76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule

Image for article 76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule
News Source : Cradrill.com

News Summary

  • The EU Cyber Resilience Act's Article 14 starts a 24-hour reporting clock the moment a manufacturer becomes aware of an actively exploited vulnerability.
  • The most common way to become aware is a researcher trying to tell you — and three out of four European vendors don't publish the standard file that lets them.
  • A researcher who can't reach you privately goes public, to a CERT, or to your customers — and your 24- hour clock starts in the worst possible way.
  • Run the 7-minute readiness drill.
Results 623European software vendor domains scanned (source the europealternatives.

Must read Articles