76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule
What happened
We scanned 623 European software vendors in August 2026: 76% of reachable sites have no security.txt at /.well-known/. From 11 September, awareness of an exploited vulnerability starts a 24-hour legal reporting clock under the EU Cyber Resilience Act.
Summary assembled by rule from the sources below