76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule
1–10 of 10 posts
Re: 76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule
#2[flagged]
Re: 76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule
#3For those on Cloudflare, it's a toggle to enable this and provide the necessary values.
https://developers.cloudflare.com/security-center/infrastruc...
Re: 76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule
#4What is the difference?
Re: 76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule
#5Those of you who publish a security.txt - how many reports do you get, and what's the typical quality level?
If I push to add one to my employer's website, will our security team thank me for doing so?
Re: 76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule
#6What is the difference? https://securitytxt.org/
This one is selling an AI summary for $39, while yours is a free explanation.
Re: 76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule
#7Recently I let claude write a script to export some data from a website. While testing the script I came across a bug that leaked the e-mail address of other users, potentially also more data related to the session.
Upon discovery Claude did recommend to check for a security.txt, but none was available. Sent a mail to their support instead. A security.txt with further instructions and maybe a PGP key would have been nice…
Re: 76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule
#8The guidance provided about CRA is difficult to follow and does not in any reasonable way cover proportional guidance for SMEs as it claims to do, but it seems websites/server side products are not subject to CRA as they are not considered digital products executing on consumer systems?
The only websites that should require it are the ones that provide downloadable software or software that is used on digital products. And it seems that European alternatives site lists primarily (pure) SaaS and only a few others?
Re: 76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule
#9Those of you who publish a security.txt - how many reports do you get, and what's the typical quality level? If I push to add one to my employer's website, will our security team thank me for doing so?
0 since June or so
Re: 76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule
#10We did something similar few days ago. https://cradata.eu/datasets#cra-exposure-study-2026
Almost identical results:
Across all 342 manufacturers
Publish a valid RFC 9116 security.txt 24 of 342 or 7%
Publish any security.txt 34 of 342 or 9.9%
Publish a discoverable CVD policy20 of 342 or 5.8%
Publish neither, confirmed by observation 257 of 342 or 75.1%