24 Hours to Talk: The EU Just Put Wallet Makers on a Very Short Clock
Under the EU's Cyber Resilience Act, commercial wallet makers must flag actively exploited flaws to regulators within 24 hours. The three-stage reporting clock started Sept. 11, 2026, and it's going to change how hardware and software teams ship. Here's what actually matters.
I spent Tuesday night reading European Commission reporting guidance instead of watching charts. That's how I know this one matters.
Anon, let me explain. Since Sept. 11, 2026, any commercial wallet hardware or software that meets the EU's product test has 24 hours to alert cyber authorities the moment it learns a vulnerability is being actively exploited. One day. Not one sprint. Not one "we'll get to it after the audit."
The Clock, In Detail
Here's the part most coverage skips. It's not one deadline. It's three.
Stage one is an early warning, filed within 24 hours of the manufacturer becoming aware of an actively exploited vulnerability or a severe security incident. Stage two is a fuller notification within 72 hours, with more detail on severity, affected products, and what's being done. Stage three is a final report inside 14 days. For actively exploited flaws the timeline compresses hard, because the clock isn't waiting on your patch.
That's the detail that should make engineers sweat. The obligation is to report, not to fix. You can file your 24-hour warning on a Monday and still ship the patch three weeks later. Reporting and remediating are two separate duties, and the EU only put a hard timer on one of them.
Scope matters too. This covers products that qualify as commercial, which pulls in connected hardware wallets and the software that talks to them. Open-source maintainers who don't sell anything aren't the target here. Manufacturers who do are.
So what does a 24-hour warning actually buy a user if the fix takes a month? Honestly, less than you'd think. What it buys is a paper trail.
This Is Bigger Than Wallet Makers
Europe did this before. GDPR turned into the global default because nobody wanted to build two compliance stacks. The CRA reporting rule is heading down the same road.
Watch the cost curve. A 24-hour turnaround needs someone on call who can write a regulatory filing at 3 a.m. That's a legal retainer plus a security ops budget plus a compliance tool. Ledger and Trezor can absorb that. A twelve-person startup in Lisbon building a niche hardware signer probably can't, at least not without raising.
That's a consolidation story wearing a safety hat. Fewer independent wallet makers, more money flowing to the ones with in-house counsel. This is bigger than people realize.
And notice what's missing. The 24-hour report goes to regulators. It doesn't go to users, and it doesn't go public. Your wallet could be under active exploit on day one and you might not hear a word until the final report lands two weeks later, if then. That gap between what Brussels knows and what you know is the real risk here.
What I'd Actually Do
Real talk: this is a net positive. Regulated disclosure forces teams to actually track their own incidents instead of quietly patching and hoping nobody noticed. The chain doesn't lie, and neither should an incident report.
But don't confuse a filing deadline with user protection. They're different things, and the EU only legislated one of them.
So here's what I'm watching. First, whether any non-EU manufacturer geo-fences the EU to dodge the reporting duty. Second, how many reports get filed in year one, because that number tells you how much was going unreported before. Third, whether the same 24-hour standard shows up in US rulemaking, which I'd bet on.
If you hold a hardware wallet, nothing changes today. But the company behind it now has a deadline it can't miss. That's a small shift with a long tail.