Add a security.txt File Now to Meet EU Cyber Resilience Act Requirements
RFC 9116 defines a simple plain text file placed at /.well-known/security.txt that gives security researchers a clear, standardised way to report vulnerabilities in a product. The file requires just three core fields — Contact, Expires, and Canonical — and can be deployed in under ten minutes with no build tools or dependencies. The EU Cyber Resilience Act, which takes full effect on 11 December 2027, mandates a coordinated vulnerability disclosure policy and a public contact address under Annex I, Part II; a valid security.txt Contact field directly satisfies the latter requirement. Fines under Article 64 of the Act also kick in from that same December 2027 deadline, making early preparation advisable since drafting a thorough disclosure policy takes considerably longer than creating the file itself. Security professionals note that without such a file, researchers who discover bugs may resort to public disclosure or simply abandon the report altogether.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in