The European Union’s Cyber Resilience Act, or CRA, officially took effect on Sept. 11, setting stricter incident-reporting obligations for providers of crypto hardware and software wallets sold in the EU market. Under the new rules, firms must file an early warning report within 24 hours after discovering an actively exploited vulnerability or a severe security flaw, then submit a full notification within 72 hours. After corrective or mitigation measures are taken, manufacturers must provide a final report within 14 days, while severe incidents must be fully reported within one month.
The European Commission said the reporting framework is meant to better protect consumers and businesses from cyber threats. The rules apply to all products with digital elements offered on the EU market and form part of the bloc’s broader cybersecurity strategy. Penalties in the final draft are substantial: companies that fail to comply with Articles 13 and 14 may face administrative fines of up to €15 million, roughly $17.3 million, or 2.5% of global annual turnover, whichever is higher. Firms that submit incorrect, incomplete, or misleading information may be fined up to €5 million.
The measure comes after several security incidents involving wallet providers. Trezor said on Sept. 4 that a data breach at logistics vendor ShipMonk affected about 67,000 U.S. customers, above the initial estimate of 14,000. This week, Trezor and BitBox also warned users about phishing emails disguised as urgent security notices. In June, Layer-1 blockchain network Zilliqa said a flaw in its Ledger app could allow attackers to recover private keys using public on-chain data.
The European Union’s Cyber Resilience Act, or CRA, officially took effect on Sept. 11, imposing tighter reporting deadlines on providers of crypto hardware and software wallets.
Under the rules, companies must submit an early warning report within 24 hours after discovering an actively exploited vulnerability or a severe security flaw. A full notification must follow within 72 hours.
Reporting timeline under the CRA
Manufacturers must also file a final report within 14 days after taking corrective or mitigation measures. For severe incidents, the reporting process must be completed within one month.
Scope and purpose of the law
The European Commission said the new reporting requirements are designed to better protect consumers and businesses from cyber threats. The framework applies to all products with digital elements sold on the EU market and is part of the bloc’s broader cybersecurity strategy.
Potential penalties for non-compliance
According to the penalty provisions in the final draft, companies that fail to comply with Articles 13 and 14 may face administrative fines of up to €15 million, about $17.3 million, or 2.5% of global annual turnover, whichever is higher.
Submitting incorrect, incomplete, or misleading information can also lead to fines of up to €5 million.
Security incidents disclosed before the measure took effect
Before the measure came into force, several hardware wallet makers had recently disclosed user data breach incidents. On Sept. 4, Trezor said a data breach involving its logistics supplier ShipMonk affected about 67,000 U.S. customers, exceeding the initial estimate of 14,000.
This week, Trezor and BitBox also warned users about phishing emails disguised as urgent security notices.
In June, Layer-1 blockchain network Zilliqa warned that a vulnerability in its Ledger app could allow attackers to recover users’ private keys from public on-chain data.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.