76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule
News Source : Cradrill.com
News Summary
- The EU Cyber Resilience Act's Article 14 starts a 24-hour reporting clock the moment a manufacturer becomes aware of an actively exploited vulnerability.
- The most common way to become aware is a researcher trying to tell you — and three out of four European vendors don't publish the standard file that lets them.
- A researcher who can't reach you privately goes public, to a CERT, or to your customers — and your 24- hour clock starts in the worst possible way.
- Run the 7-minute readiness drill.
Results 623European software vendor domains scanned (source the europealternatives.
Never miss a story from us, subscribe to our newsletter