Summary:
- The EU Cyber Resilience Act now requires manufacturers to issue early warnings for actively exploited vulnerabilities within 24 hours.
- Commercial crypto wallets may fall under the definition of products with digital elements.
Europe’s Cyber Resilience Act is tightening the timeframe for reporting exploited vulnerabilities, affecting software companies and wallet manufacturers.
Under the EU framework, manufacturers of products with digital elements must alert authorities within 24 hours of detecting actively exploited vulnerabilities.
This rule applies to connected hardware and software products sold in the European market, including commercial crypto wallets.
Implications for Crypto Wallets
Although not specifically targeted at crypto, the CRA’s definition of digital products encompasses commercial hardware wallets and wallet software.
Wallet manufacturers now face additional security obligations, emphasizing the need for prompt reporting of serious vulnerabilities.
Incident response teams must adapt to the 24-hour reporting requirement, requiring swift escalation and decision-making processes.
Regulating Wallet Security
The CRA treats wallet security as part of general software security, aligning with the evolving regulatory landscape in Europe.
Crypto companies are urged to integrate wallet security into their overall cybersecurity strategy, emphasizing operational resilience.
For more information on the European Union Cyber Resilience Act, visit Eur-lex.
This article was originally sourced from Eur-lex and has been edited by our team.
