The European Union's Cyber Resilience Act took effect on September 11, 2026, and it puts a hard clock on anyone selling connected crypto wallets into the bloc. When a manufacturer becomes aware that a vulnerability is being exploited, an early warning is due to regulators without undue delay and no later than 24 hours later, according to reporting from CryptoSlate on the newly active rules.
The requirement lands on a broad set of products. Connected hardware wallets and downloadable wallet software sold on the EU market qualify if they carry "a direct or indirect data connection to a device or network." That definition pulls in most of what people actually use to hold crypto, from USB signing devices to browser and mobile app wallets that phone home for balances and firmware updates.
The clock runs in three stages
The 24-hour early warning is only the first checkpoint. The CRA sets a three-stage timeline that escalates from a heads-up to a full account of what went wrong.
Stage one is the early warning, due within 24 hours of the manufacturer learning of an actively exploited vulnerability or a severe incident. Stage two is a fuller notification within 72 hours, spelling out the affected product, the nature of the exploit, the vulnerability itself, and any corrective measures already taken. Stage three is the final report: for vulnerabilities, it is due within 14 days after a fix becomes available; for severe incidents, within one month of the 72-hour notification.
Filings go through a Single Reporting Platform run by ENISA, the EU's cybersecurity agency, which then routes notifications to the relevant national incident response teams. That centralization matters. A wallet maker no longer picks which national regulator to tell and when. One channel, one clock, one distribution list.
Products already on shelves are covered
The rule is not limited to devices launched after this month. It reaches products placed on the EU market before December 11, 2027, which means an older hardware wallet still in active use falls under the same reporting duties as a model shipping today. For a manufacturer with years of legacy inventory in the field, the compliance surface is the whole catalog, not just the next release.
That is a meaningful shift for a sector where responsible disclosure has often moved on the vendor's own timeline. A hardware wallet company that discovers an exploited signing flaw can no longer sit on the news while it quietly ships a patch. The 24-hour warning obligation starts the moment it becomes aware, and the paper trail is filed with a government platform rather than a security blog.
Faster visibility for self-custody holders, with trade-offs
For anyone using a self-custody wallet tied to the EU market, the practical effect is faster official visibility when something breaks. Regulators, and eventually the public through downstream disclosures, should learn about exploited flaws in days rather than weeks. The Bank for International Settlements recently warned that attackers are compressing the gap between a disclosed weakness and a working exploit, so a tighter reporting window is at least aimed at the right problem.
The trade-offs are real. A 24-hour warning fired before a fix exists can tip off other attackers, and smaller wallet teams now carry a compliance load that larger issuers absorb more easily. Firmware and app updates that used to ship quietly may now arrive alongside regulatory filings, which changes the incentives around how quickly and how loudly a vulnerability gets handled.
For the crypto card users who lean on these same wallets to fund spending from their own keys, the security layer sits underneath the card. A hardware or app wallet that signs transactions is exactly the kind of connected product the CRA now governs, so the reporting clock touches the tools people use to top up and spend, not just cold storage sitting in a drawer.
Overview
The EU Cyber Resilience Act, live since September 11, 2026, forces makers of connected crypto wallets sold in the EU to warn ENISA's Single Reporting Platform within 24 hours of an exploited flaw, file a full notification within 72 hours, and submit a final report after a fix. It applies to products placed on the market before December 11, 2027, not only new releases. The upside is faster official disclosure; the cost is a heavier compliance burden and the risk of tipping off attackers before patches land.



