The European Union began enforcing a mandate on September 11 requiring manufacturers to submit an initial report to authorities within 24 hours of becoming aware that a security vulnerability in a digital product has actually been exploited. Commercial hardware wallets and wallet software may also fall under this obligation if they meet the product requirements.
EU Mandates 24-Hour Reporting for Exploited Product Vulnerabilities, Including Crypto Wallets
The EU will require companies to report actively exploited product vulnerabilities within 24 hours, a rule that also applies to crypto wallets. The measure raises the compliance stakes for wallet providers and other product makers…
finance.biggo.com
Publisher
Sep 14, 2026 at 11:51 PM UTC · Updated hace un día · 2 min de lectura

Key Signal
24 hours Initial exploit report deadline
Last Updated
hace un día
The reporting obligation is based on the Cyber Resilience Act (CRA), a cross-cutting product law that broadly covers products with digital elements. It applies to hardware and software offered on the EU market, provided that their intended use or reasonably foreseeable use includes direct or indirect connections to devices or networks. However, the guidance does not name specific wallet brands, and whether a product falls within scope is determined on a case-by-case basis according to how it is offered and applicable exemptions.
The reporting requirement covers vulnerabilities confirmed to have been exploited, as well as major security incidents affecting product safety. Manufacturers are not required to complete root-cause analysis or remediation within 24 hours; the deadline applies solely to the initial notification.
Three-Stage Reporting Process
Article Intelligence
Related Coverage
View all relatedSponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
