Guide · updated August 2026

CARF compliance for South African CASPs, explained

What the Crypto-Asset Reporting Framework actually requires of an FSCA-licensed crypto-asset service provider, in plain language — the obligations, the dates, and the practical work behind each one.

The dates that matter
  • 28 Nov 2025 — CARF Regulations gazetted under the Tax Administration Act.
  • 1 Mar 2026 — CARF takes effect. New users must self-certify before transacting. (204 days remain to re-paper existing users.)
  • 1 Mar 2027 — 12-month deadline to hold self-certifications for all pre-existing users.
  • 31 May 2027 — first CARF return due at SARS (295 days away), covering 1 Mar 2026 – 28 Feb 2027.
  • Sep 2027 — SARS begins exchanging CARF data with 120+ partner jurisdictions.

Who is caught

If you are licensed by the FSCA as a crypto-asset service provider — an exchange, broker, OTC desk, arbitrage service, wallet provider effecting transactions, or an advisory business executing crypto trades — you are almost certainly a Reporting Crypto-Asset Service Provider (RCASP) under the regulations. The obligation attaches to the business, not to its size: a two-person arbitrage shop carries the same duties as a top-tier exchange.

Obligation 1 — self-certifications (running now)

You must collect a tax-residency self-certification from every user: name, address, date of birth for individuals, every jurisdiction of tax residence, and the tax identification number for each (for South Africans, the SARS tax reference number; the SA ID number identifies the individual). Entities certify separately, including controlling persons in some cases.

The practical failure mode is not refusal — it is silence. Budget for multiple chase rounds and track completion as a burn-down against the deadline, per user, from day one.

Obligation 2 — the annual return (due 31 May 2027)

The return is an XML file following the OECD CARF schema inside a SARS wrapper (SARS_CARFDataFileV1.0). For every reportable user you aggregate the year's transactions per crypto-asset and per category: crypto-to-fiat acquisitions and disposals, crypto-to-crypto exchanges, transfers in and out (typed: airdrops, staking income, transfers between providers…), transfers to unhosted wallets, and reportable retail payment transactions — each with transaction counts, fiat values and unit totals.

SARS's External BRS adds domestic rules the OECD documents don't cover: identifier formats for MessageRefID and DocRefID, a file-naming convention for eFiling, prohibited characters, a 5MB per-file upload limit, and a strict corrections model (CARF702 messages referencing the DocRefIDs of the records they replace). Files that violate any of these are rejected — after the deadline, that matters.

What SARS does with it

Domestic visibility first: the Crypto Revenue Augmentation Unit matches reported transactions against taxpayers' returns. From September 2027 the same data flows to partner tax authorities for foreign-resident users — which is why residence jurisdictions and TINs must be captured correctly, not approximately.

Build, Big-4, or buy

A readiness checklist

  1. Confirm your RCASP status and nexus (licence, incorporation, management in ZA).
  2. Stand up self-certification collection for new users now — it is already required.
  3. Start the re-papering campaign; measure weekly against 1 March 2027.
  4. Locate every transaction category in your back office and map it to the CARF categories.
  5. Dry-run your return months early — schema validation finds data problems while there is still time to fix them.
  6. Keep the manifest of what you filed; corrections require exact record references.

This guide is general information, not tax or legal advice. For the mechanical layer, CarfReady is onboarding founding CASPs now.