The European Commission announced that the EU’s Cyber Resilience Act (CRA), which took effect on Friday, mandates strict reporting timelines for cryptocurrency hardware and software wallet providers. Manufacturers must submit an early warning for severe vulnerabilities within 24 hours of becoming aware of them, followed by a full notification within 72 hours. A final report is required 14 days after corrective measures are available, or within one month for severe incidents.

These requirements apply to all products with digital elements made available in the EU, aiming to protect consumers and businesses from cyber threats. Non-compliance under Articles 13 and 14 can result in administrative fines of up to 15 million euros ($17.3 million) or 2.5% of worldwide annual turnover, whichever is higher. Providing incorrect or misleading information carries a separate fine of up to 5 million euros. The measure follows recent security disclosures from wallet providers Trezor and BitBox regarding data breaches and phishing attempts.