The European Union (EU) has enforced rules requiring manufacturers of connected hardware and software, including cryptocurrency wallets, to report within 24 hours if they discover an actively exploited vulnerability or a major security incident.
Cryptoslate and the European Commission said on Sept. 13, local time, that the Cyber Resilience Act (CRA) reporting obligation has applied since Sept. 11. It applies to manufacturers of "products with digital elements" supplied to the EU market. Commercial hardware wallets or downloadable wallet apps that exchange data directly or indirectly with networks or other devices may also fall under the rule depending on product structure and how they are supplied. Not all cryptocurrency wallet services are automatically included.
If a manufacturer becomes aware of an actively exploited vulnerability or a major incident affecting product security, it must submit an initial alert without delay and no later than 24 hours. It must then file a formal report within 72 hours including the nature of the vulnerability or incident, product information, and damage and mitigation measures.
The deadline for the final report varies by case. For an actively exploited vulnerability, it must be filed within 14 days after corrective or mitigation measures are prepared. For a major incident, a final report must be submitted within 1 month after the 72-hour formal report. Manufacturers must also inform affected users of the incident and necessary security measures.
A report needs to be submitted only once through the Single Reporting Platform (SRP) operated by the EU Agency for Cybersecurity (ENISA). The platform forwards the report to the relevant member state's computer security incident response team (CSIRT) and ENISA. ENISA officially began operating the SRP on Sept. 11, the day the reporting obligation took effect.
The reporting obligation also applies to products launched on the EU market before Dec. 11, 2027. By contrast, the CRA's main product security requirements will apply in full from December 2027. Commercially provided free and open-source software may fall under manufacturer obligations, but non-monetised open source projects or simple code contributors are, in principle, excluded from the definition of manufacturers. Reporting obligations for a separate legal status, an "open-source software steward", will also begin from December 2027.
The move is expected to require manufacturers selling cryptocurrency wallets in the EU to treat regulatory compliance as dependent not only on security incidents themselves but also on how quickly they detect, report and fix them.