Crypto: Europe Imposes 24-Hour Deadline to Report Wallet Vulnerabilities

Share

The Cyber Resilience Act (EU Regulation 2024/2847), which entered into force on December 10, 2024, requires manufacturers of digital products sold in the European Union to report any actively exploited vulnerability to ENISA and the competent national CSIRT within 24 hours. This obligation applies to hardware wallet manufacturers such as Ledger, Trezor, BitBox, or Keystone, as well as paid wallet software publishers, while non-commercial open source projects are exempt. The regulatory timeline then requires a full notification at 72 hours, followed by a final report within 14 days or one month depending on the nature of the incident. For non-compliance, the maximum fine amounts to 15 million euros or 2.5% of global annual revenue, whichever is higher. From December 11, 2027, products will also need to bear CE marking and provide a software bill of materials.

Source: Read the original article

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles