EU Cyber Resilience Act Sets 24-Hour Reporting Deadline for Crypto Wallet Vulnerabilities
The European Union's Cyber Resilience Act (CRA) has taken effect, imposing new reporting requirements on cryptocurrency hardware and software wallet providers.
Under the CRA, manufacturers of digital products must submit an early warning for severe vulnerabilities within 24 hours after becoming aware of them.
A full notification is required within 72 hours, followed by a final report 14 days after corrective or mitigating measures are available, and no later than one month for severe incidents.
The measure aims to better protect consumers and businesses from cyber threats by extending reporting requirements to all products 'with digital elements made available in the EU.'