A new European Union cybersecurity reporting timetable is now operational for manufacturers of connected hardware and software, creating an immediate compliance issue for crypto wallet products that fall within the Cyber Resilience Act’s broad scope.
Since September 11, manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements made available in the EU. The European Commission says the reporting requirement covers products already on the market as well as newly introduced products.
The rule is not a blanket obligation to report every software defect. It is triggered when a manufacturer becomes aware of an actively exploited vulnerability or a severe security incident affecting an in-scope product. Whether a particular wallet, custody application or related service falls within the act remains a product- and business-model-specific legal assessment.
The clock starts when the manufacturer becomes aware
Article 14 of the Cyber Resilience Act requires an early warning without undue delay and, at the latest, within 24 hours of awareness. Unless the required information has already been supplied, a fuller notification is due within 72 hours.
For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the final report is due within one month after the 72-hour notification.
Reports go through the Cyber Resilience Act Single Reporting Platform operated by the European Union Agency for Cybersecurity, or ENISA. A manufacturer selects the relevant national computer security incident response team, generally based on its main place of establishment. The submission is also made available to ENISA, while the receiving team distributes it to other relevant national teams.
That makes the operational requirement more than a policy update. Wallet-product manufacturers need a documented decision path from security monitoring to legal classification and regulatory submission. A vulnerability-research inbox, outsourced security operations center or third-party component alert can no longer sit outside the incident process if it may provide the first evidence that starts the clock.
Wallet vendors need to separate product incidents from service incidents
The act applies to products with digital elements made available in the EU, a category that can include commercial software and connected hardware. For crypto businesses, the practical boundary is important: a hardware wallet or downloadable wallet application may present a clearer product case than a purely hosted financial service. Firms operating several models should not assume that one incident classification covers the entire group.
The legal duty falls on the manufacturer of the affected product. Payment and wallet groups should therefore identify which entity places each product on the EU market, who has authority to submit a report and which national response team should receive it. Contractual arrangements with developers, infrastructure suppliers and white-label partners should also provide rapid access to the technical facts required for the 24- and 72-hour stages.
ENISA’s current instructions add a practical constraint: the initial version of the reporting platform has no application programming interface. Notifications must be submitted through the online interface. Assigned representatives need personal EU Login accounts with multifactor authentication, and the platform permits one primary representative per manufacturer with additional secondary representatives.
For a security team, that argues for advance registration, backup representatives and rehearsed manual submission rather than waiting for an exploit to establish access. Internal workflows can still be automated, but the final regulatory filing currently requires a person to use the platform.
Reporting is live before the rest of the regime
The Cyber Resilience Act entered into force in December 2024, but its obligations are phased. Article 14’s reporting requirements began applying on September 11, 2026. Most of the act’s other product-security obligations apply from December 11, 2027.
This staggered timetable can create a false sense that compliance remains a 2027 project. For incident teams, the reporting clock is already running. Manufacturers should be able to preserve the awareness timestamp, determine whether exploitation is active, assess whether an incident meets the severe threshold and produce the information required at each stage.
The penalty ceiling underscores the need for disciplined handling. Under Article 64, noncompliance with Articles 13 and 14 can be subject to administrative fines of up to €15 million or, for an undertaking, 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher. Member states establish and enforce their penalty rules, so the ceiling is not a prediction of the sanction in any individual case.
For wallet and crypto-payment operators, the immediate priority is narrower than a complete 2027 product-compliance program: determine which offerings are in scope, name the responsible manufacturer, register authorized reporters and connect exploit intelligence to a filing process that can meet a 24-hour deadline.