EU Cyber Resilience Act Imposes 24-Hour Exploit Disclosure on Crypto Wallet Makers
Crypto wallet manufacturers now have just 24 hours to alert European regulators when a vulnerability in one of their products is actively exploited.
The obligation comes from Article 14 of the European Union’s Cyber Resilience Act (CRA), the bloc’s flagship cybersecurity rule for connected hardware and software, whose incident-reporting provisions took effect on September 11, 2026 — more than a year before the regulation’s broader security requirements become applicable in December 2027.
What the 24-Hour Deadline Requires Article 14 of the Cyber Resilience Act covers manufacturers of “products with digital elements” — a category that sweeps in hardware wallets and commercial wallet software because such products connect to devices and networks.
When a maker learns that a vulnerability is being actively exploited, it must submit an early warning notification to the EU’s cybersecurity agency ENISA and the designated computer security incident response team (CSIRT) through a single reporting platform within 24 hours.
This page shows the RSS-provided summary/preview. Full publisher content remains available at the original source.
Read Full Article at Source