The European Union’s Cyber Resilience Act is introducing stricter reporting duties for crypto wallet manufacturers, including a requirement to notify authorities within 24 hours after becoming aware of an actively exploited vulnerability or a severe security incident. The measure adds a formal timetable for follow-up disclosures and raises the compliance burden for wallet providers selling into the EU market.
Under the framework, companies must also submit a fuller incident notification within 72 hours. Final reporting comes later: no more than 14 days after a corrective measure is available for actively exploited vulnerabilities, and within a month of the 72-hour notice for severe incidents. Open-source software stewards are due to come under reporting obligations from December 11, 2027.
Tighter deadlines for wallet security reporting
The new rules are aimed at speeding up how security problems are disclosed and handled when crypto wallets are affected. For wallet manufacturers, the first key deadline begins once they become aware of an exploit or a serious incident, at which point the 24-hour reporting clock starts.
The CRA then requires a more complete notification within 72 hours of the incident. That creates a staged reporting process: an initial alert, a fuller account soon after, and a final report once more is known and corrective action has been prepared or completed.
Penalty structure reaches up to €15 million
The act uses a tiered penalty system. The most serious category covers core system failures and can lead to fines of up to €15 million or 2.5% of total worldwide annual turnover. According to the extracted report, this tier includes failures to build in security by design, to report exploits within 24 hours, or to provide software security updates.
A second tier addresses supply-chain failures, with penalties of up to €10 million or 2% of turnover for distributing wallets without verified CE markings, proper documentation, or conformity assessments. A third tier targets false or misleading information given to authorities, with fines of up to €5 million or 1% of turnover. Beyond fines, consequences may also include software bans, recalls, or exclusion from the market. The source article also notes that civil lawsuits could follow if a security defect causes financial loss.
What may change for wallet users
For users, the practical effect may be faster disclosure of security problems and quicker emergency updates when bugs are found. The rules could also extend support for older hardware wallet models, because manufacturers may be pushed to provide patches for longer rather than allow products to become unsupported.
The trade-off may be higher compliance costs. The source article says some smaller open-source wallets could face access restrictions in the EU if meeting the requirements becomes too expensive. It also says regulatory adjustments may contribute to higher prices for premium hardware wallets.
Next step for the sector
The immediate impact of the CRA is to formalize how wallet providers must respond to exploited vulnerabilities and severe incidents, with clear deadlines and escalating consequences for failures. That is likely to put more pressure on manufacturers to maintain documented security processes and communicate faster when problems emerge.
A later milestone is already set for the open-source segment. Open-source software stewards are scheduled to take on reporting obligations from December 11, 2027, making that date the next confirmed point of expansion in the EU’s reporting regime.
Source: Coin Edition