EU Mandates 24-Hour Reporting for Wallet Security Vulnerabilities
Under the Cyber Resilience Act (Regulation (EU) 2024/2847), manufacturers of hardware wallets and commercial software wallets must report actively exploited vulnerabilities or security incidents to ENISA and national CSIRTs within 24 hours. The regulation, which began its phased implementation on September 11, 2026, requires a full notification within 72 hours and a final report within 14 days to one month. Non-commercial open-source software is exempt, while violations can result in fines up to 15 million euros or 2.5% of global annual turnover.
Summaries are written by AI from the original article. Not investment advice.