Crypto Compliance in Cyprus

    Crypto compliance for the EU rulebook

    Evidence your supervisor can test, not policies they have to trust.

    MiCA, AML, and DAC8 all ask the same underlying question: do your records agree with the chain? We build that answer once and keep it current, for CASPs, exchanges, custodians, funds, and token issuers in Cyprus and across the EU. Facing the closed MiCA transition window? Start with MiCA readiness. Supervisor testing your AML framework? That is AML & compliance audits.

    Four Obligations, Four Authorities

    "Crypto compliance" in Cyprus is not one obligation. It is four, owed to four different authorities, and satisfying one does not satisfy the others:

    DAC8 tax reporting

    Cyprus Tax Department

    Reports about your users: identities, tax residence, and aggregated crypto transactions, exchanged automatically with other EU member states.

    How we help

    MiCA supervisory reporting

    CySEC

    Reports about your firm: own funds, safeguarding of client assets, volumes, incidents, and material changes, under your CASP authorisation.

    How we help

    Suspicious transaction reports

    MOKAS (the Cyprus FIU)

    Reports about a specific customer or transaction, filed promptly on suspicion of money laundering or terrorist financing. No threshold, no calendar.

    How we help

    Your own tax return

    Cyprus Tax Department

    Your own position, including gains on crypto disposals taxed at a flat 8% under Article 20E of the Income Tax Law since 1 January 2026.

    How we help

    The full map, with every deadline, is in our reference guide: Crypto Reporting Obligations in Cyprus.

    How Compliance Work Runs

    01

    Scope the Obligations

    We establish which regimes catch you: MiCA authorisation, AML supervision, DAC8 reporting, or all three, and the state of your records against each.

    02

    Assess the Gaps

    Controls and records tested against the requirements on real data. You get a documented gap list with the work sequenced, not a scare memo.

    03

    Build the Evidence

    Wallet control verified cryptographically, client assets evidenced as segregated, reserves attested, and books reconciled to the chain.

    04

    Keep It Current

    Compliance is a cycle, not a certificate. The reconciliation and attestation cadence repeats, so supervisory questions are answered from live records.

    Compliance FAQ

    What is MiCA, in one paragraph?

    MiCA is the Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114), the EU's single rulebook for crypto-asset markets. It has applied in full since 30 December 2024. Firms providing crypto-asset services to EU clients must be authorised as Crypto-Asset Service Providers (CASPs) in one member state, after which they can passport their services across all 27. The authorisation bar is high: governance, capital adequacy, operational resilience, segregation and safeguarding of client assets, complaints handling, and record-keeping are all tested, and the obligations continue for as long as the licence does. Stablecoin issuers face separate, stricter titles covering e-money tokens and asset-referenced tokens.

    What is an AML compliance audit for a crypto business?

    It is an independent review of the anti-money-laundering controls you actually operate, tested against the obligations that apply to you. We look at customer due diligence and onboarding, ongoing monitoring, transaction monitoring rules, sanctions and PEP screening, blockchain analytics screening of wallet exposure, Travel Rule handling, suspicious transaction reporting, record-keeping, training, and the compliance officer function. The output is a written report with findings ranked by severity and a remediation plan you can work through.

    What is DAC8, in one paragraph?

    DAC8 is the eighth amendment to the EU Directive on administrative cooperation in tax (Directive (EU) 2023/2226). It transposes the OECD Crypto-Asset Reporting Framework into EU law and applies from 1 January 2026. Crypto-asset service providers with EU-resident users must identify those users, collect tax self-certifications including tax residence and taxpayer identification numbers, aggregate their reportable transactions per user and per asset at fair market value, and report the lot to a tax authority annually. That authority then exchanges the data automatically with every member state where a user is tax resident. There is no minimum threshold: any reportable activity above zero is reported.

    More questions answered on our general FAQ.

    Not sure which regimes catch you?

    Tell us what you do and where your clients are. We will map MiCA, AML, and DAC8 against your business honestly, including the parts that do not apply.

    Talk to Us

    Last reviewed: September 2, 2026