The European Union is drastically tightening its digital security requirements with the progressive entry into force of the Cyber Resilience Act. This legislative framework now imposes increased transparency obligations on manufacturers of cryptocurrency wallets, whether hardware or software-based. Once an actively exploited vulnerability or a critical incident is detected, the company in question has a strict 24-hour window to notify ENISA and the relevant national cybersecurity authorities, such as CERT-FR in France.
The reporting timeline is particularly rigorous: following this initial alert, a full notification must be submitted within 72 hours, followed by a final report detailing the patches or mitigation measures deployed, within a period ranging from 14 days to one month depending on the nature of the incident. This procedure, centralized on a dedicated platform, aims to ensure immediate responsiveness to cyber threats while maintaining initial confidentiality. The goal is to enable authorities to manage risks in a coordinated manner without prematurely exposing users to increased exploits.
The scope of this regulation encompasses all digital products marketed commercially within the European space, directly targeting leaders in the hardware wallet market as well as software solutions monetized through commissions or subscriptions. Although non-profit open-source projects are exempt, the line is thin: as soon as open-source code serves as the foundation for a commercial activity, the publisher is subject to these obligations. This measure also requires foreign companies to appoint a legal representative in Europe, thereby ensuring effective legal accountability.
In the event of non-compliance, the planned financial penalties are dissuasive, reaching up to 15 million euros or 2.5% of annual global turnover. Beyond mere reporting, the regulation paves the way for broader structural security standards by December 2027. Ultimately, manufacturers will be required to guarantee regular updates for at least five years and obtain CE marking, effectively classifying cryptocurrency storage devices as standard connected equipment subject to strict compliance and resilience testing.