EU Cyber Resilience Act Introduces 24-Hour Vulnerability Reporting for Commercial Crypto Wallets
The European Union's Cyber Resilience Act has introduced new rules for manufacturers to report actively exploited vulnerabilities within 24 hours. This requirement applies to products with digital elements, which includes commercial crypto hardware wallets and wallet software sold in the EU.
The law draws a distinction between commercial and non-commercial open-source software, with purely non-commercial development receiving different treatment.
This new regulation aims to improve incident response and security processes for engineering teams, while also increasing regulatory compliance burdens. The 24-hour warning requirement changes how vulnerabilities are handled internally, requiring companies to escalate incidents quickly enough to decide whether the threshold has been met.