PatchClock

Free tool

security.txt generator

Create an RFC 9116 security.txt file in a minute, so researchers know how to report a vulnerability in your product. Runs in your browser, nothing is sent to us.

Use mailto:, https:// or tel:. List the preferred one first.

RFC 9116 recommends less than a year ahead. Set a reminder to renew it.

Your vulnerability disclosure policy. The CRA expects you to have one.

The URL where this file will live. Recommended if you sign it.

Your security.txt


                

    Where to put it: serve it at /.well-known/security.txt on your product's domain, over HTTPS, as text/plain. Optionally also at /security.txt.

    Signing: you can sign it with PGP (gpg --clearsign security.txt) so readers can check it came from you.

    Why security.txt matters under the CRA

    Annex I, Part II of the Cyber Resilience Act asks manufacturers to publish a contact address for vulnerability reports and to have a coordinated vulnerability disclosure policy. A security.txt file (RFC 9116) is the standard, machine-readable way to do the first part, and it points to the second.

    It is also the first thing a researcher looks for. Without it, reports end up in your sales inbox, on social media or nowhere. With the 24-hour reporting clock that applies since 11 September 2026, you want to hear about problems as early as possible. More on that in CRA Article 14 reporting.

    This guide explains the regulation in plain terms. It is not legal advice. For decisions about your obligations, speak to a qualified adviser.