Why security.txt matters under the CRA
Annex I, Part II of the Cyber Resilience Act asks manufacturers to publish a contact address for vulnerability reports and to have a coordinated vulnerability disclosure policy. A security.txt file (RFC 9116) is the standard, machine-readable way to do the first part, and it points to the second.
It is also the first thing a researcher looks for. Without it, reports end up in your sales inbox, on social media or nowhere. With the 24-hour reporting clock that applies since 11 September 2026, you want to hear about problems as early as possible. More on that in CRA Article 14 reporting.
This guide explains the regulation in plain terms. It is not legal advice. For decisions about your obligations, speak to a qualified adviser.