风险雷达

/ high

EU Cyber Resilience Act:Covered Crypto Wallet Product 进入 24 小时 Exploit Reporting 时代

自 2026 年 9 月 11 日起,CRA-covered manufacturer 对 actively exploited vulnerability / severe security incident 需 24 小时 early warning、72 小时 fuller notification;符合范围的 commercial crypto wallet hardware/software 可能适用。

2026年9月14日最后更新 10:30 UTC约 2 分钟

欧洲一个非常重要的 cybersecurity reporting requirement 已在 2026 年 9 月 11 日正式开始执行。

EU Cyber Resilience Act(CRA)要求 covered products with digital elements 的 manufacturer 报告 actively exploited vulnerabilities 和 severe security incidents。

对落入 CRA scope 的 commercial crypto wallet hardware / software,这会直接改变 incident-response workflow。

24 小时 Rule

Manufacturer 在 aware of qualifying event 后 24 小时内提交 Early Warning

对象包括:

  • Actively exploited vulnerability;
  • Severe incident affecting product security。

这不是 final technical report,重点是快速让监管体系知道风险存在。

72 小时 Notification

之后需要在 72 小时内提交更完整 notification。

Final Report

之后还有 final reporting。

EU Commission guidance 说明:

  • Actively exploited vulnerability:通常在 corrective/mitigating measure available 后不晚于 14 天
  • Severe incident:通常在 incident notification 后 1 个月内完成 final report。

Single Reporting Platform

报告通过 CRA Single Reporting Platform (SRP) 提交。

Notification 会进入 manufacturer main establishment 对应的 CSIRT,并在通常情况下同步给 ENISA。

为什么跟 Crypto Wallet 有关?

Commercial wallet 可能同时包含:

  • Software;
  • Hardware;
  • Network connectivity;
  • Key handling;
  • Transaction signing;
  • Firmware/app update。

如果产品和 manufacturer 落入 CRA perimeter,actively exploited vulnerability 会额外产生 regulatory reporting duty。

这和 Customer notice、Bug bounty、Law-enforcement report、Financial-regulator report 是分开的。

不能怎么写?

不能写成:“欧洲所有 Crypto Hack 都必须 24 小时内报告。”

是否适用取决于:

  • Entity 是否是 covered manufacturer;
  • Product 是否是 product with digital elements;
  • Event 是否满足 CRA trigger;
  • EU market / jurisdiction conditions。

为什么 Operationally 很难?

严重 wallet vulnerability 发生时,team 同时要:

  • Contain exploit;
  • Preserve forensic evidence;
  • Build patch;
  • Coordinate exchanges / infrastructure;
  • Notify customers;
  • 24h regulatory warning。

所以事前 incident-response playbook 会变得非常重要。

Evidence Status

Confirmed / Official EU Commission

9/11 effective、24h early warning、72h fuller notification、SRP reporting、CSIRT/ENISA flow、final reports required。

某个具体 wallet 是否 in scope、哪个 entity 是 manufacturer、哪个 CSIRT 接收。

Risk Assessment

High operational / compliance significance。

What to Watch Next

First enforcement examples、ENISA/CSIRT practice、wallet-vendor reporting、crypto-specific classification guidance。

FAQ

什么时候开始?

2026 年 9 月 11 日。

24 小时内交什么?

Early warning。

Full report 24 小时内吗?

不是,fuller notification 是 72 小时。

所有 Crypto Protocol 都适用吗?

不是。

Hardware / Software Wallet 可能适用吗?

可能,取决于 scope。

从哪里报告?

CRA Single Reporting Platform。