AnnexProof CRA Readiness Index · round 2

Methodology and data

How we checked whether 1,691 device and software manufacturers in 30 European countries publish a security.txt file (RFC 9116). As of 30 September 2026.

Measured
30 Sep 2026
Methodology
version 2.0
Published
3 Oct 2026
Data licence
CC BY 4.0

This is a review, not a representative study. A missing security.txt does not mean a manufacturer is not compliant with the CRA.

Manufacturers reviewed
1,69130 countries
Have security.txt
16.6%280 of 1,691
Complete file
7.7%130 of 1,691
Expires problems
14.3%40 of 280 files
Contents
  1. Summary
  2. 1. What we measure and why
  3. 2. Where the companies come from
  4. 3. How we measure
  5. 4. Exclusions and edge cases
  6. 5. Results (as of 30 September 2026)
  7. 6. Limitations
  8. 7. Ethics
  9. 8. Versions and corrections
  10. 9. How to cite
  11. 10. Contact and error reports
  12. Sources

Summary

Question
Does the manufacturer publish a security.txt file (RFC 9116)? It is the simplest public signal of where a researcher can report a vulnerability.
Who we checked
1,691 device and software manufacturers in 30 European countries. We selected 1,752 companies and excluded 61 whose websites did not respond.
Where they come from
Public exhibitor lists of trade fairs and member lists of industry associations. Companies were not selected for anything security-related.
When
Measured on 30 September 2026. The Expires field was re-checked on 1 October 2026.
How
One or two HTTPS GET requests per domain: /.well-known/security.txt, then /security.txt. If the domain did not respond, we also tried the www. host.
Result
16.6% (280 of 1,691) publish a security.txt. 7.7% have a complete file, with a Policy field and a valid Expires date.
Rule
We publish aggregate results only. We do not name companies or publish any company's own result.

01What we measure and why

The Cyber Resilience Act (Regulation (EU) 2024/2847) requires a manufacturer to have, among other things, a coordinated vulnerability disclosure (CVD) policy and a contact address for reporting vulnerabilities (Annex I, Part II, points 5 and 6). The reporting obligations of Article 14 apply from 11 September 2026; the main obligations apply from 11 December 2027.

security.txt is not a CRA requirement. It is an IETF standard (RFC 9116): a text file at /.well-known/security.txt that states three things.

example.com/.well-known/security.txtAn example file
  • Contact: mailto:security@example.comrequiredwhere to report a vulnerability
  • Expires: 2027-09-30T00:00:00Zrequireduntil when the file is current
  • Policy: https://example.com/security-policyoptionalwhere the disclosure policy is

We measure this file because it can be checked from outside in the same way for every company.

What we do not measure: PSIRT or CVD pages that security.txt does not point to, e-mail addresses published elsewhere, bug bounty programmes and internal processes. A company without the file may therefore accept reports another way. A missing security.txt does not mean a missing process, or non-compliance with the CRA.

02Where the companies come from

The sample combines two lists, both built on 30 September 2026 from public sources. At no point during selection did we look at security.txt or any other security signal.

How the sample was built

Expanded list (round 2)

  1. 9,139 unique companies from fair and association lists
  2. 6,654 profiles reviewed after a keyword pre-screen
  3. 2,195 companies judged eligible
  4. 2,053 after deduplication
  5. 1,500 after the cap, keeping the strongest profiles
  1. 252companies from the round 1 list, in 13 countries
  2. 1,752companies selected for measurement
  3. 61excluded: the website did not respond
  4. 1,691manufacturers measured

Round 1 list (252 companies, 13 countries)

Sources
The KNX Association manufacturer list. Exhibitor lists of SPS 2026, Light + Building 2026 and ISH, read through the public JSON endpoint of the Messe Frankfurt/Mesago exhibitor search; according to the round 2 notes, the ISH endpoint returned the 2025 list. The AMPER 2026 catalogue (Brno). SECUREX 2026 and ITM Industry Europe 2026 exhibitor lists (MTP Poznań). Member lists of KIGEiT, PISA, PIIT, PSME and the Interizon cluster.
Frame
Headquartered in PL, DE, AT, CH, LI, CZ, DK, SE, NO, FI, NL, BE or LU. The company makes its own hardware or software product with digital elements.
Selection
The Polish lists were small, so we screened every entry. For other countries we pooled and deduplicated the lists, put them in a seeded random order (Python random, seed 20260930) and screened in that order until each country quota was filled. 13 companies on Polish lists with a foreign headquarters were counted under their headquarters country.
Eligibility
Judged by one reviewer from the directory entry or the homepage.

Round 2 expanded list (1,500 companies, 30 countries)

Sources
  • Messe Frankfurt/Mesago exhibitor API: SPS 2026, Light + Building 2026, ISH (2025 list), Intersec 2026, PCIM Europe 2026.
  • NürnbergMesse public company index: embedded world 2027, it-sa 2026, Chillventa 2026, Perimeter Protection 2027.
  • Hannover Messe 2026, The smarter E Europe 2026 and security essen 2026.
  • MTP Poznań catalogue: SECUREX 2026, Instalacje 2026, ITM 2026, INSECON 2026, NetZero Energy 2025, EnergyON 2026, EV Solutions 2025.
  • The KNX manufacturer list for 13 more countries.

We collected company fields only, never contact persons.

Frame
Headquartered in the EU, Switzerland, Norway, the UK, Iceland or Liechtenstein.
Process
We started from 9,139 unique companies. After a keyword pre-screen we reviewed 6,654 profiles and judged 2,195 eligible. That left 2,053 after deduplication, including against the round 1 list.
Eligibility
Judged by a language model against one written rubric, in batches of 250, with manual spot checks. About 30 rows with no description were judged on the model's general knowledge.
Cap at 1,500
We dropped the rows with the weakest profile evidence of digital product features:
  • the lowest category in Germany and in countries outside our priority list;
  • part of the middle category in countries outside that list, starting with rows that had the fewest sources or no domain.

In the priority countries (Poland, Austria, Czechia, the Netherlands and the Nordics) we kept every row. This was not a random cut.

Common rules

Included
A company that makes, or sells under its own brand, hardware or installable software whose profile shows digital elements: firmware, controllers, fieldbus, network or wireless connectivity, an app or cloud service, or installable software.
Excluded
Distributors, installers, integrators and service firms; EMS and design houses; sales offices of groups headquartered outside the frame; associations, research bodies and media; makers of medical devices and automotive parts, and defence-only products; game studios and SaaS-only products; mechanical and passive products.
One company per corporate group
Local offices are counted under the parent company and its headquarters country.
Domain
Taken from the directory or the fair profile, or from the company homepage after checking it. We use one domain per company. Subsidiaries' country-code sites were not checked.
Sample composition (after exclusions)
CountryCompaniesShare
Germany82348.7%
Poland1267.5%
Italy1036.1%
Netherlands895.3%
Austria754.4%
Other 25 countries47528.1%
Total1,691100%

03How we measure

  1. An HTTPS GET request to https://<domain>/.well-known/security.txt.
  2. If no file is found there, a request to https://<domain>/security.txt (the legacy location).
  3. If the domain fails at network level (DNS, TLS, connection), steps 1 and 2 are repeated for www.<domain>.

Request settings

  • Timeout: 12 seconds per request.
  • We read the first 64 KiB of the response.
  • TLS certificates are verified.
  • HTTP redirects are followed.
  • Requests carry User-Agent: AnnexProof security.txt survey (contact@annexproof.com).

Indicator definitions

IndicatorDefinitionBase
Has security.txtHTTP 200 and a line starting with Contact:1,691 companies
Policy fieldThe file has a Policy: line1,691 companies
Valid ExpiresAn RFC 3339 date-time (lowercase "t" and "z" accepted) later than the time of measurement1,691 companies
Complete filePolicy field and valid Expires1,691 companies
Expires problemPast date, wrong format or missing field280 files
PGP signatureThe file contains BEGIN PGP SIGNED MESSAGE1,691 companies
Mentions CRAThe file contains the word "CRA" or "Cyber Resilience" (whole word, outside the PGP signature block)1,691 companies

We check whether fields are present, not their quality. We do not test whether the Contact address works, whether the Policy link leads to a policy, or whether a PGP signature is valid. We do not store the content of Contact fields.

04Exclusions and edge cases

What the request returned: 1,752 selected companies

Have security.txt (280)

File with a Contact field
280

Counted as no file (1,411)

404 (no file)
1,160
200 without a Contact field (e.g. an HTML page instead of a file)
162
403 (forbidden)
51
400 (bad request)
22
5xx (server error)
8
429 (too many requests)
3
410 (gone)
3
301 that could not be followed
2

Excluded from the measurement (61)

Connection, DNS or TLS failure
56
Timeout
5
Excluded (61 domains)
A connection, DNS or TLS failure (56) or a timeout (5). These are counted neither as having nor as lacking a file.
Legacy location
15 files were found only at /security.txt. We count them as present. RFC 9116 requires the /.well-known/ location.
www. host
4 files were found only at www.<domain>.

Sensitivity. 403, 429 and 5xx answers (62 domains) may mean bot blocking rather than a missing file. Without them the share is 17.2% (280 of 1,629). If all of them had a file, it would be 20.2%. The headline 16.6% is therefore closer to a lower bound.

Share of companies with security.txt in three variants
Headline result
16.6%280 / 1,691
Without 403, 429 and 5xx answers
17.2%280 / 1,629
If all 62 companies had a file
20.2%342 / 1,691

05Results (as of 30 September 2026)

Main indicators

IndicatorCountShare
Has security.txt28016.6%
Points to a CVD policy (Policy field)1508.9%
Valid Expires field24014.2%
Complete file (Policy and valid Expires)1307.7%
PGP-signed file342.0%
File mentions the CRA100.6%

The CRA-mention figure was corrected on 2 October 2026 (section 8). The first version of the script matched the string "cra" without word boundaries and flagged 14 files (0.8%). Re-reading those 14 files showed 4 false matches: 3 inside PGP signature blocks and 1 in a name containing "craft". The corrected script counts only the whole words "CRA" and "Cyber Resilience" outside the PGP signature block. The new rule can only reduce the number of matches, so the other files did not need to be re-read.

Expires field in the 280 files found

StatusFilesShare
Valid24085.7%
Expired (past date)145.0%
Wrong format (not RFC 3339)72.5%
Required field missing196.8%
Total with an Expires problem4014.3%

By country (countries with at least 20 companies)

The 95% intervals use the Wilson method as if the sample were random. It is not random, so read them as the minimum uncertainty, not the full uncertainty.

Share of companies with security.txt, with 95% interval
CountryShare95% interval
Norway22.7%5 / 2295% interval: 10.1–43.4%10.1–43.4%
Denmark22.2%8 / 3695% interval: 11.7–38.1%11.7–38.1%
Austria21.3%16 / 7595% interval: 13.6–31.9%13.6–31.9%
Switzerland20.9%14 / 6795% interval: 12.9–32.1%12.9–32.1%
Germany19.9%164 / 82395% interval: 17.3–22.8%17.3–22.8%
Netherlands19.1%17 / 8995% interval: 12.3–28.5%12.3–28.5%
Czechia17.6%9 / 5195% interval: 9.6–30.3%9.6–30.3%
United Kingdom17.4%8 / 4695% interval: 9.1–30.7%9.1–30.7%
Sweden16.0%8 / 5095% interval: 8.3–28.5%8.3–28.5%
France14.6%7 / 4895% interval: 7.2–27.2%7.2–27.2%
Spain14.3%4 / 2895% interval: 5.7–31.5%5.7–31.5%
Finland9.1%3 / 3395% interval: 3.1–23.6%3.1–23.6%
Belgium6.5%2 / 3195% interval: 1.8–20.7%1.8–20.7%
Poland4.0%5 / 12695% interval: 1.7–9.0%1.7–9.0%
Italy3.9%4 / 10395% interval: 1.5–9.6%1.5–9.6%
Other 15 countries (fewer than 20 each)9.5%6 / 6395% interval: 4.4–19.3%4.4–19.3%

How to read these results

  • The gap between Poland or Italy and Germany is clear (Fisher's exact test, p < 0.001).
  • The differences between Austria, Switzerland, Germany and the Netherlands are within measurement uncertainty. This is not a ranking.
  • The intervals for small countries are wide.

Source check: the same international fair lists

Polish companies come partly from different sources than most others: a full screening of association lists and of the MTP Poznań fairs. So we compared only companies from the exhibitor lists of international fairs (SPS, Light + Building, ISH, Intersec, PCIM, embedded world, it-sa, Chillventa, Perimeter Protection, Hannover Messe, The smarter E, security essen):

HQ countrysecurity.txtShare
Germany155 / 77819.9%
Poland2 / 424.8%
Italy4 / 944.3%

The gap between Poland and Germany holds within the same source (p = 0.014), but the Polish group is small. Polish companies from other sources score similarly: 2 of 59 on association lists and 1 of 28 on MTP Poznań fair lists.

By segment

Share of companies with security.txt, with 95% interval
SegmentShare95% interval
Embedded boards & modules24.0%18 / 7595% interval: 15.8–34.8%15.8–34.8%
Industrial automation & OT23.3%67 / 28795% interval: 18.8–28.6%18.8–28.6%
Installable B2B software20.5%43 / 21095% interval: 15.6–26.4%15.6–26.4%
Networking & telecom equipment18.8%9 / 4895% interval: 10.2–31.9%10.2–31.9%
Security products18.3%60 / 32795% interval: 14.5–22.9%14.5–22.9%
IoT & smart home/building12.8%50 / 39295% interval: 9.8–16.4%9.8–16.4%
EV charging & energy devices10.0%25 / 24995% interval: 6.9–14.4%6.9–14.4%
Other connected devices (POS and fiscal devices, IT hardware, measurement)7.8%8 / 10395% interval: 4.0–14.6%4.0–14.6%

Supporting cuts

  • Without Germany: 13.4% (116 of 868).
  • Companies headquartered in the EU: 16.3% (253 of 1,554). Switzerland, Norway, the UK and Liechtenstein together: 19.7% (27 of 137).

06Limitations

  1. The frame is neither complete nor random. Trade-fair exhibitors and association members tend to be larger, export-oriented and well organised. Micro-vendors and white-label makers are under-represented. Another review (CVD Portal, 2026) found that large manufacturers publish security.txt about three times as often as the rest, so our figure may be higher than for all manufacturers.
  2. Germany is 48.7% of the sample, because the largest fairs take place there. The overall result is close to the German one.
  3. Countries come from different sources. The Polish part comes mainly from a full screening of association lists and MTP fairs, other countries mainly from international fair lists. The source check in section 5 tests this in part.
  4. Eligibility depends on directory descriptions. In round 1 one reviewer decided, in round 2 a language model with spot checks. Some manufacturers may have been wrongly included or missed.
  5. One domain per company. A company may publish security.txt on another domain (for example a separate PSIRT host) or accept reports another way.
  6. A single measurement from one network location. Bot blocking and geo-restrictions can lower the result (section 4).
  7. We check that fields are present, not their quality (section 3).
  8. Exhibitor lists are a snapshot of one day. Registration for some fairs (for example SPS 2026 and embedded world 2027) was still open.
  9. Rounds are not a time series (section 8).

07Ethics

  • Only files meant for automated retrieval.

    security.txt exists so that it can be found this way. No login, no vulnerability testing, no port scanning. One or two requests per domain (up to four with the www. fallback), with a User-Agent that gives our address.

  • No personal data.

    From exhibitor lists we took company fields only. We do not store addresses from Contact fields.

  • No named results.

    We do not publish company names, domains or any company's own result: not in the report, the data, on social media or in conversations with journalists. We do not publish any breakdown with fewer than 20 companies.

  • A result only for the company concerned.

    A company can receive its own index result, for itself only. We send it to an e-mail address in that company's domain. We do not use index results in sales messages.

  • Live check.

    The free CRA Snapshot runs a new check of public signals for the domain entered. It does not show the result stored in the index. The tool does not check who is asking: anyone can enter any domain.

  • What was public before the report.

    Since 1 October 2026, CRA Snapshot has shown selected aggregate figures from this round under every result: 16.6% (security.txt), 7.7% (complete file), 14.3% (Expires problem), the results for Poland, Germany and Austria, and 7 segments.

  • Conflict of interest.

    AnnexProof sells software for meeting CRA requirements. That is why we publish the full methodology and aggregate data, and present our results next to studies by other authors.

08Versions and corrections

VersionMeasuredCompanies (after exclusions)CountriesNotes
Round 130 Sep 2026239 (of 252)13List from section 2. Result: 17.6% (42 of 239).
Round 230 Sep 20261,691 (of 1,752)30Round 1 plus the expanded list. Result: 16.6% (280 of 1,691).

Round 2 is not a later measurement. Both rounds were measured on the same day. Round 2 is a larger sample with a different mix. Differences between rounds come from the sample mix, not from changes at manufacturers. For example, Germany was 32.4% of 68 companies in round 1 and 19.9% of 823 in round 2.

Corrections log

  1. 1 Oct 2026

    The first version treated Expires dates with a lowercase "z" (allowed by RFC 3339) as invalid. After a re-check, 9 of the 30 files marked expired were valid, 7 had a wrong format and 14 had really expired. The figures on this page are already corrected.

  2. 2 Oct 2026

    The "mentions CRA" indicator: 14 → 10 files (0.8% → 0.6%). The script also counted "cra" inside other words ("craft") and in PGP signature blocks. The corrected script looks for whole words outside the signature block (section 5). No other figure changed.

Future rounds. We re-measure the same company list every quarter, with the same method, so that change over time can be shown. Each round gets a new version of the dataset.

09How to cite

Full

AnnexProof (2026). AnnexProof CRA Readiness Index, round 2 (as of 30 September 2026) [Data set], version 2.0. https://annexproof.com/en/index/methodology. Licensed under CC BY 4.0.

Short (media)

Source: AnnexProof CRA Readiness Index, round 2 (review of 1,691 manufacturers in 30 countries, as of 30 September 2026).

When citing, please add: "a review, not a representative study".

10Contact and error reports

Errors in the data or methodology: contact@annexproof.com. Corrections are listed in the corrections log (section 8) and released as a new version of the dataset.

Sources (accessed 2 October 2026)

  1. RFC 9116, A File Format to Aid in Security Vulnerability Disclosure: rfc-editor.org/rfc/rfc9116
  2. European Commission, Cyber Resilience Act (application dates 11 Sep 2026 and 11 Dec 2027): digital-strategy.ec.europa.eu
  3. Regulation (EU) 2024/2847: eur-lex.europa.eu/eli/reg/2024/2847/oj. The wording of Annex I, Part II, points 5 and 6 was checked in an unofficial consolidated text, because EUR-Lex refused automated retrieval.
  4. CVD Portal, CRA Exposure Study 2026 (larger manufacturers publish security.txt more often): cvdportal.com/research/cra-exposure-2026
  5. AnnexProof internal files: research/index-sample-method.md, research/accounts-expanded-method.md, research/securitytxt_scan.py, research/expires_recheck.py.