EU Cyber Resilience Act Brings 24-Hour Vulnerability Reporting Into Force

Summary

The EU Cyber Resilience Act imposes a new vulnerability reporting duty for products with digital elements, including many hardware and software wallets sold in the EU. If a vulnerability is being actively exploited, manufacturers must issue an early warning within 24 hours, followed by more detailed information later. This shifts incident response from waiting for a full investigation to quickly deciding whether the exploitation threshold has been met. The rule is not crypto-specific, but crypto wallet vendors may be covered because their products are treated as ordinary digital products. That adds security obligations alongside existing financial and data-protection rules. The law also distinguishes commercial products from purely non-commercial open-source development. Overall, wallet security is increasingly being regulated as standard software security under a broader operational-resilience framework.