Cyber Resilience Act: EU crypto wallet reporting deadlines

Share This Post



Cyber Resilience Act: EU crypto wallet reporting deadlines

Commercial manufacturers whose connected hardware wallets or wallet software meet the European Union’s product test must now warn cyber authorities within 24 hours of discovering an actively exploited vulnerability or severe security incident.

The requirement took effect Sept. 11, 2026, under the EU’s Cyber Resilience Act, or CRA. The European Commission’s reporting guidance says the clock applies to manufacturers of products with digital elements.

The CRA is a horizontal product law. The Commission’s implementation FAQ says it applies to hardware and software made available on the EU market. The legal test also requires the product’s intended or reasonably foreseeable use to include a direct or indirect data connection to a device or network.

A commercially supplied connected hardware wallet or downloadable wallet app can meet that test. However, EU guidance does not name wallet brands or declare every wallet service or project covered. Coverage depends on the specific product, how it is supplied and any applicable exclusion.

Related Reading

SafePal breach exposes 40,000 customers as hardware wallet attacks escalate from data leaks to $100 million theft

What manufacturers must report

The first filing is an early warning due without undue delay and no later than 24 hours after a manufacturer becomes aware of the vulnerability or incident. It must indicate, where applicable, the member states where the product is known to have been made available. For a severe incident, the warning must also say whether unlawful or malicious acts are suspected.

A fuller notification is due within 72 hours unless the relevant information was already provided. For an actively exploited vulnerability, that filing adds general information about the product, exploit and vulnerability, plus corrective or mitigating measures. For a severe incident, it adds the nature of the incident, an initial assessment and available mitigation information.