BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

EU Cyber Resilience Act News: Why Crypto Wallets Get 24-Hour Deadline?

EU Cyber Resilience Act Takes Effect: What Changes for Crypto Wallets? A major shift in crypto security regulation quietly began this month. Manufacturers of qualifying commercial connected h

AnonymousCryptoCompass newsroom
September 14, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for policy coverage.

EU Cyber Resilience Act Takes Effect: What Changes for Crypto Wallets?

A major shift in crypto security regulation quietly began this month. Manufacturers of qualifying commercial connected hardware wallets and wallet software must now alert European cybersecurity authorities within 24 hours of discovering an actively exploited vulnerability or a serious security incident. 

The obligation took hold on September 11, 2026, under the European Union's Cyber Resilience Act, a sweeping product-safety law that reaches far beyond crypto but now has real teeth for wallet makers selling into the bloc.

At a Glance

  • New reporting duty started September 11, 2026, for qualifying commercial connected wallet hardware and software

  • Manufacturers now have 24 hours to send an early warning after spotting an actively exploited flaw or a serious incident

  • A fuller notification is due within 72 hours, with separate deadlines for final reports

  • Reports go through ENISA's new Single Reporting Platform

  • The broader safety framework, including CE marking, doesn't kick in until December 11, 2027

Which Crypto Wallets Fall Under the EU Cyber Resilience Act?

The law is not written specifically for digital assets. It's a horizontal product rule that applies to hardware and software placed on the EU market whenever a product's intended or foreseeable use includes a data connection to a device or network. Commercially supplied connected hardware wallets and downloadable wallet apps can meet that bar. 

That said, regulators haven't published a list of covered brands, and not every crypto wallet project or service automatically qualifies. Whether a specific product is in scope depends on how it's supplied, its connectivity, and any exemptions that might apply.

Crypto Wallets Fall Under the EU Cyber Resilience Act

Source: Official CRA Page

Crypto Wallet Vulnerabilities Must Be Reported Within 24 Hours

This is the headline change. Once a manufacturer becomes aware of an actively exploited weakness or a severe security event, the clock starts ticking, and the first filing is due without unnecessary delay and no later than 24 hours later. 

The warning must note which member states have received the affected product and, for serious incidents, whether foul play is suspected.

CRA Requirement

Deadline

What It Covers

Early warning

Within 24 hours

Actively exploited flaw or serious incident

Full notification

Within 72 hours

Detailed vulnerability or incident information

Final vulnerability report

Within 14 days of a fix becoming available

Corrective and mitigating measures

Final incident report

Within 1 month of the 72-hour filing

Final assessment of the event

What Wallet Manufacturers Must Include in Reports

The second filing, due within 72 hours, goes deeper. For a vulnerability, it must add product details, information about the exploit, and the fixes or mitigations underway. 

For a serious incident, manufacturers must describe what happened, share an initial assessment, and outline available mitigation steps. Where action is needed, affected users, and sometimes the wider user base, must also be informed directly.

ENISA's Reporting Platform Becomes the Main Route

Manufacturers file once through the Single Reporting Platform run by ENISA, the bloc's cybersecurity agency. The portal forwards submissions to the relevant national incident response team and makes the data available to ENISA, which can then share it with other national teams as needed.

EU Market News Today

Source: CryptoSlate Post

Rules Also Reach Wallets Already Sold in the EU

One detail that's easy to miss: this reporting duty already applies to qualifying products sold before December 2027, not just wallets launched after the law fully applies. Open-source projects aren't automatically exempt either. 

Commercially distributed open-source wallet software can still trigger manufacturer obligations, though non-monetized software and individual contributors working outside their direct responsibility are treated differently. Reporting duties for open-source stewards specifically begin in December 2027.

What Happens Next: Full CRA Obligations Begin in December 2027

September 11 marked the start of rapid-reporting duties only, not the law's full rollout. The broader product-security framework, covering secure-by-design requirements, lifecycle obligations, and CE marking, becomes mandatory on December 11, 2027. Two rounds of technical standards are also expected before then, in October and December 2026.

Conclusion

The immediate effect for the crypto market is a far tighter regulatory reporting window than most wallet manufacturers have operated under before. Users won't see CE-marked wallets or sweeping design mandates yet, since those wait until late 2027, but the disclosure clock for serious flaws and incidents is already running. 

Wallet makers selling into the EU, and the users who rely on their products, should treat this as the first real enforcement milestone of the Cyber Resilience Act rather than a symbolic starting gun.

This article is for informational purposes only and does not constitute financial, legal, or investment advice. Regulatory requirements can change, and readers should consult official EU sources or qualified professionals before making decisions based on this information.

Disclaimer: Cryptocurrency markets are highly volatile and carry significant risk. This content is not financial advice. Always do your own research (DYOR) before making any investment decisions.