Most EU Software Vendors Lack security.txt File as CRA Deadline Approaches
A recent study found that 76% of 623 EU software vendors do not have a security.txt file on their websites. This file is set to become a key requirement under the EU Cyber Resilience Act (CRA), which mandates a 24-hour vulnerability reporting rule. The security.txt standard provides a standardized way for researchers to report security vulnerabilities to organizations. The findings highlight a significant compliance gap among EU vendors as CRA obligations draw closer.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in