← Back to events
ActiveTech

76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule

What happened

We scanned 623 European software vendors in August 2026: 76% of reachable sites have no security.txt at /.well-known/. From 11 September, awareness of an exploited vulnerability starts a 24-hour legal reporting clock under the EU Cyber Resilience Act.

Summary assembled by rule from the sources below

Why it's spreading

Sources