European Union flags flying outside the European Commission headquarters in Brussels
REGULATION

CRA Puts Crypto Wallets On 24-Hour Clock

Image Credit: Shutterstock

Covered crypto wallet manufacturers selling products in the European Union must now report actively exploited vulnerabilities and severe security incidents within 24 hours of becoming aware of them under the bloc’s Cyber Resilience Act (CRA).

The reporting requirement took effect on Sept. 11, more than a year before most of the law becomes applicable. Connected hardware wallets and commercial wallet software can fall within its scope when they qualify as products with digital elements offered on the EU market.

Wallet Makers Face 24-Hour and 72-Hour Reporting Deadlines 

Manufacturers must submit an early warning within 24 hours after becoming aware of an actively exploited vulnerability or severe incident affecting their product. A fuller notification is due within 72 hours.

For vulnerabilities, manufacturers must provide a final report no later than 14 days after a corrective or mitigating measure becomes available. Severe incidents require a final report within one month of the 72-hour notification.

The rules apply to covered products already available in the EU, not only products released after the reporting regime began. Existing hardware and software lines can therefore become subject to the same notification timetable when an incident meets the CRA threshold.

ENISA Platform Becomes Single Reporting Channel

Reports must be submitted through the Cyber Resilience Act Single Reporting Platform operated by the European Union Agency for Cybersecurity, or ENISA. The platform went live on Sept. 11 alongside the new reporting obligations.

The system allows manufacturers to make one filing that reaches the relevant national Computer Security Incident Response Team and other authorities where required, avoiding separate notifications across multiple EU jurisdictions.

Manufacturers may also have to inform affected users when they become aware of an actively exploited vulnerability or incident that could affect product security.

Broader CRA Security Requirements Start December 11, 2027 

The 24-hour reporting requirement is an early part of the Cyber Resilience Act. Most of the law’s product-security requirements will apply from Dec. 11, 2027, covering how manufacturers design, maintain and update hardware and software sold in the EU.

Open-source software receives separate treatment. Reporting obligations for open-source software stewards do not begin until Dec. 11, 2027, while individual developers working outside commercial activity are treated differently under the law.

For covered crypto wallet companies serving the EU market, incident reporting is already live. Becoming aware of a qualifying exploit can start the 24-hour regulatory clock before an investigation or corrective measure is complete.

More For You

Explore More News