76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule
Summary
CRA Incident Drill analyzes 623 EU software vendors and finds 76% do not publish a security.txt, highlighting a potential compliance gap as the EU Cyber Resilience Act imposes 24-hour vulnerability reporting obligations. The piece explains the methodology, results, and the regulatory importance, urging vendors to publish a security.txt for faster, private vulnerability reporting.