EU Slaps Crypto Wallet Manufacturers with 24-Hour Vulnerability Reporting Deadline
The European Union has activated Article 14 of the Cyber Resilience Act (CRA), requiring manufacturers of crypto wallets and other digital products to report active vulnerabilities within 24 hours.
The initial report is not public, but rather goes to the Computer Security Incident Response Team (CSIRT) of the manufacturer's country of establishment and to ENISA through the Single Reporting Platform.
Hardware and software wallets marketed in Europe are already covered by this requirement, despite the bulk of the CRA not taking effect until December 2027.