passed its implementing law on 27 March 2026, with retroactive effect from 1 January 2026. Retroactive is the word that matters. The late arrival of the law did not move the start of the first reporting year, so obligations run from January 2026 regardless of when the text landed. A firm that waited for the Cyprus law before starting to collect data is already behind, and the gap has to be closed by reconstruction rather than by going forward cleanly.

    The law reaches entities licensed in Cyprus under MiCA and crypto-asset operators providing services without a MiCA registration requirement. That second category catches more businesses than firms expect, which is the subject of the trap below.

    The Three Dates That Govern Your Year

    Three deadlines drive everything else. Data collection has applied since 1 January 2026, so the first reporting year is already in progress. Self-certifications from pre-existing users, meaning accounts opened before 2026, are due by 1 January 2027. The first reports, covering the 2026 calendar year, fall due in 2027, and Cyprus has set 30 June 2027. Other member states set their own dates inside the EU window, so a group filing in more than one jurisdiction should confirm each one rather than assuming the Cyprus date travels.

    The Trap: "We Are Not an Exchange, So This Is Not Us"

    The most common misreading we encounter. DAC8 attaches to the provision of crypto-asset services to EU-resident users, not to whether you think of yourself as an exchange or whether you hold a MiCA licence. A firm executing transactions on behalf of clients, operating a trading platform, or providing transfer services can be a reporting crypto-asset operator without ever having applied for anything. Being outside the EU does not help either: a non-EU platform with EU-resident users is still in scope.

    Scoping this properly is a one-off exercise that costs very little and settles the question with reasoning on the record. Assuming your way out of it is the expensive option, because the assumption is only tested when a reporting year has already closed.

    2. MiCA and CySEC: Reporting Your Firm to Your Supervisor

    The second regime is supervisory rather than fiscal. Crypto-asset service providers in Cyprus are supervised by the Cyprus Securities and Exchange Commission, and once you are authorised under MiCA, reporting is continuous rather than periodic in the way a tax filing is.

    Cyprus used the transitional period that MiCA's Article 143(3) leaves to member states, and that window has now closed. Firms registered under the old national regime could continue until 1 July 2026, and CySEC required anyone intending to seek authorisation through Cyprus to have applied by 27 February 2026, with a wind-down plan expected from those who did not. The practical consequence for September 2026 is that providing crypto-asset services from Cyprus without MiCA authorisation is no longer a transitional position, it is an unauthorised one. Everything below follows from being a supervised firm.

    What a CASP owes its supervisor falls into a few recognisable families. The exact content and frequency depend on which services you are permitted to provide, so treat the following as the shape of the obligation and confirm the specifics against your own authorisation conditions and the circulars in force.

    The families are: periodic prudential and operational reporting, covering own funds, safeguarding of client assets and business volumes; notification of material changes, meaning shareholding, management, outsourcing and any change to the services you provide; complaints reporting; incident reporting, both operational and ICT-related, where DORA has raised expectations for firms in scope; and, for issuers of asset-referenced and e-money tokens, a separate reporting stream tied to reserves and redemption.

    The failure we see here is rarely a missed return. It is that the numbers in the supervisory report cannot be reconciled to the chain or to the ledger when someone asks how they were produced. A report you cannot reproduce is a finding waiting to happen, which is why our transaction reconciliation and MiCA readiness work usually starts with the evidence trail rather than the form.

    3. AML: Reporting Suspicion to MOKAS

    The third regime is the one with no deadline, which is precisely what makes it hard to run. Suspicious transaction reports go to MOKAS, the Cyprus financial intelligence unit, under the Cyprus law implementing the EU anti-money laundering directives. The trigger is knowledge or suspicion, and the timing is "promptly", not "quarterly".

    Two things about STRs are consistently misunderstood. First, there is no monetary threshold that switches the obligation on. A small transaction that makes no sense is reportable; a large transaction that makes complete sense is not. Firms that have quietly built a de facto threshold into their escalation process have built a defect. Second, filing is not the end of the matter. Tipping off is a separate offence, and the decision about whether to continue the customer relationship after filing is one you have to document rather than default.

    The quality issue we find in reviews is not under-reporting so much as undifferentiated reporting. A firm that files everything is not demonstrating diligence, it is transferring its judgement to the FIU, and supervisors read high volume with thin narrative for what it is. We cover this and the related control gaps in more depth in our note on AML audit readiness for Cyprus crypto firms.

    The Travel Rule Is a Reporting Obligation Too

    The EU Transfer of Funds Regulation extends the travel rule to crypto-asset transfers, which means originator and beneficiary information has to accompany transfers between service providers. Firms tend to file this mentally under "AML tooling" rather than "reporting", and then discover at review time that the obligation has an evidential dimension: you have to be able to show what you sent, what you received, and what you did when the information was missing or incomplete.

    Exception handling is where this breaks. Transfers to and from self-hosted wallets, counterparties who send incomplete data, and the question of what constitutes a reasonable delay before rejecting a transfer are all areas where firms have a policy and no evidence that the policy was followed. That is a reporting failure even when no report was due.

    4. Your Own Tax Position

    The fourth regime is the one people usually mean when they ask about "crypto tax in Cyprus", and it is separate from all three above. DAC8 concerns what you report about your users. This concerns what you and your own business report about yourselves. It is also the part of the Cyprus picture that changed most in 2026, and a great deal of the advice still circulating online describes the old position.

    Cyprus Now Has a Dedicated Crypto Tax Article

    Until the end of 2025, Cyprus had no provision written specifically for digital assets. Practitioners worked from general Income Tax Law principles, the "titles" exemption and the badges of trade, and outcomes turned on whether activity was characterised as investment or as trading. That ambiguity is what produced the widely repeated claim that crypto gains in Cyprus are simply untaxed.

    That position no longer holds. The 2026 tax reform inserted Article 20E into the Income Tax Law, via the Income Tax (Amending) (No. 4) Law of 2025, and it applies from 1 January 2026. It taxes gains from the disposal of crypto-assets at a flat 8%, for individuals and companies alike. "Crypto-asset" takes the MiCA definition in Article 3(1)(5) of Regulation (EU) 2023/1114, which is a deliberate and useful piece of drafting: the tax definition and the regulatory definition are the same definition.

    Four events count as a disposal, and the last two are the ones people miss: sale for fiat, exchange of one crypto-asset for another, gift or transfer without consideration, and payment for goods or services. A crypto-to-crypto swap is a taxable disposal even though no fiat moved and nothing reached a bank account. Simply holding is not taxed.

    The Details That Change Behaviour

    Three features of Article 20E matter more than the headline rate.

    Losses are ring-fenced. A loss on a crypto disposal can be set only against crypto disposal gains realised in the same tax year. It cannot be carried forward, surrendered by group relief, or offset against other income. Unused losses are simply lost, which makes the timing of realisations matter far more than it does elsewhere in the Cyprus system.

    Mining is carved out. Crypto-assets acquired through mining fall outside the 8% regime and are dealt with under the general provisions, meaning ordinary corporate or personal rates. Staking rewards and airdrops likewise sit outside Article 20E on receipt, though a later disposal of those assets comes back inside the 8%. A business with mixed activity therefore has to track how each holding was acquired, not just what it sold, and that is a data problem long before it is a tax problem.

    Non-dom status does not exempt it. The non-domiciled regime exempts dividends and interest from the special defence contribution, and a number of people have assumed crypto gains travel with them. Under the 2026 law they do not. A non-dom Cyprus tax resident disposing of crypto-assets is within the 8%.

    Around this sit the wider reform changes: corporate income tax moved from 12.5% to 15% from 1 January 2026, in line with the OECD global minimum, so the general rate that applies to mining income and to trading profits outside Article 20E moved with it.

    This regime is new, and new regimes generate practice questions faster than guidance answers them. Cost basis on assets acquired long before 2026, valuation on crypto-to-crypto swaps, and the boundary between staking receipts and disposals are all areas where we would expect the detail to firm up. Take advice on your own facts. What we do is build and reconcile the underlying dataset, including acquisition method, cost basis and disposal history across chains and venues, which is almost always the part that is missing. The characterisation of that data is a matter for your tax advisor, and the two jobs should not be collapsed into one.

    Where These Obligations Collide

    The regimes are legally separate but they draw on overlapping data, and that overlap is where the real risk sits. Three collisions are worth planning for.

    Consistency across filings. The transaction population behind a DAC8 report, the volumes in a CySEC return and the revenue in a tax computation are different views of the same underlying activity. When they are produced by different teams from different extracts, they disagree, and the disagreement is visible to anyone who looks at two of them together. Building the three from one reconciled source is the single highest-value structural fix available.

    Self-certification and KYC are not the same record. DAC8 wants tax residency and taxpayer identification numbers. AML onboarding wants identity and source of funds. Firms frequently assume their KYC file already satisfies DAC8 and find at collection time that the tax fields were never captured, for exactly the users who are now hardest to reach.

    An STR does not discharge a reporting obligation. Filing a suspicious transaction report about a user does not remove that user from your DAC8 population, and it does not change what you report to your supervisor. Obvious when stated, and not always obvious in the moment.

    A Realistic Sequence

    If all four apply to you and none of them are in good order, the sequence below reflects what we would actually do rather than what a maturity model would suggest.

    First, scope DAC8 and write the conclusion down. It is cheap, it is time-critical because the reporting year is running, and the answer determines how much of the rest matters. Include the reasoning, not just the conclusion.

    Second, find out what your 2026 data actually looks like. Not whether you have data, but whether you can produce, for a given user, a complete and valued transaction history reconciled to the chain. Do this before building anything. Most remediation plans we see are written before anyone has looked, and are wrong in consequence.

    Third, close the self-certification gap for pre-existing users. This has a hard deadline of 1 January 2027 and it depends on customer responsiveness, which you do not control. It needs the most lead time and gets the least.

    Fourth, reconcile once and reuse. Build the reconciled transaction source that the DAC8 dataset, the supervisory returns and the tax computation all draw from, rather than three parallel extracts that will drift.

    Fifth, test the AML reporting chain end to end. Take a real alert and follow it to a filed report, or to a documented decision not to file. If the trail breaks anywhere, that is your finding, and you would rather have it than an inspector.

    What This Page Cannot Tell You

    Three honest limitations. The exact content and frequency of CySEC reporting depend on your permissions and on circulars that change, so verify against what is in force for your firm rather than against this summary. Article 20E is barely a year old, and the practice questions it raises, cost basis on assets acquired well before 2026, valuation on crypto-to-crypto swaps, and the treatment of staking receipts, will be settled by guidance and practice that does not fully exist yet. And parts of the EU AML framework are still bedding in as the AML package phases in, so where supervisory expectation has not settled, a documented interpretation with reasoning behind it is defensible and silence is not.

    Dates and positions in this article were verified in September 2026. Regulatory timetables in this area have moved more than once, and Cyprus transposed DAC8 three months late, so confirm anything you are about to rely on before you rely on it.

    How Ondology Labs can help: We work on the data underneath all four regimes rather than on the forms themselves. That means DAC8 reporting support, from applicability scoping to a reporting dataset reconciled to the chain and to your books, MiCA readiness and CASP compliance evidence, independent AML compliance audits covering the escalation and reporting chain end to end, and transaction reconciliation that gives your tax advisor an acquisition and disposal history they can actually work from. We are based in Nicosia and most of this work is done for firms supervised here.

    Related reading: AML audit readiness for crypto firms in Cyprus · The DAC8 directive explained · MiCA's transition window.