Manufacturers of connected hardware wallets or wallet software sold in the European Union must now notify cybersecurity authorities within 24 hours after discovering an actively exploited vulnerability or severe security incident, under the Cyber Resilience Act (CRA).

The reporting requirement, effective September 11, 2026, applies to products with digital elements that include a data connection to a device or network. This includes commercially supplied hardware wallets and downloadable wallet applications, though specific coverage depends on the product’s design and distribution method.

The European Commission specifies two reporting phases: an initial early warning within 24 hours and a detailed notification within 72 hours. The initial report must identify affected EU member states and indicate whether malicious activity is suspected. For actively exploited vulnerabilities, additional details about the exploit, corrective measures, and mitigation steps are required.

The final detailed report for vulnerabilities must be submitted within 14 days after a fix becomes available, while severe incident reports submit within one month of the initial notification. Manufacturers must use the EU’s Single Reporting Platform managed by ENISA, which routes incident data to national Computer Security Incident Response Teams.

Companies are also required to inform affected users directly, and provide guidance to all users if broader action is needed. The regulation applies retroactively to all in-market connected hardware and software devices placed in the EU before December 11, 2027.

Open-source software suppliers are subject to the law only when commercially distributing their products. The CRA’s open-source guidance clarifies that monetized products require reporting obligations, while non-commercial or individual-contributed code falls outside manufacturer responsibilities.

Source link

Exit mobile version