EU Crypto Wallet Manufacturers Face 24-Hour Vulnerability Disclosure Deadline
The European Union's Cyber Resilience Act has introduced a new rule requiring crypto wallet manufacturers to disclose vulnerabilities within 24 hours. Article 14 of the act, which took effect on September 11, 2026, mandates that manufacturers alert regulators when a vulnerability is being actively exploited.
When a maker learns about an exploit, it must submit an early warning notification to ENISA and the designated computer security incident response team (CSIRT) through a single reporting platform within 24 hours. A fuller vulnerability notification follows within 72 hours, and a final report is due within 14 days of a corrective or mitigating measure becoming available.
The new rule applies to hardware wallets and commercial wallet software that connect to devices and networks. The EU regime also builds in relief for smaller firms: administrative fines do not apply to microenterprises and small enterprises that miss the 24-hour early-warning deadline, although the reporting obligation itself still stands.