CARF is the OECD's standard for reporting crypto users to tax authorities, and data collection is already under way. Kryptos takes your own platform's records, works out which of your users are reportable and where, checks their tax IDs, and builds the file each authority accepts. You file once with your home authority, and the authorities exchange it between themselves. DAC8 is how the EU puts CARF into law; the UK, New Zealand and others adopt it through their own rules. And the same data does more than reporting. It can run a tax centre for your users under your own brand, so you help them file too.
SOC 1 and SOC 2 Type II. From the OECD schema to national formats like Sweden's KU94. Live in days.
Send your transaction and account data through the API or a file upload. Kryptos cleans it up and matches it to each customer.
Kryptos collects self-certifications, checks tax IDs, and works out where each user is reportable. Anyone who won't certify goes into the 60-day reminder cycle.
Kryptos works out gains and applies the retail-payment threshold per asset, in the method and currency each country asks for.
Kryptos builds the OECD file and each national format and checks them against the schema. You file once, and the authorities share it from there.
One system does the whole job, whether you report in the UK, New Zealand, or an EU country under DAC8. The same records can also give your users a tax centre under your brand.
Send your transaction and account data through the API or a file upload. Kryptos cleans it up, removes duplicates, and matches it to each customer.
Kryptos collects each user's self-certification, checks it makes sense, and validates their tax ID. If a user won't certify, it sends two reminders over 60 days, then blocks their reportable activity until they do.
Kryptos works out cost basis and value per asset and applies the retail-payment threshold. It uses the cost-basis method and currency each country asks for.
Kryptos builds valid CARF XML for the OECD network, plus the national formats a generic tool can't, like Sweden's KU94. Each authority gets the exact file it accepts.
Every file is checked against the schema before it goes out, so it isn't rejected on a technicality. Behind it sit hundreds of test cases and a schema reviewed with tax authorities.
You file with your home authority. It shares the data with each country your users live in. Kryptos processes the data for you; you stay the data controller.
We'll walk through your obligations and show it working on your own data.
You have users in many countries. Kryptos works out who's reportable and where, checks their tax IDs, and files each authority's format from one place.
If you hold crypto for users, you're a reporting CASP. Kryptos runs the self-certification and due diligence, keeps the audit trail, and files, with nothing to build.
You handle crypto for clients. Kryptos covers CARF and DAC8 next to US rules like the 1099-DA and its backup withholding, from the same data.
You get CASPs ready to report. See the whole obligation in one place, and hand clients a system that files.
CARF is the OECD's standard, and the first authorities start collecting reports in 2027. Kryptos files the OECD format plus the national one each authority accepts, and tracks every deadline.
| Jurisdiction | First report | How it's adopted |
|---|---|---|
| United Kingdom | 31 May 2027 | CARF, HMRC rules |
| Germany | 2027 | DAC8, the EU's route |
| New Zealand | 30 June 2027 | CARF, Inland Revenue |
| Sweden | 2027 | DAC8, KU94 format |
| Austria | 2027 | DAC8, plus KESt withholding |
| Finland | 2027 | DAC8, plus domestic gains |
CARF and DAC8 reporting is one task. A reporting-only tool files the report and stops there. Then you need another vendor for withholding, another for your customers' tax experience, another for accounting. Kryptos does all of it from the same data and the same integration.
| Feature | Kryptos | Reporting-only tools |
|---|---|---|
| CARF and DAC8 filing | ||
| Tax withholding at source, like Austria's KESt | ||
| Tax centre for your users, under your brand | ||
| Portfolio and treasury accounting | ||
| Audit trail and corrections | ||
| One integration, one contract |
Data collection started in January 2026, and the first reports are due in 2027. The UK's deadline is 31 May 2027, New Zealand's is 30 June 2027, and EU countries file under DAC8 in 2027. Kryptos tracks each date for you.
Often yes. CARF follows your users' tax residence, not where your business is based. If you have users who are tax resident in a country that has adopted CARF, you likely have to report on them. Kryptos works out where each user is reportable.
If a user never gives you a valid self-certification, you have to send at least two reminders over 60 days, then block their reportable activity until they do. Kryptos runs the reminders and unblocks the user the moment they certify.
Valid CARF XML for the OECD network, plus national formats such as Sweden's KU94. Every file is checked against the schema before you submit, so it isn't rejected on a technicality.
A build means a team, hundreds of edge cases, every national format, and years of audit logs to maintain. Kryptos does the same job in days, and the same data can also run withholding and a tax centre for your users.
The detail behind each step, from who you report to, to why files get rejected.
Reporting follows your users' tax residence, not where you're based. How to work out where you're on the hook.
A CARF report is one XML file with a set structure. What each part holds, section by section.
The common XML mistakes, from duplicate IDs to bad tax IDs, and how to catch them first.
The reminders, the cure period, and when you have to block a user who won't certify.
Book a demo. We'll go through your obligations and show it working on your own data.