Ireland's DAC8 and CARF crypto reporting rules explained: who counts as an RCASP, registration and self-certification deadlines, what gets reported, and the penalties.

Ireland's crypto reporting rules are now live, and most of the coverage out there is a pan-European explainer that never quite tells an Irish platform what to do. In August 2026, Revenue published Tax and Duty Manual Part 38-03-38 through eBrief 121/26, setting out the reporting obligations for Reporting Crypto-Asset Service Providers, or RCASPs. The obligations apply from 1 January 2026. If you run a crypto platform with an Irish nexus, the clock is already running.
This is Ireland's implementation of the OECD's Crypto-Asset Reporting Framework (CARF) and the EU's DAC8. It's an information-reporting regime: platforms collect and report transaction data, and Revenue exchanges it with other tax authorities. It is not a withholding or tax-collection system. Nobody is calculating your users' tax for them. But the data that flows to Revenue is detailed, and the penalties for getting it wrong are real.
Two routes bring you inside the rules.
Under CARF, an RCASP is any individual or entity that, as a business, provides a service effectuating crypto-asset transactions for or on behalf of customers, including acting as a counterparty, as an intermediary, or by making a trading platform available. Under DAC8, the net is drawn to include both any crypto-asset service provider authorised under MiCAR in Ireland and any "crypto-asset operator", that is, a provider not authorised under MiCAR, that has a Member State nexus.
That second limb matters. DAC8 deliberately pulls in operators that sit outside MiCAR authorisation. Being unregulated as a CASP does not put you outside the reporting rules. And a MiCAR-registered CASP in Ireland must register and report as an RCASP. The nexus test runs in order: tax residence, then incorporation or organisation, then place of management, then a regular place of business or branch, with MiCAR authorisation sitting at the top of the DAC8 ordering. Where an equal or higher-priority jurisdiction already handles the reporting and you notify Revenue, you can avoid duplicate reporting.
An RCASP must register with Revenue before 31 December in the year it becomes an RCASP. On registration, Revenue issues a crypto-asset operator ID.
Here is the Irish wrinkle. The registration portal was still in development when the manual published, and Revenue said it will launch before the end of 2026. So this isn't your normal ROS filing, it's a dedicated channel that platforms need to watch for. Registration captures your name, addresses, any tax identification number, the Member States where your reportable users reside, and any qualified non-Union jurisdiction where you carry out due diligence. Changes have to be notified before the last day of the month following the month the change happened.
The core due-diligence obligation is self-certification. An RCASP has to obtain a self-certification from each user to establish tax residency and reportable status.
For an individual, that means name, residence address, every jurisdiction of tax residence, a tax identification number for each, and date of birth, signed and dated on or before the platform gives the user access. For an entity, it's legal name, address, jurisdictions, and TIN, and where the entity is a passive one, you identify and self-certify its controlling persons.
The deadlines split by user type. For users who already existed as of 31 December 2025 ("pre-existing users"), you have until 31 December 2026 to obtain the self-certification. For new users, you collect it at onboarding. You can test the self-certification against the AML and KYC data you already hold for reasonableness, and you can reuse self-certifications collected for other tax purposes. A third party can do the collection for you, but the obligation stays yours, and that third party is a data processor under GDPR.
Reporting is annual and it's granular. The reportable population is your users who are resident in Ireland, in another EU Member State, or in a listed reportable jurisdiction, excluding certain excluded persons.
The reportable transactions are crypto-to-fiat exchanges, crypto-to-crypto exchanges, transfers, and reportable retail payment transactions, that last one being a transfer of crypto for goods or services above USD 50,000. For each user, you report aggregated per crypto-asset type: the asset name, acquisitions and disposals against fiat (gross amounts, units, and counts), acquisitions and disposals against other crypto (fair market value, units, and counts), retail payments, and transfers in and out, including to un-hosted or unknown wallets. Transfer sub-types you have to flag include airdrops, hard-fork airdrops, staking income, loan returns, and exchanges for goods or services.
The dates that matter:
Part 38-03-38 sets out a defined penalty schedule under sections 891HA and 891M of the Taxes Consolidation Act 1997:
There's an enforcement backstop on the data side too. A user who won't provide their information after two written reminders and 60 days must have their account closed and be barred from reopening it, and an operator's registration ID can be revoked after two reminders and 30 days.
If you hold crypto and use an Irish or EU platform, DAC8 doesn't change what you owe. Your Irish tax position is the same as before: disposals are generally subject to Capital Gains Tax at 33%, with the first EUR 1,270 of gains exempt each year. What changes is visibility. From the 2026 year, your platform reports your transaction data to Revenue, and Revenue shares it internationally. The gap between what an exchange reports and what you declare is now easy to see, so getting your own records straight matters more than it used to. Our Ireland crypto tax guide covers how disposals, income, and filing work.
The practical burden of DAC8 is data. You need clean, per-user, per-asset transaction records that reconcile to what you report, in the CARF and DAC8 XML schema, held for six years, and matched to verified self-certification data. That's a records and reconciliation problem before it's a filing problem.
It's the same problem MiCA's Article 68 record-keeping rules point at from the regulatory side, which we cover in our post on MiCA record-keeping. Kryptos Enterprise is built for the reconciliation layer underneath both: normalising activity across chains, exchanges, and custodians into transaction-level records your compliance and finance teams can query, export, and stand behind. For the wider mechanics of CARF and DAC8 across jurisdictions, our CARF and DAC8 guide goes deeper.
The obligations apply from 1 January 2026. The first reportable period is the 2026 calendar year, and the first return is due to Revenue by 31 May 2027.
Any crypto-asset service provider authorised under MiCAR in Ireland, and any other crypto-asset operator with an Irish or EU nexus. Registration is with Revenue, before 31 December in the year you become an RCASP, through a dedicated portal launching before the end of 2026.
€19,045 for a failure to file or an incorrect return, €2,535 for each day a return is outstanding, €4,000 for failing to register or to apply due diligence, and €1,265 for not complying with an authorised officer. Registration IDs can also be revoked.
No. DAC8 is an information-reporting regime. Platforms report your transaction data to Revenue, which shares it with other tax authorities. Working out and paying your tax is still your responsibility.

FASB's August 2026 proposal on digital assets and cash equivalents, explained. What it changes, the three criteria that matter, and the November 19 comment deadline.

Australia is implementing the OECD Crypto-Asset Reporting Framework. What CARF means for offshore exchange holdings, when reporting starts, and how to prepare.

The ATO taxes ordinary staking as income, but has no specific ruling on liquid staking or restaking tokens like stETH and eETH. What is settled, and what isn't.
Generate an audit-ready report aligned to your jurisdiction. No credit card required.