Contents
Summary
- Question
- Does the manufacturer publish a security.txt file (RFC 9116)? It is the simplest public signal of where a researcher can report a vulnerability.
- Who we checked
- 1,691 device and software manufacturers in 30 European countries. We selected 1,752 companies and excluded 61 whose websites did not respond.
- Where they come from
- Public exhibitor lists of trade fairs and member lists of industry associations. Companies were not selected for anything security-related.
- When
- Measured on 30 September 2026. The Expires field was re-checked on 1 October 2026.
- How
- One or two HTTPS GET requests per domain:
/.well-known/security.txt, then/security.txt. If the domain did not respond, we also tried thewww.host. - Result
- 16.6% (280 of 1,691) publish a security.txt. 7.7% have a complete file, with a Policy field and a valid Expires date.
- Rule
- We publish aggregate results only. We do not name companies or publish any company's own result.
01What we measure and why
The Cyber Resilience Act (Regulation (EU) 2024/2847) requires a manufacturer to have, among other things, a coordinated vulnerability disclosure (CVD) policy and a contact address for reporting vulnerabilities (Annex I, Part II, points 5 and 6). The reporting obligations of Article 14 apply from 11 September 2026; the main obligations apply from 11 December 2027.
security.txt is not a CRA requirement. It is an IETF standard (RFC 9116): a text file at /.well-known/security.txt that states three things.
Contact: mailto:security@example.comrequiredwhere to report a vulnerabilityExpires: 2027-09-30T00:00:00Zrequireduntil when the file is currentPolicy: https://example.com/security-policyoptionalwhere the disclosure policy is
We measure this file because it can be checked from outside in the same way for every company.
What we do not measure: PSIRT or CVD pages that security.txt does not point to, e-mail addresses published elsewhere, bug bounty programmes and internal processes. A company without the file may therefore accept reports another way. A missing security.txt does not mean a missing process, or non-compliance with the CRA.
02Where the companies come from
The sample combines two lists, both built on 30 September 2026 from public sources. At no point during selection did we look at security.txt or any other security signal.
Expanded list (round 2)
- 9,139 unique companies from fair and association lists
- 6,654 profiles reviewed after a keyword pre-screen
- 2,195 companies judged eligible
- 2,053 after deduplication
- 1,500 after the cap, keeping the strongest profiles
- 252companies from the round 1 list, in 13 countries
- 1,752companies selected for measurement
- 61excluded: the website did not respond
- 1,691manufacturers measured
Round 1 list (252 companies, 13 countries)
- Sources
- The KNX Association manufacturer list. Exhibitor lists of SPS 2026, Light + Building 2026 and ISH, read through the public JSON endpoint of the Messe Frankfurt/Mesago exhibitor search; according to the round 2 notes, the ISH endpoint returned the 2025 list. The AMPER 2026 catalogue (Brno). SECUREX 2026 and ITM Industry Europe 2026 exhibitor lists (MTP Poznań). Member lists of KIGEiT, PISA, PIIT, PSME and the Interizon cluster.
- Frame
- Headquartered in PL, DE, AT, CH, LI, CZ, DK, SE, NO, FI, NL, BE or LU. The company makes its own hardware or software product with digital elements.
- Selection
- The Polish lists were small, so we screened every entry. For other countries we pooled and deduplicated the lists, put them in a seeded random order (Python
random, seed 20260930) and screened in that order until each country quota was filled. 13 companies on Polish lists with a foreign headquarters were counted under their headquarters country. - Eligibility
- Judged by one reviewer from the directory entry or the homepage.
Round 2 expanded list (1,500 companies, 30 countries)
- Sources
- Messe Frankfurt/Mesago exhibitor API: SPS 2026, Light + Building 2026, ISH (2025 list), Intersec 2026, PCIM Europe 2026.
- NürnbergMesse public company index: embedded world 2027, it-sa 2026, Chillventa 2026, Perimeter Protection 2027.
- Hannover Messe 2026, The smarter E Europe 2026 and security essen 2026.
- MTP Poznań catalogue: SECUREX 2026, Instalacje 2026, ITM 2026, INSECON 2026, NetZero Energy 2025, EnergyON 2026, EV Solutions 2025.
- The KNX manufacturer list for 13 more countries.
We collected company fields only, never contact persons.
- Frame
- Headquartered in the EU, Switzerland, Norway, the UK, Iceland or Liechtenstein.
- Process
- We started from 9,139 unique companies. After a keyword pre-screen we reviewed 6,654 profiles and judged 2,195 eligible. That left 2,053 after deduplication, including against the round 1 list.
- Eligibility
- Judged by a language model against one written rubric, in batches of 250, with manual spot checks. About 30 rows with no description were judged on the model's general knowledge.
- Cap at 1,500
- We dropped the rows with the weakest profile evidence of digital product features:
- the lowest category in Germany and in countries outside our priority list;
- part of the middle category in countries outside that list, starting with rows that had the fewest sources or no domain.
In the priority countries (Poland, Austria, Czechia, the Netherlands and the Nordics) we kept every row. This was not a random cut.
Common rules
- Included
- A company that makes, or sells under its own brand, hardware or installable software whose profile shows digital elements: firmware, controllers, fieldbus, network or wireless connectivity, an app or cloud service, or installable software.
- Excluded
- Distributors, installers, integrators and service firms; EMS and design houses; sales offices of groups headquartered outside the frame; associations, research bodies and media; makers of medical devices and automotive parts, and defence-only products; game studios and SaaS-only products; mechanical and passive products.
- One company per corporate group
- Local offices are counted under the parent company and its headquarters country.
- Domain
- Taken from the directory or the fair profile, or from the company homepage after checking it. We use one domain per company. Subsidiaries' country-code sites were not checked.
| Country | Companies | Share |
|---|---|---|
| Germany | 823 | 48.7% |
| Poland | 126 | 7.5% |
| Italy | 103 | 6.1% |
| Netherlands | 89 | 5.3% |
| Austria | 75 | 4.4% |
| Other 25 countries | 475 | 28.1% |
| Total | 1,691 | 100% |
03How we measure
- An HTTPS GET request to
https://<domain>/.well-known/security.txt. - If no file is found there, a request to
https://<domain>/security.txt(the legacy location). - If the domain fails at network level (DNS, TLS, connection), steps 1 and 2 are repeated for
www.<domain>.
Request settings
- Timeout: 12 seconds per request.
- We read the first 64 KiB of the response.
- TLS certificates are verified.
- HTTP redirects are followed.
- Requests carry
User-Agent: AnnexProof security.txt survey (contact@annexproof.com).
Indicator definitions
| Indicator | Definition | Base |
|---|---|---|
| Has security.txt | HTTP 200 and a line starting with Contact: | 1,691 companies |
| Policy field | The file has a Policy: line | 1,691 companies |
| Valid Expires | An RFC 3339 date-time (lowercase "t" and "z" accepted) later than the time of measurement | 1,691 companies |
| Complete file | Policy field and valid Expires | 1,691 companies |
| Expires problem | Past date, wrong format or missing field | 280 files |
| PGP signature | The file contains BEGIN PGP SIGNED MESSAGE | 1,691 companies |
| Mentions CRA | The file contains the word "CRA" or "Cyber Resilience" (whole word, outside the PGP signature block) | 1,691 companies |
We check whether fields are present, not their quality. We do not test whether the Contact address works, whether the Policy link leads to a policy, or whether a PGP signature is valid. We do not store the content of Contact fields.
04Exclusions and edge cases
- Excluded (61 domains)
- A connection, DNS or TLS failure (56) or a timeout (5). These are counted neither as having nor as lacking a file.
- Legacy location
- 15 files were found only at
/security.txt. We count them as present. RFC 9116 requires the/.well-known/location. - www. host
- 4 files were found only at
www.<domain>.
Sensitivity. 403, 429 and 5xx answers (62 domains) may mean bot blocking rather than a missing file. Without them the share is 17.2% (280 of 1,629). If all of them had a file, it would be 20.2%. The headline 16.6% is therefore closer to a lower bound.
05Results (as of 30 September 2026)
Main indicators
| Indicator | Count | Share |
|---|---|---|
| Has security.txt | 280 | 16.6% |
| Points to a CVD policy (Policy field) | 150 | 8.9% |
| Valid Expires field | 240 | 14.2% |
| Complete file (Policy and valid Expires) | 130 | 7.7% |
| PGP-signed file | 34 | 2.0% |
| File mentions the CRA | 10 | 0.6% |
The CRA-mention figure was corrected on 2 October 2026 (section 8). The first version of the script matched the string "cra" without word boundaries and flagged 14 files (0.8%). Re-reading those 14 files showed 4 false matches: 3 inside PGP signature blocks and 1 in a name containing "craft". The corrected script counts only the whole words "CRA" and "Cyber Resilience" outside the PGP signature block. The new rule can only reduce the number of matches, so the other files did not need to be re-read.
Expires field in the 280 files found
| Status | Files | Share |
|---|---|---|
| Valid | 240 | 85.7% |
| Expired (past date) | 14 | 5.0% |
| Wrong format (not RFC 3339) | 7 | 2.5% |
| Required field missing | 19 | 6.8% |
| Total with an Expires problem | 40 | 14.3% |
By country (countries with at least 20 companies)
The 95% intervals use the Wilson method as if the sample were random. It is not random, so read them as the minimum uncertainty, not the full uncertainty.
| Country | Share | 95% interval |
|---|---|---|
| Norway | 22.7%5 / 2295% interval: 10.1–43.4% | 10.1–43.4% |
| Denmark | 22.2%8 / 3695% interval: 11.7–38.1% | 11.7–38.1% |
| Austria | 21.3%16 / 7595% interval: 13.6–31.9% | 13.6–31.9% |
| Switzerland | 20.9%14 / 6795% interval: 12.9–32.1% | 12.9–32.1% |
| Germany | 19.9%164 / 82395% interval: 17.3–22.8% | 17.3–22.8% |
| Netherlands | 19.1%17 / 8995% interval: 12.3–28.5% | 12.3–28.5% |
| Czechia | 17.6%9 / 5195% interval: 9.6–30.3% | 9.6–30.3% |
| United Kingdom | 17.4%8 / 4695% interval: 9.1–30.7% | 9.1–30.7% |
| Sweden | 16.0%8 / 5095% interval: 8.3–28.5% | 8.3–28.5% |
| France | 14.6%7 / 4895% interval: 7.2–27.2% | 7.2–27.2% |
| Spain | 14.3%4 / 2895% interval: 5.7–31.5% | 5.7–31.5% |
| Finland | 9.1%3 / 3395% interval: 3.1–23.6% | 3.1–23.6% |
| Belgium | 6.5%2 / 3195% interval: 1.8–20.7% | 1.8–20.7% |
| Poland | 4.0%5 / 12695% interval: 1.7–9.0% | 1.7–9.0% |
| Italy | 3.9%4 / 10395% interval: 1.5–9.6% | 1.5–9.6% |
| Other 15 countries (fewer than 20 each) | 9.5%6 / 6395% interval: 4.4–19.3% | 4.4–19.3% |
How to read these results
- The gap between Poland or Italy and Germany is clear (Fisher's exact test, p < 0.001).
- The differences between Austria, Switzerland, Germany and the Netherlands are within measurement uncertainty. This is not a ranking.
- The intervals for small countries are wide.
Source check: the same international fair lists
Polish companies come partly from different sources than most others: a full screening of association lists and of the MTP Poznań fairs. So we compared only companies from the exhibitor lists of international fairs (SPS, Light + Building, ISH, Intersec, PCIM, embedded world, it-sa, Chillventa, Perimeter Protection, Hannover Messe, The smarter E, security essen):
| HQ country | security.txt | Share |
|---|---|---|
| Germany | 155 / 778 | 19.9% |
| Poland | 2 / 42 | 4.8% |
| Italy | 4 / 94 | 4.3% |
The gap between Poland and Germany holds within the same source (p = 0.014), but the Polish group is small. Polish companies from other sources score similarly: 2 of 59 on association lists and 1 of 28 on MTP Poznań fair lists.
By segment
| Segment | Share | 95% interval |
|---|---|---|
| Embedded boards & modules | 24.0%18 / 7595% interval: 15.8–34.8% | 15.8–34.8% |
| Industrial automation & OT | 23.3%67 / 28795% interval: 18.8–28.6% | 18.8–28.6% |
| Installable B2B software | 20.5%43 / 21095% interval: 15.6–26.4% | 15.6–26.4% |
| Networking & telecom equipment | 18.8%9 / 4895% interval: 10.2–31.9% | 10.2–31.9% |
| Security products | 18.3%60 / 32795% interval: 14.5–22.9% | 14.5–22.9% |
| IoT & smart home/building | 12.8%50 / 39295% interval: 9.8–16.4% | 9.8–16.4% |
| EV charging & energy devices | 10.0%25 / 24995% interval: 6.9–14.4% | 6.9–14.4% |
| Other connected devices (POS and fiscal devices, IT hardware, measurement) | 7.8%8 / 10395% interval: 4.0–14.6% | 4.0–14.6% |
Supporting cuts
- Without Germany: 13.4% (116 of 868).
- Companies headquartered in the EU: 16.3% (253 of 1,554). Switzerland, Norway, the UK and Liechtenstein together: 19.7% (27 of 137).
06Limitations
- The frame is neither complete nor random. Trade-fair exhibitors and association members tend to be larger, export-oriented and well organised. Micro-vendors and white-label makers are under-represented. Another review (CVD Portal, 2026) found that large manufacturers publish security.txt about three times as often as the rest, so our figure may be higher than for all manufacturers.
- Germany is 48.7% of the sample, because the largest fairs take place there. The overall result is close to the German one.
- Countries come from different sources. The Polish part comes mainly from a full screening of association lists and MTP fairs, other countries mainly from international fair lists. The source check in section 5 tests this in part.
- Eligibility depends on directory descriptions. In round 1 one reviewer decided, in round 2 a language model with spot checks. Some manufacturers may have been wrongly included or missed.
- One domain per company. A company may publish security.txt on another domain (for example a separate PSIRT host) or accept reports another way.
- A single measurement from one network location. Bot blocking and geo-restrictions can lower the result (section 4).
- We check that fields are present, not their quality (section 3).
- Exhibitor lists are a snapshot of one day. Registration for some fairs (for example SPS 2026 and embedded world 2027) was still open.
- Rounds are not a time series (section 8).
07Ethics
Only files meant for automated retrieval.
security.txt exists so that it can be found this way. No login, no vulnerability testing, no port scanning. One or two requests per domain (up to four with the
www.fallback), with a User-Agent that gives our address.No personal data.
From exhibitor lists we took company fields only. We do not store addresses from Contact fields.
No named results.
We do not publish company names, domains or any company's own result: not in the report, the data, on social media or in conversations with journalists. We do not publish any breakdown with fewer than 20 companies.
A result only for the company concerned.
A company can receive its own index result, for itself only. We send it to an e-mail address in that company's domain. We do not use index results in sales messages.
Live check.
The free CRA Snapshot runs a new check of public signals for the domain entered. It does not show the result stored in the index. The tool does not check who is asking: anyone can enter any domain.
What was public before the report.
Since 1 October 2026, CRA Snapshot has shown selected aggregate figures from this round under every result: 16.6% (security.txt), 7.7% (complete file), 14.3% (Expires problem), the results for Poland, Germany and Austria, and 7 segments.
Conflict of interest.
AnnexProof sells software for meeting CRA requirements. That is why we publish the full methodology and aggregate data, and present our results next to studies by other authors.
08Versions and corrections
| Version | Companies (after exclusions) | Countries | Notes |
|---|---|---|---|
| Round 1 | 239 (of 252) | 13 | List from section 2. Result: 17.6% (42 of 239). |
| Round 2 | 1,691 (of 1,752) | 30 | Round 1 plus the expanded list. Result: 16.6% (280 of 1,691). |
Round 2 is not a later measurement. Both rounds were measured on the same day. Round 2 is a larger sample with a different mix. Differences between rounds come from the sample mix, not from changes at manufacturers. For example, Germany was 32.4% of 68 companies in round 1 and 19.9% of 823 in round 2.
Corrections log
- 1 Oct 2026
The first version treated Expires dates with a lowercase "z" (allowed by RFC 3339) as invalid. After a re-check, 9 of the 30 files marked expired were valid, 7 had a wrong format and 14 had really expired. The figures on this page are already corrected.
- 2 Oct 2026
The "mentions CRA" indicator: 14 → 10 files (0.8% → 0.6%). The script also counted "cra" inside other words ("craft") and in PGP signature blocks. The corrected script looks for whole words outside the signature block (section 5). No other figure changed.
Future rounds. We re-measure the same company list every quarter, with the same method, so that change over time can be shown. Each round gets a new version of the dataset.
09How to cite
Full
AnnexProof (2026). AnnexProof CRA Readiness Index, round 2 (as of 30 September 2026) [Data set], version 2.0. https://annexproof.com/en/index/methodology. Licensed under CC BY 4.0.
Short (media)
Source: AnnexProof CRA Readiness Index, round 2 (review of 1,691 manufacturers in 30 countries, as of 30 September 2026).
When citing, please add: "a review, not a representative study".
10Contact and error reports
Errors in the data or methodology: contact@annexproof.com. Corrections are listed in the corrections log (section 8) and released as a new version of the dataset.
Sources (accessed 2 October 2026)
- RFC 9116, A File Format to Aid in Security Vulnerability Disclosure: rfc-editor.org/rfc/rfc9116
- European Commission, Cyber Resilience Act (application dates 11 Sep 2026 and 11 Dec 2027): digital-strategy.ec.europa.eu
- Regulation (EU) 2024/2847: eur-lex.europa.eu/eli/reg/2024/2847/oj. The wording of Annex I, Part II, points 5 and 6 was checked in an unofficial consolidated text, because EUR-Lex refused automated retrieval.
- CVD Portal, CRA Exposure Study 2026 (larger manufacturers publish security.txt more often): cvdportal.com/research/cra-exposure-2026
- AnnexProof internal files:
research/index-sample-method.md,research/accounts-expanded-method.md,research/securitytxt_scan.py,research/expires_recheck.py.