The European Union’s Cyber Resilience Act introduces a 24-hour initial reporting window for manufacturers that become aware their products are being actively exploited through a vulnerability.
The requirement forms part of the EU’s broader framework for products with digital elements, covering connected hardware and software sold on the European market. Manufacturers must submit an early warning before completing the more detailed follow-up reporting required under the regime.
Commercial crypto wallets may fall within scope
The legislation is not specific to cryptocurrency. However, commercial hardware wallets and wallet software marketed in the EU may be covered because the Act regulates digital products rather than targeting a particular industry.
That could give wallet providers additional cybersecurity responsibilities alongside existing financial and data-protection obligations. The practical effect is that companies may need to notify the relevant authorities as soon as they identify active exploitation, rather than waiting for a complete technical investigation.
Faster escalation for security teams
The 24-hour window is likely to require closer coordination between engineering, legal and security teams. Companies will need internal procedures capable of rapidly escalating a suspected incident and determining whether it meets the threshold for reporting, even when the full mechanics of an exploit remain unclear.
The Act also distinguishes between purely non-commercial open-source software development and commercial products placed on the market. For crypto businesses, the framework highlights the growing overlap between wallet security, software security and broader operational resilience.
Source: European Union, Cyber Resilience Act, Regulation (EU) 2024/2847.

