EU Cyber Resilience Act now requires crypto wallet manufacturers to report actively exploited vulnerabilities within 24 hours, with broader compliance deadlines through 2027.
Regulation & Gov ·
The EU's Cyber Resilience Act has imposed new disclosure timelines on commercial hardware and software wallet providers, requiring them to alert regulatory authorities to actively exploited vulnerabilities and serious security breaches within a single day. According to CryptoSlate, the law mandates a complete formal notification 72 hours after the initial alert.
Wallet makers must deliver final vulnerability reports 14 days after fixes or workarounds are ready for deployment. For serious incidents, the final submission deadline is one month following the 72-hour notification window. These reporting obligations became operative on September 11, 2026, establishing an immediate compliance baseline for the sector.
Separate from the vulnerability-disclosure framework, a broader set of product-security requirements under the Act will commence on December 11, 2027, though the details of those obligations remain distinct from the active-threat reporting regime now in force.