Skip to content
EU Mandates 24-Hour Reporting for Crypto Wallet Vulnerabilities

EU Mandates 24-Hour Reporting for Crypto Wallet Vulnerabilities

First seen 13 Sep 2026, 15:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 13, 2026 at 15:57 UTC
  • EU's Cyber Resilience Act mandates 24-hour reporting for crypto wallet vulnerabilities.
  • Manufacturers must file initial notifications within 24 hours of discovering an incident.
  • Broader product-security requirements will take effect on December 11, 2027.

As of September 11, 2026, the European Union's Cyber Resilience Act requires manufacturers of connected hardware wallets and wallet software to report any actively exploited vulnerabilities or severe security incidents to cyber authorities within 24 hours. This law applies to products available in the EU market that have a data connection capability. Initial notifications must be submitted without undue delay, detailing the member states where the product is available. A more comprehensive report is due within 72 hours, and final reports must be filed within one month for severe incidents. The regulation also mandates that manufacturers inform impacted users about necessary actions. The rules extend to products placed on the market before December 11, 2027, and include obligations for free and open-source products. The reporting framework is facilitated through the Single Reporting Platform by ENISA.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-11
EU Cyber Resilience Act takes effect
The new law requires manufacturers to report vulnerabilities within 24 hours of discovery, impacting connected hardware wallets and wallet software.
Cryptoslate
2026-09-13
Reporting requirements detailed
Manufacturers must provide initial notifications and follow-up reports within specified timeframes as per the new EU regulations.
Kucoin

More articles in this cluster (2)