Study finds 76% of EU software vendors lack security.txt before CRA deadline
A scan of 623 European software vendor domains found that only 118 (24%) published a valid security.txt file with a working contact address, while 374 (76%) had none, according to a survey using RFC 9116 criteria. The check comes weeks before the EU Cyber Resilience Act's Article 14 takes effect, imposing a 24-hour reporting window once a vendor learns of an actively exploited vulnerability.