Original researchMeasured 2026-07-29CC BY 4.0

Fewer than one in ten EU manufacturers publish a working security contact

Article 14 of the EU Cyber Resilience Act applies on 11 September 2026. It assumes a manufacturer can be reached about a vulnerability. We scanned 342 EU manufacturers across eight sectors for the two things that make that possible, an RFC 9116 security.txt and a discoverable coordinated disclosure policy. 7% publish a security.txt that actually meets the RFC.

342
Manufacturers scanned
7%
Valid security.txt
5.8%
Discoverable CVD policy
75.1%
Neither, and observable

What was measured

A manufacturer that cannot receive a vulnerability report cannot act on one, and cannot make the Article 14 clock start on time. RFC 9116 defines /.well-known/security.txt as the machine-readable way to publish that contact. Article 13(2) and 13(8) expect a coordinated disclosure route to exist. Both are visible from outside without asking anyone.

Results are reported in three buckets, not two. A 403, a 429, a bot-protection challenge or a transport failure says nothing about whether a file exists, so those are never counted as absences. 13.2% of this frame could not be determined from outside. A naive scan counts every one of those as a manufacturer with nothing published, which moves the headline by that full 13.2 points.

Across all 342 manufacturers

Publish a valid RFC 9116 security.txt24 of 342
7%
Publish any security.txt34 of 342
9.9%
Publish a discoverable CVD policy20 of 342
5.8%
Publish neither, confirmed by observation257 of 342
75.1%
Could not be determined from outside45 of 342
13.2%

Of the 34 manufacturers that publish a security.txt at all, 29.4% publish one that fails RFC 9116, missing a Contact field or carrying an Expires date that has already passed. Publishing the file is not the same as publishing a working one.

By sector

Share publishing any security.txt, worst first. Smart metering is counted in the totals above but not broken out here, because at n=16 the cell is too small to report on its own.

Video surveillance3 of 44
6.8%
EV charging4 of 54
7.4%
Municipal and cleaning equipment3 of 40
7.5%
Automotive suppliers5 of 55
9.1%
Robotics and industrial automation4 of 44
9.1%
Lighting5 of 47
10.6%
Medical devices7 of 42
16.7%

Medical devices leads the sectors measured here, which is what you would expect from a sector already carrying cybersecurity expectations under the Medical Device Regulation. It still leaves most of that sector without a published contact.

Video surveillance sits at the bottom, and not one vendor in that cell publishes a discoverable disclosure policy. Robotics and industrial automation is at zero on the same measure. These are networked cameras and machines that share a factory floor with people, sold by manufacturers a researcher currently has no published way to contact.

This is a size effect, not an industry-wide shrug

112 large EU manufacturers across 15 countries and 30 sectors were scanned with the same tooling on the same day, as a deliberately biased control. Household names, the best-resourced manufacturers in Europe. They do more than three times better, and still most of them fail.

Large, well-known manufacturers35 of 112
31.3%
Association-membership frame, this study34 of 342
9.9%

Readiness is concentrated in the largest firms. The base the CRA actually reaches, the small and mid-sized manufacturers who make up most of the member lists these companies were drawn from, is far behind them.

Use this, with attribution

The full aggregate dataset, including every figure on this page, the per-sector breakdown and the machine-readable methodology, is published under CC BY 4.0. No individual company is named in it.

Cite as

CVD Portal, "CRA Exposure Study 2026: coordinated vulnerability disclosure readiness among EU manufacturers", 2026-07-29. https://cvdportal.com/research/cra-exposure-2026 (CC BY 4.0)

Methodology

Manufacturers listed in the published member directories of European sector associations that publish member websites alongside member names. Every source association, including those rejected and the reason, is recorded in research/sources.csv in the CVD Portal repository.

Paths fetched: https://<domain>/.well-known/security.txt, https://<domain>/security.txt, Conventional coordinated disclosure policy paths, and the Policy: URL declared in security.txt where one is present.

Results are reported as present, absent, or not determinable. A 403, a 429, a bot-protection challenge or a transport failure says nothing about whether a file exists, so those are never counted as absences. Reporting them as their own category is why the headline differs from a naive scan.

Inclusion rules:

  • Non-EU-headquartered members are excluded.
  • National subsidiary domains are folded into the corporate domain, so the unit of analysis is the manufacturer rather than the website. Where a directory links only a national or product-line site and the corporate domain is not evident from that link, the entry is dropped rather than guessed at.
  • Trade associations, universities and research institutes appearing in a member list are excluded, because they place no product on the market.
  • Where an association publishes its own member categories, those categories decide which members belong to a sector, rather than a judgement made after seeing the list.
  • Selection was fixed before the scan ran and was not adjusted after results were seen.

Deliberately not published. Source associations are not evenly distributed across the EU, so a country cut off this frame would measure which national associations publish good directories rather than which countries comply.

Limitations:

  • A manufacturer may operate a disclosure route this scan cannot see, for example on a separate product-security host that is not linked from the probed paths.
  • Sector cells below 40 are carried in the total but not broken out.
  • Sector cells are drawn from the associations that publish usable directories, so several are concentrated in one or two member states. That is why no country breakdown is published.
  • Seven manufacturers appear in both the study frame and the comparison cohort. The two are separate samples and are never pooled.
  • Where a sector cell is defined by an association's own member category, that category is self-declared by the member. In the video surveillance cell a minority of the companies are primarily installers who also badge product. The category was not overridden after the results were seen, because the only available stricter cut also removes two of the three manufacturers in that cell that do publish a security.txt.
  • This is a dated snapshot, not a maintained series.

Only paths designed for unauthenticated public retrieval were fetched. RFC 9116 exists so that security.txt is found this way. No authentication, no vulnerability probing, no port scanning. Requests were rate-limited and delayed. No individual domain, company name or per-company result is published in this artifact or anywhere else.

To question a figure or report an error, email [email protected].

Check your own domain

The same scanner that produced this study runs as a free check on any single domain. No signup. If you are missing either artifact, CVD Portal publishes both for you.

CRA deadline briefing

A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.

We use your email only to send the briefing. Unsubscribe any time with one click.