Book a Demo

Enterprise Tax

lorem ipsum dolor sit, oimn, aoimn arunv aiurevn aiournv ougnre

Enterprise Accounting

lorem ipsum dolor sit, oimn, aoimn arunv aiurevn aiournv ougnre

Malta Transposes DAC8: What Crypto-Asset Service Providers Need to Know

June 17, 2026

6 min read

Malta has formally transposed the EU’s eighth iteration of the Directive on Administrative Cooperation — commonly known as DAC8 — into domestic law. Legal Notice 162 of 2026, published in the Government Gazette on 22 May 2026, amends Malta’s Cooperation with Other Jurisdictions on Tax Matters Regulations (Subsidiary Legislation 123.127) and brings the island jurisdiction into formal compliance with Council Directive (EU) 2023/2226, with effect from 1 January 2026.

For the global crypto-asset industry, Malta’s transposition carries particular weight. The jurisdiction has long operated one of the EU’s most developed regulatory ecosystems for crypto-asset businesses, and its early embrace of the Markets in Crypto-Assets Regulation (MiCA) means that many of the world’s most significant CASPs are either authorised in Malta or are actively seeking authorisation there. With LN 162/2026 now in force, the combination of MiCA authorisation and DAC8-compliant tax reporting has become the new baseline compliance expectation for any crypto-asset service provider operating in or from the jurisdiction.

This post sets out the key obligations introduced by LN 162/2026, explains the due diligence and reporting mechanics in detail, and outlines what CASPs should be doing right now.

Who Is In Scope?

The Regulations introduce obligations for “Reporting Malta Crypto-Asset Service Providers” — a category that is broader than it might initially appear.

The primary in-scope entities are MiCA-authorised CASPs: those holding authorisation from the Malta Financial Services Authority (MFSA) or permitted to provide services in Malta following a passporting notification. But the Regulations also capture a second category: Crypto-Asset Operators (CAOs) — entities that are not MiCA-authorised but that effectuate exchange transactions for or on behalf of reportable users. A CAO falls under Maltese jurisdiction if it is tax-resident in Malta, incorporated or organised under Maltese law, managed from Malta, maintains a regular place of business in Malta, or conducts transactions through a Maltese branch.

This two-track approach reflects the underlying CARF architecture, which was deliberately designed to capture service providers that fall outside the perimeter of traditional financial services regulation. The practical implication is that a business providing crypto-to-fiat conversion services without a MiCA licence — perhaps operating under a transitional arrangement or relying on an exemption — may still be fully subject to Malta’s DAC8 reporting obligations.

The reporting obligation is triggered when a Reporting Malta CASP effects transactions for a “Reportable User” — defined as a crypto-asset user who is a reportable person resident in any EU Member State. Residency, not nationality, is the operative concept, and CASPs must apply due diligence procedures to determine the Member State of residence for each customer.

What Must Be Reported? A Detailed Look at the CARF Data Model

The asset scope of Malta’s DAC8 transposition tracks the OECD’s Crypto-Asset Reporting Framework (CARF) closely. Reporting obligations apply to “Reportable Crypto-Assets” (RCAs) — which encompass all crypto-assets other than Central Bank Digital Currencies, regulated e-money, and any crypto-asset for which the CASP has adequately determined it cannot be used for payment or investment purposes.

That last exclusion is narrower than it sounds. The burden of determination sits with the CASP, and regulators are likely to scrutinise any classification that excludes a widely-traded asset from the reporting perimeter. In practice, the universe of RCAs will cover virtually all tokens actively traded on secondary markets, including stablecoins that do not qualify as e-money under MiCA’s Title III definitions.

The reportable transaction types fall into three categories.

Exchange Transactions cover any swap between an RCA and fiat currency, and any swap between two different RCAs. This captures the bread-and-butter trading activity of most retail and institutional CASP customers.

Transfers cover movements of RCAs into or out of a user’s address or account, where the CASP cannot determine that the transaction is an Exchange Transaction. This is the more operationally complex category: it requires CASPs to make a positive determination about the nature of each transaction before deciding which reporting category applies.

Reportable Retail Payment Transactions (RRPTs) cover transfers of RCAs made in consideration for goods or services, where the value of the underlying transaction exceeds USD 50,000 (or its equivalent). This category is specifically designed to capture crypto-as-payment activity and reflects regulatory concern about the use of digital assets to settle high-value commercial transactions outside the traditional financial reporting perimeter.

For each reportable user and each transaction category, the CASP must report aggregate gross amounts paid and received, aggregate fair market values, unit counts, and transaction counts — disaggregated by whether the counterpart is fiat currency, another RCA, or a transfer to or from a distributed ledger address not associated with a known virtual asset service provider or financial institution. That last data point is significant: it effectively requires CASPs to maintain blockchain analytics capabilities sufficient to distinguish between on-chain transfers to known counterparties and transfers to unhosted or unidentified wallets.

On the customer data side, CASPs must collect and report name, address, Member State(s) of residence, and Tax Identification Numbers for each reportable user, plus date and place of birth for individuals. For entity customers with controlling persons who are themselves reportable, the same information must be collected and reported at both the entity and controlling-person level. This reflects the look-through approach that has become standard across OECD and EU automatic exchange of information frameworks.

Due Diligence: The CARF Mechanics in a Maltese Context

The DAC8 due diligence framework — and by extension the Maltese Regulations — draws heavily on the CARF procedures developed by the OECD. Understanding those mechanics is essential for CASPs building or upgrading their compliance programmes.

The framework distinguishes between new customers and pre-existing customers. For new customers onboarded on or after 1 January 2026, due diligence procedures must be completed before any reportable service is provided. For pre-existing customers — those whose relationship with the CASP pre-dates 1 January 2026 — the deadline for completing due diligence is 31 December 2026.

The core due diligence obligation is to determine each customer’s Member State of residence. CASPs may rely on self-certification for this purpose, but the self-certification must be reasonable in light of other information the CASP holds about the customer. Where the information in the CASP’s possession is inconsistent with the self-certification, the CASP cannot simply accept the certification at face value — it must resolve the inconsistency or treat the customer as a reportable person in all relevant jurisdictions.

The account freezing obligation is a notable feature of the Maltese transposition. Where a CASP has made two separate requests for information from a customer and received no response in either case, it is required to freeze the account pending resolution. This is a meaningful compliance enforcement mechanism: it effectively requires CASPs to operationalise their due diligence requests and track responses, rather than treating unanswered queries as administratively closed.

Registration: Two Different Tracks

The Regulations create separate registration pathways for MiCA-authorised CASPs and CAOs.

MiCA-authorised CASPs are not required to separately register with the Commissioner for Tax and Customs (CfTC) for DAC8 purposes. The MFSA will communicate a list of all authorised CASPs to the CfTC on a regular basis, and no later than 31 December of the relevant calendar year. This is a sensible coordination mechanism that avoids duplicative regulatory touchpoints for businesses that are already subject to MFSA oversight.

CAOs are subject to a separate registration obligation with the CfTC, in such manner and within such period as the CfTC may specify by guidelines to be published on its website. At the time of writing, the CfTC has not yet published those guidelines — a gap that Deloitte Malta has also flagged in its analysis of the Regulations. CASPs that believe they may fall into the CAO category should monitor the CfTC website closely and take legal advice on their registration obligations.

Where a CAO operates in multiple EU Member States, it is permitted to register with the competent authority of just one Member State — the single registration mechanism that mirrors the approach taken under CARF’s Qualifying Non-Union CASP rules for non-EU entities. This is an important flexibility for businesses with a multi-jurisdictional European footprint.

The Penalty Regime: Personal Liability at the Top

The Regulations introduce a structured administrative penalty framework with escalating consequences depending on the nature and duration of non-compliance.

Failure to register carries a fixed penalty of €500 — relatively modest, but the gateway obligation for the entire compliance framework. Failure to retain records for the minimum five-year period attracts a fixed penalty of €2,500. Failure to submit required information triggers a fixed penalty of €2,500 plus a daily penalty of €100, subject to a combined cap of €20,000.

Incomplete or inaccurate reporting is addressed with a two-tier approach: minor errors attract a fixed penalty of €200 plus €50 per day (capped at €5,000), while significant non-compliance can attract a penalty of up to €50,000. Failure to apply the required due diligence procedures carries a fixed penalty of €5,000, which can be imposed in addition to any reporting-related penalties arising from the same compliance gap.

The most striking feature of the penalty framework is the provision for personal liability. Where a Reporting Malta CASP is found to have submitted information that is misleading or false, every senior managing official of that CASP is personally liable to a penalty of between €10,000 and €30,000. This is a significant escalation from the corporate-level sanctions that typically characterise tax information reporting regimes, and it reflects the approach taken in a number of other EU jurisdictions that have transposed DAC8. For senior leadership of Malta-regulated CASPs, this provision warrants serious attention.

The Timeline: Shorter Than It Looks

The first reporting period under the Maltese DAC8 framework is the full calendar year beginning 1 January 2026. Information must be submitted to the CfTC within nine months of the end of the reporting period — meaning the first filing deadline is September 2027.

That may sound like a comfortable runway, but the operational reality is more compressed. CASPs that have not already completed their due diligence on pre-existing customers must do so by 31 December 2026. Systems and processes for transaction capture, customer data management, and reporting output generation need to be in place — and tested — well before the end of the first reporting year. Any data quality issues that emerge in the second half of 2026 will need to be remediated before the 30 September 2027 filing date.

The clock has been running since 1 January 2026. For CASPs that have yet to begin their DAC8 implementation, the urgency is real.

What This Means in the Broader EU Context

Malta’s transposition is part of a broader wave of DAC8 implementation activity across EU Member States. With an EU-wide compliance deadline of 31 December 2025 for transposition, and reporting obligations effective from 1 January 2026, jurisdictions are at varying stages of practical implementation. The CfTC’s pending guidance on CAO registration and reporting procedures is a reminder that formal transposition and operational readiness are not the same thing.

For CASPs operating across multiple EU jurisdictions — as most significant players do — the challenge is not simply understanding any single jurisdiction’s rules. It is building reporting infrastructure capable of handling the data collection, due diligence, and filing requirements across an increasingly harmonised but still jurisdiction-specific compliance landscape. The DAC8 framework is materially aligned with the OECD’s CARF, which means that CASPs reporting under DAC8 are also well-positioned for CARF obligations in non-EU jurisdictions that have adopted the standard — but the operational implementation still requires careful engineering.

How Taxbit Can Help

Taxbit works with the world’s largest digital asset businesses to build scalable, automated infrastructure for DAC8, CARF, and broader tax compliance obligations. Our platform is purpose-built for the data complexity of crypto-asset reporting: transaction classification, customer due diligence data management, fair market value determination, and regulator-ready output generation.

If you are a CASP operating in or from Malta and would like to discuss your DAC8 readiness, we would be glad to speak with you.

This post is provided for informational purposes only and does not constitute legal or tax advice. CASPs should seek independent legal and tax advice in relation to their specific compliance obligations under LN 162/2026 and the underlying DAC8 framework.

 

Table of Contents

Learn more

Contact Us