Under CARF, a user who won't self-certify can't transact forever. Here's the reminder cadence, the cure period, and when you have to block the account.
CARF doesn't let a user sit in limbo. If someone opens an account and never provides a valid self-certification, you can't just keep letting them trade and hope they get around to it. The framework gives you a defined path, and at the end of it, an account restriction.
When a user fails to provide a valid self-certification, a reporting crypto-asset service provider must follow up, in practice with at least two reminders over a 60-day cure period, and then restrict the user's reportable transactions if the certification is still missing.
Yes. If the cure period lapses without a valid self-certification, you must prevent the user from carrying out further reportable transactions until they comply. The restriction is lifted as soon as they provide a valid certification.
No. It is a restriction on reportable transactions, not a permanent ban. It stays in place only until the user provides the missing self-certification, at which point normal activity resumes.
Austrian providers must withhold 27.5% KESt on crypto gains. Here's what triggers it, how the moving-average basis works, and how to automate the filing.
Withhold KESt at source and your users' crypto tax is final, no return needed. Use a foreign provider and they self-declare. Here's why the difference matters.
Austria requires the gleitender Durchschnittspreis for crypto, not FIFO. Here's how the moving-average basis works and why it complicates withholding.
Generate an audit-ready report aligned to your jurisdiction. No credit card required.
When a self-certification is missing or fails validation, you have to chase it. In practice that means at least two reminders across a 60-day window. The clock and the reminders aren't a nice-to-have; they're the documented steps you point to if a regulator asks why an account was, or wasn't, restricted.
The 60 days is a cure period: the user's chance to fix the gap. Provide a valid certification inside the window and nothing happens, they carry on normally. The point isn't to punish anyone, it's to make sure you either have the tax data CARF requires or you've stopped the reportable activity that needs it.
If the cure period lapses with no valid certification, you have to prevent the user from carrying out further reportable transactions until they comply. And the moment they do certify, the restriction lifts. It's a gate, not a ban.
This is a workflow that has to run per user, on a per-user clock, forever. Doing it by hand across a large book is where teams slip, and a missed block is exactly the kind of gap that surfaces in an audit. The self-certification and validation that feed this are covered in our CARF onboarding workflow piece. Our CARF and DAC8 reporting platform runs the whole cadence: it tracks each user's certification status, sends the reminders, blocks reportable transactions when the window closes, and clears the block the instant a valid certification lands. For where this fits in a venue's stack, see exchanges and custodians, and the OECD exchange-of-information hub for the source framework.