EU Cyber Resilience Act: Manufacturers Must Issue Early Warnings for Exploited Vulnerabilities
The European Union’s Cyber Resilience Act has introduced new regulations that impact software companies, particularly in terms of reporting exploited vulnerabilities. According to the Act, manufacturers of products with digital elements are required to issue an early warning within 24 hours of becoming aware that a vulnerability is actively being exploited.
This reporting window of 24 hours is a significant change that aims to improve cybersecurity standards across connected hardware and software products sold in the European market. The Act covers a wide range of products with digital elements, including commercial crypto wallets.
Crypto Wallets and the Cyber Resilience Act
Although the Cyber Resilience Act is not specifically focused on cryptocurrencies, commercial crypto wallets fall within the scope of products with digital elements. This means that wallet manufacturers must adhere to the same security obligations as other digital products, in addition to existing financial and data protection regulations.
The Act emphasizes the need for quick reporting of actively exploited vulnerabilities, shifting away from the traditional approach of waiting for a full technical investigation to be completed. This change in incident response requires engineering teams to have processes in place for escalating and addressing vulnerabilities promptly.
The Act also distinguishes between commercial products and non-commercial open-source software, ensuring that different types of software development are treated appropriately under the regulations.
Implications for Crypto Companies
For crypto companies, the Cyber Resilience Act signifies a shift towards regulating wallet security as part of overall software security. This integration of cybersecurity measures underscores the interconnected nature of smart-contract risk, custody risk, and cybersecurity within the crypto industry.
By treating these elements as interconnected parts of operational resilience, Europe is taking a proactive approach to enhancing cybersecurity measures within the digital economy.
For more information on the European Union Cyber Resilience Act, visit Eur-lex.
This article was written by the News Desk and edited by Samuel Rae.
