Live data from Hacker News

76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule

cradrill.com

1–10 of 10 posts

Re: 76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule

#7
Recently I let claude write a script to export some data from a website. While testing the script I came across a bug that leaked the e-mail address of other users, potentially also more data related to the session. Upon discovery Claude did recommend to check for a security.txt, but none was available. Sent a mail to their support instead. A security.txt with further instructions and maybe a PGP key would have been nice…

Re: 76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule

#8
The guidance provided about CRA is difficult to follow and does not in any reasonable way cover proportional guidance for SMEs as it claims to do, but it seems websites/server side products are not subject to CRA as they are not considered digital products executing on consumer systems?

The only websites that should require it are the ones that provide downloadable software or software that is used on digital products. And it seems that European alternatives site lists primarily (pure) SaaS and only a few others?

Re: 76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule

#9
post #5

Those of you who publish a security.txt - how many reports do you get, and what's the typical quality level? If I push to add one to my employer's website, will our security team thank me for doing so?

0 since June or so

Re: 76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule

#10
We did something similar few days ago. https://cradata.eu/datasets#cra-exposure-study-2026 Almost identical results: Across all 342 manufacturers Publish a valid RFC 9116 security.txt 24 of 342 or 7% Publish any security.txt 34 of 342 or 9.9% Publish a discoverable CVD policy20 of 342 or 5.8% Publish neither, confirmed by observation 257 of 342 or 75.1%