EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Declaration obligations for wallet manufacturers: Regulations effective from September 11, 2026

2026-09-14 09:31:38
Bookmark

Effective September 11, 2026: Impact of the EU Cyberelasticity Act on cryptocurrency holders

Effective September 11, 2026, an obligation has been implemented across the EU that did not previously exist in this form: Any manufacturer that puts a product with a digital element into commercial circulation in the EU market must report the vulnerability to the competent authority within 24 hours and notify affected users of information about the vulnerability and the responses they can take on their own.

The second part is even more important for you as a cryptocurrency holder. This rule is located in Article 14 (8) of the EU's CyberResilience Act, which clarifies who is accountable for ensuring that you are aware of problems with your wallet. Previously, this was part of the company's culture; from now on, it has become a legal obligation backed by a fine framework.

This article will explain the specific application situation, effective time, application objects, and the boundary between established legal positions and excessive interpretation. Because the regulation does not name any wallet brand, any list of affected manufacturers derived therefrom is beyond the scope of the regulation itself.


Contents applicable from September 11, 2026: Article 14 of the EU Cyberelasticity Act

Introduction to the Cyberelasticity Act

The Cyber Resilience Act, or European Union Regulation (EU) 2024/2847, is often referred to simply as CRA. CRA will take effect on December 10, 2024, but will only be fully applicable from December 11, 2027. However, Article 71 (2) contains a sentence that subverts the entire timetable:

"This regulation will apply from December 11, 2027." However, Article 14 should apply from September 11, 2026, and Chapter 4 (Articles 35 to 51) should apply from June 11, 2026."

Article 14 is titled "Manufacturers 'Reporting Obligations", so it was the first part of the regulation to be activated. Everything else-conformity assessments, CE marks, basic cybersecurity requirements in Annex I-will not take effect until 2027. Therefore, reading the article "CRA has been applied" now only refers to this clause.

The core content is summarized in one sentence:

Manufacturers must simultaneously report every vulnerability in their products that has been actively exploited and every serious security incident to their designated Coordinating Computer Security Incident Response Team (CSIRT) and the European Cyber Security Agency (ENISA) through a single reporting platform.


What is CSIRT?

The Computer Security Incident Response Team is a body designated by Member States to receive, evaluate and refer security incidents. In Germany, CERT-Bund within the Federal Office for Information Security coordinates CSIRT, and BSI is also responsible for market supervision.


What are vulnerabilities that have been actively exploited?

A security flaw that the manufacturer knows is being used by an attacker. Theoretical flaws discovered in the laboratory will not trigger a 24-hour countdown. Only those that are abused in practice count.


Why product regulation involves your cryptocurrency wallet

CRA is not financial law or crypto law. It is a horizontal product law that does not care about which assets the equipment manages, only cares about whether it is a product with digital elements and whether it is commercially circulated in the EU market. This is the fundamental reason why it is related to crypto hosting.

A hardware wallet is a physical device whose firmware communicates with supporting software via USB, Bluetooth, or QR code. Wallet apps are software that providers provide for download. From a design point of view, both belong to the "software and hardware products and their remote data processing solutions" described in Article 3, paragraph 1. Article 2, paragraph 1, delineates boundaries through connectivity: The regulation applies to products whose intended use or reasonably foreseeable use includes "direct or indirect logical or physical data connection to equipment or network."

This is the point of change for cryptocurrency custody. If you keep your own balance, your safety depends entirely on two things: the quality of the equipment and software, and whether you can know if problems arise. For the former, reporting obligations have not yet been covered; the corresponding requirements will not take effect until 2027. The latter will be effective immediately. See our comparison of hardware wallets for details on which devices exist and how they differ; for software-only solutions, the considerations are the same, but the attack surface is different.


Products with numerical elements: Who counts as the manufacturer under legal testing

Whether a specific device or specific application is covered is determined by three test steps. There is no list of affected products. Step 1: Is the product placed on the EU market, i.e. supplied for distribution or use in commercial activities? Step 2: Does it constitute a software or hardware product within the meaning of Article 3? Step 3: Does its intended or reasonably foreseeable use include direct or indirect data connections?

Commercially distributed connected hardware wallets and company-provided wallet applications can meet these three issues. This is an application of legal testing, not an official determination for any specific product. Anyone who translates this into an assertion that a provider must do something now is asserting something that neither the statute nor the committee's guidance supports.

The location of the manufacturer is also important. This is detailed in Article 14 (7): Jurisdiction depends on the CSIRT where the manufacturer is mainly established within the alliance, that is, where its product cybersecurity decisions are mainly made. If it has no office at all in the EU, the order of priority applies: first, the member state of the authorized representative, second, the member state of the importer, again, the member state of the distributor, and finally the member state with the largest number of users. Therefore, providers outside Europe will not automatically be excluded from the scope of application once they serve the European market.


Connected devices with firmware and supporting software: This is exactly the design on which the regulation relies.

24 hours, 72 hours, 14 days: The chain of deadlines under Article 14 (2)

regulations require three interdependent reports. All periods are calculated from the time the manufacturer becomes aware of it.

Early warning: No more than 24 hours after knowledge.

Early warnings must state in which Member States the affected product has been placed on the market, to the extent known to the manufacturer. The regulation does not require more at this stage, which is intentional: early warnings are intended to be quick, not complete.

Vulnerability notification: No more than 72 hours after knowledge.

Add general information about the affected products, exploitation methods and nature of the vulnerability, corrective or mitigation measures that have been taken at this time, and clearly include "corrective or mitigation measures that can be taken by users."

Final report: No more than 14 days after mitigation measures are taken.

Contains a description of the vulnerability, including its severity and impact, information about the attacker if available, and information about security updates or other corrective actions.

For serious safety incidents specified in paragraph 3 of Article 14, the 24-hour and 72-hour splits also apply, but in this case the final report should be submitted within one month after the 72-hour notice. When an event constitutes a serious event is defined in paragraph 5: when it affects the product's ability to protect the availability, authenticity, integrity, or confidentiality of sensitive data or functions, or when it causes or is likely to cause the execution of malicious code.

Reporting is conducted through the CRA single reporting platform operated by ENISA. The manufacturer submits it once, and the report is provided to both competitive coordinating CSIRT and ENISA. After submitting the final report, the reporter is usually no longer able to edit the submission.


Article 14 (8): When manufacturers must notify you directly

The reporting period to CSIRT and ENISA is part of the industry media attention. For you as a user, the key sentences are located elsewhere, namely Article 14, paragraph 8. To simplify it slightly, it reads: After a manufacturer becomes aware of a vulnerability or critical security incident that has been actively exploited,

"It should notify affected users, and if necessary, all users, about the vulnerability or incident, and if necessary, of any risk mitigation and corrective actions that can be deployed."

There are three points worth reading carefully:

First: Obligations are attached to the same moment of knowledge as reporting to the authorities.

The trigger point is the same moment. However, regulations do not specify a fixed number of hours for notifying users. What is required is information relevant to knowing, and timeliness is emphasized elsewhere in the text. Anyone who converts a 24-hour period to authorities into a 24-hour period to customers is misinterpreting the clause.

Second: Users must be informed of the measures they can take to respond.

This is the core of practice. If there are measures that the user can take on their own, a notice stating that there is a problem does not conform to the wording. For wallets, these measures are relevant: updating firmware, temporarily stopping certain features, transferring balances to a new address, and manually checking signatures before confirmation.

Third: Regulations want to be in a machine-readable format.

The text refers to a structural, machine-readable format that is easy to process automatically, supplemented by a "if appropriate" qualification. For security researchers and portals that aggregate warnings, this is the most eye-catching wording in the entire paragraph.


What happens if manufacturers remain silent? CERT-Bund's role

The second sentence of clause 8 is a real new leverage:

"If manufacturers fail to promptly notify users of products with digital elements, CSIRT, as coordinator, can provide such information to users as it deems appropriate and necessary to prevent or mitigate the impact of those vulnerabilities or events."

European law thus stipulates that authorities can release information to the public about product vulnerabilities if the manufacturer fails to notify them promptly. For Germany, this means specifically: BSI's CERT-Bund receives reports as coordinating CSIRT, and BSI can take action as market watchdog. This is not an obligation to warn; the wording is "may" and depends on proportionality and necessity. But for you, this means that from now on, a second location will emerge where information about the products you use will gather.

A review of recent weeks shows that this route is necessary. When vulnerabilities in Bitcoin Lightning implementation were made public in August, operator information relied on release notes and industry media. We analyzed this case in an article on Core Lightning vulnerabilities and when nodes must be offline. How to technically verify wallet warnings, see our article on blind signing and how to turn off blind signing on hardware wallets.


The rule clearly states that there is no: There is no wallet brand list

This is a qualification that should be included in every text that honestly discusses this topic. Neither the regulations nor the European Commission's guidelines name any wallet brand, any specific device type in the crypto world, or any specific provider. CRA uses abstract product categories and legal tests that each economic operator must perform on its own.

Two conclusions are drawn from this. First, you can't tell from regulations whether the specific equipment you own is covered. This depends on how the manufacturer is organized, where it is located, how it distributes, and how the competent authority applies the legal test in a specific case. Secondly, in the next few months, you will read articles that fill this gap with names. Anyone who writes that a particular provider is "now obligated" to do something is making a legal assessment that has neither administrative decisions nor court rulings.

The only reliable thing right now is the program. If such statements interest you, check two things. Is there a statement from the manufacturer's own or a statement from the authorities behind it? And does it refer to Article 14, which applies from September 11, or does it refer to compliance obligations that will only take effect on December 11, 2027? At present, the two are often confused.


The clock starts when the manufacturer knows it, not when security updates are released.

Free and open source software: Exceptions involved in many encryption projects

A large part of the encryption infrastructure is open source and maintained by individuals, associations, or foundations. For this combination, the CRA contains its own approach, which is critical to what you can expect.

According to Article 18 of the Preamble, free and open source software refers to software whose source code is publicly shared and whose license provisions give everyone free rights to access, use, modify and redistribute. The key to determining scope lies in the commercial nature of the supply: according to the same preamble, only free and open source software placed on the market, that is, supplied for distribution or for use in commercial activities, falls within the scope. Development status and funding type clearly do not play a role.

There is also article 64, paragraph 10 (b). Under the clause, the fines stipulated there do not apply to guardians of open source software, which applies to any violation of regulations. This is one of the clearest privileges in the entire legal act.

For you as a user, this means: You should not expect anyone to have a legal obligation to notify you of wallets generated as an open source project but not commercially available. The situation is different for devices or applications provided by the company commercially, even if the source code is open. The question of who stands behind the product and how it will be distributed used to be a good choice question. From September 11, 2026, this issue will have additional legal dimensions.


Penalty of up to 15 million euros: Cost of violating Article 14

Obligations without consequences are just a call. Article 64, paragraph 2, sets the framework: violations of obligations under Articles 13 and 14 are subject to fines of up to 15 million euros, or in the case of enterprises, fines of up to 2.5% of the global total annual turnover in the preceding financial year, whichever is higher. As a result, the reporting obligation is at the highest of the three penalty levels known to the regulation.

When determining the amount in an individual case, paragraph 5 requires consideration of the nature, severity and duration of the violation, as well as the previous fine imposed on the same economic operator and the size of the business, including its market share. Micro enterprises and small and medium-sized enterprises were specifically mentioned.

There are additional exemptions for them. Article 64, paragraph 10 (a), exempts manufacturers who qualify as micro or small enterprises from fines specified in paragraphs 3 to 9, insofar as they involve a missed 24-hour period under Article 14, paragraph 2 (a) or Article 14, paragraph 4 (a). The reporting obligation itself will not disappear; only sanctions that miss that specific deadline will disappear. For a start-up small wallet company with three developers and no on-call rotation, this is the difference between strict regulations and an existential crisis.

Enforcement is the responsibility of the market supervisory authorities of each member state. In Germany, BSI is designated for this purpose. Fines imposed by authorities must be notified to market supervisory authorities in other member states through the information system under market supervisory regulations.


Annexes III and IV: Why hardware wallets appear again in 2027

Article 14 applies to all manufacturers of products with digital elements, regardless of risk level. In addition, the regulation is aware of two annexes that list particularly sensitive products, the legal consequences of which will only take effect when full application begins on December 11, 2027. Still, viewing them is valuable because it shows how lawmakers view such devices.

Annex III lists three items under the heading "Critical Products with Digital Elements": hardware devices with security boxes; smart meter gateways and "other devices used for advanced security purposes, including secure password processing"; and smart cards or similar devices, including secure elements.

Annex IVMicroprocessors and microcontrollers with safety-related functions are listed in Category I, and tamper-resistant microcontrollers are listed in Category II.

These are the components that build a hardware wallet: a secure element, a tamper-resistant microcontroller, and a shielded environment for cryptographic operations. Whether a particular device falls into one of these entries is again determined on a case-by-case basis. While the direction is identifiable, for manufacturers of such devices, this means more rigorous compliance assessments starting at the end of 2027, which may involve notified bodies.


As a wallet user, you can now actually check what

regulations target manufacturers. You don't need to act on it. But there are four things that are more informative now than before.

1. Check if your provider has secure channels you can subscribe to.

Security pages, mailing lists, channels within the application. Manufacturers who want to meet Article 14, paragraph 8 need this kind of thing. Those without it will try to contact you via press releases at critical moments.

2. Check the location of the provider.

According to Article 14 (7), the principal place of establishment within the Union determines which CSIRT has jurisdiction. For providers without an EU established office, the backup order is run by the number of authorized representatives, importers, distributors and users.

3. Distinguish between commercial products and open source projects.

For open source projects that are not commercially available, reporting obligations usually do not apply and guardians of open source software are exempt from fines. This doesn't make this type of software worse, but it changes what you can rely on.

4. For warnings, pay attention to the source.

From now on, in addition to the manufacturer, there will be one possible sender, the Coordinating CSIRT. In Germany, that's BSI's CERT-Bund. The warning from there is not a marketing announcement.

You can find the official wording of the regulation in the Official Journal of the European Union, namely Regulation (EU) 2024/2847, in German; Article 14 is located in Chapter 2 and begins to apply in Article 71, paragraph 2. Germany's reporting route includes deadlines, which are described by BSI on its page on CRA's single reporting platform.


Check wallet reporting obligations: summary of key points

The notification obligation now lies with the manufacturer, not just with you.

When a provider learns of a vulnerability that has been actively exploited, it has an obligation to inform you of the vulnerability and what actions you can take on your own. Use this as a selection criterion: Providers with effective security channels are the better choice. Which devices are candidates, see our hardware wallet comparison for details.

Check the combination your wallet offers.

Whether commercial products, open source projects, providers have an EU establishment: this determines whether reporting obligations apply and who has jurisdiction at critical moments. For application-only solutions, it's worth looking at the software wallet comparison, where provider structures and update routes differ greatly.

If you do not own your own key, the problem turns to the custodian.

Your access then depends on the provider's supervision and its hosting practices. Which platforms can display licenses in the EU can be found in our overview of regulated crypto exchanges.

(As of September 13, 2026. This article does not constitute investment advice. Price and fee structures will change; please check terms with your provider before purchasing.)

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP