EU Wallet Providers Face 24-Hour Deadline for Severe Vulnerability Reports
The European Union has introduced new cyber rules that require cryptocurrency hardware and software wallet providers to report actively exploited bugs or severe security vulnerabilities within 24 hours.
This measure is part of the EU's Cyber Resilience Act, which took effect on Friday, according to an announcement from the European Commission.
Manufacturers must submit an early warning for severe vulnerabilities within 24 hours, followed by a full notification within 72 hours. A final report will be required 14 days after corrective or mitigating measures are available and within one month for severe incidents.
The EC said the new reporting requirements aim to better protect consumers and businesses from cyber threats. The measure extends to all products 'with digital elements made available in the EU' and builds on the EU's broader cybersecurity strategy.
Companies that fail to adhere to the cybersecurity measures under Articles 13 and 14 may face an administrative fine of up to €15 million or 2.5% of worldwide annual turnover, depending on which figure is higher.