A major European cybersecurity-reporting requirement became operational on September 11, 2026.
Under the EU Cyber Resilience Act (CRA), manufacturers of covered products with digital elements must report actively exploited vulnerabilities and severe security incidents.
This can be directly relevant to commercial crypto-wallet software and hardware where the product falls within the CRA’s scope.
The 24-hour rule
Manufacturers must submit an early warning within 24 hours after becoming aware of:
- an actively exploited vulnerability; or
- a severe incident affecting the security of the product.
The early warning is not necessarily the final technical report. Its purpose is rapid regulatory awareness.
The 72-hour notification
A fuller notification is due within 72 hours.
The notification should provide more complete incident/vulnerability information available at that stage.
Final reporting
The CRA also requires later final reporting.
For actively exploited vulnerabilities, the final report is generally due no later than 14 days after a corrective or mitigating measure becomes available.
For severe incidents, final reporting is generally due within one month after the incident notification, according to EU Commission guidance.
Single Reporting Platform
Manufacturers submit reports through the CRA Single Reporting Platform (SRP).
The notification goes to the Computer Security Incident Response Team (CSIRT) responsible for the manufacturer’s main establishment and, except in particularly exceptional circumstances, is simultaneously made available to ENISA.
Why this matters to crypto wallets
A commercial crypto wallet can combine:
- software;
- hardware;
- network connectivity;
- cryptographic key handling;
- transaction signing;
- firmware or application updates.
If such a product falls within the CRA perimeter, an actively exploited vulnerability may create a regulatory reporting obligation separate from customer notification, bug-bounty disclosure, law-enforcement reporting or financial-regulator reporting.
What the CRA does not mean
The rule should not be simplified into:
“Every crypto hack must be reported to the EU within 24 hours.”
Applicability depends on:
- whether the entity is a covered manufacturer;
- whether the product is a covered product with digital elements;
- the type of vulnerability/incident;
- jurisdictional and placing-on-market conditions.
Why the timeline is operationally demanding
A serious wallet vulnerability can require teams to do several things simultaneously:
- contain exploitation;
- preserve forensic evidence;
- develop a patch;
- coordinate with exchanges or infrastructure partners;
- communicate with customers;
- meet a 24-hour regulatory clock.
That makes pre-built incident-response and regulatory-notification workflows essential.
Evidence Status
Confirmed / Official EU Commission
- Reporting obligations apply from September 11, 2026.
- 24-hour early warning required.
- 72-hour fuller notification required.
- Reporting uses the CRA Single Reporting Platform.
- CSIRTs and ENISA are part of the reporting flow.
- Later final reports are required.
Product-Specific / Requires Legal Assessment
- Whether a particular wallet or crypto product is in scope.
- Which legal entity is the manufacturer.
- Which CSIRT receives a specific company’s report.
Risk Assessment
High operational and compliance significance for covered crypto-product manufacturers.
What to Watch Next
ENISA/CSIRT implementation, first enforcement examples, wallet-vendor reporting practices, vulnerability-disclosure coordination and guidance on crypto-specific product classifications.
FAQ
When did the reporting obligation start?
September 11, 2026.
What is due within 24 hours?
An early warning for qualifying actively exploited vulnerabilities or severe incidents.
Is the full report due in 24 hours?
No. A fuller notification is due within 72 hours.
Does this apply to all crypto protocols?
No.
Can hardware or software wallets be affected?
Yes, where the product and manufacturer fall within CRA scope.
Where are reports submitted?
Through the CRA Single Reporting Platform.