EU Introduces 24-Hour Vulnerability Reporting Rule for Connected Products
The European Union's Cyber Resilience Act has introduced new rules for companies that sell connected hardware and software products in the EU market. One of the key provisions is a 24-hour vulnerability reporting requirement, which means manufacturers must issue an early warning if they become aware of a vulnerability being actively exploited.
Commercial crypto wallets can fall within the scope of this rule, as they are considered to have digital elements. This means wallet manufacturers will need to consider security obligations alongside financial and data-protection rules.
The 24-hour reporting window is a significant change from previous practices, where companies might wait until a full technical investigation was completed before reporting a vulnerability.