Crypto wallet manufacturers now have just 24 hours to alert European regulators when a vulnerability in one of their products is actively exploited. The obligation comes from Article 14 of the European Union’s Cyber Resilience Act (CRA), the bloc’s flagship cybersecurity rule for connected hardware and software, whose incident-reporting provisions took effect on September 11, 2026 — more than a year before the regulation’s broader security requirements become applicable in December 2027.
What the 24-Hour Deadline Requires
Article 14 of the Cyber Resilience Act covers manufacturers of “products with digital elements” — a category that sweeps in hardware wallets and commercial wallet software because such products connect to…







