Research methodology

This is the standing method behind CVD Portal research. It is fixed before a study runs and applies to every study unless that study states otherwise.

Sampling frame

Manufacturers listed in the published member directories of European sector associations that publish member websites alongside member names. Every source association, including those rejected and the reason, is recorded in research/sources.csv in the CVD Portal repository.

What we probe

  • https://<domain>/.well-known/security.txt
  • https://<domain>/security.txt
  • Conventional coordinated disclosure policy paths, and the Policy: URL declared in security.txt where one is present

Three outcomes, not two

Results are reported as present, absent, or not determinable. A 403, a 429, a bot-protection challenge or a transport failure says nothing about whether a file exists, so those are never counted as absences. Reporting them as their own category is why the headline differs from a naive scan.

Why there is no country breakdown

Deliberately not published. Source associations are not evenly distributed across the EU, so a country cut off this frame would measure which national associations publish good directories rather than which countries comply.

Inclusion rules

  • Non-EU-headquartered members are excluded.
  • National subsidiary domains are folded into the corporate domain, so the unit of analysis is the manufacturer rather than the website. Where a directory links only a national or product-line site and the corporate domain is not evident from that link, the entry is dropped rather than guessed at.
  • Trade associations, universities and research institutes appearing in a member list are excluded, because they place no product on the market.
  • Where an association publishes its own member categories, those categories decide which members belong to a sector, rather than a judgement made after seeing the list.
  • Selection was fixed before the scan ran and was not adjusted after results were seen.

Ethics

Only paths designed for unauthenticated public retrieval were fetched. RFC 9116 exists so that security.txt is found this way. No authentication, no vulnerability probing, no port scanning. Requests were rate-limited and delayed. No individual domain, company name or per-company result is published in this artifact or anywhere else.

Limitations

  • A manufacturer may operate a disclosure route this scan cannot see, for example on a separate product-security host that is not linked from the probed paths.
  • Two of the sector cells are not scope claims. Article 2 displaces the CRA for finished medical devices, which are covered by Regulations (EU) 2017/745 and 2017/746, and for vehicles type-approved under Regulation (EU) 2019/2144. Components and software are treated separately. One is sheltered only where the same regime covers it, such as a component designed and constructed exclusively for integration into a type-approved vehicle, and an equivalent part sold through general channels or into another market is in scope on its own account. Both cells are measured because the unit of analysis is the manufacturer rather than the product, and because being reachable about a vulnerability matters under either regime. Neither cell should be read as a claim that the manufacturers in it are subject to Article 14.
  • Sector cells below 40 are carried in the total but not broken out.
  • Sector cells are drawn from the associations that publish usable directories, so several are concentrated in one or two member states. That is why no country breakdown is published.
  • Seven manufacturers appear in both the study frame and the comparison cohort. The two are separate samples and are never pooled.
  • Where a sector cell is defined by an association's own member category, that category is self-declared by the member. In the video surveillance cell a minority of the companies are primarily installers who also badge product. The category was not overridden after the results were seen, because the only available stricter cut also removes two of the three manufacturers in that cell that do publish a security.txt.
  • This is a dated snapshot, not a maintained series.

The same method drives the research property at cradata.eu, where every dataset is published under CC BY 4.0. Back to the research index.