Commercial makers of connected hardware wallets or wallet software covered by the EU's Cyber Resilience Act must now alert cyber authorities within 24 hours of discovering an actively exploited flaw or severe security incident. The rule took effect Sept. 11, 2026, and applies even to products already on the market, with fuller filings due at 72 hours and final reports weeks later.
Wallet manufacturers whose products meet the European Union's legal test for connected devices now face a tight new clock. Under the Cyber Resilience Act, or CRA, they must warn cyber authorities within 24 hours of discovering an actively exploited vulnerability or a severe security incident.
The requirement took effect Sept. 11, 2026, and it reaches hardware and software already sold, not only future launches. The reporting rule covers in-scope products placed on the market before Dec. 11, 2027, meaning existing wallet lines fall under the clock as much as new ones.
What the filings must contain
The first submission is an early warning, due without undue delay and no later than 24 hours after a manufacturer becomes aware of the problem. For a severe incident, that warning must also say whether unlawful or malicious acts are suspected.
A fuller notification follows within 72 hours unless the information was already provided. For an exploited vulnerability, it adds detail on the product, the exploit and corrective or mitigating steps. For a severe incident, it adds the nature of the event and an initial assessment.
Final deadlines then diverge by event type. A vulnerability report is due no later than 14 days after a corrective or mitigating measure becomes available, while the CRA sets the severe-incident final report at one month after the 72-hour notification. Manufacturers file once through the Single Reporting Platform launched by ENISA, which routes the notification to the relevant national response team and makes it available to the agency.
Open-source wallets are not automatically exempt
Open-source licensing does not create a blanket carve-out. Commercially supplied free and open-source products can still trigger manufacturer obligations, though non-monetized software supplied by its maker should not count as commercial activity, and individual contributors are not treated as manufacturers for software outside their responsibility.
Their duties differ, though: open-source software stewards sit in a separate legal category, and their own reporting duties begin Dec. 11, 2027 — the same date the CRA's broader product-security and lifecycle requirements take hold. The Sept. 11 change starts only the rapid reporting regime, ahead of that wider framework.
Source: CryptoSlate
Trading involves risk.