Get the latest tech news

76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule


We scanned 623 European software vendors in August 2026: 76% of reachable sites have no security.txt at /.well-known/. From 11 September, awareness of an exploited vulnerability starts a 24-hour legal reporting clock under the EU Cyber Resilience Act.

None

Get the Android app

Or read this on Hacker News

Read more on:

Photo of security.txt

security.txt

Photo of CRA

CRA

Photo of EU software vendors

EU software vendors

Related news:

News photo

B.C. health-care workers' CRA accounts hacked after 28,000 social insurance numbers stolen in data breach | CBC News

News photo

Most IT companies fail to serve security.txt for RFC 9116 in 2025