The European Union's Cyber Resilience Act has officially gone live, forcing global technology manufacturers—including cryptocurrency wallet creators—to report actively exploited security vulnerabilities within 24 hours. Operating through ENISA's new Single Reporting Platform, this mandate retroactively covers legacy products already on the market. Non-compliance carries severe penalties of up to €15 million or 2.5% of global turnover, presenting immediate operational challenges for an industry where 66% of organizations remain unfamiliar with the law.
CRA Article 14 reporting obligations
- ▪Failure to comply with the EU Cyber Resilience Act's Article 14 reporting requirements carries administrative fines of up to €15 million or 2.5% of a company's global annual turnover, whichever is higher
- ▪Under Article 14 of the EU Cyber Resilience Act, which took effect on September 11, 2026, manufacturers of connected hardware and software must report actively exploited vulnerabilities within 24 hours of becoming aware of them
- ▪The EU Cyber Resilience Act's Article 14 reporting framework requires a detailed technical notification within 72 hours of awareness and a final report within 14 days of a corrective measure becoming available
- ▪Article 64(10)(a) of the EU Cyber Resilience Act removes late-reporting fines specifically for microenterprises and small enterprises, though the legal obligation to report still stands
ENISA Single Reporting Platform mechanics
- ▪At launch, the ENISA Single Reporting Platform does not support an application programming interface, requiring manufacturers to submit all vulnerability and incident reports manually through its web portal
- ▪The ENISA Single Reporting Platform's fields record when a vulnerability was detected rather than when a manufacturer became aware of it, requiring manufacturers to maintain separate timestamped records of awareness
- ▪The ENISA Single Reporting Platform serves as the sole legally valid channel for manufacturers to submit vulnerability and incident reports under the EU Cyber Resilience Act
Retroactive coverage of existing products
- ▪Article 69(3) of the EU Cyber Resilience Act retroactively applies Article 14 reporting obligations to all in-scope products already placed on the EU market before December 11, 2027
- ▪The general grandfathering rule that exempts pre-December 2027 products from most EU Cyber Resilience Act requirements does not apply to Article 14's vulnerability and incident reporting obligations
- ▪The 2026 CRA Awareness and Readiness Report published by the Linux Foundation and OpenSSF found that 66% of surveyed organizations remain unfamiliar with the EU Cyber Resilience Act
Cryptocurrency wallet compliance implications
- ▪Commercial cryptocurrency hardware wallets and downloadable wallet software are subject to the EU Cyber Resilience Act's 24-hour reporting mandate if they feature direct or indirect network data connections
- ▪Under the EU Cyber Resilience Act, open-source software stewards are classified as a separate legal category whose reporting obligations do not begin until December 11, 2027
Debatable claims
- ▪The EU's 24-hour cybersecurity vulnerability reporting deadline is too short
- ▪The EU Cyber Resilience Act should not retroactively apply to legacy products
Story comments
Loading comments…