EU mandates 24-hour reporting for crypto wallet vulnerabilities under Cyber Resilience Act

38 minutes ago 1



Starting September 11, 2026, any company selling a crypto wallet in the European Union will have exactly 24 hours to flag an actively exploited vulnerability to regulators. Miss that window, and fines can climb as high as €15 million or 2.5% of annual global turnover, whichever is larger. The requirement comes from the EU’s Cyber Resilience Act (CRA), a sweeping piece of legislation that treats crypto wallets, both hardware and software, the same way it treats any product with digital elements. How the reporting timeline works Article 14 of the CRA lays out a two-stage notification process. Within 24 hours of becoming aware of an actively exploited vulnerability or severe security incident, manufacturers must file an early warning through ENISA’s Single Reporting Platform. ENISA is the EU’s cybersecurity agency, and the platform routes alerts to relevant national Computer Security Incident Response Teams (CSIRTs). Within 72 hours, a more thorough notification is required, documenting the scope, severity, and technical details of the exploit. Manufacturers are also obligated to inform affected users about the security issue and share any mitigations that can be deployed. One importa...

Read Entire Article