Tech & AI News
Hacker News

76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule

Article 14 of the EU Cyber Resilience Act, effective 11 September 2026, requires manufacturers of digital-element products sold in the EU to disclose an actively exploited vulnerability within 24 hours, issue a fuller notice within 72 hours, and submit a final report later. A scan on 14 August 2026 of 623 European SaaS and software vendors found that 474 firms (76%) lack a compliant /.well-known/security.txt file with a Contact: line, despite RFC 9116. The measurement excluded 131 unreachable domains and used a single GET request allowing up to three redirects and an eight-second timeout.