EU Crypto Wallet Manufacturers Must Report Cyber Incidents Within 24 Hours
The European Union's Cyber Resilience Act (CRA) has come into effect on September 11, 2026, requiring commercial manufacturers of connected hardware wallets or wallet software to report cyber incidents within a tight deadline.
According to the EU's reporting guidance, manufacturers must warn authorities about an actively exploited vulnerability or severe security incident within 24 hours. A fuller notification is due within 72 hours, providing more detailed information about the product, exploit, and vulnerability.
The CRA applies to hardware and software made available on the EU market, including products with digital elements that have a direct or indirect data connection to a device or network. This means that commercially supplied connected hardware wallets or downloadable wallet apps are covered under the regulation.