CARF Reporting in Luxembourg: DAC8 Crypto Filing by 30 June
CARF reporting in Luxembourg starts with the data a crypto-asset platform is already generating in 2026. The Law of 27 March 2026 (Mémorial A No. 144), which transposes Directive (EU) 2023/2226 (DAC8) and brings the OECD Crypto-Asset Reporting Framework into Luxembourg tax law, makes the calendar year 2026 the first reporting period. Reporting crypto-asset service providers file their first annual return with the Administration des contributions directes (ACD) by 30 June 2027, and the ACD then exchanges that dataset with other Member States by 30 September 2027.
The Luxembourg label for the regime is the Cadre de déclaration des Crypto-actifs (CDC). It sits alongside older automatic-exchange regimes run by the ACD, but CARF has its own due-diligence rules. A Reporting Crypto-Asset Service Provider that is also a Financial Institution may rely on specified CRS due-diligence procedures, and a provider may reuse a self-certification collected for another tax purpose only where it meets the CARF requirements. The first return covers the 2026 calendar year. Firms should therefore ensure during 2026 that their due-diligence and transaction records are sufficient to produce the required annual aggregates; the published rules do not require transaction aggregates to be calculated in real time.
Related reading: CRS reporting in Luxembourg, whose self-certification and residence-determination rules intersect with the CARF due-diligence procedures.
The fixed calendar that drives every CARF-LU project plan:
- 1 January 2026: the first CARF and DAC8 reporting period opens; reporting covers the full 2026 calendar year. For pre-existing individual and entity Crypto-Asset Users, the required self-certification must be obtained by 1 January 2027.
- 30 June following each reporting year: the deadline for reporting crypto-asset service providers to file the annual return with the ACD. The first filing, for calendar year 2026, is due 30 June 2027.
- Within nine months of the calendar year-end (30 September): the ACD exchanges the information with the competent authorities of the other Member States. The first exchange, for 2026 data, falls due by 30 September 2027.
- Annual frequency thereafter, on the same 30 June and 30 September pattern.
- Registration and data-transfer procedures: to be published by the ACD (see the submission and changes sections below).
The legal basis for CARF reporting in Luxembourg: the Law of 27 March 2026 and DAC8
Three layers stack up here, and keeping them separate matters when a compliance team writes its legal-basis memo. At EU level, Directive (EU) 2023/2226 of 17 October 2023 amended the Directive on administrative cooperation to add crypto-assets as a new category of automatically exchanged information, transplanting the OECD Crypto-Asset Reporting Framework into the DAC. At Luxembourg level, the Law of 27 March 2026 transposes that Directive, amending the amended Law of 29 March 2013 on administrative cooperation in tax matters and, in the same act, the Common Reporting Standard law of 18 December 2015, the country-by-country reporting law of 23 December 2016, the DAC6 law of 25 March 2020 and the DAC7 platform-operator law of 16 May 2023.
The third layer is operational. The grand-ducal regulation of 18 May 2026 (Mémorial A No. 245) sets the form and modalities for both the registration of crypto-asset service providers and the declarations themselves. The issuing and receiving authority throughout is the ACD, which publishes the regime on its electronic-exchange pages under the Cadre de déclaration des Crypto-actifs heading.
One point of vocabulary saves confusion later. The framework the OECD wrote is CARF; the EU vehicle that carries it is DAC8; the Luxembourg instrument is the Law of 27 March 2026. The sources are related but are not interchangeable. Luxembourg filer obligations arise from the Luxembourg law and its implementing measures; DAC8 supplies the EU framework, while OECD materials are technical and interpretative sources to the extent relevant to the Luxembourg implementation.
Who must report: reporting crypto-asset service providers and the Luxembourg nexus
The reporting obligation first requires the provider to be a Reporting Crypto-Asset Service Provider: a Crypto-Asset Service Provider or Crypto-Asset Operator that conducts one or more Crypto-Asset Services effectuating Exchange Transactions for or on behalf of a Reportable User. Luxembourg nexus is then tested separately. A Reporting Crypto-Asset Service Provider is subject in Luxembourg where it is authorised by the CSSF under MiCA Article 63 or permitted to provide crypto-asset services following an Article 60 notification to the CSSF. A non-MiCA provider may instead be subject through tax residence in Luxembourg; incorporation or organisation under Luxembourg law together with legal personality in Luxembourg or an obligation to file tax or tax-information returns there in respect of the entity’s income; management from Luxembourg; a regular place of business in Luxembourg; or, for relevant transactions, a branch established in Luxembourg, subject to the applicable duplicate-reporting reliefs.
A non-MiCA Crypto-Asset Operator must meet the definition of a Reporting Crypto-Asset Service Provider and one of the applicable jurisdictional nexus tests before the Luxembourg obligation arises; EU-resident users alone do not create that nexus. Where a Crypto-Asset Operator is subject under the non-MiCA rules, DAC8 requires single registration in one Member State. Under the currently applicable Directive, the registration exception applies where the relevant reporting and due-diligence obligations are completed in another Member State; a pending Commission recast proposal would extend that exception to a Qualified Non-Union Jurisdiction, but that proposal is not yet binding. MiCA Crypto-Asset Service Providers do not register separately with the ACD, as the ACD expressly confirms.
Being a crypto-asset service provider under MiCA and being a Reporting Crypto-Asset Service Provider under DAC8 are related but not identical questions, and a firm can answer yes to one and still need to test the other. The registration route decides how a provider tells the ACD it exists; it does not decide whether the reporting duty applies. For the perimeter around who counts as a service provider in the first place, our guide to MiCA reporting obligations maps the authorisation categories that the first route relies on.
What the report contains: reportable users and the eight transaction categories
A CARF return has two halves: who the user is, and what they did. The identification block includes name, address, tax-residence and TIN information, together with specified birth data for individuals, but is governed by the CARF reporting rules. Subject to the Identification Service exception, for each Reportable User the provider reports name, address, jurisdiction or jurisdictions of residence, tax identification number and, for an individual, date and place of birth. Where the provider relies on direct confirmation of identity and tax residence through an Identification Service made available by a Member State or the Union, the alternative identification fields specified by the CARF rules apply. Where an entity user has one or more controlling persons who are reportable, the provider reports the entity’s details plus each controlling person’s identification data and the role by virtue of which that person controls the entity. The provider also reports its own identifying data: name, address and TIN, plus, where available, the individual identification number referred to in DAC8 and its global legal entity identifier.
The transaction half is reported per type of Reportable Crypto-Asset, on an aggregate basis rather than transaction by transaction. For each type the provider reports its full name and then a fixed set of aggregates covering the calendar year:
- Acquisitions against fiat currency: aggregate gross amount paid, aggregate number of units, and the number of reportable transactions.
- Disposals against fiat currency: aggregate gross amount received, number of units, and number of transactions.
- Acquisitions against other reportable crypto-assets: aggregate fair market value, number of units, and number of transactions.
- Disposals against other reportable crypto-assets: aggregate fair market value, number of units, and number of transactions.
- Reportable retail payment transactions: aggregate fair market value, number of units, and number of transactions.
- Transfers to the reportable user not already captured as acquisitions against fiat currency or other reportable crypto-assets: aggregate fair market value, aggregate number of units and number of reportable transactions, subdivided by transfer type where the provider knows it.
- Transfers by the reportable user not already captured as disposals against fiat currency, disposals against other reportable crypto-assets or reportable retail payment transactions: aggregate fair market value, aggregate number of units and number of reportable transactions, subdivided by transfer type where known.
- Transfers the provider makes to distributed-ledger addresses not known to be associated with a virtual-asset service provider or a financial institution: aggregate fair market value and number of units.
Two definitions govern what falls in the net. A Reportable Crypto-Asset is any crypto-asset other than a central bank digital currency, electronic money, or a crypto-asset for which the provider has adequately determined that it cannot be used for payment or investment purposes. A Reportable Retail Payment Transaction is a transfer of Reportable Crypto-Assets in consideration for goods or services with a value exceeding USD 50,000, or the equivalent in another currency. Where a Reporting Crypto-Asset Service Provider effectuates such transactions for or on behalf of a merchant, it also treats the merchant’s customer as the Crypto-Asset User for that transaction only where the provider is required under the applicable anti-money-laundering rules to verify that customer’s identity. Fiat amounts are reported in the currency in which they were paid or received, or converted to a single currency applied consistently; fair-market-value figures are likewise stated in a single currency valued at the time of each transaction.
Deadlines: the 30 June filing and the first 2026 reference year
The reference period is the calendar year, and the regime runs from calendar year 2026 because DAC8 requires Member States to apply the crypto-asset provisions from 1 January 2026. That start date is the load-bearing one: it means data capture, not filing, is the 2026 task.
The ACD sets the filing deadline for providers at 30 June of the year following the year to which the information relates. The first return, covering 2026, is therefore due by 30 June 2027, and the same date recurs annually. Separately, the amended Directive requires the competent authority to exchange the information with other Member States within nine months following the end of the calendar year, which places the first ACD-to-Member-State exchange by 30 September 2027. A filer’s own hard date is 30 June; the 30 September date is the ACD’s onward obligation and explains why the national deadline sits where it does.
Writing the deadline as a fixed rule rather than a moving quarter keeps a project plan honest: the year now being lived is always due by 30 June of the next year, and the reference period is always the full preceding calendar year.
Submission channel and format: the CARF XML schema and the ACD transfer
The ACD links to the OECD CARF XML Schema as a reference but has not yet published Luxembourg’s data-transfer arrangements. The current OECD CARF XML Schema and User Guide are the July 2025 update. They are designed for exchanges between competent authorities, although the OECD states that jurisdictions may also choose to use the schema domestically.
On the Luxembourg-specific mechanics, the ACD’s own pages are explicit that detail is still to come. The ACD states that the registration steps and the arrangements for transferring the data will be communicated at a later date. That means the exact portal, the file-naming convention and the resubmission or correction rules are not yet fixed in the published Luxembourg sources, and this article does not infer them. The ACD gives a functional mailbox, dac8@co.etat.lu, as the contact point for the regime while that guidance is prepared.
Validation rules and the rejection risks Luxembourg has not yet detailed
The ACD has not yet published Luxembourg’s CARF data-transfer arrangements or CARF-specific validation rules. The OECD’s July 2025 CARF XML Schema and User Guide provide the schema used for international CARF exchanges and note that jurisdictions may choose to use it domestically, but they do not by themselves establish the mandatory Luxembourg domestic filing format or the ACD’s rejection rules.
Luxembourg’s own business-rule validations and the technical documentation that lists them are not yet published. A team that has filed CRS or DAC7 through the ACD will recognise the shape of what tends to fail across automatic-exchange returns, such as missing or malformed TINs and unresolved residence data, but treating those CRS patterns as confirmed CARF-LU validation rules would be an assumption rather than a sourced fact. The safer planning posture is to watch the ACD page for the Luxembourg data-transfer format and validation rule set when it is published.
Caveats and interactions: MiCA authorisation, CRS overlap and non-EU relief
CARF does not stand alone, and three interactions change how a filer scopes the work. The first interaction is MiCA. A firm should first determine whether it meets the definition of a Reporting Crypto-Asset Service Provider and is subject to the Luxembourg reporting rules. MiCA status then determines the relevant Luxembourg nexus and whether separate ACD registration is required. The DAC7 regime for Luxembourg platform operators uses a separate single-registration mechanism for certain platform operators. It is operationally analogous, but DAC8 scope and nexus must be tested under the crypto-asset rules rather than inferred from DAC7.
The second is the CRS overlap. Because the Law of 27 March 2026 also amends the Common Reporting Standard law, the same customer relationship may give rise to reporting under both regimes where their respective scope conditions are met. A Reporting Crypto-Asset Service Provider that is also a Financial Institution may rely on specified CRS due-diligence procedures, and an existing tax self-certification may be reused only where it satisfies the CARF requirements. Firms that already run automatic-exchange reporting processes may find CARF operationally familiar, but the Luxembourg collection authority differs by regime: CARF is reported to the ACD, whereas CESOP payment data is submitted through the Administration de l’enregistrement, des domaines et de la TVA (AED).
The third is the non-EU relief and the enforcement backstop. DAC8 requires Member States to set a record-retention period of between five and ten years, but Luxembourg has fixed the period at ten years from 31 December of the calendar year in which the information must be reported. Where a user fails to supply the required information after two reminders, the provider must prevent that user from carrying out Reportable Transactions after 60 days have elapsed from the initial request. DAC8 also allows a crypto-asset operator to report EU-resident users to a qualifying non-Union jurisdiction instead of a Member State where an effective qualifying competent authority agreement is in place and the information corresponds, which prevents the same data being reported twice. The ACD also sets out the sanctions: a flat fine of EUR 5,000 for a Crypto-Asset Operator that fails to register, to notify changes in time, or registers incorrect or incomplete information, and the same flat fine for a provider that misses the filing deadline; a fine of up to EUR 250,000 applies where a control finds the due-diligence or reporting obligations were not met, other than the deadline itself. A provider fined by the ACD may appeal to the administrative tribunal.
Recent and upcoming changes: transposition done, registration detail pending
Luxembourg’s DAC8 transposition is enacted and in force, but EU legislative work is not closed: the Commission’s 24 June 2026 proposal to recast the Directive on administrative cooperation remains pending and is not yet binding. The Law of 27 March 2026 was published in Mémorial A No. 144 of 27 March 2026, and the implementing grand-ducal regulation of 18 May 2026 appeared in Mémorial A No. 245. With those in place, Luxembourg’s CARF framework applies from the 2026 calendar year in line with the DAC8 start date.
What remains open is operational rather than legal. The ACD has flagged that the registration procedures for in-scope operators and the data-transfer arrangements will be communicated later, so the practical enrolment and filing steps are the pieces to track through 2026 and into the first half of 2027. At EU level, Commission Implementing Regulation (EU) 2025/2263 applies from 1 January 2026 and sets the practical arrangements for the Crypto-Asset Operator register, including the registration information format and individual identification number. Luxembourg’s own ACD registration steps and domestic data-transfer procedures remain to be communicated. The next dated filing milestone for a Luxembourg Reporting Crypto-Asset Service Provider is the first return on 30 June 2027; 30 September 2027 is the ACD’s deadline for the first onward exchange.
Frequently Asked Questions
If a provider is authorised under MiCA and does not register separately for CARF, does it still have to file?
Not by reason of MiCA authorisation alone. A MiCA-authorised firm does not register separately under DAC8, but it is a Reporting Crypto-Asset Service Provider only if it meets the Annex VI definition, including conducting Crypto-Asset Services that effectuate Exchange Transactions for or on behalf of a Reportable User. Where it meets that definition and the applicable Luxembourg nexus, the reporting and due-diligence duties apply even though separate ACD registration is not required.
Are stablecoins and e-money tokens reportable crypto-assets?
The definition of a Reportable Crypto-Asset excludes electronic money and central bank digital currencies, so a token that qualifies as electronic money falls outside the reportable set on that basis. Whether a specific token is treated as electronic money, and therefore excluded, depends on that determination for the token in question rather than on its marketing label.
What happens if a user never provides a self-certification?
Annex VI requires the provider to send at least two reminders after the initial request. If the user still fails to supply the information and at least 60 days have passed, the provider must prevent the user from performing reportable transactions. The obligation is a hard block, not a discretionary one.
Is there a nil return where a provider had no reportable users in the year?
Yes. Where there are no Reportable Crypto-Asset Users, including where an entity user’s Controlling Persons are not Reportable Persons, a Reporting Crypto-Asset Service Provider must submit a zero-value message to the ACD by 30 June of the following year.
Which currency should the transaction aggregates be reported in?
Fiat amounts are reported in the currency in which they were paid or received; where multiple fiat currencies are involved, they are converted to a single currency at the time of each transaction using a method the provider applies consistently. Fair-market-value figures, including for crypto-to-crypto and retail payment transactions, are stated in a single currency valued at the time of each transaction.
Does a CARF report replace a user’s own tax return?
Not as a matter of the CARF reporting rules. Luxembourg’s CARF regime imposes due-diligence and reporting obligations on Reporting Crypto-Asset Service Providers, and the ACD exchanges reportable information with the competent authorities of Reportable Jurisdictions. Any separate tax-return obligation of the user is determined under the tax law applicable to that user.
Related Articles
- CRS Reporting in Luxembourg: how financial institutions run Common Reporting Standard due diligence and file with the ACD, the machinery CARF intersects with for user identification.
- DAC7 Reporting for Luxembourg Platform Operators: the sibling exchange regime and its single-registration model for operators without a domestic establishment.
- CESOP Reporting for Luxembourg Payment Providers: the cross-border payment dataset submitted in Luxembourg through the Administration de l’enregistrement, des domaines et de la TVA (AED).
- FATCA Reporting in Luxembourg: the US account-holder exchange that predates CRS and CARF and shares their due-diligence logic.
- MiCA Reporting Obligations: the authorisation categories that determine whether a firm is a crypto-asset service provider and its relevant Luxembourg nexus under the first reporting route.
Key Takeaways
- Confirm first whether the firm meets the Reporting Crypto-Asset Service Provider definition and the Luxembourg nexus; MiCA status then determines whether separate ACD registration is required.
- The first data build is calendar year 2026; the first return is due to the ACD by 30 June 2027, with annual filing on 30 June thereafter.
- Capture CARF-required self-certifications and jurisdiction of residence during the year; for pre-existing users, self-certification must be obtained by 1 January 2027.
- Build the transaction layer as per-crypto-asset aggregates, including Reportable Retail Payment Transactions above USD 50,000 and transfers made to distributed-ledger addresses not known to be associated with a virtual-asset service provider or financial institution.
- Retain the records of due-diligence steps and information relied on for ten years from 31 December of the calendar year in which the information must be reported, and apply the two-reminder, 60-day block where a user withholds required information.
- A non-MiCA Crypto-Asset Operator that meets the Reporting Crypto-Asset Service Provider definition and an applicable Member-State nexus is subject to the DAC8 single-registration rules. Under the currently applicable Directive, qualifying non-Union-jurisdiction relief may affect reporting and due-diligence obligations but does not by itself remove the Union registration requirement.
- Watch the ACD Cadre de déclaration des Crypto-actifs page for the registration steps, data-transfer channel and Luxembourg validation rules, which are not yet published.
Sources and References
- Administration des contributions directes, Cadre de déclaration des Crypto-actifs (CDC) / Crypto-Asset Reporting Framework (CARF) (filing deadline, first reporting period, mandatory zero reporting, registration and data-transfer status, contact).
- Administration des contributions directes, Legislation 2026 (Law of 27 March 2026, Mémorial A No. 144; grand-ducal regulation of 18 May 2026, Mémorial A No. 245).
- Administration des contributions directes, international information-exchange framework (DAC1 to DAC8).
- Council Directive (EU) 2023/2226 of 17 October 2023 (DAC8), including Annex VI reporting requirements and due-diligence procedures.
- Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA), Articles 60 and 63.
- Commission Implementing Regulation (EU) 2025/2263 of 12 November 2025 (Crypto-Asset Operator register practical arrangements, applying from 1 January 2026).
- OECD, Crypto-Asset Reporting Framework XML Schema and User Guide (July 2025).
- OECD, Frequently Asked Questions on the Crypto-Asset Reporting Framework.
What to put on the CARF-LU project plan now
The regime is enacted and the calendar is fixed, so the work is operational readiness for a 30 June 2027 first return covering 2026 activity. The two concrete artifacts to produce are a due-diligence process that captures CARF-required self-certifications and jurisdiction-of-residence data on users during 2026, and a transaction-aggregation build that captures the required per-crypto-asset data elements while keeping the submission-output layer adaptable until the ACD publishes the Luxembourg data-transfer format. The open item to track is the ACD’s registration and data-transfer guidance under the Cadre de déclaration des Crypto-actifs, which will fix the enrolment step and the Luxembourg validation rules before the first filing window.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
