Under the EU's Cyber Resilience Act, commercial crypto wallet manufacturers now have 24 hours to flag an actively exploited vulnerability or severe security incident to national cyber authorities. The fast-track disclosure regime took effect Sept. 11, 2026, and applies to any 'product with digital elements' with a direct or indirect data connection, pulling commercially supplied connected hardware wallets and downloadable wallet apps into scope. Filings route through ENISA's Single Reporting Platform to the coordinating national CSIRT, with a fuller notification due within 72 hours and a vulnerability report due within 14 days of a corrective measure.
Why it matters
The CRA reframes wallet security from industry best practice into a regulated product-liability function. Wallet makers now operate on a regulator-facing clock that mirrors consumer-electronics disclosure norms. Open-source projects do not get a blanket carve-out: commercially supplied free and open-source products can still face manufacturer obligations, while unpaid contributors and non-monetized manufacturer software stay out. Open-source stewards form a separate legal category whose reporting duties only begin Dec. 11, 2027. The rule also reaches existing product lines: anything placed on the EU market before Dec. 11, 2027 runs on the same 24-hour clock.
Market impact
For hardware-wallet vendors, the window tightens the cost calculus around silent patching. Smaller operators with thin incident-response benches now face the same early-warning clock as multinational device makers, and wallet providers will likely need dedicated compliance staffing or third-party CSIRT relationships. The ENISA portal centralizes visibility for every European regulator, so a single disclosure event moves from a private customer-trust problem into a multi-jurisdictional regulatory event within a day. Bullish for wallet brands with clean security track records and public vulnerability-disclosure policies; bearish for vendors that have historically relied on quiet patching. Cyber insurers writing coverage for EU-distributed wallets will likely re-price the 24-hour window into policy terms.
Frequently asked questions
-
What does the EU's 24-hour crypto wallet disclosure rule actually require?
Under the Cyber Resilience Act, commercial wallet manufacturers must file an early warning with national cyber authorities within 24 hours of discovering an actively exploited vulnerability or severe security incident, followed by a fuller notification within 72 hours. The rule took effect Sept. 11, 2026.
-
Which crypto wallets does the CRA cover?
The CRA covers commercially supplied connected hardware wallets and downloadable wallet apps that meet the 'product with digital elements' test, meaning products with a direct or indirect data connection. EU guidance does not name specific brands; coverage depends on the product and how it is supplied.
-
Are open-source crypto wallets exempt from the 24-hour clock?
No. The Commission's open-source guidance treats commercially supplied free and open-source products as in-scope, though unpaid contributors and non-monetized manufacturer software fall outside the definition. Open-source stewards form a separate category whose reporting duties begin Dec. 11, 2027.
-
Where do manufacturers file the 24-hour disclosure?
Filings go through ENISA's Single Reporting Platform, which routes the notification to the designated coordinating national Computer Security Incident Response Team and distributes it to other relevant national teams and to ENISA itself.
-
Does the 24-hour clock apply to wallets already on the market?
Yes. The reporting rule reaches products placed on the EU market before Dec. 11, 2027, pulling existing product lines into the new regime rather than only catching wallets first sold after the law's main requirements take effect.
CryptoSlate