The EU Cyber Resilience Act (CRA) requires crypto wallet manufacturers to report any actively exploited vulnerability to European authorities within 24 hours. From September 11, 2026, the obligation will also cover products already placed on the EU market.
🔑 Key takeaways
- Regulation (EU) 2024/2847 entered into force on December 10, 2024 and will fully apply on December 11, 2027.
- From September 11, 2026, hardware and software wallet makers must report exploited flaws within 24 hours.
- A detailed report follows at 72 hours, with a final report due within 14 days (vulnerability) or 1 month (severe incident).
- Notifications are filed once via ENISA’s single reporting platform and routed to national CSIRTs.
- Penalties can reach €15 million or 2.5% of total worldwide annual turnover.
The three key dates of the Cyber Resilience Act
Regulation (EU) 2024/2847, published in the Official Journal of the European Union, is the first pan-European measure setting mandatory cybersecurity requirements for products with digital elements — hardware or software — across their entire lifecycle. Its implementation timeline rests on three successive milestones.
The first deadline, September 11, 2026, activates reporting obligations for actively exploited vulnerabilities and severe incidents. This date is particularly consequential: it covers not only new products but also product lines already placed on the EU market. The second, December 11, 2026, requires Member States to have designated and notified their conformity assessment bodies to the European Commission. The third, December 11, 2027, triggers full application, including technical conformity requirements, CE marking and complete lifecycle management.
| Deadline | Obligation |
|---|---|
| September 11, 2026 | Reporting of exploited vulnerabilities and severe incidents (24h / 72h) |
| December 11, 2026 | Notification of conformity assessment bodies by Member States |
| December 11, 2027 | Full technical conformity, CE marking, lifecycle management |
<
Reporting deadlines imposed on wallet manufacturers
For cryptoasset wallets — whether connected hardware wallets or downloadable software meeting the European conformity test criteria — the CRA imposes a strict cascade of notifications. The 24-hour window corresponds to an early warning, not to remediation. The early warning must identify the Member States where the product is known to have been made available and, for a severe incident, indicate whether illicit or malicious acts are suspected.
A more detailed notification must follow within 72 hours of becoming aware of the event, unless the relevant information has already been communicated. For an actively exploited vulnerability, this report includes general product information, details on the exploit and the vulnerability, and any corrective or mitigative measures. For a severe incident, it must describe the nature of the incident, provide an initial assessment and list available mitigation information.
« The 24-hour obligation is not about the speed of remediation, but about the ability to detect and confirm active exploitation. »
Sector analyst, ContinueOps
Final reports follow distinct timelines: 14 days after a corrective measure becomes available for a vulnerability, and one month after the 72-hour notification for a severe incident. The precision required in these filings effectively mandates a Software Bill of Materials (SBOM) for wallet manufacturers.
ENISA portal, SBOM and open-source stewards
Notifications are filed once through the single reporting platform that ENISA, the European cybersecurity agency, is rolling out during 2026. The portal forwards the notification to the designated national Computer Security Incident Response Team (CSIRT), shares the information with ENISA, and then distributes it to all relevant national CSIRTs. Manufacturers must also inform affected users and, where applicable, their entire user base when action is required.
The open-source licensing regime does not create a blanket exemption. Under Commission guidance published on July 27, 2026, free and open-source products supplied commercially remain subject to manufacturer obligations. Non-monetized software supplied by its maker should not be treated as a commercial activity, while individual contributors are not treated as manufacturers for software outside their responsibility. Open-source stewards form a distinct legal category, with reporting obligations starting on December 11, 2027.
The CRA’s scope is deliberately broad: it covers products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. This definition explicitly includes software and remote data-processing solutions, well beyond physical connected devices. Products already governed by sector-specific rules — medical devices, motor vehicles, civil aviation — remain excluded.
Penalties and implications for the crypto ecosystem
Failure to meet essential requirements or manufacturer obligations exposes companies to fines of up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher. Lower ceilings apply to other infringements and the supply of incorrect information. For crypto actors, these amounts represent a significant financial risk likely to reshape cybersecurity investment priorities among wallet vendors.
Transitional provisions warrant close attention: products placed on the EU market before December 11, 2027 and compliant with existing legislation may continue to be made available until that date without meeting full CRA conformity requirements. However, these transitional provisions do not waive the reporting obligations that activate in September 2026 — a point existing product line makers must integrate into their governance immediately.
Conclusion
The Cyber Resilience Act reshapes the liability chain for crypto wallet manufacturers operating in the European market. The 24-hour window to report an exploited vulnerability forces a redesign of detection and incident escalation processes, with SBOM as an operational prerequisite. By September 2026, wallet vendors — including commercialized open-source projects — will need to have mapped their software dependencies, designated CSIRT contact points and trained their teams to draft compliant notifications.
The most likely scenario remains gradual application, punctuated by guidance from ENISA and the Commission. One open question: the broad definition of « products with digital elements » could eventually pull in categories currently on the margins — crypto SDKs, browser extensions — and impose an unprecedented compliance burden on the broader Web3 value chain.
Sources
- CryptoSlate — Crypto wallet creators now have just 24 hours to alert regulators when flaws are exploited
- ContinueOps — Cyber Resilience Act Timeline
- OpenMetal — Why the EU Cyber Resilience Act’s reporting clock depends on your infrastructure
- CyberResilienceAct.eu — Explained
- OpenSSF — EU Cyber Resilience Act
- European Commission — Cyber Resilience Act
This article is for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

