Line 12 of the schedule carries a watch mark that is really a countdown. Since 1 January 2026, UK cryptoasset service providers have been collecting identity and transaction data on their users under the Cryptoasset Reporting Framework. The first reports reach HMRC by 31 May 2027, covering the whole 2026 calendar year — and unlike the international frameworks people half-remember, this one includes UK residents on UK platforms.
What actually changes
Nothing about the tax. Every rule on the schedule applied before CARF and applies after; the framework creates no new liability. What changes is symmetry. HMRC has bought exchange data piecemeal for years — the nudge letter campaigns run on it. CARF replaces piecemeal with systematic: identity details, tax residency and reference numbers, and transaction-level reporting from every in-scope provider, refreshed annually, exchanged internationally among the 50-plus committed jurisdictions — and reported domestically for UK users too. The pseudonymity assumption that priced a lot of quiet non-compliance is being switched off on a published schedule.
The mechanics, briefly
Reporting cryptoasset service providers — exchanges, brokers, some wallet providers — must perform due diligence on users and report to HMRC. Users are obliged to provide the requested self-certification: declining can cost the individual up to £300 in penalties, and providers face up to £300 per user for incomplete or unverified reports, so platforms have every incentive to insist. The first reporting period is calendar 2026; reports are due by 31 May 2027; international exchanges of the data follow later that year. If a platform has recently asked you for tax residency details and a National Insurance number or UTR, this is why.
A nudge letter today means HMRC bought some data and matched it. A nudge letter in 2028 means the data arrived on schedule, from everywhere, labelled with your tax reference.
What it does to the letters
Around 81,000 crypto letters went out in the year to April 2026, on the old, patchy data. The current wave runs to March 2027. Then the first CARF cycle lands, and the matching that produces letters starts running on provider-reported, identity-verified, transaction-level data. Expect volume, and expect precision: letters that reference specific platforms and specific years, harder to answer with a general assurance. The gap between "what HMRC can see" and "what was declared" becomes a computed number rather than an inference.
The honest read for a holder
- Past years are the exposure, not 2026. The 2026 activity now being collected will mostly be declared on time by people who know it is visible. The risk concentrates in earlier years, filed or unfiled, that the new data will contradict.
- The unprompted window has a shape. A disclosure before HMRC writes sits in the lowest penalty bands — and there is no mechanism to reserve that status in advance. Between now and the post-CARF letter cycles is the window. It is measured in months, not years.
- "My platform is offshore" is expiring as a theory. CARF is an exchange framework: data reported to one committed jurisdiction flows to the others. A provider outside every committed jurisdiction is a shrinking category with its own risk profile.
- Records beat memory. When a letter cites provider-reported figures, the answer is your reconstruction — pools, matching, sterling values. Built now, calmly, it serves every later stage; built after a deadline is already running, it costs more and shows it.
Why this line stays "watch"
Guidance on scope and edge cases is still being filled in, the first cycle has not yet run, and enforcement behaviour after May 2027 is a prediction, not a fact. We publish the dates, which are law, and mark the consequences as watch — this note will be updated as the first cycle lands, through the change log, like everything else.
This is a position note about a reporting framework in its first cycle. It is not advice on your affairs, and reading it creates no professional relationship.