EU Mandates Strict Twenty Four Hour Flaw Notice for Crypto Wallets

TL;DR
- The EU activated Article 14 of the Cyber Resilience Act, requiring crypto wallet manufacturers to report active vulnerabilities within 24 hours.
- The initial report is not public: it goes to the CSIRT of the manufacturer’s country of establishment and to ENISA through the Single Reporting Platform.
- Hardware and software wallets marketed in Europe are already covered, even though the bulk of the CRA only takes effect in December 2027.
The European Union activated one of the most demanding obligations of the Cyber Resilience Act (CRA): manufacturers of products with digital elements available on the European market, including crypto wallets, must notify competent authorities within 24 hours of becoming aware of an actively exploited vulnerability or a serious security incident.
The EU brought forward this requirement —contained in Article 14 of the CRA— ahead of the rest of the regulatory framework, which will enter into force in December 2027.
The legal obligation falls on the manufacturer, understood as the person or company that develops a product and markets it under their name or brand. Hardware wallets and desktop or mobile applications distributed commercially in Europe fall within the scope of the regulation, given that they involve logical or physical connections with devices or networks. The law also covers products already available on the market before December 2027, not only future ones.
… Continue reading the full article at the original source below.


