The EU’s Cyber Resilience Act now requires in-scope commercial hardware wallet and wallet software manufacturers to report actively exploited vulnerabilities or serious security incidents to cyber authorities within 24 hours, according to CryptoSlate.

A full notification is due within 72 hours. Final vulnerability reports must be submitted within 14 days after corrective or mitigating measures become available, while final reports for serious incidents are due one month after the 72-hour notification. The reporting rules took effect on Sept. 11, 2026, while broader product-security obligations will begin on Dec. 11, 2027.