Commercial manufacturers whose connected hardware wallets or wallet software meet the European Union’s product test must now warn cyber authorities within 24 hours of discovering an actively exploited vulnerability or severe security incident.
The requirement took effect Sept. 11, 2026, under the EU’s Cyber Resilience Act, or CRA. The European Commission’s reporting guidance says the clock applies to manufacturers of products with digital elements.
The CRA is a horizontal product law. The Commission’s implementation FAQ says it applies to hardware and software made available on the EU market. The legal test also requires the product’s intended or reasonably foreseeable use to include a direct or indirect data connection to a device or…







