Commercial manufacturers whose connected hardware wallets or wallet software meet the European Union’s product test must now warn cyber authorities within 24 hours of discovering an actively exploited vulnerability or severe security incident. This stringent reporting requirement, enacted on September 11, 2026, under the EU’s Cyber Resilience Act (CRA), marks a significant shift in how digital product security incidents will be managed within the bloc. The European Commission’s official reporting guidance explicitly states that this accelerated timeline applies to manufacturers of all products featuring digital elements that are made available on the EU market.

The Cyber Resilience Act is designed as a horizontal product law, meaning its scope is broad and intended to encompass a wide range of digital products, not just those within the traditional IT sector. According to the Commission’s implementation frequently asked questions (FAQ), the CRA applies to both hardware and software products distributed within the EU. A key criterion for inclusion is that the product’s intended or reasonably foreseeable use involves a direct or indirect data connection to another device or network. This broad definition clearly encompasses commercially supplied connected hardware wallets and downloadable wallet applications, which are intrinsically linked to networks for transaction processing and security updates.

While the EU guidance does not specifically name individual wallet brands or explicitly declare every crypto wallet service as covered, the applicability hinges on the specific product’s characteristics, its method of supply, and any potential exclusions outlined in the legislation. This nuanced approach means that manufacturers of crypto wallets must carefully assess their products against the CRA’s criteria to determine their regulatory obligations. The emphasis on "commercially supplied" also suggests that products intended for enterprise or widespread consumer use are more likely to fall under the Act’s purview, distinguishing them from purely experimental or hobbyist projects.

The Three-Stage Reporting Mandate

Manufacturers falling under the CRA’s purview are now subject to a rapid, three-stage reporting process for serious cybersecurity events. The initial and most critical filing is an "early warning," which must be submitted without undue delay and no later than 24 hours after the manufacturer becomes aware of an actively exploited vulnerability or a severe security incident. This initial report is crucial for immediate situational awareness and must, where applicable, specify the EU member states where the product is known to have been made available. For severe incidents, the manufacturer must also indicate whether unlawful or malicious acts are suspected, providing law enforcement with early intelligence.

Following the initial alert, a more comprehensive notification is due within 72 hours, provided that the necessary information was not already included in the first filing. For actively exploited vulnerabilities, this second report requires detailed information about the product, the exploit itself, and the nature of the vulnerability. It must also outline any corrective or mitigating measures the manufacturer is implementing or plans to implement. In the case of a severe incident, the 72-hour report needs to detail the nature of the incident, an initial assessment of its impact, and any available mitigation strategies.

The final deadline for reporting varies depending on the nature of the security event. For vulnerabilities, the final report is due no later than 14 days after a corrective or mitigating measure becomes available to users. The CRA establishes a distinct deadline for severe incidents, requiring the final report to be submitted one month after the initial 72-hour notification. These tiered deadlines are meticulously detailed in the official EU regulation.

A Centralized Reporting Mechanism

To streamline the reporting process and ensure efficient dissemination of critical security information, manufacturers are required to file their notifications through the Single Reporting Platform. This platform was launched by ENISA, the European Union Agency for Cybersecurity, serving as a centralized hub for all CRA-related incident and vulnerability reporting. Upon submission, the platform automatically forwards the notification to the designated coordinating Computer Security Incident Response Team (CSIRT) within the relevant member state. The information is also made available to ENISA, which then facilitates its distribution to other national CSIRTs and relevant authorities.

Beyond regulatory reporting, manufacturers have a direct obligation to inform impacted users about security incidents and vulnerabilities. This includes providing clear guidance on any necessary actions users can take to protect themselves, such as applying software updates or modifying their usage patterns. Transparency with end-users is a cornerstone of the CRA’s approach to fostering a more resilient digital ecosystem.

Crypto wallet creators now have just 24 hours to alert regulators when flaws are exploited

Extended Reach and Open-Source Considerations

The reporting requirements stipulated by the CRA extend to in-scope products that were placed on the market before December 11, 2027. This means that the new, accelerated reporting clock is relevant not only for new product lines introduced after the broader law takes effect but also for existing product lines that continue to be supplied within the EU. This retroactive application ensures that a significant portion of the digital product landscape is brought under the new security framework.

The legislation also addresses the complex issue of open-source software. The Commission’s guidance on open-source clarifies that free and open-source products supplied commercially can still trigger manufacturer obligations under the CRA. This means that companies distributing open-source software as part of their commercial offerings cannot claim exemption solely based on the software’s licensing model. However, non-monetized software supplied directly by its original manufacturer is generally not considered commercial activity. Furthermore, individual contributors to open-source projects are typically not treated as manufacturers for software outside their direct area of responsibility.

A separate legal category has been established for open-source software stewards, who will have their own reporting duties commencing on December 11, 2027. This date also marks the full implementation of the CRA’s main product security requirements, including secure design principles and product lifecycle management. The September 11, 2026, change specifically initiated the rapid reporting regime for exploited vulnerabilities and severe incidents, distinct from the broader secure-design and lifecycle obligations that will follow.

Broader Implications for the Crypto Industry

The implications of the EU’s Cyber Resilience Act for the cryptocurrency industry, particularly for wallet manufacturers, are substantial. The 24-hour reporting deadline for actively exploited vulnerabilities places immense pressure on companies to maintain robust security monitoring and rapid incident response capabilities. This necessitates significant investment in security infrastructure, threat intelligence, and internal processes to detect, analyze, and report such events within the tight timeframe.

This regulatory push is likely to accelerate the trend towards greater professionalization and formalization within the crypto space. Companies that have historically operated with less stringent oversight may find it challenging to adapt to these new compliance demands. Conversely, established players with strong security postures may find themselves at a competitive advantage, having already invested in the necessary systems and protocols.

The requirement to report to a centralized EU platform also signifies a growing harmonization of regulatory approaches across member states. This can simplify compliance for companies operating in multiple EU countries but also means that a single failure to comply can have repercussions across the entire bloc. The focus on "connected" products means that even hardware wallets that connect to the internet or user devices are within scope, highlighting the interconnectedness of the digital asset ecosystem and the need for security across all its touchpoints.

The emphasis on informing users about security incidents is also a critical development. This will empower users with timely information to protect their assets, fostering greater trust and potentially reducing the impact of widespread scams or exploits. For the crypto industry, which has often grappled with public perception challenges related to security and fraud, this increased transparency could be a net positive in the long term.

As the CRA’s full provisions come into effect, it is expected to drive a higher standard of security across all digital products available in the EU market. For crypto wallet manufacturers, this means a future where proactive security measures, rapid incident response, and transparent communication are not just best practices but regulatory imperatives. The tight deadlines are a clear signal from EU regulators that the security of digital products, especially those handling sensitive financial data, is a top priority.