Skip to content
UK MarketsIndependent UK news, policy and video briefings from @OneGenMedia
OGM OneGeneration News | OGMUK news, policy, and video briefings powered by @OneGenMedia Subscribe @OneGenMedia

Cryptoasset Reporting Framework UK: What CARF Means for Platforms and Users

UK Cryptoasset Reporting Framework, secure provider reporting data and regulatory context editorial illustration
UK Cryptoasset Reporting Framework, secure provider reporting data and regulatory context editorial illustration

What the Cryptoasset Reporting Framework UK is

The Cryptoasset Reporting Framework UK is the UK implementation of an international data-exchange standard that requires certain businesses providing cryptoasset services to collect, retain and report specified information about their users and user transactions to HM Revenue & Customs (HMRC). The phrase Cryptoasset Reporting Framework UK will be used throughout this article to denote the UK statutory framework and the practical reporting route set out by HMRC, the secondary legislation that gives it effect in UK law and the published agency materials that explain provider duties.

The scope and mechanics of the Cryptoasset Reporting Framework UK are not a statement about any person’s tax liability. Instead, the framework defines obligations for businesses that meet the statutory definition of a UK reporting cryptoasset service provider; it sets the form, timing and content of provider reports to HMRC; and it establishes certain due-diligence, record-keeping and notification duties for those providers. This article explains those published duties and where they sit in relation to separate UK regulatory activity in the crypto sector.

For the avoidance of doubt: the term Cryptoasset Reporting Framework UK, as used here, refers to the UK rules and guidance that govern which provider businesses must prepare and transmit data to HMRC, what data they must keep and report, and the timetable and format in which that transmission must take place. The framework is implemented in secondary legislation and supported by HMRC’s operational guidance on reporting.

Where this article cites published HMRC or statutory material it does so to describe provider duties and public deadlines only. It does not provide a personalised reading of an individual’s tax obligations arising from entries in any provider report, nor does it advise on tax, legal, financial or compliance matters. Read the official guidance at HMRC’s published page on reporting cryptoasset user and transaction data for the primary operational detail: https://www.gov.uk/guidance/reporting-cryptoasset-user-and-transaction-data.

Key statutory dates and what each date describes

The framework in the UK sits on two complementary pillars of public material: the secondary legislation that established provider duties and the HMRC operational guidance that sets out how and when those duties are to be carried out. The legislation and guidance together produce a set of key dates that apply to providers and to the first reporting cycle under the Cryptoasset Reporting Framework UK.

At a glance, the headline dates under the framework that are set out in statute and guidance are listed below and explained in the following paragraphs. The short descriptive table that follows compares the two most frequently referenced years, 2026 and 2027, and the actions associated with each.

Year Relevant action under the Cryptoasset Reporting Framework UK
2026 Reporting year: providers collect data for the calendar year 1 January 2026 to 31 December 2026, as described in HMRC guidance and the regulations.
2027 First report submission window: providers submit the first report for 2026 between 1 January 2027 and 31 May 2027; provider notification to reportable persons for first year is due on or before 31 January 2027.

The legislative instrument that sets out provider duties was made on 24 June 2025 and entered into force on 1 January 2026. That instrument is available in full as secondary legislation; the statutory text describes the legal definition of a UK reporting cryptoasset service provider and the categories of due-diligence, record-keeping, reporting, notification and registration requirements that follow from that definition. The statutory instrument can be consulted at the official legislation website: https://www.legislation.gov.uk/uksi/2025/744.

HMRC’s published operational guidance clarifies how reports will be submitted, what they contain and the timing for the first filing and subsequent annual filings. HMRC states that the first report will be supplied during the period 1 January 2027 to 31 May 2027 and will cover the calendar year 1 January 2026 to 31 December 2026. From the second reporting year onwards, subsequent reports are due by 31 May for the previous calendar year. The HMRC reporting guidance provides the detailed operational description: https://www.gov.uk/guidance/reporting-cryptoasset-user-and-transaction-data.

Those statutory and guidance dates mean that calendar-year data collection for the period 2026 is the basis for the first set of electronic reports to HMRC in early 2027. The legislation’s commencement and the reporting timetable are therefore distinct items: the regulations came into force on 1 January 2026 and HMRC’s guidance sets the reporting window for the first report as between 1 January 2027 and 31 May 2027, with later years repeating the annual 31 May deadline for the preceding calendar year.

It is important to treat those dates as descriptive facts about the framework’s schedule rather than as a template for individual tax or compliance action. The statutory instrument sets provider duties; HMRC sets the reporting form and timetable; and the dates above describe the first and subsequent filing periods under the Cryptoasset Reporting Framework UK.

Who the framework addresses

The Cryptoasset Reporting Framework UK addresses businesses that meet the statutory definition of a UK reporting cryptoasset service provider under the applicable regulations. The regulations define that category of provider by reference to the CARF rules and impose the attendant duties on businesses that fall within that legal definition.

The public wording in the statutory instrument and HMRC’s guidance frames the obligations in provider terms: it is businesses providing cryptoasset services in the UK that must collect user data, apply specified due diligence, keep provider records and, if the provider has reportable information, transmit that information to HMRC. The framework distinguishes between data collection (which may cover all users) and the subset of users whose information will be reported to HMRC (which is limited to particular tax residencies). HMRC’s guidance explains this provider-level distinction: https://www.gov.uk/guidance/reporting-cryptoasset-user-and-transaction-data.

The regulations and guidance do not alter the separate supervisory framework for cryptoasset activity that sits with regulators; they are focused on data collection, reporting and record retention. The FCA, for example, has published a separate and distinct programme of regulatory work on cryptoassets and related firms; the FCA commentary is available at the regulator’s public page: https://www.fca.org.uk/firms/new-regime-cryptoasset-regulation.

When reading the statutory and guidance text it is useful to hold three things in mind simultaneously: first, that the Cryptoasset Reporting Framework UK sets duties for businesses that meet the statutory definition of providers; second, that the provider duties focus on information collection, retention and reporting; and third, that the framework limits the set of users whose information is reported to HMRC to those tax resident in the UK or another jurisdiction that has adopted CARF and is within scope for exchange under the framework.

What providers collect and what they report

Published HMRC guidance makes a clear operational distinction between the data providers are expected to collect and the subset of that data that providers will report to HMRC under the Cryptoasset Reporting Framework UK. The guidance emphasises that providers typically collect details for all users in the ordinary course of business, but they report only on users who are tax resident in the UK or in another jurisdiction signed up to CARF rules and therefore reportable under the framework.

In HMRC’s operational description the reporting content covers user identifying details and a summary of transactions. HMRC describes the report as an XML file transmitted through the online reporting service that HMRC will provide. File-size constraints and the electronic format are specified in HMRC’s guidance and are discussed further in this article.

HMRC’s guidance also explains the ‘no information’ position: if a provider has no information to report for a given reporting year, it does not submit a report for that year. That point is important because the framework is framed around the duty to report reportable data, not around a blanket filing obligation where no reportable data exists. See HMRC for the official wording: https://www.gov.uk/guidance/reporting-cryptoasset-user-and-transaction-data.

The distinction between collection and reporting under the Cryptoasset Reporting Framework UK can be summarised in neutral terms:

  • Collection: providers gather and retain user and transaction details as part of their business processes.
  • Reporting: providers transmit a subset of collected data—only information on users who are reportable under the CARF definition—to HMRC in an electronic file, following HMRC directions.

HMRC’s publicly available guidance lists the operational items providers should expect to transmit and the format requirements for transmission. The guidance also notes potential penalties in the event of failure to file a report, late filing, or where a report is inaccurate, incomplete or unverified. That guidance includes a statement that a penalty of up to £300 per user may apply in such circumstances, and HMRC presents that as its published approach to compliance and enforcement for providers. This article repeats that published guidance purely as a description of HMRC’s stated position; it is not an assessment or an attempt to forecast or interpret any individual liability.

Why a report is not an individual tax determination

A core purpose of the Cryptoasset Reporting Framework UK is data exchange: to enable competent authorities to identify and exchange information about certain users and their transactions across jurisdictions that participate in the international CARF standard. The presence of a person’s details in a provider report does not itself make or determine any tax outcome for that person. It is simply a transfer of information from a provider to HMRC that may be used by HMRC in the course of its own enquiries or cross-border information exchanges.

There are several neutral, factual reasons why a provider report should not be read as an individual tax determination:

  • Different purposes: the provider report is primarily an administrative transfer of user and transaction data to HMRC as part of the CARF data-exchange process. Determination of tax liabilities remains a separate matter for tax authorities and for the application of domestic tax law.
  • Different standards and processes: a provider’s duty is to collect and report specified data according to defined technical and due-diligence rules. Tax assessments, if any, would be made under domestic tax law and processes, which have separate evidential and substantive standards.
  • Limited content: HMRC’s guidance explains that providers report user details and a summary of transactions. That is a defined dataset rather than a full accounting or adjudication of taxable gains or losses for an individual under tax law.

It follows from those points that appearing in a provider report should be understood as inclusion in a data set transmitted to HMRC, not as the receipt of a tax assessment or determination. The statutory and operational documents that comprise the Cryptoasset Reporting Framework UK describe provider duties and the mechanics of reporting; they do not make tax liability determinations for the subjects of those reports.

Provider record-keeping under the regulations

The secondary legislation that implements the Cryptoasset Reporting Framework UK sets out provider record-keeping obligations as an integral part of the duties imposed on in-scope businesses. The regulations require providers to establish and maintain appropriate arrangements for applying specified due-diligence procedures. Providers are to keep a record of the steps they have taken and the information collected under those procedures.

The regulations also specify the retention period for those provider records. As stated in the regulatory text, provider records are to be kept for five years beginning after the end of the relevant calendar year. That is a statutory retention period that follows from the regulations and forms a central part of the record-keeping duties to which providers are subject under the Cryptoasset Reporting Framework UK. The full regulatory text is available at the UK legislation site: https://www.legislation.gov.uk/uksi/2025/744.

The requirement to retain the record of steps taken and information collected is separate from the requirement to file a report with HMRC. In practice, the regulations make record-keeping a contemporaneous part of the due-diligence process: providers must maintain the evidence that they followed the required procedures and must retain that evidence for the five-year statutory period after the end of the corresponding calendar year.

Readers should note that these statutory retention obligations apply to providers as specified in the legislation; they are not a compulsory instruction for individuals or non-provider entities. The legislation frames the duty in provider terms and sets the retention period in the regulation itself. Any further operational detail about format, location or access to such records is a matter for the provider to manage in accordance with the regulatory requirement to maintain and preserve those provider records for the stated period.

User notification and international exchange context

The regulations include a notification duty that applies where a report will include information on a reportable user or reportable person. Where a provider expects to include a person’s information in a report to HMRC, the provider must notify that person that the information will be reported to HMRC and may be transferred to the competent authority of another jurisdiction under CARF.

For the first reporting year, the regulations set an explicit deadline for that notification: it is due on or before 31 January 2027. That deadline applies to providers in scope and relates to the first reporting window and first set of exchanges under the Cryptoasset Reporting Framework UK.

The notification requirement is part of the wider international context in which CARF operates. CARF is an international standard for the exchange of cryptoasset user and transaction data between participating jurisdictions. The UK’s Cryptoasset Reporting Framework UK is the domestic implementation that aligns the reporting duties for UK providers with that international standard. Under the international CARF model, information may be transferred between competent authorities in different jurisdictions where both are participants in the standard. HMRC’s guidance on reporting makes this international exchange context explicit and explains that reported information may be transferred beyond the UK in line with CARF.

Again, it is important to emphasise that the notification duty is a provider duty set out in the statutory instrument. That duty requires the provider to inform the reportable person that the person’s information will be reported and may be exchanged internationally; the regulation prescribes the timing of that notification for the first reporting year. The notification is thus a statutory step in the data-exchange process and is not an adjudication of tax liability.

Electronic submission, XML and the published HMRC service status

HMRC’s public guidance on the practical operation of the Cryptoasset Reporting Framework UK sets out the electronic nature of provider submissions. HMRC states that the report is submitted as an XML file and that the online reporting service is not yet live. The guidance also specifies a maximum file size of 250MB for the XML transmission. Those are concrete operational details drawn from the HMRC guidance and should be read in the context of HMRC’s ongoing IT and process development.

The technical specification for the XML file and the precise mechanics of submission will be the subject of HMRC operational directions. HMRC has stated publicly that its reporting service is not live at present, and that submissions will be electronic and in XML format when the service is enabled. Providers should therefore expect HMRC to publish further operational direction as the service becomes available. For the published HMRC guidance on this point see: https://www.gov.uk/guidance/reporting-cryptoasset-user-and-transaction-data.

The legislative regulations require that provider reports be made electronically and under directions from HMRC. The statutory deadline to make the report is on or before 31 May following the calendar year, and the guidance about the file format, maximum file size and service availability is provided by HMRC. The combination of statutory instruction and operational guidance is the structure through which the Cryptoasset Reporting Framework UK will be applied in practice.

CARF reporting and the FCA’s separate cryptoasset regime

It is important to distinguish the data-reporting framework that CARF establishes from the separate regulatory regime being implemented by the Financial Conduct Authority (FCA) in the UK. The Cryptoasset Reporting Framework UK is focused on data collection, due diligence and the reporting of certain user and transaction information to HMRC under an international exchange standard. By contrast, the FCA’s programme concerns the regulatory permissions, rules and supervision applied to firms carrying out certain cryptoasset activities under the Financial Services and Markets Act (FSMA) and associated instruments.

The FCA has publicly stated procedural milestones and timing in relation to its work on cryptoasset regulation. On 30 June 2026 the FCA published final rules and guidance that the FCA says will apply to cryptoasset firms granted permission under FSMA on or after 25 October 2027. The FCA expects its new regime to come into force on 25 October 2027. The FCA’s public description of that timetable and those rules is available from the regulator’s website: https://www.fca.org.uk/firms/new-regime-cryptoasset-regulation.

The key point for readers is that CARF reporting and FCA regulation are separate frameworks. CARF reporting duties are statutory reporting and record-keeping duties for providers that fall within the UK reporting cryptoasset service provider definition; they relate to the collection and transmission of user and transaction data to HMRC. FCA regulatory activity concerns the permissions, conduct and prudential frameworks that the regulator applies to firms acting within its remit. The two regimes may apply to overlapping sets of businesses, but they operate under different legal bases, different objectives and different supervisory authorities.

Readers seeking detailed commentary on the FCA’s programme should consult the FCA’s own publications. For background on the broader regulatory context in the UK, OGM has published explainer pieces on the UK crypto regulatory programme and specific topics within it; those items are linked in the Related OGM Crypto coverage section below and should be read alongside the primary material for CARF reporting itself.

Common wording that can be misunderstood

Public pronouncements and technical descriptions of the Cryptoasset Reporting Framework UK contain specific phrases that are sometimes read in ways not intended by the legislation or HMRC guidance. The paragraphs below highlight a number of those commonly misunderstood phrases and explain, in neutral factual terms, what the published materials actually say.

“Provider collects details of all users”

What the guidance says: providers typically collect data for all users in the ordinary course of their business operations. What this does not mean: that all users’ information will be transmitted to HMRC. HMRC’s guidance clarifies that only users who are tax resident in the UK or in another CARF signatory jurisdiction are reportable and therefore the only users whose information will be transferred under the CARF reporting mechanism.

“Reportable user” or “reportable person”

What the guidance says: these are persons whose tax residency falls within the categories that trigger reporting under the CARF rules. What this does not mean: that the person’s presence in a report represents any tax assessment or conclusion. It is a description of the person’s inclusion in the dataset that will be transmitted to HMRC, based on the provider’s application of the due-diligence procedures.

“Report submitted between 1 January and 31 May 2027”

What the guidance says: the first report covering the 2026 calendar year is to be submitted in that window. What this does not mean: that the legislation or HMRC guidance has created a new form of tax return for individuals. The dates are an administrative timetable for provider submission of data to HMRC under the reporting framework.

“Penalty of up to £300 per user”

What the guidance says: HMRC’s guidance presents a published approach to potential penalties where a provider’s report is not submitted or is late, inaccurate, incomplete or unverified. What this does not mean: that the guidance here is any sort of legal determination of liability for any individual. The penalty wording is a statement of HMRC’s enforcement position as described in the guidance and applies to providers as the enforcement target, not as an automatic tax adjudication for users whose data appear in a report.

Reading the precise statutory and guidance wording with the distinctions above in mind reduces the risk of conflating administrative reporting duties and data transfers with decisions about an individual’s tax position.

A neutral reading framework for public announcements

Public announcements from providers, government agencies or regulators about the Cryptoasset Reporting Framework UK can include a mixture of technical description, operational detail and forward-looking scheduling. To read such material neutrally and without over-interpretation, it is useful to apply a short checklist-type approach focused on the nature of the statement, not on any particular action.

  • Identify the source: check whether the statement is legislative text, HMRC operational guidance, regulatory commentary or a provider announcement.
  • Identify the subject: is the statement about collection, reporting, record-keeping, notification or registration? These are distinct duties under the Cryptoasset Reporting Framework UK and should be read on their own terms.
  • Check the dates: distinguish between the calendar year covered, the statutory commencement date, the reporting window and the notification deadlines. The primary statutory dates are the regulations’ commencement on 1 January 2026, the 2026 calendar year that forms the first reporting year, and the first report window between 1 January and 31 May 2027, with a notification deadline of on or before 31 January 2027 for the first year.
  • Look for procedural detail: HMRC has stated that the report will be an XML file, that the online reporting service is not yet live, and that the maximum file size is 250MB. That is operational detail rather than a substantive tax ruling.
  • Separate data transfer from liability: if a statement concerns inclusion in or transmission of data, remember that the transfer is not itself a determination of tax or legal liability for the person whose data are included.

Using that neutral reading framework when assessing announcements will help avoid conflating provider duties with individual tax consequences, and will keep the focus on the published mechanics and timelines that underpin the Cryptoasset Reporting Framework UK.

What the official material does not decide for a reader

The regulations and HMRC guidance that implement the Cryptoasset Reporting Framework UK define provider duties and reporting mechanics. There are, however, a number of matters that the official material does not decide for an individual reader. The bullet list below summarises those boundaries explicitly and neutrally.

  • The official material does not itself determine whether any individual taxpayer owes tax, how much tax they owe, or the precise tax treatment of particular holdings or transactions under domestic tax law. Those matters remain for the application of UK tax legislation and for HMRC’s tax administration processes where relevant.
  • The official material does not provide personalised tax, legal, financial, investment or compliance advice. It sets provider duties and reporting mechanics; interpreting the effect of reported data on an individual’s tax position would require applying tax law and assessing individual circumstances, which is outside the scope of the statutory reporting texts and HMRC’s reporting guidance.
  • The regulations do not prescribe provider workflows beyond the statutory requirement to apply specified due-diligence procedures, retain records for five years after the calendar year to which they relate, notify reportable persons in respect of information that will be included in a report, and file the electronic report as directed by HMRC. Operational details about how providers design internal processes to satisfy those duties are matters for the providers themselves.
  • The HMRC guidance does not constitute a final statement about enforcement outcomes for any particular case. It sets out HMRC’s approach to submissions, technical format and the potential for penalties in the circumstances described in the guidance, but HMRC’s guidance is about process and compliance posture rather than adjudication of individual liabilities.
  • The published material does not mean that inclusion of a person’s details in a provider report is evidence that a tax liability exists or that no liability exists. Inclusion in a report is a data-transfer event within the CARF information-exchange framework.

Readers who want to understand the implications of reported data in the context of their own personal affairs should treat the official material as an explanation of provider duties and an indication of the processes HMRC will use to receive data, not as an adjudication of individual tax liability. The legal liability questions remain matters for the relevant tax legislation and HMRC’s law-applied processes.

How the first reporting cycle is structured

The Reporting Cryptoasset Service Providers (Due Diligence and Reporting Requirements) Regulations 2025 came into force on 1 January 2026. Those regulations place specific duties on UK reporting cryptoasset service providers to establish and maintain due-diligence and record-keeping arrangements, to notify affected users in certain circumstances, and to submit annual electronic reports to HM Revenue & Customs (HMRC) in the format and by the dates set out in the rules.

For practical timing, the first statutory reporting cycle under these Regulations covers the calendar year 1 January 2026 to 31 December 2026. A provider’s first annual report against that cycle must be submitted to HMRC electronically on or before 31 May 2027; the rules make clear that the reporting window for that first return runs from 1 January 2027 through 31 May 2027. Thereafter, the routine structure is that each later report is due by 31 May following the preceding calendar year.

HMRC has said that its online service for these reports is not live yet, and that when providers do submit they will send XML files with a maximum file size of 250MB. HMRC also says that providers collect details of all users but report only users who are tax resident in the UK or in another jurisdiction that has adopted CARF rules, and that reports include a summary of transactions for reported users. If a provider has no information to report in a year, the rules specify that it does not submit a report for that year.

The statutory regime for reporting under the Regulations is separate from other regulatory frameworks that apply to cryptoasset activity. HM Treasury and the Financial Conduct Authority have set out a distinct timetable for a separate FCA cryptoasset regime that is expected to come into force on 25 October 2027; that is a separate schedule and does not alter the CARF reporting calendar set out above.

Notifications and the distinction between reporting and notification

The Regulations require a formal distinction between notification to a person and the act of reporting information to HMRC. If a provider’s report will include information about a reportable user or reportable person, the provider must notify that person in advance that the information will be reported to HMRC and that it may be transferred to the competent authority of another jurisdiction under CARF. For the first reporting year, that notification is due on or before 31 January 2027.

What “notification” means in this context

Notification is a discrete legal step: it is the provider informing the individual or entity that their information will be reported. It is separate from the electronic transmission of the report to HMRC. The notification requirement therefore sits earlier in the administrative sequence for the first year: where a provider will include a person’s details in the 2026 report, the provider must issue the required notification by the 31 January 2027 date, and then the provider’s report must be submitted to HMRC during the 1 January–31 May 2027 reporting window.

What “reporting” means in this context

Reporting is the transmission of the provider’s annual file to HMRC in the prescribed electronic format. HMRC’s statements indicate that providers should expect to submit XML files and that the online service for doing so is not yet available. The file-size cap HMRC has stated for those XML reports is 250MB. If a provider concludes that it has no information to report for a given calendar year, the Regulations set out that the provider does not submit an annual report for that year.

It is important to keep the two steps distinct in planning or in reading the law: notification is a required communication to an affected person where their data will be included; reporting is the statutory transmission of the provider’s dataset to HMRC for the calendar year. Neither the act of notification nor the act of reporting carries an automatic determination of a person’s tax status by itself. Provider data reporting does not itself determine any individual’s tax position.

What the statutes describe about provider records

The Regulations obligate providers to establish and maintain arrangements to apply the specified due-diligence procedures. Those arrangements are to be documented: providers must keep a record of the steps taken under due diligence and of the information collected in the course of those procedures. The statutory text requires that those provider records be retained for five years beginning after the end of the relevant calendar year.

Put plainly, for activity falling in the 2026 calendar year a provider must retain the records that document the due-diligence steps and the information collected for five years starting after 31 December 2026. That retention requirement is an express feature of the Regulations and applies to the provider records described in the statutory duty to keep a record of steps taken and information collected.

The Regulations frame these record-keeping duties alongside the wider obligations to carry out due diligence, to notify affected persons where reporting will include their details, and to register or be otherwise recognised as a reporting provider where the CARF rules require it. The statutory approach is to make record-keeping a core part of the reporting and notification architecture.

Reading annual reporting dates without over-interpretation

When reading the statutory calendar it is helpful to adhere closely to the dates the Regulations set out, and to avoid drawing inferences beyond the plain text. The rules establish a simple annual rhythm: a provider makes an annual report to HMRC electronically on or before 31 May following the calendar year in question. The first cycle to which that rule applies covers 1 January to 31 December 2026, with the first return submitted any time between 1 January 2027 and 31 May 2027.

Practical details that HMRC has disclosed should be treated as operational specifics, not as statements about tax outcomes. HMRC has said that the online service is not yet live, that reports are XML files, and that the maximum file size is 250MB. HMRC has also described which users are in scope for reporting: providers collect details of all users but report those who are tax resident in the UK or in another CARF jurisdiction, together with a summary of their transactions. If a provider has no information to report in a year, it does not submit a report.

Those items — data format, file-size limit, online service availability, the scope of reported users and the “no-report” position where there is no information — are operational attributes that sit under the Regulation’s statutory deadlines. They do not create or alter an individual’s tax liability by themselves. Provider data reporting does not itself determine any individual’s tax position.

Item Date or Period Notes
Regulations in force 1 January 2026 Due-diligence, record-keeping, notification, reporting duties commence
First reporting year covered 1 January–31 December 2026 First report covers this calendar year
Notification deadline for first year On or before 31 January 2027 Where a provider’s report will include a reportable person
First report submission window 1 January–31 May 2027 Electronic report to HMRC; first report must be submitted on or before 31 May 2027
Ongoing annual reporting deadline On or before 31 May (following calendar year) Each later report due by 31 May for the preceding calendar year
Provider records retention Five years beginning after end of relevant calendar year Records of steps taken and information collected under due diligence
HMRC technical notes XML reports; max 250MB; online service not live Operational details stated by HMRC

A short no-advice boundary

This supplement sets out the statutory structure, deadlines and record-keeping features as provided in the Reporting Cryptoasset Service Providers (Due Diligence and Reporting Requirements) Regulations 2025 and as described by HMRC in its public statements about the reporting process. It does not attempt to interpret those facts into personalised guidance, and it does not make any determination about an individual’s tax position. Provider data reporting does not itself determine any individual’s tax position.

This supplement is general information and not personalised tax, legal, financial, investment or compliance advice.

OGM has published additional explanatory material on adjacent topics that may help readers situate the Cryptoasset Reporting Framework UK within the broader policy and regulatory landscape. These internal articles are intended as background information and should be read alongside the primary HMRC and legislative texts cited earlier.

  • UK crypto regulation 2026 — background on the regulatory work programmes announced in the UK in 2026 and their intended implementation timelines.
  • HMRC crypto tax records 2026 — explanation of HMRC’s public guidance on record-keeping and reporting as it was set out in 2026.
  • FCA stablecoin rules explained — a focused explainer on one element of the FCA’s reform programme, illustrating how regulatory activity and tax-reporting activity can run on parallel tracks.

No-advice statement

This article is general information and not personalised tax, legal, financial, investment or compliance advice.

The published material and statutory instruments referenced in this article should be consulted directly for authoritative statements of provider duties and procedural detail. HMRC’s guidance on how providers should report cryptoasset user and transaction data is available at: https://www.gov.uk/guidance/reporting-cryptoasset-user-and-transaction-data. The secondary legislation that gives statutory effect to the framework is available at: https://www.legislation.gov.uk/uksi/2025/744. For information on the FCA’s distinct regulatory timetable and final rules applicable to firms entering the regime, see the FCA’s own page: https://www.fca.org.uk/firms/new-regime-cryptoasset-regulation.

Two compact descriptive comparisons

Below are two compact, purely descriptive tables provided to assist readers in distinguishing dates and responsibilities under the Cryptoasset Reporting Framework UK. These tables restate factual elements from the regulations and HMRC guidance and are intended as neutral summaries.

2026/2027: calendar, reporting and notification overview
Item Description (factual)
2026 calendar year Defined in HMRC guidance as the first reporting year that providers will summarise and report. Data collection for 1 January 2026 to 31 December 2026 forms the basis of the first report.
First report submission window (2027) The first report covering the 2026 calendar year is to be submitted between 1 January 2027 and 31 May 2027, according to HMRC guidance.
First-year notification to reportable persons Regulations require providers to notify reportable persons that their information will be reported and may be transferred internationally; for the first reporting year the notification is due on or before 31 January 2027.
Subsequent annual filings For later reporting years, HMRC guidance indicates that reports are due by 31 May for the previous calendar year.
Provider reporting / FCA regime / individual tax position
Framework element Scope and function (descriptive)
Provider reporting (Cryptoasset Reporting Framework UK) Statutory duties for in-scope providers to collect specified data, apply due diligence, retain records for five years, notify reportable persons, and submit an electronic XML report to HMRC by the published deadlines.
FCA cryptoasset regime Separate regulatory framework concerning permissions, rules and supervision for firms carrying out regulated crypto asset activities under FSMA; it operates independently from CARF reporting duties and has its own timetable and legal basis.
Individual tax position Determined under UK tax law and HMRC’s tax administration processes; inclusion in a provider report is a data-transfer event and not a determination of tax liability by itself.

These tables are summaries of published obligations and contexts. They are not exhaustive lists of legal requirements and should be read alongside the primary guidance and legislation linked earlier in the article.

Closing factual reminders

To conclude this explainer on the Cryptoasset Reporting Framework UK, the following factual reminders summarise the most relevant, source-connected points set out in the statutory and HMRC materials:

  • The secondary legislation that establishes the provider duties was made on 24 June 2025 and came into force on 1 January 2026. See the legislation at: https://www.legislation.gov.uk/uksi/2025/744.
  • HMRC’s operational guidance states that providers collect details for all users but report only those users who are tax resident in the UK or another CARF signatory jurisdiction. HMRC’s guidance on reporting is available at: https://www.gov.uk/guidance/reporting-cryptoasset-user-and-transaction-data.
  • The first report, covering the calendar year 1 January 2026 to 31 December 2026, is to be submitted between 1 January 2027 and 31 May 2027. Thereafter, reports are due by 31 May for the previous calendar year, per HMRC guidance.
  • HMRC has stated that the online reporting service is not yet live, that submissions will be made as XML files and that the maximum file size for submissions is 250MB.
  • The regulations require providers to maintain due-diligence arrangements, keep records of steps taken and information collected, and to retain those provider records for five years beginning after the end of the relevant calendar year.
  • Where a report will include information on a reportable person, the provider must notify that person that the information will be reported to HMRC and may be transferred to the competent authority of another jurisdiction under CARF; for the first reporting year that notification is due on or before 31 January 2027.
  • HMRC’s guidance sets out that a penalty of up to £300 per user may apply where a report is not submitted, is late, or is inaccurate, incomplete or unverified; this article reproduces that published guidance as a factual statement about HMRC’s stated approach and does not interpret or apply it to any person.
  • The FCA’s regulatory work on cryptoassets is a separate framework to CARF reporting; the FCA published final rules and guidance on 30 June 2026 and expects its regime to come into force on 25 October 2027 for firms granted permission on or after that date. See the FCA’s page for the regulator’s published position: https://www.fca.org.uk/firms/new-regime-cryptoasset-regulation.

Readers looking to consult the primary texts should follow the links throughout this article to HMRC, to the legislation and to the FCA for the official sources. The OGM items listed above provide background context and are linked in the Related OGM Crypto coverage section.

Again, this article was prepared to explain the published elements of the Cryptoasset Reporting Framework UK and to distinguish provider duties from individual tax determinations. It does not provide personalised tax, legal, financial, investment or compliance advice.