2026年8月14日的一项扫描结果显示,在623家欧洲软件供应商中,76%的企业未发布符合RFC 9116标准的security.txt文件 1。这一文件的缺失,将直接影响相关企业在欧盟《网络弹性法案》(CRA)第14条下的合规能力,使其难以满足在24小时内报告被积极利用漏洞的要求 1。
根据CRA第14条规定,所有在欧盟市场销售含数字元素产品的制造商,在知悉漏洞后必须在24小时内向ENISA及CSIRT提交预警,并在72小时内提交更完整的通知,并提交最终报告 1。该法案第69(3)条进一步明确,上述报告义务适用于2027年12月11日之前投放市场的所有产品 1。此次扫描的样本数据来源于europealternatives.com,研究人员通过单次GET请求访问目标域名的“/.well-known/security.txt”路径进行核查,并在计算比例时排除了131个无法访问的域名 1。
A scan conducted on August 14, 2026, and highlighted by Hacker News and cradrill.com, revealed that 76% of 623 European software vendors have not published a security.txt file compliant with RFC 9116 1. The assessment, which sourced its vendor population from europealternatives.com, was carried out via a single GET request to the /.well-known/security.txt path for each domain 1. During the evaluation, 131 unreachable domains were excluded from the final percentages 1. This absence of a standardized vulnerability reporting channel could affect these vendors' compliance capabilities under Article 14 of the European Union's Cyber Resilience Act (CRA) for reporting actively exploited vulnerabilities within 24 hours 1.
Under Article 14 of the CRA, manufacturers of products with digital elements sold in the EU must initiate a 24-hour reporting clock upon becoming aware of an actively exploited vulnerability 1. They are required to submit an early warning to the European Union Agency for Cybersecurity (ENISA) and the Computer Security Incident Response Team (CSIRT) within this 24-hour window 1. A fuller notification must follow within 72 hours, followed by a final report 1. Furthermore, Article 69(3) of the legislation mandates that these Article 14 obligations apply to all products placed on the market before December 11, 2027 1.
评论
还没有评论,欢迎留下第一条。