The European Union's Cyber Resilience Act (CRA) reporting obligations took effect on September 11, 2026, imposing a mandatory 24-hour exploit-disclosure window on manufacturers of all products with digital elements sold in the EU — including hardware and software cryptocurrency wallets. Non-compl...
"The streamlined reporting and sharing of information on actively exploited vulnerabilities and severe incidents helps to build a more resilient Digital Single Market." — Juhan Lepassaar, Executive Director, ENISA
The European Union's Cyber Resilience Act (CRA) reporting obligations took effect on September 11, 2026, imposing a mandatory 24-hour exploit-disclosure window on manufacturers of all products with digital elements sold in the EU — including hardware and software cryptocurrency wallets. Non-compliance carries fines of up to €15 million or 2.5% of global turnover, whichever is higher.
The regulation arrives at a moment of acute relevance for the crypto wallet industry. In July 2026, a single wallet-related incident resulted in losses exceeding 1,778 BTC (approximately $112.7 million). Trezor disclosed on September 4 that a breach at shipping provider ShipMonk exposed 67,000 U.S. customer records. The DCENT App Wallet reported abnormal asset transfers on September 15, urging users to move funds to hardware devices. The CRA converts what were previously discretionary disclosure practices into a legally enforced, time-bound reporting regime overseen by ENISA, the EU's cybersecurity agency.
The hardware wallet market, valued at an estimated $720 million to $914 million in 2026 and growing at a 29–34% CAGR, now faces its first sector-wide cybersecurity compliance mandate from a major jurisdiction.
Articles 13 and 14 of the Cyber Resilience Act establish a three-stage reporting framework triggered by two categories of events: actively exploited vulnerabilities and severe security incidents affecting product integrity.
Stage 1 — Early Warning (24 hours). Manufacturers must file an initial notification within 24 hours of becoming aware of an actively exploited vulnerability or severe incident. The clock starts when the manufacturer gains awareness of active exploitation — not when an independent researcher files a theoretical bug report.
Stage 2 — Detailed Notification (72 hours). A comprehensive follow-up is required within 72 hours, documenting the scope, severity, and technical details of the exploit.
Stage 3 — Final Report (14 days / 30 days). A final report is due within 14 days of corrective or mitigating measures becoming available for actively exploited vulnerabilities, and within 30 days for severe incidents.
Manufacturers must also inform affected users about security issues and share available mitigations. Delayed disclosure or severity downplaying constitutes a finable offense.
Penalties. The primary fine ceiling is €15 million or 2.5% of worldwide annual turnover, whichever is higher. A secondary tier — up to €5 million — applies for supplying incorrect, incomplete, or misleading information to regulators. Micro and small enterprises are exempt from fines specifically tied to the 24-hour early warning requirement, though they remain subject to the broader framework.
ENISA launched the CRA Single Reporting Platform (SRP) on September 11, 2026 — the same day reporting obligations became binding. The platform is accessible at portal.cra-srp.enisa.europa.eu.
The SRP operates on a "report once" model. Manufacturers submit a single notification, which ENISA routes simultaneously to the Computer Security Incident Response Team (CSIRT) designated as coordinator in the manufacturer's EU member state of main establishment. That coordinator then distributes the notification to CSIRTs in other member states where the affected product is available.
Registration requires EU Login with multi-factor authentication. Each manufacturer designates one Primary Authorised Representative (AR) and may appoint up to 20 Secondary ARs for out-of-hours coverage. CSIRTs validate associations, but manufacturers may file up to 20 notifications while verification is pending.
At launch, the platform operates as a web interface only — no API is available. The interface is English-only, with translations planned for future phases. Voluntary reporting under Article 15 is also deferred to a later release.
The CRA applies to "all products with digital elements made available in the EU." For the crypto industry, this includes:
Crucially, companies headquartered outside the EU face the same requirements if their products are available on the European market. The regulation determines applicability based on where cybersecurity decisions are "predominantly taken" — typically at engineering sites rather than corporate headquarters.
Ledger and Trezor together control more than 70% of the global hardware wallet market, according to industry estimates. Ledger holds approximately 31.7–40% market share, with Trezor at approximately 18.4–30%, depending on the source. Both companies have significant EU customer bases.
The CRA's reporting obligations arrive against a backdrop of escalating wallet-related security events:
Trezor / ShipMonk breach (disclosed September 4, 2026). Trezor disclosed that 67,000 U.S. customer records — names, email addresses, phone numbers, shipping addresses, and order numbers — were exposed via a breach at third-party logistics provider ShipMonk. The breach exploited CVE-2026-72898 (CVSS 10.0), a critical SQL injection flaw in Metabase, attributed to the ShinyHunters extortion group. Trezor had previously notified 13,700 customers on August 13, bringing the total exposure to approximately 80,700 accounts. Trezor stated it had "repeatedly requested and received written assurance confirming the deletion of the data" from ShipMonk — data that should have been purged under a 90-day retention policy.
DCENT App Wallet (September 15, 2026). DCENT reported abnormal asset transfers from its App Wallet and launched an investigation. The company urged users to transfer assets to hardware wallets. DCENT's hardware wallets were reported as unaffected.
Zilliqa Ledger app vulnerability. A separate vulnerability in the Zilliqa Ledger application was found to allow potential private key recovery.
Broader DeFi context. DeFi protocols have lost at least $1.3 billion to exploits in the first eight months of 2026. Compromised private keys overtook smart contract bugs as the leading attack vector for the first time on record, according to industry data. Chainalysis attributes approximately 76% of crypto-related hack losses globally in 2026 to state-backed actors linked to the Lazarus Group.
Under the CRA framework, each of these incidents — to the extent they involve products with digital elements available in the EU — would trigger mandatory reporting obligations on the manufacturer.
The CRA imposes direct operational costs on wallet manufacturers, though the regulation's economic analysis focuses on the broader digital product ecosystem rather than the crypto sector in isolation.
Compliance infrastructure requirements include:
For smaller wallet manufacturers and open-source wallet projects, these requirements represent a material step-up in operational overhead. The micro/small enterprise exemption from 24-hour early-warning fines provides partial relief, but does not exempt these firms from the reporting obligation itself.
The hardware wallet market's estimated $720–914 million size in 2026 suggests compliance costs will be absorbed differently across the industry. Ledger — which completed a $100 million Series C in 2023 and has scaled to serve millions of users — is better positioned to absorb compliance overhead than smaller manufacturers with thinner margins.
September 11 marks only the first phase. The CRA's broader security-by-design mandates, conformity assessment procedures, and CE marking requirements take effect on December 11, 2027. These provisions will require:
Open-source software stewards face the same reporting obligations starting December 11, 2027. For the crypto industry, this has implications for open-source wallet projects such as Sparrow, Electrum, and others distributed in the EU.
The question of how hardware wallets will be classified — as standard, important, or critical products — remains open. The European Commission's delegated acts specifying product categories have not yet been finalized. Classification as "important" or "critical" would require third-party conformity assessment rather than self-certification, adding cost and time.
The CRA creates a third regulatory layer for crypto wallet providers operating in the EU, alongside MiCA (Markets in Crypto-Assets Regulation) and the NIS2 Directive. According to legal analysis from Crowell & Moring, firms must manage "parallel obligations under CRA, NIS 2, and GDPR in a single, coherent workflow."
MiCA, which entered full application in December 2024, establishes licensing requirements for crypto-asset service providers but does not address product-level cybersecurity. The CRA fills that gap by targeting the product itself — the wallet hardware and software — rather than the service provider entity.
NIS2, effective since October 2024, covers essential and important entities across critical sectors. Where a wallet manufacturer also qualifies as a critical infrastructure operator, NIS2's incident reporting obligations (also 24 hours for early warning) run in parallel with the CRA's product-level requirements.
The enforcement posture will vary by EU member state, according to legal advisors. Documented good-faith preparation is expected to carry weight in early enforcement actions.
The CRA marks the first time a major jurisdiction has imposed mandatory, time-bound vulnerability disclosure on crypto wallet manufacturers as a product category. The regulation treats wallet hardware and software like any other connected device sold in the EU — subject to the same reporting timelines, the same penalties, and the same ENISA oversight.
For the wallet industry, the compliance burden is real but bounded. The 24-hour reporting window forces organizational capabilities — on-call security teams, pre-built notification templates, supply chain monitoring — that most large manufacturers should already maintain. The harder test comes in December 2027 when security-by-design requirements and potential third-party conformity assessments take effect.
The economic question is whether compliance costs accelerate market concentration. Ledger and Trezor, which already control over 70% of the hardware wallet market, have the resources to absorb the overhead. Smaller manufacturers and open-source projects may not. The CRA does not set out to pick winners, but its structure favors scale.