Key Takeaways
- Reporting starts only after active exploitation.
- First warning arrives within 24 hours.
- Commercial wallet products are likely covered.
- Most CRA rules start December 2027.
The 24-hour reporting rule starts before the wider CRA
From September 11, manufacturers must report actively exploited vulnerabilities and severe security incidents affecting products with digital elements made available on the EU market. The report is submitted through the Single Reporting Platform operated by ENISA to the CSIRT in the Member State of the manufacturer’s main establishment and, in normal circumstances, to ENISA.
Most of the EU Cyber Resilience Act (CRA) applies from December 11, 2027, including its wider requirements around product design, documentation and conformity. Article 14, the provision covering exploited vulnerabilities and severe incidents, starts earlier.
That means a wallet company may not yet...


English (US)