DAC8 & Tax Reporting

    DAC8 crypto tax reporting, built from the data up

    The first reporting year is already running.

    DAC8 reporting readiness and data preparation for crypto-asset service providers, and tax-ready records for the businesses those providers report on. We scope who and what is reportable, aggregate and value transactions from exchange records and the chain itself, reconcile the dataset to your books, and prepare it for your tax advisor to file. In Cyprus and across the EU.

    1 Jan 2026

    Collection live

    DAC8 applies. The first reporting year is already running.

    1 Jan 2027

    Pre-existing users

    Self-certifications due for accounts opened before 2026.

    30 Jun 2027

    First reports in Cyprus

    Filings covering the 2026 year. Other member states set their own 2027 dates.

    Cyprus transposed DAC8 on 27 March 2026, retroactive to 1 January 2026. The late law did not move the deadlines.

    Two Sides of the Same Regime

    Providers report. Everyone else gets reported on. Both need records that agree with the chain.

    For CASPs and crypto-asset operators

    If you provide crypto-asset services to EU-resident users, DAC8 has applied to you since 1 January 2026. You are already in the first reporting year: self-certifications to collect, transactions to aggregate per user and per asset at fair market value, and a first report due in 2027. We build that dataset from your records and the chain itself, reconcile it, and prepare it for filing with your tax advisor.

    • Applicability scoped against MiCA authorisation and operator status
    • Reportable transactions aggregated and valued from source data
    • A dataset your advisor can file and your auditor can rely on

    For crypto businesses, funds, and treasuries

    You may have no DAC8 reporting duty of your own, but every exchange you use now reports your activity to the tax authorities automatically. What they report should match what you file, and that takes tax-ready records: cost basis tracked, realised gains and losses computed from actual on-chain history, and internal transfers kept out of the taxable numbers. We reconstruct and maintain exactly that.

    • Cost-basis and realised gains built from chain and exchange records
    • Your filings reconciled against what platforms report about you
    • Defensible answers ready before a tax authority asks the question

    What the Service Covers

    From scoping whether you report at all to a validated dataset your tax advisor can file, with every figure traceable to source.

    Applicability assessment

    Whether you are a reporting crypto-asset service provider at all, which entities and products are caught, and which member state you report to. Documented, so the conclusion survives staff changes and regulator questions.

    Due diligence readiness

    Self-certification collection reviewed against the deadlines: onboarding flows for new users, the backlog of pre-existing users due by 1 January 2027, and the reminder-and-block procedure DAC8 requires for users who refuse.

    Transaction aggregation and valuation

    Reportable transactions compiled per user and per crypto-asset: fiat-to-crypto, crypto-to-crypto, transfers, and retail payments, each valued at fair market value in the way the report requires.

    Reconciliation to the chain and the books

    The reporting dataset tied back to on-chain movement and the accounting ledger, so the numbers you report agree with the numbers you audit. Breaks are investigated, not plugged.

    Report preparation

    The validated dataset prepared in the structure the submission requires, ready for your tax advisor to review and file, with a documented trail from every reported figure back to its source.

    Annual cycle and remediation

    DAC8 repeats every year. We set up the collection and reconciliation so year two is routine, and we reconstruct historical data where the first year started late or incomplete.

    How an Engagement Runs

    Scoped honestly, built from source data, reconciled before anything is reported.

    01

    Scoping

    We establish whether and where you report, which users and products are in scope, and the state of your data. If you are not caught by DAC8 at all, we say so and stop there.

    02

    Gap assessment

    Self-certifications, transaction records, valuations, and TINs checked against what the report needs. You get a concrete list of what is missing and what it takes to close each gap.

    03

    Dataset build

    Reportable transactions aggregated per user and per asset from exchange records, internal systems, and the chain, valued at fair market value at the right points in time.

    04

    Reconciliation and validation

    The dataset reconciled to on-chain movement and the ledger, with unexplained differences investigated before anything is reported rather than after.

    05

    Handover and filing support

    The prepared report goes to your tax advisor for review and submission. We stay available for their questions, and for the tax authority follow-ups that come with a first year.

    Where Our Role Starts and Stops

    We do the data. Tax law belongs to tax advisors, and pretending otherwise would make both jobs worse.

    We do

    • Determine your reportable footprint and document the basis
    • Build, value, and reconcile the reporting dataset from source data
    • Reconstruct historical records where collection started late
    • Prepare the report for your tax advisor and support their review

    We do not

    • Give tax or legal advice, or take positions on contested tax points
    • File the report; submission stays with you and your tax advisor
    • Review your AML framework, which is a separate compliance audit
    • Report numbers we could not tie back to the chain or your records

    If your books have never been tied to on-chain activity, start with transaction reconciliation. For the AML side of the same supervisory picture, see AML & compliance audits.

    DAC8 & Tax Reporting FAQ

    What is DAC8, in one paragraph?

    DAC8 is the eighth amendment to the EU Directive on administrative cooperation in tax (Directive (EU) 2023/2226). It transposes the OECD Crypto-Asset Reporting Framework into EU law and applies from 1 January 2026. Crypto-asset service providers with EU-resident users must identify those users, collect tax self-certifications including tax residence and taxpayer identification numbers, aggregate their reportable transactions per user and per asset at fair market value, and report the lot to a tax authority annually. That authority then exchanges the data automatically with every member state where a user is tax resident. There is no minimum threshold: any reportable activity above zero is reported.

    Who actually has to report under DAC8?

    Reporting crypto-asset service providers, which covers two groups: providers authorised under MiCA, and crypto-asset operators serving EU users without a MiCA authorisation, including non-EU platforms with EU-resident customers. Exchanges, brokers, custodial wallet providers, and platforms that control access to user assets are all caught. Individuals and ordinary companies that merely hold or trade crypto do not file DAC8 reports themselves, but they are the subject of the reports their platforms file, which is why their own records need to agree with what is reported about them.

    What are the deadlines we are actually working against?

    Three matter. Data collection has applied since 1 January 2026, so the first reporting year is already running and cannot be started retroactively without reconstruction work. Self-certifications from pre-existing users, meaning accounts opened before 2026, are due by 1 January 2027. The first reports, covering the 2026 calendar year, fall due in 2027; Cyprus has set 30 June 2027, and other member states set their own dates within the EU window. We confirm the exact filing deadline for your reporting jurisdiction at scoping rather than leaving you to assume it.

    Has Cyprus actually transposed DAC8?

    Yes. Cyprus missed the original 31 December 2025 transposition deadline, then passed the implementing law on 27 March 2026 with retroactive effect from 1 January 2026. Retroactive is the important word: the late law did not move the start of the first reporting year, so obligations run from January 2026 regardless of when the law arrived. The law applies to entities licensed in Cyprus under MiCA and to crypto-asset operators providing services without a MiCA registration requirement.

    What happens if a user refuses to provide a self-certification?

    DAC8 puts the enforcement on you. After the initial request and two reminders, once 60 days have passed, the provider is required to block the user from performing reportable transactions until the self-certification arrives. That means your onboarding and operations need a working reminder-and-block procedure, with the dates evidenced, not just a policy document that mentions one. It is one of the specific things we test in the due diligence readiness review.

    What data ends up in the report?

    For each reportable user: identity, tax residence, and taxpayer identification number, all supported by a valid self-certification. For their activity: aggregate amounts per crypto-asset for exchanges between crypto and fiat, exchanges between crypto-assets, certain transfers including to unhosted wallets, and retail payment transactions, together with the number of transactions and fair market values. The aggregation sounds simple and is not: it requires classifying every movement correctly, and misclassified internal transfers are the most common way a report ends up wrong.

    Are you tax advisors? Who actually files the report?

    We are not tax advisors, and this service is deliberately drawn to stop where tax advice starts. What we do is the data: determining your reportable footprint, building the aggregated dataset from chain and exchange records, reconciling it, and preparing it for submission with every figure traceable to source. Interpretation of tax law, positions on contested points, and the filing itself belong to your tax advisor, and we work alongside whoever that is. If you do not have one, we can involve the tax team of CYAUSE, the ICPAC-licensed firm we deliver statutory audits with.

    We are not a CASP, just a business holding crypto. Why would we need this?

    Because from 2026 the information flows whether you participate or not. Every EU-facing platform you use reports your activity, identified by your tax number, to your tax authority. If your filings are built on incomplete records, the mismatch is now visible automatically. The useful response is tax-ready records: cost basis reconstructed from actual transaction history, realised gains and losses computed consistently, internal transfers between your own wallets excluded from taxable events, and the whole thing reconcilable to the chain. That is this service for non-reporting businesses, and it is the same discipline we apply in transaction reconciliation.

    We did not start collecting data in January 2026. How bad is it?

    Recoverable, and common: the first year of any new reporting regime finds most firms mid-stream. The chain does not forget, exchange records can be exported after the fact, and valuations can be established retrospectively from market data. Self-certifications are the harder gap because they depend on users responding, which is why the backlog work should start immediately rather than in the autumn of 2027. The honest framing is that reconstruction costs more than collection, and the cost grows with the delay.

    How does DAC8 relate to CARF and to non-EU jurisdictions?

    DAC8 is the EU implementation of the OECD Crypto-Asset Reporting Framework, and dozens of non-EU jurisdictions have committed to CARF exchanges on a similar timetable. In practice that means the reporting architecture you build for DAC8 is the same one CARF will ask of you elsewhere, and data prepared properly once serves both. It also means moving operations outside the EU does not move you outside the regime: a non-EU platform with EU-resident users is still a reporting crypto-asset operator under DAC8.

    How does this fit with your audit and reconciliation services?

    They share one foundation: records that agree with the chain. Transaction reconciliation is the underlying discipline and is where to start if your books have never been tied to on-chain activity. DAC8 reporting builds the regulatory dataset on top of reconciled records. And when your financial statements are audited, whether through our own audit service with CYAUSE or with your existing auditor through crypto audit support, the same verified data serves the audit evidence. Firms that treat these as one data problem pay for the work once; firms that treat them separately pay three times.

    More questions answered on our general FAQ.

    Behind on the 2026 reporting year?

    Tell us whether you hold a MiCA authorisation, where your users are, and what your records look like today. We will tell you honestly whether you report, what is missing, and what it takes to be ready before the deadline rather than after it.

    • A clear answer on whether DAC8 catches you at all
    • A gap list with the work sequenced against the deadlines
    • A dataset your tax advisor can file without redoing it