← All CRA guides

CVD policy & security.txt: the forgotten obligation

The CRA requires a public channel for vulnerability reports. Done in an hour.

What does the CRA require?

Annex I Part II obliges manufacturers to run a coordinated vulnerability disclosure policy: security researchers must be able to report vulnerabilities, and the manufacturer must respond in an orderly way. Without a public reporting contact this obligation is not met.

What is security.txt?

A standardised text file (RFC 9116) at /.well-known/security.txt on your website. It states the reporting contact, the policy URL and an expiry date, the established way for researchers to find the right contact.

How to implement it

Set up a security mailbox (e.g. security@…), define response times (acknowledgement, first assessment), formulate a safe-harbour commitment, publish both. KONFORMA generates the policy and security.txt from your details: download, upload, obligation ticked.

Put it into practice, instead of just reading about it.

KONFORMA walks you from the software inventory through monitoring to the Declaration of Conformity, self-service, per release, starting free.