The European Union just tightened its security rules: crypto wallet developers now have to report any vulnerabilities in their software within 24 hours of discovery. This requirement is part of the updated Cyber Resilience Act, which took effect on September 11.
What the Law Requires
The new rules say that as soon as a maker finds out about a vulnerability or a major security incident, they need to send an early warning within a day. A full statement has to be filed within 72 hours.
Who Has to Comply
These rules apply to both hardware and software crypto wallet providers registered in the EU. That means it covers everyone from hardware manufacturers to software developers.
When the Rules Kick In
The requirements went live on September 11. Any EU-based company working with crypto wallets now has to set up fast-track incident reporting to meet these strict deadlines.
