What the Rules Require The European Union's cyber incident reporting obligations for hardware wallet makers and other connected product manufacturers are now in force. The incident-reporting
What the Rules Require
The European Union's cyber incident reporting obligations for hardware wallet makers and other connected product manufacturers are now in force. The incident-reporting provisions of the EU's Cyber Resilience Act (CRA) took effect on September 11, 2026, more than a year before the rest of the regulation becomes fully applicable.
Article 14 of the CRA covers manufacturers of "products with digital elements," a category that sweeps in hardware wallets and commercial wallet software because such products connect to devices and networks.Manufacturers must also notify any severe incident having an impact on the security of the product with digital elements simultaneously to the CSIRT designated as coordinator and to ENISA.
The CRA's Single Reporting Platform (SRP), operated by ENISA, is now the EU-wide gateway through which those notifications must flow. Manufacturers submit one notification through the SRP to the relevant CSIRT designated as coordinator and to ENISA.The initial report is not public: it goes to the CSIRT of the manufacturer's country of establishment and to ENISA through the Single Reporting Platform.
A Three-Stage Reporting Timeline
The reporting framework is built on a three-stage timeline that ensures regulators receive increasingly detailed information as a crisis unfolds. After the initial early warning, manufacturers have 72 hours to submit a more complete vulnerability notification.Once a corrective or mitigating measure is available, the manufacturer then has 14 days to deliver a final report, explaining what happened, how the issue was addressed, and what steps are being taken to prevent a recurrence.
The information sent to the CSIRT and ENISA is subject to confidentiality protection, including source code and trade secrets. Public disclosure only proceeds when necessary to prevent or mitigate a serious incident, and generally requires prior consultation with the manufacturer.
The requirement is part of the bloc's effort to build a stronger cybersecurity baseline for connected hardware and software. The regulation's broader obligations, including security-by-design, conformity assessment, and CE marking, will not become fully applicable until December 11, 2027, but the incident-reporting provisions have already created a significant shift in how wallet makers must think about vulnerabilities.
Open-source projects are not exempt either.
Sources:Crowell and Moring: EU Cyber Resilience Act Reporting Now LiveCyber Resilience Act Article 14 Full TextKuCoin News: EU CRA Requires 24-Hour Exploit Disclosure for Crypto Wallet Makers